{"resultsPerPage":72,"startIndex":0,"totalResults":72,"format":"NVD_CVE","version":"2.0","timestamp":"2026-08-05T14:29:10.249","vulnerabilities":[{"cve":{"id":"CVE-2026-24457","sourceIdentifier":"emo@eclipse.org","published":"2026-03-05T19:16:02.780","lastModified":"2026-08-05T08:16:32.897","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An unsafe parsing of OpenMQ's configuration in OpenMQ versions <6.5.2 and <6.9.0, allows a remote attacker to read arbitrary files from a MQ Broker's server. A full exploitation could read unauthorized files of the OpenMQ’s host OS. In some scenarios RCE could be achieved. This is fixed in OpenMQ 6.5.2, 6.9.0, and in GlassFish 7.0.26, 7.1.1, and 8.0.2."},{"lang":"es","value":"Un análisis inseguro de la configuración de OpenMQ permite a un atacante remoto leer archivos arbitrarios de un servidor de MQ Broker. Una explotación completa podría leer archivos no autorizados del sistema operativo anfitrión de OpenMQ. En algunos escenarios se podría lograr RCE."}],"affected":[{"source":"emo@eclipse.org","affectedData":[{"vendor":"Eclipse Foundation","product":"Eclipse OpenMQ","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"6.5.2","versionType":"semver","status":"affected"},{"version":"6.6.0","lessThan":"6.9.0","versionType":"semver","status":"affected"}]},{"vendor":"Eclipse Foundation","product":"Eclipse GlassFish","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"7.0.26","versionType":"semver","status":"affected"},{"version":"7.1.0","lessThan":"7.1.1","versionType":"semver","status":"affected"},{"version":"8.0.0","lessThan":"8.0.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"emo@eclipse.org","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","baseScore":9.1,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.2},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-03-06T16:00:31.715526Z","id":"CVE-2026-24457","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"emo@eclipse.org","type":"Secondary","description":[{"lang":"en","value":"CWE-22"},{"lang":"en","value":"CWE-27"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-22"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:eclipse:openmq:*:*:*:*:*:*:*:*","versionEndIncluding":"6.5.1","matchCriteriaId":"D0C54C08-8788-4481-97CC-EAFFC7702412"}]}]}],"references":[{"url":"https://gitlab.eclipse.org/security/cve-assignment/-/issues/84","source":"emo@eclipse.org","tags":["Vendor Advisory"]}]}},{"cve":{"id":"CVE-2026-53703","sourceIdentifier":"secalert@redhat.com","published":"2026-06-15T20:16:33.563","lastModified":"2026-08-05T09:18:14.820","vulnStatus":"Awaiting Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability was found in the GStreamer RealMedia demuxer (gst-plugins-ugly). When processing a RealMedia (.rm) file, the demuxer parses MDPR (media properties) chunks to configure audio streams. For audio stream header versions 4 and 5, the parser reads fields such as codec type, packet size, sample rate, channel count, and extra codec data length from fixed offsets within the chunk without first checking that the chunk contains enough data. If a malicious file provides an MDPR chunk that is too small to contain a complete audio stream header, the parser reads beyond the end of the buffer. This can cause the application to crash. In some cases, bytes read past the buffer boundary may be incorporated into stream metadata, which could result in limited information disclosure."}],"affected":[{"source":"secalert@redhat.com","affectedData":[{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"gstreamer1-plugins-ugly-free","cpes":["cpe:/o:redhat:enterprise_linux:10.2"],"versions":[{"version":"0:1.26.7-2.el10_2.1","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10.0 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"gstreamer1-plugins-ugly-free","cpes":["cpe:/o:redhat:enterprise_linux_eus:10.0"],"versions":[{"version":"0:1.24.11-1.el10_0.2","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"gstreamer1-plugins-ugly-free","cpes":["cpe:/a:redhat:enterprise_linux:9::appstream"],"versions":[{"version":"0:1.22.12-6.el9_8.1","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9.6 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"gstreamer1-plugins-ugly-free","cpes":["cpe:/a:redhat:rhel_eus:9.6::appstream"],"versions":[{"version":"0:1.22.12-4.el9_6.1","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 7","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"gstreamer1-plugins-ugly-free","cpes":["cpe:/o:redhat:enterprise_linux:7"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"gstreamer1-plugins-ugly-free","cpes":["cpe:/o:redhat:enterprise_linux:8"]}]}],"metrics":{"cvssMetricV31":[{"source":"secalert@redhat.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":4.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-06-16T15:05:30.391525Z","id":"CVE-2026-53703","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"secalert@redhat.com","type":"Secondary","description":[{"lang":"en","value":"CWE-125"}]}],"references":[{"url":"https://access.redhat.com/errata/RHSA-2026:36673","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:36674","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:50688","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:50691","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2026-53703","source":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2487613","source":"secalert@redhat.com"}]}},{"cve":{"id":"CVE-2026-53704","sourceIdentifier":"secalert@redhat.com","published":"2026-06-15T20:16:33.697","lastModified":"2026-08-05T09:18:15.290","vulnStatus":"Awaiting Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"A flaw was found in GStreamer's RealMedia demuxer in the gst-plugins-ugly package. When processing a RealMedia file containing a specially crafted FILEINFO metadata section, the demuxer parses variable-name and variable-value pairs using re_skip_pascal_string() without validating that offsets remain within the mapped buffer. Additionally, the element count controlling the parsing loop is read from attacker-controlled data without validation, which can cause an infinite loop. A crafted RealMedia file can cause the application to crash, hang, or potentially read limited adjacent memory contents."}],"affected":[{"source":"secalert@redhat.com","affectedData":[{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10.0 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"gstreamer1-plugins-ugly-free","cpes":["cpe:/o:redhat:enterprise_linux_eus:10.0"],"versions":[{"version":"0:1.24.11-1.el10_0.2","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"gstreamer1-plugins-ugly-free","cpes":["cpe:/a:redhat:enterprise_linux:9::appstream"],"versions":[{"version":"0:1.22.12-6.el9_8.1","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9.6 Extended Update Support","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"gstreamer1-plugins-ugly-free","cpes":["cpe:/a:redhat:rhel_eus:9.6::appstream"],"versions":[{"version":"0:1.22.12-4.el9_6.1","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"gstreamer1-plugins-ugly-free","cpes":["cpe:/o:redhat:enterprise_linux:10"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 7","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"gstreamer1-plugins-ugly-free","cpes":["cpe:/o:redhat:enterprise_linux:7"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"gstreamer1-plugins-ugly-free","cpes":["cpe:/o:redhat:enterprise_linux:8"]}]}],"metrics":{"cvssMetricV31":[{"source":"secalert@redhat.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":4.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-06-16T12:46:47.069346Z","id":"CVE-2026-53704","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"secalert@redhat.com","type":"Secondary","description":[{"lang":"en","value":"CWE-125"}]}],"references":[{"url":"https://access.redhat.com/errata/RHSA-2026:36674","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:50688","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:50691","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2026-53704","source":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2487614","source":"secalert@redhat.com"}]}},{"cve":{"id":"CVE-2026-16242","sourceIdentifier":"secalert@redhat.com","published":"2026-07-20T08:16:29.833","lastModified":"2026-08-05T08:16:30.670","vulnStatus":"Awaiting Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authentication), so client certificates were not validated. A remote attacker who can reach the Konnectivity cluster endpoint could connect as an unauthenticated agent, join the routing pool, and potentially proxy, inspect, modify, or drop control-plane-to-node traffic."}],"affected":[{"source":"secalert@redhat.com","affectedData":[{"vendor":"Red Hat","product":"multicluster engine for Kubernetes 2.1","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"multicluster-engine/hypershift-rhel9-operator","cpes":["cpe:/a:redhat:multicluster_engine:2.10::el9"],"versions":[{"version":"1784905766","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"multicluster engine for Kubernetes 2.1","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"multicluster-engine/hypershift-rhel9-operator","cpes":["cpe:/a:redhat:multicluster_engine:2.10::el9"],"versions":[{"version":"1784905766","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"multicluster engine for Kubernetes 2.11.0","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"multicluster-engine/hypershift-rhel9-operator","cpes":["cpe:/a:redhat:multicluster_engine:2.11::el9"],"versions":[{"version":"1784945966","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"multicluster engine for Kubernetes 2.17","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"multicluster-engine/hypershift-rhel9-operator","cpes":["cpe:/a:redhat:multicluster_engine:2.17::el9"],"versions":[{"version":"1784856942","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"multicluster engine for Kubernetes 2.6","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"multicluster-engine/hypershift-rhel9-operator","cpes":["cpe:/a:redhat:multicluster_engine:2.6::el9"],"versions":[{"version":"1784905804","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"multicluster engine for Kubernetes 2.8","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"multicluster-engine/hypershift-rhel9-operator","cpes":["cpe:/a:redhat:multicluster_engine:2.8::el9"],"versions":[{"version":"1784905783","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"multicluster engine for Kubernetes 2.9","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"multicluster-engine/hypershift-rhel9-operator","cpes":["cpe:/a:redhat:multicluster_engine:2.9::el9"],"versions":[{"version":"1784905769","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.19","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-hypershift-rhel9","cpes":["cpe:/a:redhat:openshift:4.19::el9"],"versions":[{"version":"1784913720","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.20","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-hypershift-rhel9","cpes":["cpe:/a:redhat:openshift:4.20::el9"],"versions":[{"version":"1785288843","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.21","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-hypershift-rhel9","cpes":["cpe:/a:redhat:openshift:4.21::el9"],"versions":[{"version":"1785301941","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4.22","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift4/ose-hypershift-rhel9","cpes":["cpe:/a:redhat:openshift:4.22::el9"],"versions":[{"version":"1785192936","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Logging Subsystem for Red Hat OpenShift","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift-logging/cluster-logging-rhel9-operator","cpes":["cpe:/a:redhat:logging:6"]},{"vendor":"Red Hat","product":"Multicluster Engine for Kubernetes","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"multicluster-engine/cluster-curator-controller-rhel9","cpes":["cpe:/a:redhat:multicluster_engine"]},{"vendor":"Red Hat","product":"Multicluster Engine for Kubernetes","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"multicluster-engine/hypershift-addon-rhel9-operator","cpes":["cpe:/a:redhat:multicluster_engine"]},{"vendor":"Red Hat","product":"Multicluster Engine for Kubernetes","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"multicluster-engine/hypershift-cli-rhel9","cpes":["cpe:/a:redhat:multicluster_engine"]},{"vendor":"Red Hat","product":"Multicluster Engine for Kubernetes","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"multicluster-engine/managedcluster-import-controller-rhel9","cpes":["cpe:/a:redhat:multicluster_engine"]},{"vendor":"Red Hat","product":"OpenShift API for Data Protection","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"oadp/oadp-hypershift-velero-plugin-rhel9","cpes":["cpe:/a:redhat:openshift_api_data_protection:1"]},{"vendor":"Red Hat","product":"OpenShift API for Data Protection","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"oadp/oadp-rhel9-operator","cpes":["cpe:/a:redhat:openshift_api_data_protection:1"]},{"vendor":"Red Hat","product":"Red Hat Advanced Cluster Management for Kubernetes 2","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhacm2/acm-multicluster-observability-addon-rhel9","cpes":["cpe:/a:redhat:acm:2"]},{"vendor":"Red Hat","product":"Red Hat Advanced Cluster Management for Kubernetes 2","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhacm2/acm-must-gather-rhel9","cpes":["cpe:/a:redhat:acm:2"]},{"vendor":"Red Hat","product":"Red Hat Advanced Cluster Management for Kubernetes 2","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhacm2/endpoint-monitoring-rhel9-operator","cpes":["cpe:/a:redhat:acm:2"]},{"vendor":"Red Hat","product":"Red Hat Advanced Cluster Management for Kubernetes 2","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhacm2/grafana-dashboard-loader-rhel9","cpes":["cpe:/a:redhat:acm:2"]},{"vendor":"Red Hat","product":"Red Hat Advanced Cluster Management for Kubernetes 2","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhacm2/metrics-collector-rhel9","cpes":["cpe:/a:redhat:acm:2"]},{"vendor":"Red Hat","product":"Red Hat Advanced Cluster Management for Kubernetes 2","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhacm2/multicluster-observability-rhel9-operator","cpes":["cpe:/a:redhat:acm:2"]},{"vendor":"Red Hat","product":"Red Hat Advanced Cluster Management for Kubernetes 2","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhacm2/rbac-query-proxy-rhel9","cpes":["cpe:/a:redhat:acm:2"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift4/ose-aws-ebs-csi-driver-rhel9-operator","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift4/ose-aws-efs-csi-driver-rhel9-operator","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift4/ose-azure-disk-csi-driver-rhel9-operator","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift4/ose-azure-file-csi-driver-operator-rhel9","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift4/ose-cluster-csi-snapshot-controller-rhel9-operator","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift4/ose-cluster-network-operator","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift4/ose-cluster-network-rhel9-operator","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift4/ose-cluster-node-tuning-rhel9-operator","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift4/ose-cluster-storage-rhel9-operator","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift4/ose-csi-driver-manila-rhel9-operator","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift4/ose-hypershift-rhel8","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift4/ose-openstack-cinder-csi-driver-rhel9-operator","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift4/ose-powervs-block-csi-driver-rhel9-operator","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift4/ose-smb-csi-driver-rhel9-operator","cpes":["cpe:/a:redhat:openshift:4"]}]}],"metrics":{"cvssMetricV31":[{"source":"secalert@redhat.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L","baseScore":9.4,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":5.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-21T14:56:23.371685Z","id":"CVE-2026-16242","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"secalert@redhat.com","type":"Secondary","description":[{"lang":"en","value":"CWE-306"}]}],"references":[{"url":"https://access.redhat.com/errata/RHSA-2026:46885","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:47388","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:47735","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:47949","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:47953","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:47974","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:48284","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:48657","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:48670","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:48676","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:48693","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2026-16242","source":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2502690","source":"secalert@redhat.com"},{"url":"https://github.com/openshift/hypershift/pull/9031","source":"secalert@redhat.com"}]}},{"cve":{"id":"CVE-2026-65512","sourceIdentifier":"audit@patchstack.com","published":"2026-07-23T12:18:44.253","lastModified":"2026-08-05T09:18:15.727","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"Cross-Site request forgery (CSRF) vulnerability in Melapress WP Activity Log and Melapress WP Activity Log Premium allows Cross Site Request Forgery.\n\nThis issue affects WP Activity Log: through 5.6.4; WP Activity Log Premium: through 5.6.4."}],"affected":[{"source":"audit@patchstack.com","affectedData":[{"vendor":"Melapress","product":"WP Activity Log","defaultStatus":"unaffected","collectionURL":"https://wordpress.org/plugins","packageName":"wp-security-audit-log","versions":[{"version":"0","lessThanOrEqual":"5.6.4","versionType":"custom","status":"affected","changes":[{"at":"5.6.5","status":"unaffected"}]}]},{"vendor":"Melapress","product":"WP Activity Log Premium","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"5.6.4","versionType":"custom","status":"affected","changes":[{"at":"5.6.5","status":"unaffected"}]}]}]}],"metrics":{"cvssMetricV31":[{"source":"audit@patchstack.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":2.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-23T13:40:38.178600Z","id":"CVE-2026-65512","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"audit@patchstack.com","type":"Secondary","description":[{"lang":"en","value":"CWE-352"}]}],"references":[{"url":"https://patchstack.com/database/WordPress/Plugin/wp-security-audit-log-premium/vulnerability/wordpress-wp-activity-log-premium-plugin-5-6-4-cross-site-request-forgery-csrf-vulnerability","source":"audit@patchstack.com"},{"url":"https://patchstack.com/database/wordpress/plugin/wp-security-audit-log/vulnerability/wordpress-wp-activity-log-plugin-5-6-4-cross-site-request-forgery-csrf-vulnerability?_s_id=cve","source":"audit@patchstack.com"}]}},{"cve":{"id":"CVE-2026-64534","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-27T08:16:22.643","lastModified":"2026-08-05T08:16:35.860","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path\n\nIn nvmet_tcp_try_recv_ddgst(), when a data digest mismatch is detected,\nnvmet_req_uninit() is called unconditionally. However, if the command\narrived via the nvmet_tcp_handle_req_failure() path, nvmet_req_init()\nhad returned false and percpu_ref_tryget_live() was never executed. The\nunconditional percpu_ref_put() inside nvmet_req_uninit() then causes a\nrefcount underflow, leading to a WARNING in\npercpu_ref_switch_to_atomic_rcu, a use-after-free diagnostic, and\neventually a permanent workqueue deadlock.\n\nCheck cmd->flags & NVMET_TCP_F_INIT_FAILED before calling\nnvmet_req_uninit(), matching the existing pattern in\nnvmet_tcp_execute_request()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/nvme/target/tcp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"91edfca6f8b364d60cde3ddefaf7d03ddf35774b","lessThan":"22ec7a9fe9153d2737ee9b2fa6d2e43a1491decf","versionType":"git","status":"affected"},{"version":"fda871c0ba5d2eed2cd1c881573168129da70058","lessThan":"ba35b1c674ca3841c0dfadd698f2c1b3ec542d4e","versionType":"git","status":"affected"},{"version":"fda871c0ba5d2eed2cd1c881573168129da70058","lessThan":"c7874dad84b20433c0fe3919f291a762d40de08b","versionType":"git","status":"affected"},{"version":"fda871c0ba5d2eed2cd1c881573168129da70058","lessThan":"e602c93b25bda4a9d0ff1791a4bdbfdcbb074af1","versionType":"git","status":"affected"},{"version":"fda871c0ba5d2eed2cd1c881573168129da70058","lessThan":"d306da8833e75f669d93424fd84940236f3850bc","versionType":"git","status":"affected"},{"version":"fda871c0ba5d2eed2cd1c881573168129da70058","lessThan":"2ed3c9d955e8cd6361f130623baa664a75fb345f","versionType":"git","status":"affected"},{"version":"fda871c0ba5d2eed2cd1c881573168129da70058","lessThan":"4606467a75cfc16721937272ed29462a750b60c8","versionType":"git","status":"affected"},{"version":"4b17476d809273617d3317fa0d4ae78aa488d760","versionType":"git","status":"affected"},{"version":"5.10.20","lessThan":"5.10.261","versionType":"semver","status":"affected"},{"version":"5.11.3","lessThan":"5.12","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/nvme/target/tcp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.12","status":"affected"},{"version":"0","lessThan":"5.12","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/22ec7a9fe9153d2737ee9b2fa6d2e43a1491decf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2ed3c9d955e8cd6361f130623baa664a75fb345f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4606467a75cfc16721937272ed29462a750b60c8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ba35b1c674ca3841c0dfadd698f2c1b3ec542d4e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c7874dad84b20433c0fe3919f291a762d40de08b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d306da8833e75f669d93424fd84940236f3850bc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e602c93b25bda4a9d0ff1791a4bdbfdcbb074af1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64535","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-07-27T08:16:22.773","lastModified":"2026-08-05T08:16:36.013","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet-tcp: Fix potential UAF when ddgst mismatch\n\nShivam Kumar found via vulnerability testing:\nWhen data digest is enabled on an NVMe/TCP connection and a digest\nmismatch occurs on a non-final H2C_DATA PDU during an R2T-based\ndata transfer, the digest error handler in nvmet_tcp_try_recv_ddgst()\ncalls nvmet_req_uninit() — which performs percpu_ref_put() on the\nsubmission queue — but does NOT mark the command as completed. It\ndoes not set cqe->status, does not modify rbytes_done, and does not\nclear any flag. When the subsequent fatal error triggers queue\nteardown, nvmet_tcp_uninit_data_in_cmds() iterates all commands,\nchecks nvmet_tcp_need_data_in() for each one, and finds that the\nalready-uninited command still appears to need data (because\nrbytes_done < transfer_len and cqe->status == 0). It therefore calls\nnvmet_req_uninit() a second time on the same command — a double\npercpu_ref_put against a single percpu_ref_get."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/nvme/target/tcp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"fda871c0ba5d2eed2cd1c881573168129da70058","lessThan":"96fe2513df590e74b04253a45089cae75569570e","versionType":"git","status":"affected"},{"version":"fda871c0ba5d2eed2cd1c881573168129da70058","lessThan":"e091ff83d962f9ed00d9bd70443676de9fe98bdc","versionType":"git","status":"affected"},{"version":"fda871c0ba5d2eed2cd1c881573168129da70058","lessThan":"6f9442983a3e4227afd1c83a5251ddbca585ea21","versionType":"git","status":"affected"},{"version":"fda871c0ba5d2eed2cd1c881573168129da70058","lessThan":"088ee46c18d99baef453afd74181dd40ade044ad","versionType":"git","status":"affected"},{"version":"fda871c0ba5d2eed2cd1c881573168129da70058","lessThan":"dbbd07d0a7020b80f6a7028e561908f7b83b3d5a","versionType":"git","status":"affected"},{"version":"91edfca6f8b364d60cde3ddefaf7d03ddf35774b","versionType":"git","status":"affected"},{"version":"4b17476d809273617d3317fa0d4ae78aa488d760","versionType":"git","status":"affected"},{"version":"5.10.20","lessThan":"5.11","versionType":"semver","status":"affected"},{"version":"5.11.3","lessThan":"5.12","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/nvme/target/tcp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.12","status":"affected"},{"version":"0","lessThan":"5.12","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}]},"references":[{"url":"https://git.kernel.org/stable/c/088ee46c18d99baef453afd74181dd40ade044ad","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6f9442983a3e4227afd1c83a5251ddbca585ea21","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/96fe2513df590e74b04253a45089cae75569570e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dbbd07d0a7020b80f6a7028e561908f7b83b3d5a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e091ff83d962f9ed00d9bd70443676de9fe98bdc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-18477","sourceIdentifier":"secalert@redhat.com","published":"2026-08-03T17:16:33.897","lastModified":"2026-08-05T08:16:32.277","vulnStatus":"Awaiting Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. This could lead to unauthorized file modification or, in some cases, privilege escalation. Exploitation does not require the attacker to modify or craft the archive, and standard backup and restore workflows—including extracting into a newly created directory without using the -P option do not mitigate the issue."}],"affected":[{"source":"secalert@redhat.com","affectedData":[{"vendor":"Red Hat","product":"Red Hat Hardened Images","defaultStatus":"affected","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"tar-main","cpes":["cpe:/a:redhat:hummingbird:1"],"versions":[{"version":"1.35-9.1.hum1","lessThan":"*","versionType":"rpm","status":"unaffected"}]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"tar","cpes":["cpe:/o:redhat:enterprise_linux:10"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 6","defaultStatus":"unknown","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"tar","cpes":["cpe:/o:redhat:enterprise_linux:6"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 7","defaultStatus":"unknown","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"tar","cpes":["cpe:/o:redhat:enterprise_linux:7"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"tar","cpes":["cpe:/o:redhat:enterprise_linux:8"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"tar","cpes":["cpe:/o:redhat:enterprise_linux:9"]},{"vendor":"Red Hat","product":"Red Hat Hardened Images","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"aardvark-dns","cpes":["cpe:/a:redhat:hummingbird:1"]},{"vendor":"Red Hat","product":"Red Hat Hardened Images","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"chunkah","cpes":["cpe:/a:redhat:hummingbird:1"]},{"vendor":"Red Hat","product":"Red Hat Hardened Images","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"grafana12.4","cpes":["cpe:/a:redhat:hummingbird:1"]},{"vendor":"Red Hat","product":"Red Hat Hardened Images","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"grafana13.1","cpes":["cpe:/a:redhat:hummingbird:1"]},{"vendor":"Red Hat","product":"Red Hat Hardened Images","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"netavark","cpes":["cpe:/a:redhat:hummingbird:1"]},{"vendor":"Red Hat","product":"Red Hat Hardened Images","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"nodejs26","cpes":["cpe:/a:redhat:hummingbird:1"]},{"vendor":"Red Hat","product":"Red Hat Hardened Images","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"python-cryptography","cpes":["cpe:/a:redhat:hummingbird:1"]},{"vendor":"Red Hat","product":"Red Hat Hardened Images","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rust","cpes":["cpe:/a:redhat:hummingbird:1"]},{"vendor":"Red Hat","product":"Red Hat Hardened Images","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rust-rpm-sequoia","cpes":["cpe:/a:redhat:hummingbird:1"]},{"vendor":"Red Hat","product":"Red Hat Hardened Images","defaultStatus":"unaffected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"yarnpkg","cpes":["cpe:/a:redhat:hummingbird:1"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhcos","cpes":["cpe:/a:redhat:openshift:4"]}]}],"metrics":{"cvssMetricV31":[{"source":"secalert@redhat.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N","baseScore":4.4,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":0.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-03T16:25:22.002230Z","id":"CVE-2026-18477","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"secalert@redhat.com","type":"Secondary","description":[{"lang":"en","value":"CWE-367"}]}],"references":[{"url":"https://access.redhat.com/errata/RHSA-2026:49361","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2026-18477","source":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2509735","source":"secalert@redhat.com"}]}},{"cve":{"id":"CVE-2026-66257","sourceIdentifier":"security@apache.org","published":"2026-08-05T06:16:38.423","lastModified":"2026-08-05T08:16:38.313","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service.\n\nThis issue affects Apache Qpid Proton-J: through 0.34.1.\n\nUsers are recommended to upgrade to version 0.35.0, which fixes the issue."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache Qpid Proton-J","defaultStatus":"unaffected","collectionURL":"https://repo.maven.apache.org/maven2","packageName":"org.apache.qpid:proton-j","versions":[{"version":"0","lessThanOrEqual":"0.34.1","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"references":[{"url":"https://lists.apache.org/thread/dnczt6bgfcq2x6q8ljco177h1qmv59fm","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/04/8","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2026-66273","sourceIdentifier":"security@apache.org","published":"2026-08-05T06:16:38.593","lastModified":"2026-08-05T08:16:38.423","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service.\n\nThis issue affects Apache Qpid Proton-J: through 0.34.1.\n\nUsers are recommended to upgrade to version 0.35.0, which fixes the issue."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache Qpid Proton-J","defaultStatus":"unaffected","collectionURL":"https://repo.maven.apache.org/maven2","packageName":"org.apache.qpid:proton-j","versions":[{"version":"0","lessThanOrEqual":"0.34.1","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-789"}]}],"references":[{"url":"https://lists.apache.org/thread/z34s9v5w05qk4qqtz5fs3v9wpxz6fnbh","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/04/9","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2026-67465","sourceIdentifier":"security@apache.org","published":"2026-08-05T06:16:39.160","lastModified":"2026-08-05T08:16:38.947","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service.\n\nThis issue affects Apache Qpid Proton-Dotnet: through 1.0.0.\n\nUsers are recommended to upgrade to version 1.1.0, which fixes the issue."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache Qpid Proton Dotnet","defaultStatus":"unaffected","packageName":"Apache.Qpid.Proton","versions":[{"version":"0","lessThanOrEqual":"1.0.0","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"references":[{"url":"https://lists.apache.org/thread/zl2pj5fo32lbyrwof89tdyrgt67bbo0m","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/04/21","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2026-67551","sourceIdentifier":"security@apache.org","published":"2026-08-05T06:16:39.313","lastModified":"2026-08-05T08:16:39.053","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service.\n\nThis issue affects Apache Qpid Proton-Dotnet: through 1.0.0.\n\nUsers are recommended to upgrade to version 1.1.0, which fixes the issue."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache Qpid Proton Dotnet","defaultStatus":"unaffected","packageName":"org.apache.qpid","versions":[{"version":"0","lessThanOrEqual":"1.0.0","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-789"}]}],"references":[{"url":"https://lists.apache.org/thread/o566fhkrr3gg0lyzt24xwvz9w94oo6ro","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/04/22","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2026-67588","sourceIdentifier":"security@apache.org","published":"2026-08-05T06:16:39.450","lastModified":"2026-08-05T08:16:39.577","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service.\n\nThis issue affects Apache Qpid ProtonJ2: through 1.1.0.\n\nUsers are recommended to upgrade to version 1.2.0, which fixes the issue."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache Qpid ProtonJ2","defaultStatus":"unaffected","collectionURL":"https://repo.maven.apache.org/maven2","packageName":"org.apache.qpid:protonj2","versions":[{"version":"0","lessThanOrEqual":"1.1.0","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"references":[{"url":"https://lists.apache.org/thread/vk4j02dzggfdrdkwvzmqo4jro2tgj0jt","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/04/27","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2026-67589","sourceIdentifier":"security@apache.org","published":"2026-08-05T06:16:39.583","lastModified":"2026-08-05T08:16:39.677","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service.\n\nThis issue affects Apache Qpid ProtonJ2: through 1.1.0.\n\nUsers are recommended to upgrade to version 1.2.0, which fixes the issue."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache Qpid ProtonJ2","defaultStatus":"unaffected","collectionURL":"https://repo.maven.apache.org/maven2","packageName":"org.apache.qpid:protonj2","versions":[{"version":"0","lessThanOrEqual":"1.1.0","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-789"}]}],"references":[{"url":"https://lists.apache.org/thread/bs24x4778dh72xtfs299cy8krvdlo47q","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/04/28","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2026-68060","sourceIdentifier":"security@apache.org","published":"2026-08-05T06:16:39.737","lastModified":"2026-08-05T08:16:40.087","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service.\n\nThis issue affects Apache Qpid Broker-J: through 10.0.1.\n\nUsers are recommended to upgrade to version 10.1.0, which fixes the issue."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache Qpid Broker-J","defaultStatus":"unaffected","collectionURL":"https://repo.maven.apache.org/maven2","packageName":"org.apache.qpid:qpid-broker-plugins-amqp-1-0-protocol","versions":[{"version":"0","lessThanOrEqual":"10.0.1","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"references":[{"url":"https://lists.apache.org/thread/0slvl8h25w3z4opnh08yyn8l3chko5c9","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/04/14","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2026-68074","sourceIdentifier":"security@apache.org","published":"2026-08-05T06:16:39.877","lastModified":"2026-08-05T08:16:40.290","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service.\n\nThis issue affects Apache Qpid Broker-J: through 10.0.1.\n\nUsers are recommended to upgrade to version 10.1.0, which fixes the issue."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache Qpid Broker-J","defaultStatus":"unaffected","collectionURL":"https://repo.maven.apache.org/maven2","packageName":"org.apache.qpid:qpid-broker-plugins-amqp-1-0-protocol","versions":[{"version":"0","lessThanOrEqual":"10.0.1","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"references":[{"url":"https://lists.apache.org/thread/9t1pvl36z69ssww6449od5g0tszqnhjs","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/04/16","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2026-49004","sourceIdentifier":"psirt@zte.com.cn","published":"2026-08-05T07:16:37.333","lastModified":"2026-08-05T08:16:33.327","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The built-in PostgreSQL service on the mobile device suffers from misconfiguration flaws and command injection vulnerabilities. This service listens on a specific port, runs with root privileges, and is protected by weak credentials. The database supports the COPY FROM PROGRAM syntax, allowing local attackers to bypass Android's permission sandbox and gain full root access."}],"affected":[{"source":"psirt@zte.com.cn","affectedData":[{"vendor":"ZTE","product":"NX799J (Red Magic 11 Air)","defaultStatus":"unaffected","versions":[{"version":"GEN_CN_NX799JV1.0.0B15","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@zte.com.cn","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"PHYSICAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":0.7,"impactScore":5.3}]},"weaknesses":[{"source":"psirt@zte.com.cn","type":"Secondary","description":[{"lang":"en","value":"CWE-89"}]}],"references":[{"url":"https://support.zte.com.cn/zte-iccp-isupport-webui/bulletin/detail/460174866982027405","source":"psirt@zte.com.cn"}]}},{"cve":{"id":"CVE-2026-66274","sourceIdentifier":"security@apache.org","published":"2026-08-05T07:16:37.590","lastModified":"2026-08-05T08:16:38.523","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service.\n\nThis issue affects Apache Qpid Proton-J: through 0.34.1.\n\nUsers are recommended to upgrade to version 0.35.0, which fixes the issue."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache Qpid Proton-J","defaultStatus":"unaffected","collectionURL":"https://repo.maven.apache.org/maven2","packageName":"org.apache.qpid:proton-j","versions":[{"version":"0","lessThanOrEqual":"0.34.1","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-674"}]}],"references":[{"url":"https://lists.apache.org/thread/h7xolzws2by2qhdjf7scbx87foxojb5h","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/04/10","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2026-66275","sourceIdentifier":"security@apache.org","published":"2026-08-05T07:16:37.717","lastModified":"2026-08-05T08:16:38.630","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service.\n\nThis issue affects Apache Qpid Proton-J: through 0.34.1.\n\nUsers are recommended to upgrade to version 0.35.0, which fixes the issue."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache Qpid Proton-J","defaultStatus":"unaffected","collectionURL":"https://repo.maven.apache.org/maven2","packageName":"org.apache.qpid:proton-j","versions":[{"version":"0","lessThanOrEqual":"0.34.1","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"references":[{"url":"https://lists.apache.org/thread/jds59nxrgcxtlx7xl0kvl5hqt07thxzt","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/04/11","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2026-66276","sourceIdentifier":"security@apache.org","published":"2026-08-05T07:16:37.847","lastModified":"2026-08-05T08:16:38.730","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial of service.\n\nThis issue affects Apache Qpid Proton-J: through 0.34.1.\n\nUsers are recommended to upgrade to version 0.35.0, which fixes the issue."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache Qpid Proton-J","defaultStatus":"unaffected","collectionURL":"https://repo.maven.apache.org/maven2","packageName":"org.apache.qpid:proton-j","versions":[{"version":"0","lessThanOrEqual":"0.34.1","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-606"}]}],"references":[{"url":"https://lists.apache.org/thread/14nj0lpsqpnd3q0hw0t0tw44qvdo1jc2","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/04/12","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2026-66277","sourceIdentifier":"security@apache.org","published":"2026-08-05T07:16:37.967","lastModified":"2026-08-05T08:16:38.837","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service.\n\nThis issue affects Apache Qpid Proton-J: through 0.34.1.\n\nUsers are recommended to upgrade to version 0.35.0, which fixes the issue."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache Qpid Proton-J","defaultStatus":"unaffected","collectionURL":"https://repo.maven.apache.org/maven2","packageName":"org.apache.qpid:proton-j","versions":[{"version":"0","lessThanOrEqual":"0.34.1","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"references":[{"url":"https://lists.apache.org/thread/48tflr3sx0sxq9bcdy5rh06oy3gmwx02","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/04/13","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2026-67552","sourceIdentifier":"security@apache.org","published":"2026-08-05T07:16:38.103","lastModified":"2026-08-05T08:16:39.160","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service.\n\nThis issue affects Apache Qpid Proton-Dotnet through 1.0.0.\n\nUsers are recommended to upgrade to version 1.1.0, which fixes the issue"}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache Qpid Proton Dotnet","defaultStatus":"unaffected","packageName":"org.apache.qpid","versions":[{"version":"0","lessThanOrEqual":"1.0.0","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-674"}]}],"references":[{"url":"https://lists.apache.org/thread/4dyg0gycrv55ox4oywqght61b053g8xj","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/04/23","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2026-67553","sourceIdentifier":"security@apache.org","published":"2026-08-05T07:16:38.223","lastModified":"2026-08-05T08:16:39.257","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service.\n\nThis issue affects Apache Qpid Proton-Dotnet: through 1.0.0.\n\nUsers are recommended to upgrade to version 1.1.0, which fixes the issue."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache Qpid Proton Dotnet","defaultStatus":"unaffected","packageName":"org.apache.qpid","versions":[{"version":"0","lessThanOrEqual":"1.0.0","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"references":[{"url":"https://lists.apache.org/thread/hvsncmcbgjrn85crs909nf4y3dqqrywo","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/04/24","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2026-67554","sourceIdentifier":"security@apache.org","published":"2026-08-05T07:16:38.347","lastModified":"2026-08-05T08:16:39.370","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial of service.\n\nThis issue affects Apache Qpid Proton-Dotnet: through 1.0.0.\n\nUsers are recommended to upgrade to version 1.1.0, which fixes the issue."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache Qpid Proton Dotnet","defaultStatus":"unaffected","packageName":"org.apache.qpid","versions":[{"version":"0","lessThanOrEqual":"1.0.0","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-606"}]}],"references":[{"url":"https://lists.apache.org/thread/5ndlowz29464ytj98gz9z9ljhwnmb2hm","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/04/25","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2026-67555","sourceIdentifier":"security@apache.org","published":"2026-08-05T07:16:38.470","lastModified":"2026-08-05T08:16:39.470","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service\n\nThis issue affects Apache Qpid Proton-Dotnet: through 1.0.0.\n\nUsers are recommended to upgrade to version 1.1.0, which fixes the issue."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache Qpid Proton Dotnet","defaultStatus":"unaffected","packageName":"org.apache.qpid","versions":[{"version":"0","lessThanOrEqual":"1.0.0","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"references":[{"url":"https://lists.apache.org/thread/dwrb02dp714lvlfxdj4o5bc9h3z54sw3","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/04/26","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2026-67590","sourceIdentifier":"security@apache.org","published":"2026-08-05T07:16:38.613","lastModified":"2026-08-05T08:16:39.780","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service.\n\nThis issue affects Apache Qpid ProtonJ2: through 1.1.0.\n\nUsers are recommended to upgrade to version 1.2.0, which fixes the issue."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache Qpid ProtonJ2","defaultStatus":"unaffected","collectionURL":"https://repo.maven.apache.org/maven2","packageName":"org.apache.qpid:protonj2","versions":[{"version":"0","lessThanOrEqual":"1.1.0","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-674"}]}],"references":[{"url":"https://lists.apache.org/thread/kmov6k7f3moqy01m1s370fl61vgos3ly","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/04/29","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2026-67591","sourceIdentifier":"security@apache.org","published":"2026-08-05T07:16:38.737","lastModified":"2026-08-05T08:16:39.890","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service.\n\nThis issue affects Apache Qpid ProtonJ2: through 1.1.0.\n\nUsers are recommended to upgrade to version 1.2.0, which fixes the issue."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache Qpid ProtonJ2","defaultStatus":"unaffected","collectionURL":"https://repo.maven.apache.org/maven2","packageName":"org.apache.qpid:protonj2","versions":[{"version":"0","lessThanOrEqual":"1.1.0","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"references":[{"url":"https://lists.apache.org/thread/rwmggh2bkm6qotxpdfcplht3jgw5n036","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/04/30","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2026-67592","sourceIdentifier":"security@apache.org","published":"2026-08-05T07:16:38.853","lastModified":"2026-08-05T08:16:39.983","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service.\n\nThis issue affects Apache Qpid ProtonJ2: through 1.1.0.\n\nUsers are recommended to upgrade to version 1.2.0, which fixes the issue"}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache Qpid ProtonJ2","defaultStatus":"unaffected","collectionURL":"https://repo.maven.apache.org/maven2","packageName":"org.apache.qpid:protonj2","versions":[{"version":"0","lessThanOrEqual":"1.1.0","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"references":[{"url":"https://lists.apache.org/thread/b4pv9hfdk7ox78pss77sb4nzwjrvqhhz","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/04/31","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2026-68073","sourceIdentifier":"security@apache.org","published":"2026-08-05T07:16:38.973","lastModified":"2026-08-05T08:16:40.183","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service.\n\nThis issue affects Apache Qpid Broker-J: through 10.0.1.\n\nUsers are recommended to upgrade to version 10.1.0, which fixes the issue."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache Qpid Broker-J","defaultStatus":"unaffected","collectionURL":"https://repo.maven.apache.org/maven2","packageName":"org.apache.qpid:qpid-broker-plugins-amqp-1-0-protocol","versions":[{"version":"0","lessThanOrEqual":"10.0.1","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-674"}]}],"references":[{"url":"https://lists.apache.org/thread/djz1gnrk882vzjo8rykyf9bnywqbvwwr","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/04/15","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2026-68075","sourceIdentifier":"security@apache.org","published":"2026-08-05T07:16:39.090","lastModified":"2026-08-05T08:16:40.413","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service.\n\nThis issue affects Apache Qpid Broker-J: through 10.0.1.\n\nUsers are recommended to upgrade to version 10.1.0, which fixes the issue."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache Qpid Broker-J","defaultStatus":"unaffected","collectionURL":"https://repo.maven.apache.org/maven2","packageName":"org.apache.qpid:qpid-broker-plugins-amqp-1-0-protocol","versions":[{"version":"0","lessThanOrEqual":"10.0.1","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"references":[{"url":"https://lists.apache.org/thread/lht725jgkowmyyjl039roffg6pyvbxz0","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/04/17","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2026-68077","sourceIdentifier":"security@apache.org","published":"2026-08-05T07:16:39.210","lastModified":"2026-08-05T08:16:40.530","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial of service.\n\nThis issue affects Apache Qpid Broker-J: through 10.0.1.\n\nUsers are recommended to upgrade to version 10.1.0, which fixes the issue."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache Qpid Broker-J","defaultStatus":"unaffected","collectionURL":"https://repo.maven.apache.org/maven2","packageName":"org.apache.qpid:qpid-broker-plugins-amqp-1-0-protocol","versions":[{"version":"0","lessThanOrEqual":"10.0.1","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-606"}]}],"references":[{"url":"https://lists.apache.org/thread/gzc78gdrlw2711v8jzgmsto8bqvg28y8","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/04/18","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2026-68078","sourceIdentifier":"security@apache.org","published":"2026-08-05T07:16:39.327","lastModified":"2026-08-05T08:16:40.643","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service.\n\nThis issue affects Apache Qpid Broker-J: through 10.0.1.\n\nUsers are recommended to upgrade to version 10.1.0, which fixes the issue."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache Qpid Broker-J","defaultStatus":"unaffected","collectionURL":"https://repo.maven.apache.org/maven2","packageName":"org.apache.qpid:qpid-broker-plugins-amqp-1-0-protocol","versions":[{"version":"0","lessThanOrEqual":"10.0.1","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"references":[{"url":"https://lists.apache.org/thread/m8gs6pfp1fmbgwcjr8zsgn95hfh15f8o","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/04/19","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2026-68080","sourceIdentifier":"security@apache.org","published":"2026-08-05T07:16:39.443","lastModified":"2026-08-05T08:16:40.743","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"It was not possible to govern the rate at which the broker would respond to an echo flow, enabling an authenticated attacker to cause excessive resource usage and potential denial of service.\n\nThis issue affects Apache Qpid Broker-J: through 10.0.1.\n\nUsers are recommended to upgrade to version 10.1.0, which fixes the issue."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache Qpid Broker-J","defaultStatus":"unaffected","collectionURL":"https://repo.maven.apache.org/maven2","packageName":"org.apache.qpid:qpid-broker-plugins-amqp-1-0-protocol","versions":[{"version":"0","lessThanOrEqual":"10.0.1","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-406"}]}],"references":[{"url":"https://lists.apache.org/thread/tcnrv5nhmnsrzz92o4owxgycro6llt57","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/08/04/20","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2026-11969","sourceIdentifier":"security@wordfence.com","published":"2026-08-05T08:16:30.040","lastModified":"2026-08-05T08:16:30.040","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The WP TripAdvisor Review Slider plugin for WordPress is vulnerable to generic SQL Injection via 'curselrevs[]' Parameter in all versions up to, and including, 14.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"jgwhite33","product":"WP TripAdvisor Review Slider","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"14.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N","baseScore":4.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":3.6}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-89"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/wp-tripadvisor-review-slider/tags/14.2/admin/class-wp-tripadvisor-review-slider-admin.php#L599","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/wp-tripadvisor-review-slider/tags/14.2/admin/class-wp-tripadvisor-review-slider-admin.php#L671","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/wp-tripadvisor-review-slider/tags/14.2/includes/class-wp-tripadvisor-review-slider.php#L285","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/wp-tripadvisor-review-slider/tags/14.3/admin/class-wp-tripadvisor-review-slider-admin.php#L599","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/wp-tripadvisor-review-slider/tags/14.3/admin/class-wp-tripadvisor-review-slider-admin.php#L671","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/wp-tripadvisor-review-slider/tags/14.3/includes/class-wp-tripadvisor-review-slider.php#L285","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3570513%40wp-tripadvisor-review-slider%2Ftags%2F14.4%2Fadmin%2Fclass-wp-tripadvisor-review-slider-admin.php&old=3549944%40wp-tripadvisor-review-slider%2Ftags%2F14.3%2Fadmin%2Fclass-wp-tripadvisor-review-slider-admin.php&sfp_email=&sfph_mail=","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9bdfa6e8-0bf6-4ca5-b145-af66d99dbf6c?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-12000","sourceIdentifier":"security@wordfence.com","published":"2026-08-05T08:16:30.367","lastModified":"2026-08-05T08:16:30.367","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Page and Post Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to and including 1.4.0 via the WordPress core REST endpoints /wp-json/wp/v2/pages, /wp-json/wp/v2/pages/<id>, /wp-json/wp/v2/posts, and /wp-json/wp/v2/posts/<id>. This is due to the plugin's REST guards — papr_restrict_page_post_rest_api() and the the_posts filter registered by papr_filter_posts() — sourcing their restricted-ID list exclusively from papr_get_restricted_posts_id(), which only reads the per-page metabox options papr_allowed_redirect_for_pages and papr_allowed_redirect_for_posts and never consults the two global toggles papr_access_for_only_loggedin and papr_access_for_only_loggedin_posts that the plugin's own UI describes as 'Make all Pages Private' / 'Make all Posts Private'. This makes it possible for unauthenticated attackers to read the full rendered content of every published page and post on sites configured with the documented global toggles, bypassing the security boundary enforced on the frontend by papr_restrict_logged_in_users()."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"cyberlord92","product":"Page and Post Restriction","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"1.4.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-862"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/page-and-post-restriction/tags/1.4.0/page-and-post-restriction.php#L484","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/page-and-post-restriction/tags/1.4.0/page-and-post-restriction.php#L69","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/page-and-post-restriction/tags/1.4.0/page-and-post-restriction.php#L94","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/page-and-post-restriction/tags/1.4.0/page-restriction-utility.php#L701","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/page-and-post-restriction/tags/1.4.1/page-and-post-restriction.php#L484","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/page-and-post-restriction/tags/1.4.1/page-and-post-restriction.php#L69","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/page-and-post-restriction/tags/1.4.1/page-and-post-restriction.php#L94","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/page-and-post-restriction/tags/1.4.1/page-restriction-utility.php#L701","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?new=3578420%40page-and-post-restriction%2Ftags%2F1.4.2&old=3560846%40page-and-post-restriction%2Ftags%2F1.4.1","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f01302aa-00ef-440a-9c37-4fde6bb4bb4d?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-17505","sourceIdentifier":"security@wordfence.com","published":"2026-08-05T08:16:31.977","lastModified":"2026-08-05T08:16:31.977","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Translate Multilingual sites – TranslatePress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in versions up to, and including, 3.2.5. This is due to the translate_page() function unconditionally replacing the plugin's internal #!trpst# and #!trpen# marker tokens with literal angle brackets across the entire HTML page output after WordPress has already sanitized and escaped user input — allowing the attacker to bypass WordPress's normal HTML escaping by using these tokens, which are not HTML special characters, in the search query. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a specially crafted link."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"cozmoslabs","product":"TranslatePress – Translate Multilingual sites with AI Translation","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"3.2.5","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/translatepress-multilingual/tags/3.2.5/class-translate-press.php#L443","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/translatepress-multilingual/tags/3.2.5/includes/class-search.php#L150","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/translatepress-multilingual/tags/3.2.5/includes/class-translation-render.php#L538","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3624567%40translatepress-multilingual%2Ftrunk%2Fincludes%2Fclass-translation-render.php&old=3617108","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/81d28e90-252f-4b5f-a55b-8cb96292538e?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-17532","sourceIdentifier":"security@wordfence.com","published":"2026-08-05T08:16:32.123","lastModified":"2026-08-05T08:16:32.123","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Seraphinite Accelerator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'seraph_accel_prep' parameter in versions up to, and including, 2.29.15. This is due to the CacheExtractPreparePageParams() function using PHP's loose inequality operator (!=) to compare the expected HMAC string against the JSON-decoded 'nonce' value — supplying the JSON boolean true causes any non-empty HMAC string to compare as loosely equal, bypassing the signature check — combined with insufficient output escaping in the _CbContentFinishSkip() function, which concatenates the attacker-controlled 'selfTest' field directly into the HTML response body. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a specially crafted link."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"seraphinitesoft","product":"Seraphinite Accelerator","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"2.29.18","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/seraphinite-accelerator/tags/2.29.15/cache.php#L76","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/seraphinite-accelerator/tags/2.29.15/cache_ex.php#L838","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/seraphinite-accelerator/tags/2.29.15/common.php#L6036","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/seraphinite-accelerator/tags/2.29.18/cache.php#L76","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/seraphinite-accelerator/tags/2.29.18/cache_ex.php#L838","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/seraphinite-accelerator/tags/2.29.18/common.php#L6036","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3624461%40seraphinite-accelerator%2Ftrunk%2Fcache_ex.php&old=3619618%40seraphinite-accelerator%2Ftrunk%2Fcache_ex.php&sfp_email=&sfph_mail=","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3624461%40seraphinite-accelerator%2Ftrunk%2Fcommon.php&old=3619618%40seraphinite-accelerator%2Ftrunk%2Fcommon.php&sfp_email=&sfph_mail=","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5aeea62b-bd6c-4fe2-8c0f-8c9919688e87?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-4431","sourceIdentifier":"security@wordfence.com","published":"2026-08-05T08:16:33.457","lastModified":"2026-08-05T08:16:33.457","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Easy Post Submission plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `create_post()` function in all versions up to, and including, 2.3.0. This is due to the `rbsm_submit_post` AJAX action being registered for unauthenticated users via `wp_ajax_nopriv_rbsm_submit_post` without any authorization checks when a `postId` parameter is supplied. This makes it possible for unauthenticated attackers to modify the title, content, excerpt, categories, and tags of arbitrary posts, as well as change the post status to draft (effectively unpublishing them) via the 'postId' parameter."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"themeruby","product":"Easy Post Submission – Frontend Posting, Guest Publishing & Submit Content for WordPress","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"2.3.0","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","baseScore":9.1,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.2}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-862"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/easy-post-submission/tags/2.2.0/includes/client-ajax-handler.php#L1157","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/easy-post-submission/tags/2.2.0/includes/client-ajax-handler.php#L38","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/easy-post-submission/tags/2.2.0/includes/client-ajax-handler.php#L974","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3488045%40easy-post-submission%2Ftrunk&old=3427523%40easy-post-submission%2Ftrunk","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/15494ccf-7c9d-4566-9e80-2da94172a3dd?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-5108","sourceIdentifier":"security@wordfence.com","published":"2026-08-05T08:16:34.730","lastModified":"2026-08-05T08:16:34.730","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Super Progressive Web Apps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `superpwa_settings[offline_message_txt]` setting in all versions up to, and including, 2.2.43. This is due to insufficient input sanitization and output escaping. The offline message value is stored without sanitization, passed to the frontend via `wp_localize_script()` without escaping, and rendered using `innerHTML` in the JavaScript snackbar component. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user triggers the offline snackbar."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"superpwa","product":"Super Progressive Web Apps","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"2.2.43","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N","baseScore":4.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.3,"impactScore":2.7}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/super-progressive-web-apps/tags/2.2.41/public/js/register-sw.js#L177","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/super-progressive-web-apps/tags/2.2.41/public/sw.php#L386","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?reponame=&new=3506063%40super-progressive-web-apps%2Ftrunk&old=3494263%40super-progressive-web-apps%2Ftrunk","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/0332e106-1f97-4c52-b084-ea15d31dee72?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-5116","sourceIdentifier":"security@wordfence.com","published":"2026-08-05T08:16:34.870","lastModified":"2026-08-05T08:16:34.870","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.0.5. This is due to insufficient output escaping on form shortcode keys displayed in the admin \"Scan Forms for Post Meta and User Data Keys\" page. This makes it possible for authenticated attackers, with Editor-level access and above, to inject arbitrary web scripts that execute when an Administrator runs the scan feature."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"sevenspark","product":"DTX – Dynamic Text Extension for Contact Form 7","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"5.0.5","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N","baseScore":4.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.3,"impactScore":2.7}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/contact-form-7-dynamic-text-extension/tags/5.0.4/includes/admin/settings.php#L544","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/contact-form-7-dynamic-text-extension/tags/5.0.4/includes/admin/settings.php#L559","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?new=3561908%40contact-form-7-dynamic-text-extension%2Ftags%2F5.0.6&old=3463604%40contact-form-7-dynamic-text-extension%2Ftags%2F5.0.5","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/759add85-3d72-46d5-a973-dd8dcfb9f336?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-5581","sourceIdentifier":"security@wordfence.com","published":"2026-08-05T08:16:35.007","lastModified":"2026-08-05T08:16:35.007","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to unauthorized arbitrary media deletion in all versions up to, and including, 1.1.8. This is due to missing capability checks in the `plupload_ajax_delete_file()` function, which is registered via `wp_ajax_nopriv_gfmu_delete_file`. The nonce intended for CSRF protection is exposed on any public-facing page containing a multi-uploader form field via the `GFMU_options` JavaScript object. This makes it possible for unauthenticated attackers to permanently delete any WordPress media attachment by supplying its attachment ID, potentially leading to complete media library destruction."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"sh1zen","product":"Multi Uploader for Gravity Forms","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"1.1.8","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","baseScore":9.1,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.2}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-862"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/gf-multi-uploader/tags/1.1.8/GFMUAddon.class.php#L131","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/gf-multi-uploader/tags/1.1.8/inc/GFMUHandlePluploader.class.php#L66","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/gf-multi-uploader/trunk/GFMUAddon.class.php#L131","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/gf-multi-uploader/trunk/inc/GFMUHandlePluploader.class.php#L66","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3501985%40gf-multi-uploader%2Ftrunk&old=3421317%40gf-multi-uploader%2Ftrunk&sfp_email=&sfph_mail=","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/16dca898-1a98-4e0b-8f48-dc01ba2dc4e6?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-5651","sourceIdentifier":"security@wordfence.com","published":"2026-08-05T08:16:35.150","lastModified":"2026-08-05T08:16:35.150","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Askeet plugin for WordPress is vulnerable to SQL Injection via the 'sql_query' parameter in multiple AJAX actions (askeet_execute_sql_query, askeet_export_all_results) in all versions up to, and including, 3.0. This is due to the askeet_is_safe_query() filter being bypassable using MySQL conditional comments (e.g., /*!UNION*/). The filter strips regular block comments before checking for forbidden SQL keywords, but MySQL interprets conditional comments as executable code. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"2wstechnologies","product":"Askeet — Talk to Your WooCommerce Data","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"3.0","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N","baseScore":4.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":3.6}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-89"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/askeet/tags/2.5/askeet.php#L563","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/askeet/tags/2.5/askeet.php#L767","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/askeet/trunk/askeet.php#L767","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?new=3525593%40askeet%2Ftrunk&old=3521172%40askeet%2Ftrunk","source":"security@wordfence.com"},{"url":"https://wordpress.org/plugins/askeet/","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b95af878-f324-44ae-a4bf-0c1e994bb3c1?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-61483","sourceIdentifier":"security@apache.org","published":"2026-08-05T08:16:35.330","lastModified":"2026-08-05T08:16:35.330","vulnStatus":"Received","cveTags":[{"sourceIdentifier":"security@apache.org","tags":["unsupported-when-assigned"]}],"descriptions":[{"lang":"en","value":"** UNSUPPORTED WHEN ASSIGNED ** Uncontrolled Recursion vulnerability in Apache Lucy.\n\nThis issue affects Apache Lucy: all versions.\n\nAs this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users.\n\nNOTE: This vulnerability only affects products that are no longer supported by the maintainer."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache Lucy","defaultStatus":"unaffected","collectionURL":"https://cpan.org/modules","packageName":"Lucy","packageURL":"pkg:cpan/Lucy","versions":[{"version":"0","lessThanOrEqual":"*","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Primary","description":[{"lang":"en","value":"CWE-674"}]}],"references":[{"url":"https://lists.apache.org/thread/ltp8320c0nsy45bpzm8342jd7yj05z1h","source":"security@apache.org"}]}},{"cve":{"id":"CVE-2026-61484","sourceIdentifier":"security@apache.org","published":"2026-08-05T08:16:35.487","lastModified":"2026-08-05T08:16:35.487","vulnStatus":"Received","cveTags":[{"sourceIdentifier":"security@apache.org","tags":["unsupported-when-assigned"]}],"descriptions":[{"lang":"en","value":"** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy.\n\nThis issue affects Apache Lucy: all versions.\n\nAs this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users.\n\nNOTE: This vulnerability only affects products that are no longer supported by the maintainer."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache Lucy","defaultStatus":"unaffected","collectionURL":"https://cpan.org/modules","packageName":"Lucy","packageURL":"pkg:cpan/Lucy","versions":[{"version":"0","lessThan":"*","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Primary","description":[{"lang":"en","value":"CWE-502"}]}],"references":[{"url":"https://lists.apache.org/thread/942t3pwgz2nrhnklrtyt5zr7g4wqc9cb","source":"security@apache.org"}]}},{"cve":{"id":"CVE-2026-61485","sourceIdentifier":"security@apache.org","published":"2026-08-05T08:16:35.610","lastModified":"2026-08-05T08:16:35.610","vulnStatus":"Received","cveTags":[{"sourceIdentifier":"security@apache.org","tags":["unsupported-when-assigned"]}],"descriptions":[{"lang":"en","value":"** UNSUPPORTED WHEN ASSIGNED ** Memory Allocation with Excessive Size Value vulnerability in Apache Lucy.\n\nThis issue affects Apache Lucy: all versions.\n\nAs this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users.\n\nNOTE: This vulnerability only affects products that are no longer supported by the maintainer."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache Lucy","defaultStatus":"unaffected","collectionURL":"https://cpan.org/modules","packageName":"Lucy","packageURL":"pkg:cpan/Lucy","versions":[{"version":"0","lessThanOrEqual":"*","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Primary","description":[{"lang":"en","value":"CWE-789"}]}],"references":[{"url":"https://lists.apache.org/thread/4q9rfscp3tkjr3kt7lsg97szhmydl23s","source":"security@apache.org"}]}},{"cve":{"id":"CVE-2026-61486","sourceIdentifier":"security@apache.org","published":"2026-08-05T08:16:35.733","lastModified":"2026-08-05T08:16:35.733","vulnStatus":"Received","cveTags":[{"sourceIdentifier":"security@apache.org","tags":["unsupported-when-assigned"]}],"descriptions":[{"lang":"en","value":"** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apache Lucy.\n\nThis issue affects Apache Lucy: all versions.\n\nAs this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users.\n\nNOTE: This vulnerability only affects products that are no longer supported by the maintainer."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache Lucy","defaultStatus":"unaffected","collectionURL":"https://cpan.org/modules","packageName":"Lucy","packageURL":"pkg:cpan/Lucy","versions":[{"version":"0","lessThanOrEqual":"*","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Primary","description":[{"lang":"en","value":"CWE-121"}]}],"references":[{"url":"https://lists.apache.org/thread/z88yv1z19ppsd4td4nqtg7q72fvqh01b","source":"security@apache.org"}]}},{"cve":{"id":"CVE-2026-64566","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-05T08:16:36.140","lastModified":"2026-08-05T08:16:36.140","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: iptfs: propagate SKBFL_SHARED_FRAG in iptfs_skb_add_frags()\n\nWhen iptfs_skb_add_frags() copies frag references from the source\nfrag walk into a new SKB, it increments the page reference count via\n__skb_frag_ref() but does not propagate SKBFL_SHARED_FRAG to the\ndestination SKB's skb_shinfo->flags.\n\nIf the source SKB carries shared frags (e.g. from a page-pool backed\nreceive path), the new inner SKB will appear to ESP as having privately\nowned frags.  A subsequent esp_input() call for a nested transport-mode\nSA then takes the no-COW fast path and decrypts in place, writing over\npages that are still referenced by the outer IPTFS SKB.  This causes\nkernel-visible memory corruption and can trigger a panic.\n\nAll other frag-transfer helpers in the kernel (skb_try_coalesce,\nskb_gro_receive, __pskb_copy_fclone, skb_shift, skb_segment) correctly\npropagate SKBFL_SHARED_FRAG; align iptfs_skb_add_frags() with this\nconvention by setting the flag inside the loop immediately after\n__skb_frag_ref() and nr_frags++, so every exit path that attaches a frag\nunconditionally propagates SKBFL_SHARED_FRAG."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/xfrm/xfrm_iptfs.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5f2b6a9095743a6bf1f34c43c4fe78fa8bdf5ad7","lessThan":"d8aaf06b29f5a0b6186cf68d21c7d63678ee3891","versionType":"git","status":"affected"},{"version":"5f2b6a9095743a6bf1f34c43c4fe78fa8bdf5ad7","lessThan":"ffd64e0717efd83fbf3396ab4e5ac6d795dac4d0","versionType":"git","status":"affected"},{"version":"5f2b6a9095743a6bf1f34c43c4fe78fa8bdf5ad7","lessThan":"430ea57d6daf765e88f90046afbfd1e071cb7200","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/xfrm/xfrm_iptfs.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.14","status":"affected"},{"version":"0","lessThan":"6.14","versionType":"semver","status":"unaffected"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.6","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/430ea57d6daf765e88f90046afbfd1e071cb7200","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d8aaf06b29f5a0b6186cf68d21c7d63678ee3891","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ffd64e0717efd83fbf3396ab4e5ac6d795dac4d0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64567","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-05T08:16:36.277","lastModified":"2026-08-05T08:16:36.277","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: reject free space cache with more entries than pages\n\nWhen loading a v1 free space cache, __load_free_space_cache() takes\nnum_entries and num_bitmaps straight from the on-disk\nbtrfs_free_space_header. That header is stored in the tree_root under a key\nwith type 0, which the tree-checker has no case for, so neither count is\nvalidated before the load trusts it.\n\nThe load loops num_entries times and maps the next page whenever the current\none runs out, going through io_ctl_check_crc() -> io_ctl_map_page(), which\ndoes io_ctl->pages[io_ctl->index++]. But pages[] is allocated in\nio_ctl_init() from the cache inode's i_size, not from num_entries:\n\n\tnum_pages = DIV_ROUND_UP(i_size_read(inode), PAGE_SIZE);\n\tio_ctl->pages = kcalloc(num_pages, sizeof(struct page *), GFP_NOFS);\n\nSo if num_entries claims more records than the pages can hold, io_ctl->index\nruns off the end of pages[]. The write side never hits this because\nio_ctl_add_entry() and io_ctl_add_bitmap() both stop once\nio_ctl->index >= io_ctl->num_pages; the read side just never had the same\ncheck.\n\nTo trigger it, take a clean cache (num_entries = <N> here), set num_entries\nin the header to 0x10000, and fix up the leaf checksum so it still passes\nthe tree-checker. The cache inode has i_size = 65536, so num_pages is 16 and\npages[] is a 16-pointer (kmalloc-128) array. The load now tries to read\n65536 entries, io_ctl->index walks up to 16, and pages[16] is read past the\narray:\n\n  BUG: KASAN: slab-out-of-bounds in io_ctl_check_crc (fs/btrfs/free-space-cache.c:420 fs/btrfs/free-space-cache.c:565)\n  Read of size 8 at addr ffff88800c833a80 by task kworker/u8:3/58\n   io_ctl_check_crc (fs/btrfs/free-space-cache.c:420 fs/btrfs/free-space-cache.c:565)\n   __load_free_space_cache (fs/btrfs/free-space-cache.c:655 fs/btrfs/free-space-cache.c:820)\n   load_free_space_cache (fs/btrfs/free-space-cache.c:1017)\n   caching_thread (fs/btrfs/block-group.c:880)\n   btrfs_work_helper (fs/btrfs/async-thread.c:312)\n   process_one_work\n   worker_thread\n   kthread\n   ret_from_fork\n\nfree-space-cache.c:420 is io_ctl_map_page(), inlined into io_ctl_check_crc()\nat line 565, which is why that is the frame KASAN names. The out-of-bounds\nslot is then treated as a struct page and handed to crc32c(), so the bad\nread turns into a GP fault.\n\nAdd the missing check to io_ctl_check_crc(), which is where both the entry\nloop and the bitmap loop end up. When num_entries is too large the load now\nfails like any corrupt cache: __load_free_space_cache() drops it and rebuilds\nthe free space from the extent tree, so a valid cache is never rejected."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/btrfs/free-space-cache.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5b0e95bf607ddd59b39f52d3d55e6581c817b530","lessThan":"33878ba25e2638bc0c61623d7a05c9ca2b74c039","versionType":"git","status":"affected"},{"version":"5b0e95bf607ddd59b39f52d3d55e6581c817b530","lessThan":"404a0b986e0b6e79738fdf1f0ebbbc43b9acd2a2","versionType":"git","status":"affected"},{"version":"5b0e95bf607ddd59b39f52d3d55e6581c817b530","lessThan":"5e1b2ca6b34939e70fb0785e8222b53cf060016f","versionType":"git","status":"affected"},{"version":"5b0e95bf607ddd59b39f52d3d55e6581c817b530","lessThan":"f9fef131fa3f59b857217f522fa5ea430d1b707c","versionType":"git","status":"affected"},{"version":"5b0e95bf607ddd59b39f52d3d55e6581c817b530","lessThan":"a2d8d5647ed854e38f941741aea45b9eb15a6350","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/btrfs/free-space-cache.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.2","status":"affected"},{"version":"0","lessThan":"3.2","versionType":"semver","status":"unaffected"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.6","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/33878ba25e2638bc0c61623d7a05c9ca2b74c039","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/404a0b986e0b6e79738fdf1f0ebbbc43b9acd2a2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5e1b2ca6b34939e70fb0785e8222b53cf060016f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a2d8d5647ed854e38f941741aea45b9eb15a6350","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f9fef131fa3f59b857217f522fa5ea430d1b707c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64568","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-05T08:16:36.423","lastModified":"2026-08-05T08:16:36.423","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: fix unsol_bcast_probe_resp double free on alloc failure\n\nieee80211_set_unsol_bcast_probe_resp() calls kfree_rcu() on the old\ntemplate before allocating the replacement. If the kzalloc() then fails,\nit returns -ENOMEM while link->u.ap.unsol_bcast_probe_resp still points\nat the object already queued for freeing. A later update or AP teardown\nre-queues that same rcu_head; the second free is caught by KASAN when the\nRCU sheaf is processed in softirq:\n\n  BUG: KASAN: double-free in rcu_free_sheaf (mm/slub.c:5850)\n  Free of addr ffff88800d06f300 by task exploit/145\n   ...\n   __rcu_free_sheaf_prepare (mm/slub.c:2634 mm/slub.c:2940)\n   rcu_free_sheaf (mm/slub.c:5850)\n   rcu_core (kernel/rcu/tree.c:2617 kernel/rcu/tree.c:2869)\n   handle_softirqs (kernel/softirq.c:622)\n  The buggy address belongs to the cache kmalloc-128 of size 128\n\nQueue the old object for kfree_rcu() only after the new one is published,\nmatching ieee80211_set_probe_resp() and ieee80211_set_s1g_short_beacon()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/mac80211/cfg.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3b1c256eb4aedfc71dd97d5951ccff824b41d628","lessThan":"ca27a81cd77b698e5eb586a011bee6800c7ee4bd","versionType":"git","status":"affected"},{"version":"3b1c256eb4aedfc71dd97d5951ccff824b41d628","lessThan":"d62b55b7c7dc62887d7fd5648fb38f0bfaef53ae","versionType":"git","status":"affected"},{"version":"3b1c256eb4aedfc71dd97d5951ccff824b41d628","lessThan":"0ace76e410d7f7d813b605825a3e593a79c3958f","versionType":"git","status":"affected"},{"version":"3b1c256eb4aedfc71dd97d5951ccff824b41d628","lessThan":"1d067abcd37062426c59ec73dbc4e87a63f33fea","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/mac80211/cfg.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.7","status":"affected"},{"version":"0","lessThan":"6.7","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.6","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0ace76e410d7f7d813b605825a3e593a79c3958f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1d067abcd37062426c59ec73dbc4e87a63f33fea","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ca27a81cd77b698e5eb586a011bee6800c7ee4bd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d62b55b7c7dc62887d7fd5648fb38f0bfaef53ae","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64569","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-05T08:16:36.547","lastModified":"2026-08-05T08:16:36.547","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n\n\nOn CONFIG_INET=n builds, mpls_valid_fib_dump_req() walks the parsed\nattribute table itself instead of calling ip_valid_fib_dump_req(). The\nRTA_OIF arm passes tb[RTA_OIF] to nla_get_u32() without checking it is\npresent, so an RTM_GETROUTE dump for AF_MPLS with strict checking and no\nRTA_OIF hits a NULL dereference.\n\nRTM_GETROUTE is RTNL_KIND_GET, which rtnetlink_rcv_msg() permits without\nCAP_NET_ADMIN, so an unprivileged user can trigger it.\n\n  Oops: general protection fault, probably for non-canonical address\n        0xdffffc0000000000: 0000 [#1] SMP KASAN NOPTI\n  KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]\n  RIP: 0010:mpls_valid_fib_dump_req (net/mpls/af_mpls.c:2189)\n  Call Trace:\n   mpls_dump_routes (net/mpls/af_mpls.c:2236)\n   netlink_dump (net/netlink/af_netlink.c:2331)\n   __netlink_dump_start (net/netlink/af_netlink.c:2446)\n   rtnetlink_rcv_msg (net/core/rtnetlink.c:7033)\n   netlink_rcv_skb (net/netlink/af_netlink.c:2556)\n   netlink_unicast (net/netlink/af_netlink.c:1345)\n   netlink_sendmsg (net/netlink/af_netlink.c:1900)\n   __sock_sendmsg (net/socket.c:790)\n   ____sys_sendmsg (net/socket.c:2684)\n   ___sys_sendmsg (net/socket.c:2738)\n   __sys_sendmsg (net/socket.c:2770)\n   do_syscall_64 (arch/x86/entry/syscall_64.c:94)\n   entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)\n\nSkip unset attributes, as ip_valid_fib_dump_req() does."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/mpls/af_mpls.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"196cfebf897266c3450519e916bab9daff74e52c","lessThan":"d6eee7cd078aaf9dd75efc801f6c9b608a37cd71","versionType":"git","status":"affected"},{"version":"196cfebf897266c3450519e916bab9daff74e52c","lessThan":"ad6284ced6a15e4abd57ca4d0793b7bd15ca52ce","versionType":"git","status":"affected"},{"version":"196cfebf897266c3450519e916bab9daff74e52c","lessThan":"5f6e7b32bd1fbde10fd31a4143260735ea535b8a","versionType":"git","status":"affected"},{"version":"196cfebf897266c3450519e916bab9daff74e52c","lessThan":"06db79411a280707c7e4bf4b221ff4e664b51502","versionType":"git","status":"affected"},{"version":"196cfebf897266c3450519e916bab9daff74e52c","lessThan":"56d96fededd61192cd7cc8d2b0f36adfd59036c3","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/mpls/af_mpls.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.20","status":"affected"},{"version":"0","lessThan":"4.20","versionType":"semver","status":"unaffected"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.6","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/06db79411a280707c7e4bf4b221ff4e664b51502","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/56d96fededd61192cd7cc8d2b0f36adfd59036c3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5f6e7b32bd1fbde10fd31a4143260735ea535b8a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ad6284ced6a15e4abd57ca4d0793b7bd15ca52ce","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d6eee7cd078aaf9dd75efc801f6c9b608a37cd71","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64570","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-05T08:16:36.680","lastModified":"2026-08-05T08:16:36.680","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: fix fils_discovery double free on alloc failure\n\nieee80211_set_fils_discovery() calls kfree_rcu() on the old template\nbefore allocating the replacement. If the kzalloc() then fails, it\nreturns -ENOMEM while link->u.ap.fils_discovery still points at the\nobject already queued for freeing. A later update or AP teardown\n(ieee80211_stop_ap()) re-queues that same rcu_head; the second free is\ncaught by KASAN when the RCU sheaf is processed in softirq:\n\n  BUG: KASAN: double-free in rcu_free_sheaf (mm/slub.c:5850)\n  Free of addr ffff88800c065280 by task swapper/0/0\n   ...\n   __rcu_free_sheaf_prepare (mm/slub.c:2634 mm/slub.c:2940)\n   rcu_free_sheaf (mm/slub.c:5850)\n   rcu_core (kernel/rcu/tree.c:2617 kernel/rcu/tree.c:2869)\n   handle_softirqs (kernel/softirq.c:622)\n  The buggy address belongs to the cache kmalloc-96 of size 96\n\nQueue the old object for kfree_rcu() only after the new one is published,\nmatching ieee80211_set_probe_resp() and ieee80211_set_s1g_short_beacon()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/mac80211/cfg.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3b1c256eb4aedfc71dd97d5951ccff824b41d628","lessThan":"e2c55079155a953db669ca1986a985fa286bad95","versionType":"git","status":"affected"},{"version":"3b1c256eb4aedfc71dd97d5951ccff824b41d628","lessThan":"5baaa1042f71dd4b8e418f2cdd516808702d229b","versionType":"git","status":"affected"},{"version":"3b1c256eb4aedfc71dd97d5951ccff824b41d628","lessThan":"1981fba71797ec95e6755fb882cad88899a2a84f","versionType":"git","status":"affected"},{"version":"3b1c256eb4aedfc71dd97d5951ccff824b41d628","lessThan":"286e52a799fa158bdbd77da1426c4d93f9a6e7ad","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/mac80211/cfg.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.7","status":"affected"},{"version":"0","lessThan":"6.7","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.6","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1981fba71797ec95e6755fb882cad88899a2a84f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/286e52a799fa158bdbd77da1426c4d93f9a6e7ad","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5baaa1042f71dd4b8e418f2cdd516808702d229b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e2c55079155a953db669ca1986a985fa286bad95","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64571","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-05T08:16:36.797","lastModified":"2026-08-05T08:16:36.797","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: p54: validate RX frame length in p54_rx_eeprom_readback()\n\np54_rx_eeprom_readback() copies the requested EEPROM slice out of a\ndevice-supplied readback frame without checking that the skb actually holds\nthat many bytes. Commit da1b9a55ff11 (\"wifi: p54: prevent buffer-overflow in\np54_rx_eeprom_readback()\") closed the destination overflow by copying a\nfixed priv->eeprom_slice_size (and rejecting a mismatched advertised len),\nbut the source side is still unbounded: nothing verifies the frame is long\nenough to supply that many bytes.\n\nA malicious USB device can send a short frame whose advertised len matches\npriv->eeprom_slice_size while the payload is truncated. The equality check\npasses and memcpy() reads past the end of the skb, leaking adjacent heap:\n\n  BUG: KASAN: slab-out-of-bounds in p54_rx (drivers/net/wireless/intersil/p54/txrx.c:507)\n  Read of size 1016 at addr ffff88800f077114 by task swapper/0/0\n  Call Trace:\n   <IRQ>\n   ...\n   __asan_memcpy (mm/kasan/shadow.c:105)\n   p54_rx (drivers/net/wireless/intersil/p54/txrx.c:507)\n   p54u_rx_cb (drivers/net/wireless/intersil/p54/p54usb.c:163)\n   __usb_hcd_giveback_urb (drivers/usb/core/hcd.c:1657)\n   dummy_timer (drivers/usb/gadget/udc/dummy_hcd.c:2005)\n   ...\n   </IRQ>\n\n  The buggy address belongs to the object at ffff88800f0770c0\n   which belongs to the cache skbuff_small_head of size 704\n  The buggy address is located 84 bytes inside of\n   allocated 704-byte region [ffff88800f0770c0, ffff88800f077380)\n\nCheck that the slice fits in the skb before copying."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/wireless/intersil/p54/txrx.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7cb770729ba895f73253dfcd46c3fcba45d896f9","lessThan":"25c3b85af3fc4f8043159b14e65790fc3bbdaf48","versionType":"git","status":"affected"},{"version":"7cb770729ba895f73253dfcd46c3fcba45d896f9","lessThan":"f46f8f9c43fd02f4dd5f716d4bda296a523c04f0","versionType":"git","status":"affected"},{"version":"7cb770729ba895f73253dfcd46c3fcba45d896f9","lessThan":"d38f5d868a0a4770e3bcd0925e16c46acdbc9509","versionType":"git","status":"affected"},{"version":"7cb770729ba895f73253dfcd46c3fcba45d896f9","lessThan":"9096e1f7014174067239a63df18ae5f28301990d","versionType":"git","status":"affected"},{"version":"7cb770729ba895f73253dfcd46c3fcba45d896f9","lessThan":"ebd6d37fa94bee929e0b4c9ca19fdf9b1dcf6cea","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/wireless/intersil/p54/txrx.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.28","status":"affected"},{"version":"0","lessThan":"2.6.28","versionType":"semver","status":"unaffected"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.6","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/25c3b85af3fc4f8043159b14e65790fc3bbdaf48","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9096e1f7014174067239a63df18ae5f28301990d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d38f5d868a0a4770e3bcd0925e16c46acdbc9509","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ebd6d37fa94bee929e0b4c9ca19fdf9b1dcf6cea","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f46f8f9c43fd02f4dd5f716d4bda296a523c04f0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64572","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-05T08:16:36.927","lastModified":"2026-08-05T08:16:36.927","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nipv4: fib: free fib_alias with kfree_rcu() on insert error path\n\nfib_table_insert() publishes new_fa into the leaf's fa_list with\nfib_insert_alias() before calling the fib entry notifiers. When a\nnotifier fails, the error path removes new_fa with fib_remove_alias()\n(hlist_del_rcu) and frees it right away with kmem_cache_free().\n\nfib_table_lookup() walks that list under rcu_read_lock() only, so a\nconcurrent lookup that already reached new_fa keeps reading it after the\nfree:\n\n BUG: KASAN: slab-use-after-free in fib_table_lookup (net/ipv4/fib_trie.c:1601)\n Read of size 1 at addr ffff88810676d4eb by task exploit/297\n Call Trace:\n  fib_table_lookup (net/ipv4/fib_trie.c:1601)\n  ip_route_output_key_hash_rcu (net/ipv4/route.c:2814)\n  ip_route_output_key_hash (net/ipv4/route.c:2705)\n  __ip4_datagram_connect (net/ipv4/datagram.c:49)\n  udp_connect (net/ipv4/udp.c:2144)\n  __sys_connect (net/socket.c:2167)\n  __x64_sys_connect (net/socket.c:2173)\n  do_syscall_64\n  entry_SYSCALL_64_after_hwframe\n which belongs to the cache ip_fib_alias of size 56\n\nTriggering the error path needs CAP_NET_ADMIN and a registered fib\nnotifier that can reject a route; a netdevsim device whose IPv4 FIB\nresource is exhausted is enough.\n\nFree new_fa with alias_free_mem_rcu(), as fib_table_delete() already\ndoes for a fib_alias removed from the trie."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/ipv4/fib_trie.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"a6c76c17df021b141b0d306828c9fe4ba2d2717c","lessThan":"8150b5365f026e72250cacc527ea00be30f40105","versionType":"git","status":"affected"},{"version":"a6c76c17df021b141b0d306828c9fe4ba2d2717c","lessThan":"d007056868723de9c0cc3f5ffaad47a8d468b9a4","versionType":"git","status":"affected"},{"version":"a6c76c17df021b141b0d306828c9fe4ba2d2717c","lessThan":"cb8be318b4432abd88d3172ec157330f27a5f7a7","versionType":"git","status":"affected"},{"version":"a6c76c17df021b141b0d306828c9fe4ba2d2717c","lessThan":"b8d2ea75c76abcd0d72679c2f488271f573e32fb","versionType":"git","status":"affected"},{"version":"a6c76c17df021b141b0d306828c9fe4ba2d2717c","lessThan":"f2f152e94a67bc746afaf05a1b2702c195553112","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/ipv4/fib_trie.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.6","status":"affected"},{"version":"0","lessThan":"5.6","versionType":"semver","status":"unaffected"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.6","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/8150b5365f026e72250cacc527ea00be30f40105","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b8d2ea75c76abcd0d72679c2f488271f573e32fb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cb8be318b4432abd88d3172ec157330f27a5f7a7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d007056868723de9c0cc3f5ffaad47a8d468b9a4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f2f152e94a67bc746afaf05a1b2702c195553112","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64573","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-05T08:16:37.057","lastModified":"2026-08-05T08:16:37.057","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: qca: fix NVM tag length underflow in TLV parser\n\nIn the TLV_TYPE_NVM branch of qca_tlv_check_data() the tag loop bound is\n\"while (idx < length - sizeof(struct tlv_type_nvm))\". \"length\" is a signed\nint from the firmware TLV header and sizeof(struct tlv_type_nvm) is a\nsize_t (12), so \"length\" is converted to size_t and any firmware-supplied\n\"length\" < 12 makes the subtraction wrap to a huge value. The loop body\nthen reads a 12-byte struct tlv_type_nvm past the end of the short\nvmalloc'd firmware buffer (and the EDL_TAG_ID_* handlers can write past it).\n\nRewrite the bound as \"idx + sizeof(struct tlv_type_nvm) <= length\"; both\noperands are non-negative, so it no longer underflows and a \"length\" too\nsmall for one record correctly skips the loop.\n\n  BUG: KASAN: vmalloc-out-of-bounds in qca_download_firmware.isra.0 (drivers/bluetooth/btqca.c:421)\n  Read of size 2 at addr ffffc900000e5004 by task kworker/u9:0/52\n  Workqueue: hci0 hci_power_on\n  Call Trace:\n   ...\n   kasan_report (mm/kasan/report.c:595)\n   qca_download_firmware.isra.0 (drivers/bluetooth/btqca.c:421 drivers/bluetooth/btqca.c:617)\n   qca_uart_setup (drivers/bluetooth/btqca.c:948)\n   qca_setup (drivers/bluetooth/hci_qca.c:2029)\n   hci_uart_setup (drivers/bluetooth/hci_ldisc.c:438)\n   hci_dev_open_sync (net/bluetooth/hci_sync.c:5227)\n   hci_power_on (net/bluetooth/hci_core.c:920)\n   process_one_work (kernel/workqueue.c:3322)\n   worker_thread (kernel/workqueue.c:3486)\n   kthread (kernel/kthread.c:436)\n   ret_from_fork (arch/x86/kernel/process.c:158)\n   ret_from_fork_asm (arch/x86/entry/entry_64.S:245)"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/bluetooth/btqca.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"427281f9498ed614f9aabc80e46ec077c487da6d","lessThan":"70354dbb5f72d9a76da7b031de3cbaf6c7d8fc24","versionType":"git","status":"affected"},{"version":"2e4edfa1e2bd821a317e7d006517dcf2f3fac68d","lessThan":"59fd2f075bca94f030c7c78e94878ea0803d7690","versionType":"git","status":"affected"},{"version":"2e4edfa1e2bd821a317e7d006517dcf2f3fac68d","lessThan":"a087ed960fce54e9302796229e9d545bbc9bcd4a","versionType":"git","status":"affected"},{"version":"2e4edfa1e2bd821a317e7d006517dcf2f3fac68d","lessThan":"4fcfb5b2c736785464ff9745f94c6726c5ee2d85","versionType":"git","status":"affected"},{"version":"2e4edfa1e2bd821a317e7d006517dcf2f3fac68d","lessThan":"c90164ca0f7036942ba088eb7ea8d3f6c2352020","versionType":"git","status":"affected"},{"version":"ed53949cc92e28aaa3463d246942bda1fbb7f307","versionType":"git","status":"affected"},{"version":"1caceadfb50432dbf6d808796cb6c34ebb6d662c","versionType":"git","status":"affected"},{"version":"02f05ed44b71152d5e11d29be28aed91c0489b4e","versionType":"git","status":"affected"},{"version":"6.6.31","lessThan":"6.6.148","versionType":"semver","status":"affected"},{"version":"5.15.159","lessThan":"5.16","versionType":"semver","status":"affected"},{"version":"6.1.91","lessThan":"6.2","versionType":"semver","status":"affected"},{"version":"6.8.10","lessThan":"6.9","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/bluetooth/btqca.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.9","status":"affected"},{"version":"0","lessThan":"6.9","versionType":"semver","status":"unaffected"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.6","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/4fcfb5b2c736785464ff9745f94c6726c5ee2d85","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/59fd2f075bca94f030c7c78e94878ea0803d7690","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/70354dbb5f72d9a76da7b031de3cbaf6c7d8fc24","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a087ed960fce54e9302796229e9d545bbc9bcd4a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c90164ca0f7036942ba088eb7ea8d3f6c2352020","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64574","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-05T08:16:37.203","lastModified":"2026-08-05T08:16:37.203","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: tear down new links on vif update error path\n\nWhen ieee80211_vif_update_links() adds new links it allocates a link\ncontainer for each and calls ieee80211_link_init() (which registers the\nper-link debugfs files with file->private_data pointing into the container)\nand ieee80211_link_setup(). If the subsequent drv_change_vif_links() fails,\nthe error path restores the old pointers and jumps to 'free', which frees\nthe new containers but never removes their debugfs entries or stops the\nlinks. The debugfs files survive with file->private_data dangling at the\nfreed container, so a later open()+read() (e.g. link-1/txpower)\ndereferences freed memory in ieee80211_if_read_link(), a use-after-free.\n\nThe removal path already dismantles links correctly via\nieee80211_tear_down_links(), which removes each link's keys and debugfs\nentries and calls ieee80211_link_stop(); the add path on the error branch\ndoes not. Commit be1ba9ed221f (\"wifi: mac80211: avoid weird state in error\npath\") hardened this same error path for the link-removal case\n(new_links == 0) but left the newly-added links' teardown unaddressed.\n\ndrv_change_vif_links() can fail at runtime on MLO drivers (internal\nallocation / queue / firmware command failures).\n\nRemove the new links' debugfs entries and stop them before freeing.\n\n  BUG: KASAN: slab-use-after-free in ieee80211_if_read_link (net/mac80211/debugfs_netdev.c:127)\n  Read of size 8 at addr ffff888011290000 by task exploit/145\n  Call Trace:\n   ...\n   ieee80211_if_read_link (net/mac80211/debugfs_netdev.c:127)\n   short_proxy_read (fs/debugfs/file.c:373)\n   vfs_read (fs/read_write.c:572)\n   ksys_read (fs/read_write.c:716)\n   do_syscall_64 (arch/x86/entry/syscall_64.c:94)\n   entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)\n  ...\n  Oops: general protection fault, probably for non-canonical address 0xdffffc000000000a\n  RIP: 0010:ieee80211_if_read_link (net/mac80211/debugfs_netdev.c:127)\n  Kernel panic - not syncing: Fatal exception"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/mac80211/link.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"170cd6a66d9a164180eb4dc72d50afa6ce1ce566","lessThan":"329589417214d3b7221432e5b266ed2bba7ff674","versionType":"git","status":"affected"},{"version":"170cd6a66d9a164180eb4dc72d50afa6ce1ce566","lessThan":"c57d97f381306bbfba174e8f708419e007824e0c","versionType":"git","status":"affected"},{"version":"170cd6a66d9a164180eb4dc72d50afa6ce1ce566","lessThan":"0f7eaeb950adb77f71beb546e5ab30f90b41fe6f","versionType":"git","status":"affected"},{"version":"170cd6a66d9a164180eb4dc72d50afa6ce1ce566","lessThan":"901a73523e093beff123b54b1ceaf3113f18acc9","versionType":"git","status":"affected"},{"version":"170cd6a66d9a164180eb4dc72d50afa6ce1ce566","lessThan":"952c02b33f56207a160421bcd61e7ac53c9c59ae","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/mac80211/link.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.4","status":"affected"},{"version":"0","lessThan":"6.4","versionType":"semver","status":"unaffected"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.6","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc5","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0f7eaeb950adb77f71beb546e5ab30f90b41fe6f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/329589417214d3b7221432e5b266ed2bba7ff674","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/901a73523e093beff123b54b1ceaf3113f18acc9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/952c02b33f56207a160421bcd61e7ac53c9c59ae","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c57d97f381306bbfba174e8f708419e007824e0c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64575","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-05T08:16:37.363","lastModified":"2026-08-05T08:16:37.363","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: tcp: fix double sock release on batch realloc\n\nbpf_iter_tcp_batch() releases the current batch via\nbpf_iter_tcp_put_batch(), which drops the socket refs and rewrites\neach slot with the socket cookie, then grows the batch. cur_sk/end_sk\nare kept for bpf_iter_tcp_resume(), but on realloc failure the function\nreturns ERR_PTR() before resume runs, leaving cur_sk < end_sk over\nslots that now hold cookies rather than sock pointers.\nbpf_iter_tcp_seq_stop() then calls bpf_iter_tcp_put_batch() again and\ndereferences a cookie as a struct sock.\n\nEmpty the batch on the failure path so stop() does not release it\nagain. The sockets were already freed by the first\nbpf_iter_tcp_put_batch(), so nothing leaks, and a later read() rescans\nthe bucket from the start instead of skipping it. The sibling\nGFP_NOWAIT failure path still holds real socket references and is left\nfor stop() to release.\n\n  BUG: KASAN: null-ptr-deref in __sock_gen_cookie\n  Read of size 8 at addr 0000000000000059 by task exploit\n   ...\n   __sock_gen_cookie (net/core/sock_diag.c:28)\n   bpf_iter_tcp_put_batch (net/ipv4/tcp_ipv4.c:2918)\n   bpf_iter_tcp_seq_stop (net/ipv4/tcp_ipv4.c:3270)\n   bpf_seq_read (kernel/bpf/bpf_iter.c:205)\n   vfs_read (fs/read_write.c:572)\n   ksys_read (fs/read_write.c:716)\n   do_syscall_64\n   entry_SYSCALL_64_after_hwframe\n  Kernel panic - not syncing: Fatal exception"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/ipv4/tcp_ipv4.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"cdec67a489d4fdae3e83e04fca0419136a83c4c2","lessThan":"9f27c4f0ae35b5390ce4f7a54d3501144e41a54d","versionType":"git","status":"affected"},{"version":"cdec67a489d4fdae3e83e04fca0419136a83c4c2","lessThan":"8a726e9585ffe7bfbfad2b5279277a00973970f3","versionType":"git","status":"affected"},{"version":"cdec67a489d4fdae3e83e04fca0419136a83c4c2","lessThan":"980a813452754f8001704744e92f7aa697c53dd3","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/ipv4/tcp_ipv4.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.17","status":"affected"},{"version":"0","lessThan":"6.17","versionType":"semver","status":"unaffected"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.6","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc5","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/8a726e9585ffe7bfbfad2b5279277a00973970f3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/980a813452754f8001704744e92f7aa697c53dd3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9f27c4f0ae35b5390ce4f7a54d3501144e41a54d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64576","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-05T08:16:37.483","lastModified":"2026-08-05T08:16:37.483","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnexthop: initialize extack in nh_res_bucket_migrate()\n\nnh_res_bucket_migrate() passes an uninitialized netlink_ext_ack to\ncall_nexthop_res_bucket_notifiers(). When\nnh_notifier_res_bucket_info_init() fails (e.g. the kzalloc returns\n-ENOMEM), the error is propagated back before any notifier sets\nextack._msg, and the error path formats the stale pointer with\npr_err_ratelimited(\"%s\\n\", extack._msg). With CONFIG_INIT_STACK_NONE\nthis dereferences uninitialized stack memory:\n\n  Oops: general protection fault, probably for non-canonical address ...\n  KASAN: maybe wild-memory-access in range [...]\n  RIP: 0010:string (lib/vsprintf.c:730)\n   vsnprintf (lib/vsprintf.c:2945)\n   _printk (kernel/printk/printk.c:2504)\n   nh_res_bucket_migrate (net/ipv4/nexthop.c:1816)\n   nh_res_table_upkeep (net/ipv4/nexthop.c:1866)\n   rtm_new_nexthop (net/ipv4/nexthop.c:3323)\n   rtnetlink_rcv_msg (net/core/rtnetlink.c:7076)\n   netlink_sendmsg (net/netlink/af_netlink.c:1900)\n  Kernel panic - not syncing: Fatal exception\n\nZero-initialize extack so _msg is NULL on error paths that never set it."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/ipv4/nexthop.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7c37c7e00411b3d1e0c5292368317aca69d1f324","lessThan":"c0936c131a71657afc635d0db2ab096d15d473e1","versionType":"git","status":"affected"},{"version":"7c37c7e00411b3d1e0c5292368317aca69d1f324","lessThan":"3081702ea5aca0aeed9c1ade8eadf6cde8db6b7d","versionType":"git","status":"affected"},{"version":"7c37c7e00411b3d1e0c5292368317aca69d1f324","lessThan":"d536bf205c71f700f6de2086038c3e1d77724715","versionType":"git","status":"affected"},{"version":"7c37c7e00411b3d1e0c5292368317aca69d1f324","lessThan":"18506d7263768d76ac8e057ba55a4d9da50aad66","versionType":"git","status":"affected"},{"version":"7c37c7e00411b3d1e0c5292368317aca69d1f324","lessThan":"6347c5314cee49f364aaf2e40ff15415a57a116e","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/ipv4/nexthop.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.13","status":"affected"},{"version":"0","lessThan":"5.13","versionType":"semver","status":"unaffected"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.6","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc5","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/18506d7263768d76ac8e057ba55a4d9da50aad66","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3081702ea5aca0aeed9c1ade8eadf6cde8db6b7d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6347c5314cee49f364aaf2e40ff15415a57a116e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c0936c131a71657afc635d0db2ab096d15d473e1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d536bf205c71f700f6de2086038c3e1d77724715","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64577","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-05T08:16:37.630","lastModified":"2026-08-05T08:16:37.630","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ngtp: check skb_pull_data() return in gtp1u_send_echo_resp()\n\ngtp1u_send_echo_resp() ignores skb_pull_data()'s return value. Its\ncaller gtp1u_udp_encap_recv() only guarantees 16 bytes (udphdr +\ngtp1_header), but the pull requests 20 (gtp1_header_long + udphdr). For\na 16-19 byte echo request the pull fails and returns NULL without\nadvancing skb->data; execution continues, and the following skb_push()\nplus the IP header pushed by iptunnel_xmit() move skb->data below\nskb->head, tripping skb_under_panic().\n\nFix it by dropping the packet when skb_pull_data() fails.\n\n  skbuff: skb_under_panic: ...\n  kernel BUG at net/core/skbuff.c:214!\n  Call Trace:\n   skb_push (net/core/skbuff.c:2648)\n   iptunnel_xmit (net/ipv4/ip_tunnel_core.c:82)\n   gtp_encap_recv (drivers/net/gtp.c:701 drivers/net/gtp.c:808 drivers/net/gtp.c:920)\n   udp_queue_rcv_one_skb (net/ipv4/udp.c:2388)\n   ...\n  Kernel panic - not syncing: Fatal exception in interrupt"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/gtp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"9af41cc33471ea1efa6f77e188f055cc77d0a5c5","lessThan":"b3c733eaae7f362601c28ac1533d47a961cd3e1c","versionType":"git","status":"affected"},{"version":"9af41cc33471ea1efa6f77e188f055cc77d0a5c5","lessThan":"4fc7923871d176ce0e5fecf4a9b7bb915af790ed","versionType":"git","status":"affected"},{"version":"9af41cc33471ea1efa6f77e188f055cc77d0a5c5","lessThan":"961e9b1e33445f8e42859ecc020c9f60d8b69a8b","versionType":"git","status":"affected"},{"version":"9af41cc33471ea1efa6f77e188f055cc77d0a5c5","lessThan":"cf45d748e437b8dd2dd987f27ee79c8c86f95c88","versionType":"git","status":"affected"},{"version":"9af41cc33471ea1efa6f77e188f055cc77d0a5c5","lessThan":"cd170f051dba9ac146fabcd1b91726487c0cb9fa","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/gtp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.18","status":"affected"},{"version":"0","lessThan":"5.18","versionType":"semver","status":"unaffected"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.6","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc5","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/4fc7923871d176ce0e5fecf4a9b7bb915af790ed","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/961e9b1e33445f8e42859ecc020c9f60d8b69a8b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b3c733eaae7f362601c28ac1533d47a961cd3e1c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cd170f051dba9ac146fabcd1b91726487c0cb9fa","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cf45d748e437b8dd2dd987f27ee79c8c86f95c88","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64578","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-05T08:16:37.760","lastModified":"2026-08-05T08:16:37.760","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: validate compound request size before reading StructureSize2\n\nWhen ksmbd validates a compound (chained) SMB2 request,\nksmbd_smb2_check_message() reads pdu->StructureSize2 without first\nchecking that the compound element is large enough to contain it.\nStructureSize2 is a 2-byte field at offset 64\n(__SMB2_HEADER_STRUCTURE_SIZE) from the start of each element.\n\nThe compound-walking logic only guarantees that a full 64-byte SMB2\nheader is present for the trailing element: when NextCommand is 0, len is\nreduced to the number of bytes remaining after next_smb2_rcv_hdr_off. A\nremote client can craft a compound request whose last element has exactly\n64 bytes, so the 2-byte StructureSize2 read at offset 64 extends one byte\npast the receive buffer, producing a slab-out-of-bounds read.\n\n  BUG: KASAN: slab-out-of-bounds in ksmbd_smb2_check_message (fs/smb/server/smb2misc.c:402)\n  Read of size 2 at addr ffff888012ae31ac by task kworker/0:1/14\n  The buggy address is located 172 bytes inside of allocated 173-byte region\n  Workqueue: ksmbd-io handle_ksmbd_work\n  Call Trace:\n   ...\n   kasan_report (mm/kasan/report.c:595)\n   ksmbd_smb2_check_message (fs/smb/server/smb2misc.c:402)\n   handle_ksmbd_work (fs/smb/server/server.c:119)\n   process_one_work (kernel/workqueue.c:3314)\n   worker_thread (kernel/workqueue.c:3397)\n   kthread (kernel/kthread.c:436)\n   ret_from_fork (arch/x86/kernel/process.c:158)\n   ret_from_fork_asm (arch/x86/entry/entry_64.S:245)\n\nReject any compound element that is too small to hold StructureSize2\nbefore dereferencing it."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/smb/server/smb2misc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9","lessThan":"2c307126ed8e7adddab82b8e31d962d3a2156ab1","versionType":"git","status":"affected"},{"version":"e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9","lessThan":"f7550a91ab211726f59cb137523b7a9eae1ac6eb","versionType":"git","status":"affected"},{"version":"e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9","lessThan":"f0e337e7db67cc1c832958bbb6c4026bdceacfdb","versionType":"git","status":"affected"},{"version":"e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9","lessThan":"ea128f06d2fb2186f0cac0c9f3e953e4d1f5c29a","versionType":"git","status":"affected"},{"version":"e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9","lessThan":"15b38176fd1530372905c602fde51fe89ec8c877","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/smb/server/smb2misc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.15","status":"affected"},{"version":"0","lessThan":"5.15","versionType":"semver","status":"unaffected"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.6","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/15b38176fd1530372905c602fde51fe89ec8c877","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2c307126ed8e7adddab82b8e31d962d3a2156ab1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ea128f06d2fb2186f0cac0c9f3e953e4d1f5c29a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f0e337e7db67cc1c832958bbb6c4026bdceacfdb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f7550a91ab211726f59cb137523b7a9eae1ac6eb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64579","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-05T08:16:37.893","lastModified":"2026-08-05T08:16:37.893","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert\n\nxfrm_hash_rebuild()'s first loop preallocates the bins/chains the reinsert\nloop needs, so the reinsert (after hlist_del_rcu()) cannot allocate or\nfail. But its guard is inverted: it skips policies with prefixlen <\nthreshold and preallocates for the rest.\n\nprefixlen < threshold is exactly when policy_hash_bysel() returns NULL and\nthe reinsert takes the allocating xfrm_policy_inexact_insert() path. So the\nloop preallocates for the exact policies (which never allocate) and skips\nthe inexact ones, whose bin/node is then allocated GFP_ATOMIC during\nreinsert. On failure the error path only WARN_ONCE()s and continues,\nleaving a poisoned bydst node; the next rebuild's hlist_del_rcu()\ndereferences LIST_POISON2 and takes a GPF. Reachable under memory pressure,\ndeterministic via failslab.\n\nInvert the guard so preallocation covers exactly the reinserted policies;\nthe reinsert then allocates nothing and cannot fail.\n\nCrash:\n  Oops: general protection fault, probably for non-canonical address\n  0xfbd59c0000000024: 0000 [#1] SMP KASAN NOPTI\n  KASAN: maybe wild-memory-access in range [0xdead...]\n  ...\n  Workqueue: events xfrm_hash_rebuild\n  RIP: 0010:xfrm_hash_rebuild+0x5b3/0x1190\n  RAX: dead000000000122   (LIST_POISON2 + offset)\n  ...\n  Call Trace:\n   hlist_del_rcu (include/linux/rculist.h:599)\n   xfrm_hash_rebuild (net/xfrm/xfrm_policy.c:1365)\n   process_one_work (kernel/workqueue.c:3322)\n   worker_thread (kernel/workqueue.c:3486)\n   kthread (kernel/kthread.c:436)\n   ret_from_fork (arch/x86/kernel/process.c:158)\n   ret_from_fork_asm (arch/x86/entry/entry_64.S:245)\n   ...\n  Kernel panic - not syncing: Fatal exception in interrupt"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/xfrm/xfrm_policy.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"24969facd704a5f0dd8e08da86bf32a9ce972bee","lessThan":"d9d9cc21cc90014724a14c447e3d587be9447107","versionType":"git","status":"affected"},{"version":"24969facd704a5f0dd8e08da86bf32a9ce972bee","lessThan":"94c00391a5117530188334f740ce26d3f1256190","versionType":"git","status":"affected"},{"version":"24969facd704a5f0dd8e08da86bf32a9ce972bee","lessThan":"7acc5ed2f33608a3d83b64f50a5766843b6e2485","versionType":"git","status":"affected"},{"version":"24969facd704a5f0dd8e08da86bf32a9ce972bee","lessThan":"6aa3796d18a9fda953ad76a62b57bf6c145cb9ef","versionType":"git","status":"affected"},{"version":"24969facd704a5f0dd8e08da86bf32a9ce972bee","lessThan":"f38f8cce2f7e79775b3db7e8a5eacda04ac908e4","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/xfrm/xfrm_policy.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.0","status":"affected"},{"version":"0","lessThan":"5.0","versionType":"semver","status":"unaffected"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.6","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/6aa3796d18a9fda953ad76a62b57bf6c145cb9ef","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7acc5ed2f33608a3d83b64f50a5766843b6e2485","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/94c00391a5117530188334f740ce26d3f1256190","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d9d9cc21cc90014724a14c447e3d587be9447107","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f38f8cce2f7e79775b3db7e8a5eacda04ac908e4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64580","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-05T08:16:38.027","lastModified":"2026-08-05T08:16:38.027","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm6: clear dst.dev on error to avoid double netdev_put in xfrm6_fill_dst()\n\nOn the error path where in6_dev_get(dev) returns NULL, xfrm6_fill_dst()\nreleases the device reference with netdev_put() but leaves\nxdst->u.dst.dev set. dst_destroy() later calls netdev_put(dst->dev)\nagain, so the same net_device reference is released twice, underflowing\nits refcount (ref_tracker WARNING + \"unregister_netdevice: waiting for\n<dev> to become free\").\n\nClear xdst->u.dst.dev after the netdev_put(), the same way the XFRM\ndevice-offload paths xfrm_dev_state_add() and xfrm_dev_policy_add() in\nnet/xfrm/xfrm_device.c NULL ->dev when releasing the reference on error.\n\n  ref_tracker: reference already released.\n  ref_tracker: allocated in:\n   xfrm6_fill_dst (net/ipv6/xfrm6_policy.c:86)\n   ...\n   udpv6_sendmsg (net/ipv6/udp.c:1696)\n   ...\n  ref_tracker: freed in:\n   xfrm6_fill_dst (net/ipv6/xfrm6_policy.c:90)\n   ...\n  WARNING: lib/ref_tracker.c:322 at ref_tracker_free+0x58b/0x780\n   dst_destroy (net/core/dst.c:115)\n   rcu_core\n   handle_softirqs\n   ..."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/ipv6/xfrm6_policy.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"84c4a9dfbf430861e7588d95ae3ff61535dca351","lessThan":"df6856c2dda9187601d29b5fbd7a81b3b178cedf","versionType":"git","status":"affected"},{"version":"84c4a9dfbf430861e7588d95ae3ff61535dca351","lessThan":"43de8a49335e611adb271bbd52e84dfbc11fc185","versionType":"git","status":"affected"},{"version":"84c4a9dfbf430861e7588d95ae3ff61535dca351","lessThan":"ff636d7b7cba6dea82ecf580415ea57f2c1a11b6","versionType":"git","status":"affected"},{"version":"84c4a9dfbf430861e7588d95ae3ff61535dca351","lessThan":"e078da1b4e11390cff3201c19a9a1fe70c5b934f","versionType":"git","status":"affected"},{"version":"84c4a9dfbf430861e7588d95ae3ff61535dca351","lessThan":"136992de9bb91871084ae52d172610541c76e4d2","versionType":"git","status":"affected"},{"version":"a7e22d0c0e81dde129a51ee413644124f4b59954","versionType":"git","status":"affected"},{"version":"01b0d887f67a388fb2a658ee2bdd74e5ba146818","versionType":"git","status":"affected"},{"version":"a98124aac0b5adc5de8ae54f11322781cb4d85c3","versionType":"git","status":"affected"},{"version":"e27b7bee743d921f037b1da6f071237345bef7c1","versionType":"git","status":"affected"},{"version":"3.0.79","lessThan":"3.1","versionType":"semver","status":"affected"},{"version":"3.2.46","lessThan":"3.3","versionType":"semver","status":"affected"},{"version":"3.4.46","lessThan":"3.5","versionType":"semver","status":"affected"},{"version":"3.9.3","lessThan":"3.10","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/ipv6/xfrm6_policy.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.10","status":"affected"},{"version":"0","lessThan":"3.10","versionType":"semver","status":"unaffected"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.6","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/136992de9bb91871084ae52d172610541c76e4d2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/43de8a49335e611adb271bbd52e84dfbc11fc185","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/df6856c2dda9187601d29b5fbd7a81b3b178cedf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e078da1b4e11390cff3201c19a9a1fe70c5b934f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ff636d7b7cba6dea82ecf580415ea57f2c1a11b6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-64581","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-08-05T08:16:38.177","lastModified":"2026-08-05T08:16:38.177","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: fix sk_dst_cache double-free in xfrm_user_policy()\n\nxfrm_user_policy() clears the socket dst cache with __sk_dst_reset(),\ni.e. the non-atomic __sk_dst_set(sk, NULL): it reads sk_dst_cache with\nrcu_dereference_protected(), stores NULL and dst_release()s the old dst.\nThat is only safe if no other thread modifies sk_dst_cache concurrently.\n\nFor a connected UDP socket that does not hold: the transmit fast path\n(udp_sendmsg -> sk_dst_check -> sk_dst_reset) resets the cache locklessly\nwith an atomic xchg(). A per-socket policy change racing a send can make\nboth sides observe the same old dst and each dst_release() it, dropping\nthe socket's single reference twice and freeing the xfrm_dst bundle while\nit is still referenced:\n\n  BUG: KASAN: slab-use-after-free in dst_release\n  Write of size 4 at addr ffff88801897b6c0 by task exploit/155\n  Call Trace:\n   ...\n   dst_release (... ./include/linux/rcuref.h:109)\n   xfrm_user_policy (./include/net/sock.h:2239 ./include/net/sock.h:2256 net/xfrm/xfrm_state.c:3053)\n   do_ip_setsockopt (net/ipv4/ip_sockglue.c:1347)\n   ip_setsockopt (net/ipv4/ip_sockglue.c:1417)\n   do_sock_setsockopt (net/socket.c:2368)\n   __sys_setsockopt (net/socket.c:2393)\n   __x64_sys_setsockopt (net/socket.c:2396)\n   do_syscall_64 (arch/x86/entry/syscall_64.c:94)\n   entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)\n\nReachable by an unprivileged user via a user+network namespace.\n\nUse the atomic sk_dst_reset() so the cache is cleared and released with a\nsingle xchg(): whichever side wins releases the dst once, the other sees\nNULL and does nothing. Behaviour is otherwise unchanged."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/xfrm/xfrm_state.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2b06cdf3e688b98fcc9945873b5d42792bd4eee0","lessThan":"96b678d08268b5f5c6fc99d4289d9b7e334fc683","versionType":"git","status":"affected"},{"version":"2b06cdf3e688b98fcc9945873b5d42792bd4eee0","lessThan":"c283e9ada7fcb7dd4b10592623086b2e6d2f9925","versionType":"git","status":"affected"},{"version":"72f157be2f81910ae759bfe2e5c2256fc4625645","versionType":"git","status":"affected"},{"version":"9e9fe58a92a46c6d154d2901735bf230d91b8507","versionType":"git","status":"affected"},{"version":"adc1ec6cdc20d430aa01b86497220709b9149466","versionType":"git","status":"affected"},{"version":"b54033eb1cfd77aba471269ddd804ed8d3e35dea","versionType":"git","status":"affected"},{"version":"c9e82cb34c3c2ee895af01bc899c6ed0bc6eb04a","versionType":"git","status":"affected"},{"version":"5eef9b51114fcc65651d671add52f267f91b9451","versionType":"git","status":"affected"},{"version":"3.16.52","lessThan":"3.17","versionType":"semver","status":"affected"},{"version":"4.4.163","lessThan":"4.5","versionType":"semver","status":"affected"},{"version":"3.18.101","lessThan":"3.19","versionType":"semver","status":"affected"},{"version":"4.1.52","lessThan":"4.2","versionType":"semver","status":"affected"},{"version":"4.4.123","lessThan":"4.5","versionType":"semver","status":"affected"},{"version":"4.9.89","lessThan":"4.10","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/xfrm/xfrm_state.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.14","status":"affected"},{"version":"0","lessThan":"4.14","versionType":"semver","status":"unaffected"},{"version":"7.1.6","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc4","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/96b678d08268b5f5c6fc99d4289d9b7e334fc683","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c283e9ada7fcb7dd4b10592623086b2e6d2f9925","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-6020","sourceIdentifier":"security@wordfence.com","published":"2026-08-05T08:16:40.850","lastModified":"2026-08-05T08:16:40.850","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The ShopLentor plugin for WordPress is vulnerable to arbitrary function execution via the woolentoropt/v1/custom-action REST API endpoint in all versions up to, and including, 3.3.7. This is due to the handle_action() method passing user-supplied input directly to call_user_func() without an allowlist of permitted callbacks. This makes it possible for authenticated attackers, with Administrator-level access and above, to execute arbitrary PHP callable functions via the 'callback' parameter."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"devitemsllc","product":"ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"3.3.7","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":7.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.2,"impactScore":5.9}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-470"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/woolentor-addons/trunk/includes/admin-panel/includes/classes/Api/Custom_Actions.php#L99","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3504292%40woolentor-addons%2Ftrunk&old=3493678%40woolentor-addons%2Ftrunk&sfp_email=&sfph_mail=","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/00138875-d892-460c-b0ce-7a01335d26dc?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-6147","sourceIdentifier":"security@wordfence.com","published":"2026-08-05T08:16:41.140","lastModified":"2026-08-05T08:16:41.140","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The LightSync Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the rest_replace_media() function in all versions up to, and including, 2.1.6. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"lightsyncpro","product":"LightSync Pro – Connect & Sync Cloud Assets | Lightroom, Canva, Figma, Dropbox & Shutterstock","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"2.1.6","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-434"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/lightsyncpro/tags/2.0.1/includes/admin/class-admin.php#L6755","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/lightsyncpro/tags/2.0.1/includes/admin/class-admin.php#L6814","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3507389%40lightsyncpro%2Ftrunk&old=3476495%40lightsyncpro%2Ftrunk&sfp_email=&sfph_mail=","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9ccdf08b-8b74-4b58-8779-3b07ef2d7b2f?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-6627","sourceIdentifier":"security@wordfence.com","published":"2026-08-05T08:16:41.280","lastModified":"2026-08-05T08:16:41.280","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The WPFormify – Stripe Payments with Form and Checkout plugin for WordPress is vulnerable to unauthorized modification and deletion of Stripe payment credentials in all versions up to, and including, 1.1.1. This is due to missing capability checks and nonce verification on the `wpf_stripe_callback_success()` and `wpf_stripe_disconnect()` functions, both hooked to `admin_init`. The `admin_init` hook fires on `admin-post.php` which is accessible without authentication. This makes it possible for unauthenticated attackers to overwrite the site's Stripe API credentials with attacker-controlled values (redirecting payments to the attacker's Stripe account) or disconnect the Stripe integration entirely by deleting the stored credentials."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"saadiqbal","product":"WPFormify – Stripe Payments with Form and Checkout","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"1.1.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L","baseScore":8.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":4.2}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-862"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/wpformify/tags/1.1.1/modules/payments/stripe_authorization.php#L49","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/wpformify/tags/1.1.1/modules/payments/stripe_authorization.php#L79","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?new=3557764%40wpformify%2Ftags%2F1.1.2&old=3299310%40wpformify/tags","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/44cd696c-fff3-4942-b2c9-628ba281ba44?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-6639","sourceIdentifier":"security@wordfence.com","published":"2026-08-05T08:16:41.427","lastModified":"2026-08-05T08:16:41.427","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.6. This is due to the `getCurrentTaskResults()` method in `modules/workspace/controller.php` being accessible without authentication or authorization checks. The method is not included in the workspace controller's `getNoncedMethods()` array, the base `getPermissions()` returns an empty array, and all AJAX actions are registered with `wp_ajax_nopriv_` hooks (`classes/frame.php:282`). When tasks are created via features like the Bulk Post Generator, the task parameters — including the OpenAI API key in plaintext, AI prompts, keywords, and full AI model configuration — are stored in the database and returned in the JSON response. This makes it possible for unauthenticated attackers to enumerate sequential task IDs and retrieve sensitive configuration data including API keys."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"wupsales","product":"AI Copilot – Content Generator","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"1.4.6","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-862"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/ai-copilot-content-generator/tags/1.4.6/classes/frame.php#L282","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/ai-copilot-content-generator/tags/1.4.6/modules/workspace/controller.php#L83","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/ai-copilot-content-generator/tags/1.4.6/modules/workspace/models/tasks.php#L106","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?new=3528734%40ai-copilot-content-generator%2Ftrunk&old=3525474%40ai-copilot-content-generator%2Ftrunk","source":"security@wordfence.com"},{"url":"https://wordpress.org/plugins/ai-copilot-content-generator/","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/247b1921-70a6-4e65-819a-2895bc395e9f?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-6972","sourceIdentifier":"security@wordfence.com","published":"2026-08-05T08:16:41.560","lastModified":"2026-08-05T08:16:41.560","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The SKT Skill Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `chart_size` attribute of the `skillwrapper` shortcode in all versions up to, and including, 2.6. This is due to insufficient input sanitization and output escaping on the `chart_size` attribute, which is concatenated directly into an inline `<style>` block. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"sonalsinha21","product":"SKT Skill Bar","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"2.6","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":2.7}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/skt-skill-bar/tags/2.6/sktskillbar.php#L240","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/skt-skill-bar/tags/2.6/sktskillbar.php#L541","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/skt-skill-bar/tags/2.6/sktskillbar.php#L56","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/skt-skill-bar/trunk/sktskillbar.php#L240","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?reponame=&new=3565730%40skt-skill-bar%2Ftrunk&old=3565726%40skt-skill-bar%2Ftrunk","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/eb689760-837f-45e6-ba51-a834053be6ae?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-7441","sourceIdentifier":"security@wordfence.com","published":"2026-08-05T08:16:44.247","lastModified":"2026-08-05T08:16:44.247","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Simple Yearly Archive plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `posttype` attribute of the `SimpleYearlyArchive` shortcode in all versions up to, and including, 2.2.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"alphawolf","product":"Simple Yearly Archive","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"2.2.4","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":2.7}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/simple-yearly-archive/tags/2.2.4/simple-yearly-archive.php#L135","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/simple-yearly-archive/tags/2.2.4/simple-yearly-archive.php#L502","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/simple-yearly-archive/trunk/simple-yearly-archive.php#L135","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?new=3525626%40simple-yearly-archive%2Ftrunk&old=3461850%40simple-yearly-archive%2Ftrunk","source":"security@wordfence.com"},{"url":"https://wordpress.org/plugins/simple-yearly-archive","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/e6b35dc7-bd1d-4cdd-808f-41cf2ebfbb1e?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-7693","sourceIdentifier":"security@wordfence.com","published":"2026-08-05T08:16:44.703","lastModified":"2026-08-05T08:16:44.703","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all versions up to, and including, 2.1.5.1 due to insufficient sanitization of the `file` POST parameter on the `restoreBackup()` AJAX handler. The handler applies `esc_attr()` — an HTML-context sanitizer that does not strip shell metacharacters — and concatenates the result, unquoted, into a `php-cli -f … bmi_restore <file> <remote>` command passed to `exec()`. This makes it possible for authenticated attackers, with Administrator-level access (or any user granted the plugin's `do_backups` capability) and above, to execute arbitrary OS commands as the web-server user, bypassing WordPress hardening constants such as `DISALLOW_FILE_EDIT` and `DISALLOW_FILE_MODS` that would otherwise prevent code execution from the admin UI. This is an incomplete fix of CVE-2023-7002, which patched the same pattern only in the `$_POST['url']` path of `handleQuickMigration()`; the equivalent mitigations (`rawurlencode()` + explicit shell-metachar replacement + double-quoting in `exec()`) were never applied to `$backupName`."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"inisev","product":"Backup Migration","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"2.1.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":7.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.2,"impactScore":5.9}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-77"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/backup-backup/tags/2.1.5.1/includes/ajax.php#L3019","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/backup-backup/tags/2.1.5.1/includes/ajax.php#L3025","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/backup-backup/tags/2.1.5.1/includes/ajax.php#L3422","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/backup-backup/tags/2.1.5.1/includes/ajax.php#L3444","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/backup-backup/tags/2.1.5.1/includes/initializer.php#L136","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/backup-backup/trunk/includes/ajax.php#L3025","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?new=3540041%40backup-backup%2Ftags%2F2.1.5.2&old=3512153%40backup-backup%2Ftags%2F2.1.5.1","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/af6a7052-6dab-42f0-a2af-0cf459d309d7?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-7726","sourceIdentifier":"security@wordfence.com","published":"2026-08-05T08:16:44.840","lastModified":"2026-08-05T08:16:44.840","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Layouts for WPBakery plugin for WordPress is vulnerable to unauthorized actions due to a missing capability check on the `Layouts_WPB_Remote::template_sync()` callback registered via `wp_ajax_nopriv_handle_sync` in all versions up to, and including, 1.1.3. This makes it possible for unauthenticated attackers to force the WordPress server to issue outbound HTTP requests to the plugin vendor's external API (`https://www.layoutsforwpbakery.com/wp-json/layoutsforwpbakery/v1/{templates,categories}`) and to write the JSON-decoded responses verbatim into the site's `wp_options` table via `set_transient()` — at any rate the attacker chooses, with no nonce verification, capability check, or rate limiting."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"techeshta","product":"Layouts for WPBakery","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"1.1.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":2.5}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-862"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/layouts-for-wpbakery/trunk/includes/api/class-layouts-remote.php#L46","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/layouts-for-wpbakery/trunk/includes/api/class-layouts-remote.php#L53","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/layouts-for-wpbakery/trunk/includes/class-layout-importer.php#L25","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?new=3543686%40layouts-for-wpbakery%2Ftrunk&old=3543685%40layouts-for-wpbakery%2Ftrunk","source":"security@wordfence.com"},{"url":"https://wordpress.org/plugins/layouts-for-wpbakery/","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2beaf82f-3709-48de-bcc2-535479c4fafe?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-10059","sourceIdentifier":"secalert@redhat.com","published":"2026-08-05T09:18:13.720","lastModified":"2026-08-05T09:18:13.720","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namespace-scoped privileges can exploit this vulnerability by creating a namespaced ClusterCurator. This action inadvertently grants the tenant administrator the ability to mint a token for a ServiceAccount with cluster-wide administrative authority. This leads to a privilege escalation, allowing the tenant administrator to gain full control over the cluster."}],"affected":[{"source":"secalert@redhat.com","affectedData":[{"vendor":"Red Hat","product":"Multicluster Engine for Kubernetes","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"multicluster-engine/cluster-curator-controller-rhel9","cpes":["cpe:/a:redhat:multicluster_engine"]}]}],"metrics":{"cvssMetricV31":[{"source":"secalert@redhat.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H","baseScore":9.1,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.3,"impactScore":6.0}]},"weaknesses":[{"source":"secalert@redhat.com","type":"Primary","description":[{"lang":"en","value":"CWE-266"}]}],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-10059","source":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2483187","source":"secalert@redhat.com"}]}},{"cve":{"id":"CVE-2026-10090","sourceIdentifier":"secalert@redhat.com","published":"2026-08-05T09:18:14.667","lastModified":"2026-08-05T09:18:14.667","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cluster Management for Kubernetes (ACM). A user with namespace-scoped \"edit\" privileges in an ACM hub namespace can create a Channel resource pointing to a Helm repository they control and a Subscription resource referencing it. The app-subscription controller fetches and applies the Helm chart contents with its own elevated authority, without verifying whether the subscription creator holds the \"open-cluster-management:subscription-admin\" role and without restricting applied resources to the subscription namespace. This allows the attacker to include cluster-scoped resources in the Helm chart, such as a ClusterRoleBinding granting the attacker's ServiceAccount the \"cluster-admin\" ClusterRole. Successful exploitation results in full cluster-admin privilege escalation. This contradicts the ACM documentation which states that non-subscription-admin users should have resources deployed into the subscription namespace only."}],"affected":[{"source":"secalert@redhat.com","affectedData":[{"vendor":"Red Hat","product":"Red Hat Advanced Cluster Management for Kubernetes 2","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhacm2/multicluster-operators-subscription-rhel9","cpes":["cpe:/a:redhat:acm:2"]}]}],"metrics":{"cvssMetricV31":[{"source":"secalert@redhat.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","baseScore":9.9,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.1,"impactScore":6.0}]},"weaknesses":[{"source":"secalert@redhat.com","type":"Primary","description":[{"lang":"en","value":"CWE-267"}]}],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-10090","source":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2483292","source":"secalert@redhat.com"}]}}]}