{"resultsPerPage":514,"startIndex":0,"totalResults":514,"format":"NVD_CVE","version":"2.0","timestamp":"2026-09-05T17:33:43.513","vulnerabilities":[{"cve":{"id":"CVE-2026-74235","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-04T13:20:08.217","lastModified":"2026-09-04T16:17:57.137","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"GFI Exinda AI and ClearView before 7.6.5 contains a path traversal vulnerability in the system maintenance configuration download handler. The wcf_handle_download() function accepts parameters prefixed with v_del_ and appends their values directly to the base configuration directory path without sanitizing for directory traversal sequences. An authenticated attacker with Admin privileges can read arbitrary files from the system in the context of root."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"GFI Software","product":"GFI Exinda AI","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"7.6.5","versionType":"semver","status":"affected"}]},{"vendor":"GFI Software","product":"GFI ClearView","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"7.6.5","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":6.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"HIGH","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N","baseScore":4.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":3.6}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-22"}]}],"references":[{"url":"https://gfi.ai/products-and-solutions/network-management-solutions/exinda-networkorchestrator/resources/documentation/product-releases","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/gfi-exinda-ai-clearview-path-traversal-via-configuration-download-handler","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-74236","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-04T13:20:08.420","lastModified":"2026-09-04T16:17:57.257","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"GFI Exinda AI and ClearView before 7.6.5 contains a path traversal vulnerability in the diagnostic file deletion handler. The unlink_or_email_file() function accepts parameters prefixed with v_file_row_ and appends their values directly to a base directory path without sanitizing for directory traversal sequences. An authenticated attacker with Admin privileges can delete arbitrary files from the system in the context of root."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"GFI Software","product":"GFI Exinda AI","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"7.6.5","versionType":"semver","status":"affected"}]},{"vendor":"GFI Software","product":"GFI ClearView","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"7.6.5","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":7.0,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"HIGH","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.2,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T13:03:03.552824Z","id":"CVE-2026-74236","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-22"}]}],"references":[{"url":"https://gfi.ai/products-and-solutions/network-management-solutions/exinda-networkorchestrator/resources/documentation/product-releases","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/gfi-exinda-ai-clearview-path-traversal-via-diagnostic-file-deletion-handler","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-74237","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-04T13:20:08.607","lastModified":"2026-09-04T16:17:57.710","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"GFI Exinda AI and ClearView before 7.6.5 contains an argument injection vulnerability in the Tools Iperf Client functionality. The web_tools_cmd() function constructs an iperf command using the server and options parameters without sanitization, permitting injection of arbitrary iperf flags. An authenticated attacker with Unprivileged (lowest-level) access can supply the iperf -F flag to read an arbitrary file from the system and transmit its contents to an attacker-controlled server."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"GFI Software","product":"GFI Exinda AI","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"7.6.5","versionType":"semver","status":"affected"}]},{"vendor":"GFI Software","product":"GFI ClearView","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"7.6.5","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-88"}]}],"references":[{"url":"https://gfi.ai/products-and-solutions/network-management-solutions/exinda-networkorchestrator/resources/documentation/product-releases","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/gfi-exinda-ai-clearview-argument-injection-via-tools-iperf-client","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-82309","sourceIdentifier":"9b29abf9-4ab0-4765-b253-1875cd9b441e","published":"2026-09-04T13:20:10.667","lastModified":"2026-09-04T15:17:35.840","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Robots::Validate versions from 0.3.2 before 0.3.11 for Perl allow unbounded outbound DNS queries per validation via a forward-confirmation loop that does not bound the names it queries.\n\n_check_dns issues one PTR query for the client address, keeps the returned names matching the rule's domain, and issues a forward query for each until one resolves back to that address. Nothing bounds that list, and a client controls the reverse zone for its own address, so it chooses how many names the PTR answer holds. Net::DNS refetches a truncated answer over TCP by default, so the 512-byte UDP payload does not cap it either.\n\nAny client whose User-Agent matches a rule with a domain reaches _check_dns. Each forward name is distinct and client-chosen, so every query misses the local cache and is resolved against the authoritative servers for that domain. The queries are synchronous, so the caller is held until all of them answer or time out."}],"affected":[{"source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","affectedData":[{"defaultStatus":"unaffected","collectionURL":"https://cpan.org/modules","packageName":"Robots-Validate","modules":["Robots::Validate"],"programFiles":["lib/Robots/Validate.pm"],"programRoutines":[{"name":"Robots::Validate::_check_dns"}],"repo":"https://github.com/robrwo/Robots-Validate","packageURL":"pkg:cpan/Robots-Validate","versions":[{"version":"0.3.2","lessThan":"0.3.11","versionType":"custom","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"9b29abf9-4ab0-4765-b253-1875cd9b441e","type":"Secondary","description":[{"lang":"en","value":"CWE-405"},{"lang":"en","value":"CWE-770"}]}],"references":[{"url":"https://github.com/robrwo/Robots-Validate/commit/6426178c49ff6c440922f31a92a6feb3c661b143.patch","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"url":"https://github.com/robrwo/Robots-Validate/security/advisories/GHSA-6399-5qhh-48h5","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"url":"https://metacpan.org/release/RRWO/Robots-Validate-v0.4.0/changes","source":"9b29abf9-4ab0-4765-b253-1875cd9b441e"},{"url":"http://www.openwall.com/lists/oss-security/2026/09/04/3","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2026-85513","sourceIdentifier":"cna@vuldb.com","published":"2026-09-04T13:20:11.130","lastModified":"2026-09-04T13:22:24.073","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"A weakness has been identified in StackStorm st2 up to 3.9.0. This issue affects the function assert_user_is_admin_if_user_query_param_is_provided of the file st2api/st2api/controllers/v1/actionexecutions.py of the component NoOp RBAC backend. This manipulation of the argument User causes improper privilege management. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. Prior advisory CVE-2022-44009 was reported as a follow-up on the same sink, but this issue is distinct: it needs no Jinja RBAC und affects default install with RBAC disabled. The project was informed of the problem early through an issue report but has not responded yet."}],"affected":[{"source":"cna@vuldb.com","affectedData":[{"vendor":"StackStorm","product":"st2","cpes":["cpe:2.3:a:stackstorm:st2:*:*:*:*:*:*:*:*"],"modules":["NoOp RBAC backend"],"versions":[{"version":"3.0","status":"affected"},{"version":"3.1","status":"affected"},{"version":"3.2","status":"affected"},{"version":"3.3","status":"affected"},{"version":"3.4","status":"affected"},{"version":"3.5","status":"affected"},{"version":"3.6","status":"affected"},{"version":"3.7","status":"affected"},{"version":"3.8","status":"affected"},{"version":"3.9.0","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":2.1,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"LOW","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"PROOF_OF_CONCEPT","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"cna@vuldb.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","baseScore":6.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":3.4}],"cvssMetricV2":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"cna@vuldb.com","type":"Primary","description":[{"lang":"en","value":"CWE-266"},{"lang":"en","value":"CWE-269"}]}],"references":[{"url":"https://github.com/StackStorm/st2/","source":"cna@vuldb.com"},{"url":"https://github.com/StackStorm/st2/issues/6379","source":"cna@vuldb.com"},{"url":"https://vuldb.com/cve/CVE-2026-85513","source":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/894916","source":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/398678","source":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/398678/cti","source":"cna@vuldb.com"}]}},{"cve":{"id":"CVE-2026-85514","sourceIdentifier":"cna@vuldb.com","published":"2026-09-04T13:20:11.300","lastModified":"2026-09-04T18:18:03.303","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"A security vulnerability has been detected in StackStorm st2 up to 3.9.0. Impacted is an unknown function of the file st2api/st2api/controllers/v1/auth.py of the component API Key Handler. Such manipulation of the argument api_key_api.user leads to improper privilege management. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet."}],"affected":[{"source":"cna@vuldb.com","affectedData":[{"vendor":"StackStorm","product":"st2","cpes":["cpe:2.3:a:stackstorm:st2:*:*:*:*:*:*:*:*"],"modules":["API Key Handler"],"versions":[{"version":"3.0","status":"affected"},{"version":"3.1","status":"affected"},{"version":"3.2","status":"affected"},{"version":"3.3","status":"affected"},{"version":"3.4","status":"affected"},{"version":"3.5","status":"affected"},{"version":"3.6","status":"affected"},{"version":"3.7","status":"affected"},{"version":"3.8","status":"affected"},{"version":"3.9.0","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":2.1,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"LOW","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"PROOF_OF_CONCEPT","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","baseScore":6.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":3.4}],"cvssMetricV2":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T17:59:53.644606Z","id":"CVE-2026-85514","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cna@vuldb.com","type":"Secondary","description":[{"lang":"en","value":"CWE-266"},{"lang":"en","value":"CWE-269"}]}],"references":[{"url":"https://github.com/StackStorm/st2/","source":"cna@vuldb.com"},{"url":"https://github.com/StackStorm/st2/issues/6380","source":"cna@vuldb.com"},{"url":"https://vuldb.com/cve/CVE-2026-85514","source":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/894917","source":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/398679","source":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/398679/cti","source":"cna@vuldb.com"},{"url":"https://github.com/StackStorm/st2/issues/6380","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}]}},{"cve":{"id":"CVE-2026-85516","sourceIdentifier":"cna@vuldb.com","published":"2026-09-04T13:20:11.470","lastModified":"2026-09-04T13:22:24.073","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability was detected in code-projects Vehicle Management System 1.0. The affected element is an unknown function of the file /busprofile.php. Performing a manipulation of the argument busid results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used."}],"affected":[{"source":"cna@vuldb.com","affectedData":[{"vendor":"code-projects","product":"Vehicle Management System","cpes":["cpe:2.3:a:code-projects:vehicle_management_system:*:*:*:*:*:*:*:*"],"versions":[{"version":"1.0","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"LOW","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"PROOF_OF_CONCEPT","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"cna@vuldb.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","baseScore":7.3,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":3.4}],"cvssMetricV2":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"cna@vuldb.com","type":"Primary","description":[{"lang":"en","value":"CWE-74"},{"lang":"en","value":"CWE-89"}]}],"references":[{"url":"https://code-projects.org/","source":"cna@vuldb.com"},{"url":"https://github.com/ahmadmarz10-hub/CVEsMarz/blob/main/SQL%20Injection%20Vulnerability%20in%20Vehicle%20Management%20System%20%60busid%60%20Parameter.md","source":"cna@vuldb.com"},{"url":"https://vuldb.com/cve/CVE-2026-85516","source":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/895112","source":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/398680","source":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/398680/cti","source":"cna@vuldb.com"}]}},{"cve":{"id":"CVE-2026-85649","sourceIdentifier":"5a6e4751-2f3f-4070-9419-94fb35b644e8","published":"2026-09-04T13:20:11.760","lastModified":"2026-09-04T18:18:05.730","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"(Holloway) Chew, Kean Ho's Actualizer v1.2.0 and earlier contains a fail-open password validation vulnerability in the Alpha user and root user password loops of Shell/debian-minbase-install.sh. The installer invokes mkpasswd to generate yescrypt password hashes but does not check the command's return value and unconditionally accepts the result. If mkpasswd fails to generate a yescrypt hash, for example because an incompatible mkpasswd implementation or an environment without yescrypt support is used, the resulting password hash variable can be empty and the build proceeds. The resulting image can therefore contain empty password fields for the root and alpha accounts, potentially permitting passwordless authentication depending on the authentication configuration."}],"affected":[{"source":"5a6e4751-2f3f-4070-9419-94fb35b644e8","affectedData":[{"vendor":"chewkeanho","product":"software-actualizer","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"1.2.0","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"5a6e4751-2f3f-4070-9419-94fb35b644e8","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N","baseScore":7.9,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.5,"impactScore":5.8}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T17:59:16.199359Z","id":"CVE-2026-85649","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"5a6e4751-2f3f-4070-9419-94fb35b644e8","type":"Secondary","description":[{"lang":"en","value":"CWE-252"},{"lang":"en","value":"CWE-636"}]}],"references":[{"url":"https://doi.org/10.5281/zenodo.22169659","source":"5a6e4751-2f3f-4070-9419-94fb35b644e8"},{"url":"https://github.com/ChewKeanHo/software-actualizer/blob/v1.2.0/Shell/debian-minbase-install.sh#L788","source":"5a6e4751-2f3f-4070-9419-94fb35b644e8"},{"url":"https://github.com/ChewKeanHo/software-actualizer/commit/50a0932ac705635d9af62955c353e7c6df003a61.patch","source":"5a6e4751-2f3f-4070-9419-94fb35b644e8"},{"url":"https://github.com/ChewKeanHo/software-actualizer/releases/tag/v1.2.1","source":"5a6e4751-2f3f-4070-9419-94fb35b644e8"}]}},{"cve":{"id":"CVE-2026-12483","sourceIdentifier":"security@wordfence.com","published":"2026-09-04T14:17:17.480","lastModified":"2026-09-04T18:17:46.777","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The LearnDash LMS plugin for WordPress is vulnerable to Unrestricted File Type Upload in versions up to and including 5.1.5. This is due to insufficient input validation in the 'learndash_fileupload_process' function, which iterates through an entire array and validates only the first file. This makes it possible for authenticated attackers, with subscriber-level access and above who are enrolled in a course with assignment uploads enabled, to upload arbitrary disallowed files, including PHP files, to the server's wp-content/uploads/learndash/assignments/ directory. The uploaded files can only be used for Remote Code Execution if default server configurations have been changed to allow for execution."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"StellarWP","product":"LearnDash LMS","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"5.1.5","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.6,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T17:56:47.329965Z","id":"CVE-2026-12483","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@wordfence.com","type":"Secondary","description":[{"lang":"en","value":"CWE-434"}]}],"references":[{"url":"https://www.liquidweb.com/software/learndash/","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a539ba27-ad9b-4fe6-8df4-71e262c7b158?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-19057","sourceIdentifier":"iletisim@usom.gov.tr","published":"2026-09-04T14:17:17.963","lastModified":"2026-09-04T18:17:50.810","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Gastromenum Gastromenum Ticket and QR Menu System allows Stored XSS.\n\nThis issue affects Gastromenum Ticket and QR Menu System: before 2026.08.31."}],"affected":[{"source":"iletisim@usom.gov.tr","affectedData":[{"vendor":"Gastromenum","product":"Gastromenum Ticket and QR Menu System","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"2026.08.31","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"iletisim@usom.gov.tr","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T17:21:59.410982Z","id":"CVE-2026-19057","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"iletisim@usom.gov.tr","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-1012","source":"iletisim@usom.gov.tr"}]}},{"cve":{"id":"CVE-2026-19081","sourceIdentifier":"iletisim@usom.gov.tr","published":"2026-09-04T14:17:18.193","lastModified":"2026-09-04T18:17:50.993","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Missing Authorization vulnerability in Gastromenum Gastromenum Ticket and QR Menu System allows Accessing Functionality Not Properly Constrained by ACLs.\n\nThis issue affects Gastromenum Ticket and QR Menu System: before 2026.08.31."}],"affected":[{"source":"iletisim@usom.gov.tr","affectedData":[{"vendor":"Gastromenum","product":"Gastromenum Ticket and QR Menu System","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"2026.08.31","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"iletisim@usom.gov.tr","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T17:21:36.496904Z","id":"CVE-2026-19081","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"iletisim@usom.gov.tr","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]}],"references":[{"url":"https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-1012","source":"iletisim@usom.gov.tr"}]}},{"cve":{"id":"CVE-2026-52691","sourceIdentifier":"security@apache.org","published":"2026-09-04T14:17:19.417","lastModified":"2026-09-04T15:17:33.603","vulnStatus":"Received","cveTags":[{"sourceIdentifier":"security@apache.org","tags":["unsupported-when-assigned"]}],"descriptions":[{"lang":"en","value":"** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Griffin Hive Metastore Module. \n\n\n\nThis issue affects Apache Griffin Hive Metastore Module: all versions.\n\n\n\nAs this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users.\n\n\n\nNOTE: This vulnerability only affects products that are no longer supported by the maintainer."}],"affected":[{"source":"security@apache.org","affectedData":[{"vendor":"Apache Software Foundation","product":"Apache Griffin Hive Metastore Module","defaultStatus":"unaffected","collectionURL":"https://repo.maven.apache.org/maven2","packageName":"org.apache.griffin:service","versions":[{"version":"0","lessThanOrEqual":"*","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-89"}]}],"references":[{"url":"https://lists.apache.org/thread/ocjolvzl804qlkto2vx685f8o23vxxlo","source":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/09/04/4","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2026-77818","sourceIdentifier":"iletisim@usom.gov.tr","published":"2026-09-04T14:17:19.900","lastModified":"2026-09-04T18:17:56.100","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. Library Information and Document Automation Program allows Content Spoofing.\n\nThis issue affects Library Information and Document Automation Program: from v22.1 before v22.2."}],"affected":[{"source":"iletisim@usom.gov.tr","affectedData":[{"vendor":"Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc.","product":"Library Information and Document Automation Program","defaultStatus":"unaffected","versions":[{"version":"v22.1","lessThan":"v22.2","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"iletisim@usom.gov.tr","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T17:22:22.334961Z","id":"CVE-2026-77818","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"iletisim@usom.gov.tr","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-1011","source":"iletisim@usom.gov.tr"}]}},{"cve":{"id":"CVE-2026-85517","sourceIdentifier":"cna@vuldb.com","published":"2026-09-04T14:17:22.633","lastModified":"2026-09-04T18:18:03.433","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"A flaw has been found in code-projects Vehicle Management System 1.0. The impacted element is an unknown function of the file /vehicle_management.sql of the component SQL Database Backup File Handler. Executing a manipulation can lead to information disclosure. It is possible to launch the attack remotely. The exploit has been published and may be used."}],"affected":[{"source":"cna@vuldb.com","affectedData":[{"vendor":"code-projects","product":"Vehicle Management System","cpes":["cpe:2.3:a:code-projects:vehicle_management_system:*:*:*:*:*:*:*:*"],"modules":["SQL Database Backup File Handler"],"versions":[{"version":"1.0","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"PROOF_OF_CONCEPT","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T18:05:05.688359Z","id":"CVE-2026-85517","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cna@vuldb.com","type":"Secondary","description":[{"lang":"en","value":"CWE-200"},{"lang":"en","value":"CWE-284"}]}],"references":[{"url":"https://code-projects.org/","source":"cna@vuldb.com"},{"url":"https://github.com/ahmadmarz10-hub/CVEsMarz/blob/main/Vehicle%20Management%20System%20in%20PHP%20%E2%80%93%20Sensitive%20Information%20Disclosure%20via%20Exposed%20Database%20File.md","source":"cna@vuldb.com"},{"url":"https://vuldb.com/cve/CVE-2026-85517","source":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/895113","source":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/398681","source":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/398681/cti","source":"cna@vuldb.com"}]}},{"cve":{"id":"CVE-2026-85522","sourceIdentifier":"cna@vuldb.com","published":"2026-09-04T14:17:22.807","lastModified":"2026-09-04T16:18:18.310","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability was detected in valkey-io valkey up to 9.5.4/9.1.0. Affected by this vulnerability is the function createSlotImportJob of the file src/cluster_migrateslots.c of the component Slot Migration. The manipulation of the argument job_name results in out-of-bounds read. The attack can be executed remotely. The exploit is now public and may be used. Upgrading to version 9.0.5 and 9.1.1 addresses this issue. The patch is identified as f4dc3ca09eb650c2fe14060090a41c524eca803f. Upgrading the affected component is advised."}],"affected":[{"source":"cna@vuldb.com","affectedData":[{"vendor":"valkey-io","product":"valkey","cpes":["cpe:2.3:a:valkey-io:valkey:*:*:*:*:*:*:*:*"],"modules":["Slot Migration"],"versions":[{"version":"9.0","status":"affected"},{"version":"9.1.0","status":"affected"},{"version":"9.5.0","status":"affected"},{"version":"9.5.1","status":"affected"},{"version":"9.5.2","status":"affected"},{"version":"9.5.3","status":"affected"},{"version":"9.5.4","status":"affected"},{"version":"9.0.5","status":"unaffected"},{"version":"9.1.1","status":"unaffected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"LOW","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"PROOF_OF_CONCEPT","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T16:01:32.851377Z","id":"CVE-2026-85522","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cna@vuldb.com","type":"Secondary","description":[{"lang":"en","value":"CWE-119"},{"lang":"en","value":"CWE-125"}]}],"references":[{"url":"https://github.com/valkey-io/valkey/","source":"cna@vuldb.com"},{"url":"https://github.com/valkey-io/valkey/commit/f4dc3ca09eb650c2fe14060090a41c524eca803f","source":"cna@vuldb.com"},{"url":"https://github.com/valkey-io/valkey/issues/4207","source":"cna@vuldb.com"},{"url":"https://github.com/valkey-io/valkey/pull/4210","source":"cna@vuldb.com"},{"url":"https://github.com/valkey-io/valkey/releases/tag/9.1.1","source":"cna@vuldb.com"},{"url":"https://vuldb.com/cve/CVE-2026-85522","source":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/895119","source":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/398707","source":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/398707/cti","source":"cna@vuldb.com"}]}},{"cve":{"id":"CVE-2026-14466","sourceIdentifier":"cert@airbus.com","published":"2026-09-04T15:17:32.540","lastModified":"2026-09-04T15:17:32.540","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"It’s possible to run a stored XSS in Stormshield’s web administration panel.\n\n\n\nTo exploit this vulnerability, a SNS administrator with appropriate permissions must inject  some malicious script in a group’s comments in the webservices administration interface."}],"affected":[{"source":"cert@airbus.com","affectedData":[{"vendor":"Stormshield","product":"Stormshield Network Security","defaultStatus":"unknown","versions":[{"version":"4.8.0","lessThanOrEqual":"4.8.16","versionType":"semver","status":"affected"},{"version":"5.0.0","lessThanOrEqual":"5.0.6","versionType":"semver","status":"affected"},{"version":"4.8.17","versionType":"semver","status":"unaffected"},{"version":"5.0.7","versionType":"semver","status":"unaffected"},{"version":"5.1.0","versionType":"semver","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cert@airbus.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":0.7,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T14:40:47.477086Z","id":"CVE-2026-14466","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cert@airbus.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://advisories.stormshield.eu/2026-006","source":"cert@airbus.com"}]}},{"cve":{"id":"CVE-2026-19205","sourceIdentifier":"iletisim@usom.gov.tr","published":"2026-09-04T15:17:33.360","lastModified":"2026-09-04T18:17:51.130","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Observable response discrepancy vulnerability in GastroMenum GastroMenum Web Panel allows Account Footprinting.\n\nThis issue affects GastroMenum Web Panel: before 31.08.2026."}],"affected":[{"source":"iletisim@usom.gov.tr","affectedData":[{"vendor":"GastroMenum","product":"GastroMenum Web Panel","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"31.08.2026","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"iletisim@usom.gov.tr","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T17:20:50.611576Z","id":"CVE-2026-19205","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"iletisim@usom.gov.tr","type":"Secondary","description":[{"lang":"en","value":"CWE-204"}]}],"references":[{"url":"https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-1013","source":"iletisim@usom.gov.tr"}]}},{"cve":{"id":"CVE-2026-19727","sourceIdentifier":"iletisim@usom.gov.tr","published":"2026-09-04T15:17:33.480","lastModified":"2026-09-04T18:17:51.787","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. Library Information and Document Automation Program allows XSS Targeting HTML Attributes.\n\nThis issue affects Library Information and Document Automation Program: before v22.2."}],"affected":[{"source":"iletisim@usom.gov.tr","affectedData":[{"vendor":"Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc.","product":"Library Information and Document Automation Program","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"v22.2","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"iletisim@usom.gov.tr","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T17:21:13.929230Z","id":"CVE-2026-19727","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"iletisim@usom.gov.tr","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-1011","source":"iletisim@usom.gov.tr"}]}},{"cve":{"id":"CVE-2026-6958","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-04T15:17:35.360","lastModified":"2026-09-04T16:17:57.010","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Acunetix 25.11.251107123 for Windows contains a local privilege escalation vulnerability in the Web Vulnerability Scanning Engine (wvsc.exe) that allows low-privileged local attackers to execute arbitrary code as SYSTEM by exploiting a missing hardcoded directory path for OpenSSL-related files. Attackers can create the missing directory, place a malicious file at the expected path, and cause the SYSTEM-level wvsc.exe process to load and execute it, resulting in full privilege escalation."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"Invicti Security Corp.","product":"Acunetix","defaultStatus":"affected","versions":[{"version":"25.11.251107123","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.5,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-427"}]}],"references":[{"url":"https://olografix.org/acme/_poc/CVE-2026-6958.pdf","source":"disclosure@vulncheck.com"},{"url":"https://seclists.org/fulldisclosure/2026/Sep/0","source":"disclosure@vulncheck.com"},{"url":"https://www.acunetix.com/","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/acunetix-local-privilege-escalation-via-wvsc-exe","source":"disclosure@vulncheck.com"},{"url":"http://seclists.org/fulldisclosure/2026/Sep/0","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2026-81832","sourceIdentifier":"psirt@us.ibm.com","published":"2026-09-04T15:17:35.550","lastModified":"2026-09-04T16:18:15.863","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 SAP Adapter is vulnerable to an XML external entity (XXE) attack."}],"affected":[{"source":"psirt@us.ibm.com","affectedData":[{"vendor":"IBM","product":"App Connect Enterprise","cpes":["cpe:2.3:a:ibm:app_connect_enterprise:13.0.1.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:app_connect_enterprise:13.0.8.1:*:*:*:*:*:*:*","cpe:2.3:a:ibm:app_connect_enterprise:12.0.1.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:app_connect_enterprise:12.0.12.28:*:*:*:*:*:*:*"],"versions":[{"version":"13.0.1.0","lessThanOrEqual":"13.0.8.1","versionType":"semver","status":"affected"},{"version":"12.0.1.0","lessThanOrEqual":"12.0.12.28","versionType":"semver","status":"affected"}]},{"vendor":"IBM","product":"Integration Bus for z/OS","cpes":["cpe:2.3:a:ibm:integration_bus_for_zos:10.1.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:integration_bus_for_zos:10.1.0.7:*:*:*:*:*:*:*"],"versions":[{"version":"10.1.0.0","lessThanOrEqual":"10.1.0.7","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","baseScore":7.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":4.0}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T15:59:16.191502Z","id":"CVE-2026-81832","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"psirt@us.ibm.com","type":"Secondary","description":[{"lang":"en","value":"CWE-611"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7286372","source":"psirt@us.ibm.com"}]}},{"cve":{"id":"CVE-2026-81859","sourceIdentifier":"psirt@us.ibm.com","published":"2026-09-04T15:17:35.690","lastModified":"2026-09-04T19:17:29.113","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"CP4BA - IBM Enterprise Records could allow a local attacker to obtain sensitive information due to the use of a broken or risky cryptographic algorithm."}],"affected":[{"source":"psirt@us.ibm.com","affectedData":[{"vendor":"IBM","product":"Cloud Pak for Business Automation","cpes":["cpe:2.3:a:ibm:cloud_pak_for_business_automation:26.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:cloud_pak_for_business_automation:26.0.0:interim_fix_001:*:*:*:*:*:*","cpe:2.3:a:ibm:cloud_pak_for_business_automation:25.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:cloud_pak_for_business_automation:25.0.0:interim_fix_005:*:*:*:*:*:*","cpe:2.3:a:ibm:cloud_pak_for_business_automation:24.0.1:*:*:*:*:*:*:*","cpe:2.3:a:ibm:cloud_pak_for_business_automation:24.0.1:interim_fix_008:*:*:*:*:*:*","cpe:2.3:a:ibm:cloud_pak_for_business_automation:24.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:cloud_pak_for_business_automation:24.0.0:interim_fix_009:*:*:*:*:*:*"],"versions":[{"version":"26.0.0","lessThanOrEqual":"26.0.0 Interim Fix 001","versionType":"semver","status":"affected"},{"version":"25.0.0","lessThanOrEqual":"25.0.0 Interim Fix 005","versionType":"semver","status":"affected"},{"version":"24.0.1","lessThanOrEqual":"24.0.1 Interim Fix 008","versionType":"semver","status":"affected"},{"version":"24.0.0","lessThanOrEqual":"24.0.0 Interim Fix 009","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":6.2,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.5,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T17:39:54.654339Z","id":"CVE-2026-81859","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"psirt@us.ibm.com","type":"Secondary","description":[{"lang":"en","value":"CWE-327"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7285931","source":"psirt@us.ibm.com"}]}},{"cve":{"id":"CVE-2026-82728","sourceIdentifier":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db","published":"2026-09-04T15:17:35.943","lastModified":"2026-09-04T20:17:29.797","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint mint allows a remote HTTP server to exhaust memory on the client host and cause a denial of service.\n\nTwo HTTP/1 response-parser states accumulate server data without any cap. In lib/mint/http1.ex, decode_status_line/4 stores the unconsumed data in conn.buffer when the status line is incomplete, and decode_body/5 does the same for an unterminated chunk-extension line. Both wait for a CRLF the server never has to send, and conn.buffer is prepended to every subsequent socket message. The :max_header_list_size budget is wired only into decode_headers/5 and decode_trailer_headers/4, so neither of these states is covered by it. A malicious server, or one reached through an attacker-controlled redirect or a fetched URL, streams bytes indefinitely until the BEAM node is killed by the operating system out-of-memory handler. The chunk-extension variant is reached after a valid status line and a complete, valid header section, so an intermediary inspecting only headers sees an ordinary 200 response.\n\nThis issue affects mint: from 0.1.0 before 1.10.0."}],"affected":[{"source":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db","affectedData":[{"vendor":"elixir-mint","product":"mint","defaultStatus":"unaffected","collectionURL":"https://repo.hex.pm","packageName":"mint","cpes":["cpe:2.3:a:elixir-mint:mint:*:*:*:*:*:*:*:*"],"modules":["'Elixir.Mint.HTTP1'"],"programFiles":["lib/mint/http1.ex"],"programRoutines":[{"name":"'Elixir.Mint.HTTP1':decode_status_line/4"},{"name":"'Elixir.Mint.HTTP1':decode_body/5"}],"repo":"https://github.com/elixir-mint/mint","packageURL":"pkg:hex/mint","versions":[{"version":"0.1.0","lessThan":"1.10.0","versionType":"semver","status":"affected"}]},{"vendor":"elixir-mint","product":"mint","defaultStatus":"unaffected","collectionURL":"https://github.com","packageName":"elixir-mint/mint","cpes":["cpe:2.3:a:elixir-mint:mint:*:*:*:*:*:*:*:*"],"modules":["'Elixir.Mint.HTTP1'"],"programFiles":["lib/mint/http1.ex"],"programRoutines":[{"name":"'Elixir.Mint.HTTP1':decode_status_line/4"},{"name":"'Elixir.Mint.HTTP1':decode_body/5"}],"repo":"https://github.com/elixir-mint/mint","packageURL":"pkg:github/elixir-mint/mint","versions":[{"version":"c088e4b6430545338841ab8d294369e45d39856a","lessThan":"19be5558b6a317e271c78666498dd78b151e490a","versionType":"git","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T19:32:07.642690Z","id":"CVE-2026-82728","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"references":[{"url":"https://cna.erlef.org/cves/CVE-2026-82728.html","source":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db"},{"url":"https://github.com/elixir-mint/mint/commit/19be5558b6a317e271c78666498dd78b151e490a","source":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db"},{"url":"https://github.com/elixir-mint/mint/security/advisories/GHSA-g83f-2j6r-q6m4","source":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db"},{"url":"https://osv.dev/vulnerability/EEF-CVE-2026-82728","source":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db"},{"url":"https://github.com/elixir-mint/mint/security/advisories/GHSA-g83f-2j6r-q6m4","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}]}},{"cve":{"id":"CVE-2026-82729","sourceIdentifier":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db","published":"2026-09-04T15:17:36.120","lastModified":"2026-09-04T20:17:29.953","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Inefficient Algorithmic Complexity vulnerability in elixir-mint mint allows a remote HTTP server to exhaust CPU on the client host and cause a denial of service.\n\nparse_hex_prefix/2 in lib/mint/http1/parse.ex folds each hex digit of a chunked response's chunk-size field into an arbitrary-precision accumulator with acc * 16 + digit and imposes no limit on the digit count. Because the accumulator grows without bound, the multiplication is not constant time and one pass over N digits costs O(N squared). handle_data/2 prepends conn.buffer and re-parses from the start on every socket message, so a server that dribbles the digits out in small packets makes the client pay that cost repeatedly. A run of roughly 512,000 hex digits costs over ten seconds of CPU in a single pass, measured on stock defaults. The parser reaches this state after a valid status line and a complete, valid header section, so an intermediary inspecting only headers sees an ordinary 200 response.\n\nThis issue affects mint: from 1.9.3 before 1.10.0."}],"affected":[{"source":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db","affectedData":[{"vendor":"elixir-mint","product":"mint","defaultStatus":"unaffected","collectionURL":"https://repo.hex.pm","packageName":"mint","cpes":["cpe:2.3:a:elixir-mint:mint:*:*:*:*:*:*:*:*"],"modules":["'Elixir.Mint.HTTP1.Parse'","'Elixir.Mint.HTTP1'"],"programFiles":["lib/mint/http1/parse.ex","lib/mint/http1.ex"],"programRoutines":[{"name":"'Elixir.Mint.HTTP1.Parse':chunk_size/1"},{"name":"'Elixir.Mint.HTTP1':decode_body/5"}],"repo":"https://github.com/elixir-mint/mint","packageURL":"pkg:hex/mint","versions":[{"version":"1.9.3","lessThan":"1.10.0","versionType":"semver","status":"affected"}]},{"vendor":"elixir-mint","product":"mint","defaultStatus":"unaffected","collectionURL":"https://github.com","packageName":"elixir-mint/mint","cpes":["cpe:2.3:a:elixir-mint:mint:*:*:*:*:*:*:*:*"],"modules":["'Elixir.Mint.HTTP1.Parse'","'Elixir.Mint.HTTP1'"],"programFiles":["lib/mint/http1/parse.ex","lib/mint/http1.ex"],"programRoutines":[{"name":"'Elixir.Mint.HTTP1.Parse':chunk_size/1"},{"name":"'Elixir.Mint.HTTP1':decode_body/5"}],"repo":"https://github.com/elixir-mint/mint","packageURL":"pkg:github/elixir-mint/mint","versions":[{"version":"fc7d16538db7e40b56ed489f08683225cb0197fa","lessThan":"bd2a4e7513594997c140cfef9fe0e968712fb588","versionType":"git","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":6.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"LOW","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T19:33:08.928597Z","id":"CVE-2026-82729","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db","type":"Secondary","description":[{"lang":"en","value":"CWE-407"}]}],"references":[{"url":"https://cna.erlef.org/cves/CVE-2026-82729.html","source":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db"},{"url":"https://github.com/elixir-mint/mint/commit/bd2a4e7513594997c140cfef9fe0e968712fb588","source":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db"},{"url":"https://github.com/elixir-mint/mint/security/advisories/GHSA-7p8w-j234-7qc8","source":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db"},{"url":"https://osv.dev/vulnerability/EEF-CVE-2026-82729","source":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db"},{"url":"https://github.com/elixir-mint/mint/security/advisories/GHSA-7p8w-j234-7qc8","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}]}},{"cve":{"id":"CVE-2026-85605","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-04T15:17:41.233","lastModified":"2026-09-04T18:18:04.047","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Slink before 1.12.3 fails to properly authorize access to image comment endpoints, allowing unauthenticated attackers to read comment threads via GET /api/image/{imageId}/comments and server-sent-events subscriptions. Attackers who obtain image IDs out of band can retrieve full comment threads on public images and subscribe to live comment updates without authentication or authorization checks."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"andrii-kryvoviaz","product":"slink","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"1.12.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":6.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T17:45:50.205979Z","id":"CVE-2026-85605","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]}],"references":[{"url":"https://github.com/andrii-kryvoviaz/slink","source":"disclosure@vulncheck.com"},{"url":"https://github.com/andrii-kryvoviaz/slink/commit/221315b1ac51","source":"disclosure@vulncheck.com"},{"url":"https://github.com/andrii-kryvoviaz/slink/commit/fe04a7dffe8a7ed2f834f7364281a9414e394600","source":"disclosure@vulncheck.com"},{"url":"https://github.com/andrii-kryvoviaz/slink/releases/tag/v1.12.3","source":"disclosure@vulncheck.com"},{"url":"https://github.com/andrii-kryvoviaz/slink/security/advisories/GHSA-hxx4-4hwq-8258","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/slink-before-1.12.3-missing-authorization-on-image-comment-endpoints","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-85606","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-04T15:17:41.393","lastModified":"2026-09-04T15:17:41.393","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"firecrawl-mcp-server 3.20.2 contains an arbitrary local file read vulnerability in the firecrawl_parse tool that accepts unconstrained filePath arguments without directory containment validation. Attackers can supply absolute paths or directory traversal sequences to read sensitive files like credentials and environment variables, which are then uploaded and returned to the model context."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"firecrawl","product":"firecrawl-mcp-server","defaultStatus":"unaffected","packageURL":"pkg:npm/firecrawl-mcp","versions":[{"version":"0","lessThanOrEqual":"3.24.0","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Primary","description":[{"lang":"en","value":"CWE-22"}]}],"references":[{"url":"https://github.com/firecrawl/firecrawl-mcp-server","source":"disclosure@vulncheck.com"},{"url":"https://github.com/firecrawl/firecrawl-mcp-server/blob/v3.24.1/src/index.ts","source":"disclosure@vulncheck.com"},{"url":"https://github.com/firecrawl/firecrawl-mcp-server/issues/306","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/firecrawl-mcp-server-3.20.2-arbitrary-local-file-read-via-filepath","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-85607","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-04T15:17:41.547","lastModified":"2026-09-04T15:17:41.547","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Blinko 1.8.7 contains an authorization bypass (IDOR) vulnerability in multiple tRPC procedures (message.list, message.update, message.delete, message.clearAfter in server/routerTrpc/message.ts and conversation.clearMessages in server/routerTrpc/conversation.ts). Although these procedures require authentication, they query the database by caller-supplied conversation or message ID without verifying that the resource belongs to the requesting account. Any authenticated user can therefore read another user's full AI chat history, modify individual message content, and delete or wipe entire conversations by enumerating sequential integer IDs."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"blinkospace","product":"blinko","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"1.8.8","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Primary","description":[{"lang":"en","value":"CWE-639"}]}],"references":[{"url":"https://github.com/blinkospace/blinko","source":"disclosure@vulncheck.com"},{"url":"https://github.com/blinkospace/blinko/blob/1.8.8/server/routerTrpc/conversation.ts","source":"disclosure@vulncheck.com"},{"url":"https://github.com/blinkospace/blinko/blob/1.8.8/server/routerTrpc/message.ts","source":"disclosure@vulncheck.com"},{"url":"https://github.com/blinkospace/blinko/issues/1218","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/blinko-1.8.7-cross-user-ai-conversation-read-and-write-via-message-trpc-router","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-85608","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-04T15:17:41.707","lastModified":"2026-09-04T16:18:19.663","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Douyin_TikTok_Download_API through 4.1.2 contains a server-side request forgery vulnerability in the /api/download and /api/hybrid/video_data endpoints that allows unauthenticated attackers to fetch arbitrary URLs by supplying a url query parameter. Attackers can request internal services including cloud metadata endpoints and retrieve response bodies containing sensitive credentials through error messages."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"Evil0ctal","product":"Douyin_TikTok_Download_API","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"4.1.2","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T15:44:00.756964Z","id":"CVE-2026-85608","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-918"}]}],"references":[{"url":"https://github.com/Evil0ctal/Douyin_TikTok_Download_API","source":"disclosure@vulncheck.com"},{"url":"https://github.com/Evil0ctal/Douyin_TikTok_Download_API/blob/V4.1.2/crawlers/douyin/web/utils.py","source":"disclosure@vulncheck.com"},{"url":"https://github.com/Evil0ctal/Douyin_TikTok_Download_API/issues/729","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/douyin-tiktok-download-api-4.1.2-ssrf-via-url-parameter","source":"disclosure@vulncheck.com"},{"url":"https://github.com/Evil0ctal/Douyin_TikTok_Download_API/issues/729","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}]}},{"cve":{"id":"CVE-2026-85618","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-04T15:17:41.857","lastModified":"2026-09-04T15:17:41.857","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"ConvertX 0.17.0 contains an arbitrary file read vulnerability in the xelatex converter that allows authenticated users to read files by uploading LaTeX files with input directives. Attackers can upload .tex files containing \\\\input{path} or \\\\verbatiminput{path} directives to have the TeX engine read arbitrary files accessible to the server process and include them in downloadable PDF output."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"C4illin","product":"ConvertX","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"0.18.0","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Primary","description":[{"lang":"en","value":"CWE-22"}]}],"references":[{"url":"https://github.com/C4illin/ConvertX","source":"disclosure@vulncheck.com"},{"url":"https://github.com/C4illin/ConvertX/blob/v0.18.0/src/converters/xelatex.ts","source":"disclosure@vulncheck.com"},{"url":"https://github.com/C4illin/ConvertX/issues/573","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/convertx-0.17.0-arbitrary-file-read-via-latex-input-directives","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-85619","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-04T15:17:42.003","lastModified":"2026-09-04T18:18:04.773","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"AppFlowy-Cloud 0.9.64 fails to verify that requested collab objects belong to the workspace in authorization checks, allowing attackers to access documents and database rows across workspaces. Attackers can supply a victim's object ID with their own workspace ID to bypass access controls and read, modify, or delete cross-workspace data."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"AppFlowy-IO","product":"AppFlowy-Cloud","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"0.9.64","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":7.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","attackRequirements":"PRESENT","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.6,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T17:55:50.046578Z","id":"CVE-2026-85619","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]}],"references":[{"url":"https://github.com/AppFlowy-IO/AppFlowy-Cloud","source":"disclosure@vulncheck.com"},{"url":"https://github.com/AppFlowy-IO/AppFlowy-Cloud/blob/0.9.64/libs/access-control/src/casbin/collab.rs","source":"disclosure@vulncheck.com"},{"url":"https://github.com/AppFlowy-IO/AppFlowy-Cloud/issues/1624","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/appflowy-cloud-0.9.64-cross-workspace-collab-access-via-http-api","source":"disclosure@vulncheck.com"},{"url":"https://github.com/AppFlowy-IO/AppFlowy-Cloud/issues/1624","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}]}},{"cve":{"id":"CVE-2026-85620","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-04T15:17:42.150","lastModified":"2026-09-04T15:17:42.150","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Postgres MCP Pro 0.3.0 contains a restricted-mode bypass vulnerability where function-name validation is not applied to RangeFunction nodes in FROM clauses. Attackers can execute file-reading functions like pg_read_file through FROM-clause syntax to read arbitrary files despite restricted-mode protections."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"crystaldba","product":"postgres-mcp","defaultStatus":"unaffected","packageURL":"pkg:pypi/postgres-mcp","versions":[{"version":"0","lessThanOrEqual":"0.3.0","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":9.2,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"HIGH","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N","baseScore":8.6,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":4.0}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"references":[{"url":"https://github.com/crystaldba/postgres-mcp","source":"disclosure@vulncheck.com"},{"url":"https://github.com/crystaldba/postgres-mcp/blob/v0.3.0/src/postgres_mcp/sql/safe_sql.py","source":"disclosure@vulncheck.com"},{"url":"https://github.com/crystaldba/postgres-mcp/issues/178","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/postgres-mcp-pro-0.3.0-restricted-mode-bypass-via-from-clause-function","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-85621","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-04T15:17:42.293","lastModified":"2026-09-04T15:17:42.293","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"LobeChat (LobeHub) 2.2.1 does not properly verify inbound chat-platform webhook signatures in the QQ and Feishu adapters. The webhook route (/api/agent/webhooks/:platform) is unauthenticated by design and delegates verification to each adapter; the QQ adapter performs no Ed25519 signature verification on dispatched message events, and the Feishu adapter only performs an optional static-token comparison that is skipped when no token is configured (the default) and is not a body signature. An unauthenticated attacker who knows the public webhook URL can POST forged inbound messages with an attacker-chosen sender identity and arbitrary text, causing the bot owner's agent to process attacker-controlled input and treat the attacker as a trusted platform sender."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"lobehub","product":"lobehub","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"2.2.15","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":6.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":2.5}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Primary","description":[{"lang":"en","value":"CWE-345"}]}],"references":[{"url":"https://github.com/lobehub/lobehub","source":"disclosure@vulncheck.com"},{"url":"https://github.com/lobehub/lobehub/blob/v2.2.15/packages/chat-adapter-feishu/src/adapter.ts","source":"disclosure@vulncheck.com"},{"url":"https://github.com/lobehub/lobehub/blob/v2.2.15/packages/chat-adapter-qq/src/adapter.ts","source":"disclosure@vulncheck.com"},{"url":"https://github.com/lobehub/lobehub/issues/16538","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/lobechat-2.2.1-webhook-signature-verification-bypass-qq-feishu","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-85622","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-04T15:17:42.447","lastModified":"2026-09-04T16:18:20.110","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"AppFlowy-Cloud through 0.9.64 fails to validate workspace membership when establishing WebSocket connections in the establish_ws_connection_v2 handler, allowing authenticated users to bind sessions to workspaces they do not belong to. Attackers can send sync Manifest messages with victim object identifiers to read full document or database state from collaborations in other workspaces without victim involvement."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"AppFlowy-IO","product":"AppFlowy-Cloud","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"0.9.64","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":6.0,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","attackRequirements":"PRESENT","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T15:39:45.690714Z","id":"CVE-2026-85622","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]}],"references":[{"url":"https://github.com/AppFlowy-IO/AppFlowy-Cloud","source":"disclosure@vulncheck.com"},{"url":"https://github.com/AppFlowy-IO/AppFlowy-Cloud/blob/0.9.64/src/api/ws.rs","source":"disclosure@vulncheck.com"},{"url":"https://github.com/AppFlowy-IO/AppFlowy-Cloud/issues/1629","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/appflowy-cloud-through-0.9.64-cross-workspace-collab-read-via-websocket","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-85623","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-04T15:17:42.587","lastModified":"2026-09-04T15:17:42.587","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"goose 1.37.0 executes arbitrary commands from recipe stdio extensions and retry.checks without security inspection. Attackers can distribute malicious recipes that execute shell commands as the user running goose, bypassing the recipe security scan which does not inspect extensions or retry configurations."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"aaif-goose","product":"goose","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"1.49.0","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"PASSIVE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Primary","description":[{"lang":"en","value":"CWE-94"}]}],"references":[{"url":"https://github.com/aaif-goose/goose","source":"disclosure@vulncheck.com"},{"url":"https://github.com/aaif-goose/goose/blob/v1.49.0/crates/goose/src/agents/extension_manager.rs","source":"disclosure@vulncheck.com"},{"url":"https://github.com/aaif-goose/goose/blob/v1.49.0/crates/goose/src/recipe/mod.rs","source":"disclosure@vulncheck.com"},{"url":"https://github.com/aaif-goose/goose/issues/10325","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/goose-1.37.0-arbitrary-command-execution-via-recipe-extensions","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-85624","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-04T15:17:42.737","lastModified":"2026-09-04T18:18:05.000","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Blinko 1.8.7 contains a cross-user private note disclosure vulnerability in the noteReferenceList procedure that performs no ownership verification on supplied note identifiers. Authenticated attackers can enumerate sequential note IDs and retrieve complete content of other users' private notes including attachments and tags."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"blinkospace","product":"blinko","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"1.8.8","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T17:54:42.581883Z","id":"CVE-2026-85624","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-639"}]}],"references":[{"url":"https://github.com/blinkospace/blinko","source":"disclosure@vulncheck.com"},{"url":"https://github.com/blinkospace/blinko/blob/1.8.8/server/routerTrpc/note.ts","source":"disclosure@vulncheck.com"},{"url":"https://github.com/blinkospace/blinko/issues/1217","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/blinko-1.8.7-cross-user-private-note-disclosure-via-notereferencelist","source":"disclosure@vulncheck.com"},{"url":"https://github.com/blinkospace/blinko/issues/1217","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}]}},{"cve":{"id":"CVE-2026-85625","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-04T15:17:42.880","lastModified":"2026-09-04T15:17:42.880","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"sift (sift.js) 17.1.3 enumerates query keys with for...in, which walks the object prototype chain, and dispatches any matched operator key including $where. The $where operation compiles a string value into a function using new Function unless CSP_ENABLED is set (not set by default). As a result, if a prototype-pollution primitive elsewhere in the process sets Object.prototype.$where to a malicious string, even benign filter calls such as sift({}) execute arbitrary JavaScript. Additionally, passing an untrusted query object containing a string $where directly to sift results in code execution under the default configuration."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"crcn","product":"sift.js","defaultStatus":"unaffected","packageURL":"pkg:npm/sift","versions":[{"version":"0","lessThanOrEqual":"17.1.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":9.2,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"HIGH","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.2,"impactScore":5.9}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Primary","description":[{"lang":"en","value":"CWE-1321"}]}],"references":[{"url":"https://github.com/crcn/sift.js","source":"disclosure@vulncheck.com"},{"url":"https://github.com/crcn/sift.js/blob/v17.1.3/src/core.ts","source":"disclosure@vulncheck.com"},{"url":"https://github.com/crcn/sift.js/issues/276","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/sift-17.1.3-prototype-pollution-remote-code-execution-via-where","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-85626","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-04T15:17:43.040","lastModified":"2026-09-04T15:17:43.040","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"git-mcp-server 2.15.1 contains an argument injection vulnerability in the ref and object parameters of git_log, git_diff, and git_show tools that lack leading-dash validation. Attackers can inject git command-line options like --output= to write files outside the repository to arbitrary paths accessible by the process."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"cyanheads","product":"git-mcp-server","defaultStatus":"unaffected","packageURL":"pkg:npm/%40cyanheads/git-mcp-server","versions":[{"version":"0","lessThanOrEqual":"2.15.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Primary","description":[{"lang":"en","value":"CWE-88"}]}],"references":[{"url":"https://github.com/cyanheads/git-mcp-server","source":"disclosure@vulncheck.com"},{"url":"https://github.com/cyanheads/git-mcp-server/blob/v2.15.3/src/services/git/providers/cli/operations/commits/log.ts","source":"disclosure@vulncheck.com"},{"url":"https://github.com/cyanheads/git-mcp-server/blob/v2.15.3/src/services/git/providers/cli/utils/command-builder.ts","source":"disclosure@vulncheck.com"},{"url":"https://github.com/cyanheads/git-mcp-server/issues/53","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/git-mcp-server-2.15.1-argument-injection-via-git-ref-parameters","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-85650","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-04T15:17:43.190","lastModified":"2026-09-04T16:18:20.560","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Trigger.dev before 4.5.2 contains a server-side request forgery vulnerability in webhook alert channel delivery URLs that are fetched without validation or SSRF protection. Authenticated users with organization membership can create alert channels with URLs targeting internal services and metadata endpoints, allowing the server to issue POST requests to restricted resources."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"triggerdotdev","product":"trigger.dev","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"4.5.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T15:31:41.621339Z","id":"CVE-2026-85650","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-918"}]}],"references":[{"url":"https://github.com/triggerdotdev/trigger.dev","source":"disclosure@vulncheck.com"},{"url":"https://github.com/triggerdotdev/trigger.dev/commit/34b1a181c2a1d33a53ebab88f84b05f81fea4254","source":"disclosure@vulncheck.com"},{"url":"https://github.com/triggerdotdev/trigger.dev/issues/4172","source":"disclosure@vulncheck.com"},{"url":"https://github.com/triggerdotdev/trigger.dev/releases/tag/v4.5.2","source":"disclosure@vulncheck.com"},{"url":"https://github.com/triggerdotdev/trigger.dev/security/advisories/GHSA-xxv7-2vv3-h682","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/trigger-dev-before-4.5.2-server-side-request-forgery-via-webhook-alert-channel","source":"disclosure@vulncheck.com"},{"url":"https://github.com/triggerdotdev/trigger.dev/issues/4172","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}]}},{"cve":{"id":"CVE-2026-85651","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-04T15:17:43.347","lastModified":"2026-09-04T15:17:43.347","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Trigger.dev versions before 4.5.2 fail to validate environment membership during run replay operations, allowing authenticated attackers to inject task runs into arbitrary environments. Attackers can replay their own runs into other organizations' or projects' environments to consume victim resources and pollute run history."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"triggerdotdev","product":"trigger.dev","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"4.5.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.4,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"LOW","subConfidentialityImpact":"NONE","subIntegrityImpact":"HIGH","subAvailabilityImpact":"LOW","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L","baseScore":8.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":3.1,"impactScore":4.7}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Primary","description":[{"lang":"en","value":"CWE-862"}]}],"references":[{"url":"https://github.com/triggerdotdev/trigger.dev","source":"disclosure@vulncheck.com"},{"url":"https://github.com/triggerdotdev/trigger.dev/commit/34b1a181c2a1d33a53ebab88f84b05f81fea4254","source":"disclosure@vulncheck.com"},{"url":"https://github.com/triggerdotdev/trigger.dev/issues/4173","source":"disclosure@vulncheck.com"},{"url":"https://github.com/triggerdotdev/trigger.dev/releases/tag/v4.5.2","source":"disclosure@vulncheck.com"},{"url":"https://github.com/triggerdotdev/trigger.dev/security/advisories/GHSA-qxpp-qjg8-x4jv","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/trigger-dev-before-4.5.2-unauthorized-environment-access-via-run-replay","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-85660","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-04T15:17:43.490","lastModified":"2026-09-04T18:18:06.293","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"cli-mcp-server 0.2.5 contains a command allowlist bypass vulnerability in the _validate_command_with_operators function when ALLOW_SHELL_OPERATORS is enabled. Attackers can use shell command substitution syntax like $(...) or backticks to execute non-allowlisted commands that bypass the ALLOWED_COMMANDS validation check."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"MladenSU","product":"cli-mcp-server","defaultStatus":"unaffected","packageURL":"pkg:pypi/cli-mcp-server","versions":[{"version":"0","lessThanOrEqual":"0.2.5","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":9.2,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"HIGH","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.2,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T17:50:11.066401Z","id":"CVE-2026-85660","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-78"}]}],"references":[{"url":"https://github.com/MladenSU/cli-mcp-server","source":"disclosure@vulncheck.com"},{"url":"https://github.com/MladenSU/cli-mcp-server/blob/main/src/cli_mcp_server/server.py","source":"disclosure@vulncheck.com"},{"url":"https://github.com/MladenSU/cli-mcp-server/issues/17","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/cli-mcp-server-0.2.5-command-allowlist-bypass-via-shell-substitution","source":"disclosure@vulncheck.com"},{"url":"https://github.com/MladenSU/cli-mcp-server/issues/17","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}]}},{"cve":{"id":"CVE-2026-85661","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-04T15:17:43.643","lastModified":"2026-09-04T15:17:43.643","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"excel-mcp-server 0.1.8 fails to enforce path confinement in stdio mode when EXCEL_FILES_PATH is unset, allowing attackers to read and write arbitrary files. Attackers can supply unchecked file paths to read and write tools to access any file accessible to the process."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"haris-musa","product":"excel-mcp-server","defaultStatus":"unaffected","packageURL":"pkg:pypi/excel-mcp-server","versions":[{"version":"0","lessThanOrEqual":"0.1.8","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":9.3,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Primary","description":[{"lang":"en","value":"CWE-22"}]}],"references":[{"url":"https://github.com/haris-musa/excel-mcp-server","source":"disclosure@vulncheck.com"},{"url":"https://github.com/haris-musa/excel-mcp-server/blob/v0.1.8/src/excel_mcp/server.py","source":"disclosure@vulncheck.com"},{"url":"https://github.com/haris-musa/excel-mcp-server/blob/v0.1.8/src/excel_mcp/validation.py","source":"disclosure@vulncheck.com"},{"url":"https://github.com/haris-musa/excel-mcp-server/issues/149","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/excel-mcp-server-0.1.8-arbitrary-file-read-write-via-stdio-mode","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-85662","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-04T15:17:43.797","lastModified":"2026-09-04T15:17:43.797","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Marqo 2.26.0 contains a server-side request forgery vulnerability in the add_documents endpoint that allows unauthenticated attackers to trigger requests to arbitrary URLs by supplying malicious media field values. Attackers can exploit download_image_from_url and fetch_content_sample functions which lack destination filtering and host validation to access internal services and cloud metadata endpoints."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"marqo-ai","product":"marqo","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"2.26.0","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":6.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Primary","description":[{"lang":"en","value":"CWE-918"}]}],"references":[{"url":"https://github.com/marqo-ai/marqo","source":"disclosure@vulncheck.com"},{"url":"https://github.com/marqo-ai/marqo/blob/2.26.0/components/inference_orchestrator/src/inference_orchestrator/services/media_download_and_preprocess/image_download.py","source":"disclosure@vulncheck.com"},{"url":"https://github.com/marqo-ai/marqo/issues/1452","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/marqo-2.26.0-server-side-request-forgery-via-media-urls","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-85663","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-04T15:17:43.947","lastModified":"2026-09-04T16:18:21.027","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Aim 3.29.1 remote tracking server fails to authenticate requests and dispatches arbitrary methods through getattr without allowlist validation. Unauthenticated attackers can register clients, instantiate Repo resources, and invoke arbitrary methods to read experiments or delete runs."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"aimhubio","product":"aim","defaultStatus":"unaffected","packageURL":"pkg:pypi/aim","versions":[{"version":"0","lessThanOrEqual":"3.29.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":9.3,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T15:27:48.417179Z","id":"CVE-2026-85663","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-306"}]}],"references":[{"url":"https://github.com/aimhubio/aim","source":"disclosure@vulncheck.com"},{"url":"https://github.com/aimhubio/aim/blob/v3.29.1/aim/ext/transport/server.py","source":"disclosure@vulncheck.com"},{"url":"https://github.com/aimhubio/aim/blob/v3.29.1/aim/ext/transport/tracking.py","source":"disclosure@vulncheck.com"},{"url":"https://github.com/aimhubio/aim/issues/3412","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/aim-3.29.1-remote-code-execution-via-unauthenticated-method-dispatch","source":"disclosure@vulncheck.com"},{"url":"https://github.com/aimhubio/aim/issues/3412","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}]}},{"cve":{"id":"CVE-2026-85664","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-04T15:17:44.097","lastModified":"2026-09-04T15:17:44.097","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Chroma 1.5.9 fails to validate maximum bounds on HNSW index parameters max_neighbors, ef_construction, and ef_search in collection-create requests. Unauthenticated attackers can supply arbitrarily large parameter values to exhaust server memory and cause denial of service during index compaction."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"chroma-core","product":"chroma","defaultStatus":"unaffected","packageURL":"pkg:pypi/chromadb","versions":[{"version":"0","lessThanOrEqual":"1.5.9","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Primary","description":[{"lang":"en","value":"CWE-770"}]}],"references":[{"url":"https://github.com/chroma-core/chroma","source":"disclosure@vulncheck.com"},{"url":"https://github.com/chroma-core/chroma/blob/1.5.9/rust/frontend/src/auth/mod.rs","source":"disclosure@vulncheck.com"},{"url":"https://github.com/chroma-core/chroma/blob/1.5.9/rust/types/src/hnsw_configuration.rs","source":"disclosure@vulncheck.com"},{"url":"https://github.com/chroma-core/chroma/issues/7225","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/chroma-1.5.9-unbounded-hnsw-index-parameters-memory-exhaustion","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-85665","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-04T15:17:44.247","lastModified":"2026-09-05T11:16:45.577","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Bruno versions through 4.1.0 fail to validate file paths in request body declarations, allowing attackers to read arbitrary local files by using parent-directory traversal segments. When a collection is executed, attackers can craft a request with a body:file path containing ../ sequences that resolve outside the collection directory, causing the application to read and exfiltrate arbitrary files to attacker-controlled endpoints."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"usebruno","product":"bruno","defaultStatus":"unaffected","packageURL":"pkg:npm/%40usebruno/cli","versions":[{"version":"0","lessThanOrEqual":"4.1.0","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"PASSIVE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T18:41:25.999363Z","id":"CVE-2026-85665","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-22"}]}],"references":[{"url":"https://github.com/usebruno/bruno","source":"disclosure@vulncheck.com"},{"url":"https://github.com/usebruno/bruno/blob/v4.1.0/packages/bruno-cli/src/runner/prepare-request.js","source":"disclosure@vulncheck.com"},{"url":"https://github.com/usebruno/bruno/issues/8230","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/bruno-3.4.2-arbitrary-file-read-via-unconfined-body-file-path","source":"disclosure@vulncheck.com"},{"url":"https://github.com/usebruno/bruno/issues/8230","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}]}},{"cve":{"id":"CVE-2026-85666","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-04T15:17:44.397","lastModified":"2026-09-04T15:17:44.397","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"OGX (formerly Llama Stack, affected at commit fbe8e0f) contains an unauthenticated server-side request forgery vulnerability in the OpenAI-compatible POST /v1/responses endpoint. MCP tool definitions accept a server_url parameter (along with headers and authorization values) that is fetched server-side without destination validation; the existing validate_url_not_private() guard used for other URL inputs is not applied to server_url. On the default starter configuration, which runs without authentication, a remote unauthenticated attacker can cause the server to open connections to arbitrary internal addresses (including cloud metadata endpoints such as http://169.254.169.254/) and forward attacker-supplied headers and bearer tokens to those destinations."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"ogx-ai","product":"ogx","defaultStatus":"unaffected","packageURL":"pkg:pypi/ogx","versions":[{"version":"0","lessThanOrEqual":"1.3.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Primary","description":[{"lang":"en","value":"CWE-918"}]}],"references":[{"url":"https://github.com/ogx-ai/ogx","source":"disclosure@vulncheck.com"},{"url":"https://github.com/ogx-ai/ogx/blob/v1.3.1/src/ogx/providers/utils/tools/mcp.py","source":"disclosure@vulncheck.com"},{"url":"https://github.com/ogx-ai/ogx/issues/6287","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/ogx-1.3.1-server-side-request-forgery-via-mcp-tool-server-url","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-85667","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-04T15:17:44.543","lastModified":"2026-09-04T15:17:44.543","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"xiaobei through 5.5.2 fails to implement authentication or signature validation on webhook endpoints, allowing unauthenticated attackers to inject arbitrary messages into the agent pipeline. Attackers can publish malicious messages via the /webhook_worktool handler and exploit unvalidated media URL fetching to perform server-side request forgery against internal services."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"TeamWiseFlow","product":"xiaobei","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"5.5.2","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":9.3,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","baseScore":9.1,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":5.2}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Primary","description":[{"lang":"en","value":"CWE-306"}]}],"references":[{"url":"https://github.com/TeamWiseFlow/xiaobei","source":"disclosure@vulncheck.com"},{"url":"https://github.com/TeamWiseFlow/xiaobei/blob/v5.5.2/awada/awada-server/src/routes/webhook-worktool.ts","source":"disclosure@vulncheck.com"},{"url":"https://github.com/TeamWiseFlow/xiaobei/issues/440","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/xiaobei-through-5.5.2-unauthenticated-webhook-message-injection","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-85668","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-04T15:17:44.693","lastModified":"2026-09-04T16:18:21.520","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Xinference (affected commit 4a94832, v3.x) contains an unauthenticated arbitrary-path file read vulnerability in the POST /v1/models/llm/auto-register endpoint, which accepts a caller-supplied model_path parameter without authentication or path confinement. The endpoint reads and parses config.json, tokenizer_config.json, and chat_template.jinja files at the supplied path and reflects the parsed content back to the caller, allowing an unauthenticated attacker to probe the server filesystem and extract content of files with those names in any directory."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"xorbitsai","product":"inference","defaultStatus":"unaffected","packageURL":"pkg:pypi/xinference","versions":[{"version":"0","lessThanOrEqual":"3.3.0","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T15:20:09.121487Z","id":"CVE-2026-85668","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-73"}]}],"references":[{"url":"https://github.com/xorbitsai/inference","source":"disclosure@vulncheck.com"},{"url":"https://github.com/xorbitsai/inference/blob/v3.3.0/xinference/model/llm/config_parser.py","source":"disclosure@vulncheck.com"},{"url":"https://github.com/xorbitsai/inference/issues/5176","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/xinference-3.3.0-unauthenticated-arbitrary-path-file-read-via-v1-models-llm-auto-register","source":"disclosure@vulncheck.com"},{"url":"https://github.com/xorbitsai/inference/issues/5176","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}]}},{"cve":{"id":"CVE-2026-85669","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-04T15:17:44.847","lastModified":"2026-09-04T15:17:44.847","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"potpie through 2.0.0 fails to verify user ownership on the POST /conversations/{conversation_id}/code-changes/sync endpoint. Authenticated attackers can write arbitrary file changes into other users' conversations by supplying their conversation IDs, allowing unauthorized modification of pending changes."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"potpie-ai","product":"potpie","defaultStatus":"unaffected","packageURL":"pkg:pypi/potpie","versions":[{"version":"0","lessThanOrEqual":"2.0.0","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Primary","description":[{"lang":"en","value":"CWE-862"}]}],"references":[{"url":"https://github.com/potpie-ai/potpie","source":"disclosure@vulncheck.com"},{"url":"https://github.com/potpie-ai/potpie/blob/v2.0.0/legacy/app/modules/conversations/conversations_router.py","source":"disclosure@vulncheck.com"},{"url":"https://github.com/potpie-ai/potpie/issues/870","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/potpie-through-2.0.0-missing-ownership-check-via-code-changes-sync","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-85670","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-04T15:17:44.993","lastModified":"2026-09-04T18:18:06.417","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"tokenizers (Hugging Face) is affected by an out-of-bounds buffer access in BpeBuilder::build (tokenizers/src/models/bpe/model.rs). When loading a tokenizer.json via Tokenizer::from_file/from_str, the builder sizes a scratch buffer to the longest vocabulary key, then writes each concatenated merge rule into it. A merge whose concatenated token exceeds the longest vocabulary key overruns the buffer, which Rust turns into a panic that aborts the process in Rust and FFI embeddings. This occurs at load time with no encoding required, so an attacker who supplies a crafted tokenizer.json can cause a denial of service. A secondary defect at the same location can cause a usize underflow (panic in debug, potential memory corruption in release) when continuing_subword_prefix is set and a merge token is shorter than the prefix. Observed in version 0.23.1."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"huggingface","product":"tokenizers","defaultStatus":"unaffected","packageURL":"pkg:pypi/tokenizers","versions":[{"version":"0","lessThanOrEqual":"0.23.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"PASSIVE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T17:49:21.636135Z","id":"CVE-2026-85670","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-787"}]}],"references":[{"url":"https://github.com/huggingface/tokenizers","source":"disclosure@vulncheck.com"},{"url":"https://github.com/huggingface/tokenizers/blob/v0.23.2/tokenizers/src/models/bpe/model.rs","source":"disclosure@vulncheck.com"},{"url":"https://github.com/huggingface/tokenizers/issues/2094","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/tokenizers-bpebuilder-buffer-overflow-via-merge-token","source":"disclosure@vulncheck.com"},{"url":"https://github.com/huggingface/tokenizers/issues/2094","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}]}},{"cve":{"id":"CVE-2026-85671","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-04T15:17:45.150","lastModified":"2026-09-04T15:17:45.150","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"QAnything 2.0.0 contains an authentication bypass vulnerability in the /api/local_doc_qa/get_file_base64 and /api/local_doc_qa/get_doc endpoints that allows unauthenticated attackers to access any uploaded file or document. Attackers can enumerate file identifiers through unauthenticated endpoints and retrieve base64-encoded files or parsed document chunks without ownership verification to disclose cross-tenant knowledge base content."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"netease-youdao","product":"QAnything","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"2.0.0","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Primary","description":[{"lang":"en","value":"CWE-306"}]}],"references":[{"url":"https://github.com/netease-youdao/QAnything","source":"disclosure@vulncheck.com"},{"url":"https://github.com/netease-youdao/QAnything/blob/v2.0.0/qanything_kernel/qanything_server/handler.py","source":"disclosure@vulncheck.com"},{"url":"https://github.com/netease-youdao/QAnything/issues/670","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/qanything-2.0.0-unauthenticated-cross-user-file-disclosure","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-85672","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-04T15:17:45.293","lastModified":"2026-09-04T15:17:45.293","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"zerox 1.1.20 contains an OS command injection vulnerability in the file download mechanism where the temporary file extension derived from document URLs is interpolated unsanitized into shell commands executed by poppler utilities. Attackers can craft document URLs with malicious file extensions containing command substitution syntax to execute arbitrary OS commands before document processing occurs."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"getomni-ai","product":"zerox","defaultStatus":"unaffected","packageURL":"pkg:npm/zerox","versions":[{"version":"0","lessThanOrEqual":"1.1.20","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":9.3,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Primary","description":[{"lang":"en","value":"CWE-78"}]}],"references":[{"url":"https://github.com/getomni-ai/zerox","source":"disclosure@vulncheck.com"},{"url":"https://github.com/getomni-ai/zerox/blob/main/node-zerox/src/utils/file.ts","source":"disclosure@vulncheck.com"},{"url":"https://github.com/getomni-ai/zerox/issues/206","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/zerox-1.1.20-os-command-injection-via-document-url-file-extension","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-85673","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-04T15:17:45.440","lastModified":"2026-09-04T16:18:22.060","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"LLaMA-Factory contains a server-side request forgery vulnerability in the OpenAI-compatible API multimodal media URL handler that allows unauthenticated attackers to bypass SSRF validation. The check_ssrf_url guard validates URLs once but requests.get follows redirects and re-resolves DNS without re-validation, enabling attackers to use HTTP redirects or DNS rebinding to access internal addresses and cloud metadata endpoints."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"hiyouga","product":"LlamaFactory","defaultStatus":"unaffected","packageURL":"pkg:pypi/llamafactory","versions":[{"version":"0","lessThanOrEqual":"0.9.5","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T15:16:16.164011Z","id":"CVE-2026-85673","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-918"}]}],"references":[{"url":"https://github.com/hiyouga/LlamaFactory","source":"disclosure@vulncheck.com"},{"url":"https://github.com/hiyouga/LlamaFactory/blob/v0.9.5/src/llamafactory/api/chat.py","source":"disclosure@vulncheck.com"},{"url":"https://github.com/hiyouga/LlamaFactory/blob/v0.9.5/src/llamafactory/api/common.py","source":"disclosure@vulncheck.com"},{"url":"https://github.com/hiyouga/LlamaFactory/issues/10646","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/llama-factory-ssrf-guard-bypass-via-redirect-and-dns-rebinding","source":"disclosure@vulncheck.com"},{"url":"https://github.com/hiyouga/LlamaFactory/issues/10646","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}]}},{"cve":{"id":"CVE-2026-85674","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-04T15:17:45.597","lastModified":"2026-09-04T15:17:45.597","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"aider (aider-chat) automatically loads a .aider.conf.yml configuration file from the root of the git repository it is launched in. A crafted repository can set test-cmd (executed at startup) or lint-cmd (executed on the first file edit), which aider runs through a shell (subprocess with shell=True) without any user confirmation, LLM interaction, or API key. Consequently, a user who clones and runs aider inside an attacker-supplied repository achieves arbitrary command execution on their machine. The behavior is long-standing and was confirmed on 0.86.3.dev (current main)."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"Aider-AI","product":"aider","defaultStatus":"unaffected","packageURL":"pkg:pypi/aider-chat","versions":[{"version":"0","lessThanOrEqual":"0.86.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.5,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"PASSIVE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Primary","description":[{"lang":"en","value":"CWE-94"}]}],"references":[{"url":"https://github.com/Aider-AI/aider","source":"disclosure@vulncheck.com"},{"url":"https://github.com/Aider-AI/aider/blob/v0.86.2/aider/main.py","source":"disclosure@vulncheck.com"},{"url":"https://github.com/Aider-AI/aider/issues/5254","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/aider-0.86.2-remote-code-execution-via-aider-conf-yml","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-85675","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-04T15:17:45.763","lastModified":"2026-09-04T18:18:06.540","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"OWL's DocumentProcessingToolkit contains a server-side request forgery vulnerability in the extract_document_content tool that fetches caller-supplied URLs with no scheme, host, or IP filtering. Attackers can inject malicious URLs through prompt injection to make the server fetch internal resources, with responses returned to the agent context."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"camel-ai","product":"owl","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"fba1dd5b3a9e8cc15f16221bb002cca7e3de2d9d","versionType":"git","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T17:46:48.318369Z","id":"CVE-2026-85675","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-918"}]}],"references":[{"url":"https://github.com/camel-ai/owl","source":"disclosure@vulncheck.com"},{"url":"https://github.com/camel-ai/owl/blob/fba1dd5b3a9e8cc15f16221bb002cca7e3de2d9d/owl/utils/document_toolkit.py","source":"disclosure@vulncheck.com"},{"url":"https://github.com/camel-ai/owl/issues/615","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/owl-documentprocessingtoolkit-server-side-request-forgery-via-url-fetching","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-85676","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-04T15:17:45.923","lastModified":"2026-09-04T15:17:45.923","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Dub contains an open redirect vulnerability in the redir_url query parameter that is accepted on every short link without validation or domain allowlist enforcement. Attackers can append the redir_url parameter to any short link to redirect visitors to arbitrary external URLs through the trusted Dub domain, bypassing destination blacklists and potentially enabling phishing attacks with link cloaking enabled."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"dubinc","product":"dub","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"73415cf5e6be13ce9adb7ba5e97474307db34a17","versionType":"git","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"PASSIVE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Primary","description":[{"lang":"en","value":"CWE-601"}]}],"references":[{"url":"https://github.com/dubinc/dub","source":"disclosure@vulncheck.com"},{"url":"https://github.com/dubinc/dub/blob/73415cf5e6be13ce9adb7ba5e97474307db34a17/apps/web/lib/middleware/utils/get-final-url.ts","source":"disclosure@vulncheck.com"},{"url":"https://github.com/dubinc/dub/issues/4337","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/dub-open-redirect-via-unrestricted-redir-url-parameter","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-85684","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-04T15:17:46.077","lastModified":"2026-09-04T15:17:46.077","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"marker through 2.0.0 contains a path traversal vulnerability in the FastAPI /marker/upload handler that fails to sanitize the file.filename parameter. Unauthenticated attackers can supply filenames containing directory traversal sequences to write arbitrary files to any location or delete existing files on the system."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"datalab-to","product":"marker","defaultStatus":"unaffected","packageURL":"pkg:pypi/marker-pdf","versions":[{"version":"0","lessThanOrEqual":"2.0.0","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","baseScore":9.1,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.2}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Primary","description":[{"lang":"en","value":"CWE-73"}]}],"references":[{"url":"https://github.com/datalab-to/marker","source":"disclosure@vulncheck.com"},{"url":"https://github.com/datalab-to/marker/blob/v2.0.0/marker/scripts/server.py","source":"disclosure@vulncheck.com"},{"url":"https://github.com/datalab-to/marker/issues/1047","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/marker-through-2.0.0-path-traversal-via-upload-filename","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-85685","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-04T15:17:46.220","lastModified":"2026-09-04T16:18:22.517","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"AgentScope through 2.0.7.post1 contains a path traversal vulnerability in LocalWorkspace.add_skill that copies arbitrary server directories into the agent workspace via an unconfined source path parameter. Attackers can supply any directory path in the skill_path request parameter to copy files into the skills directory, making them accessible through the workspace skill listing."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"agentscope-ai","product":"agentscope","defaultStatus":"unaffected","packageURL":"pkg:pypi/agentscope","versions":[{"version":"0","lessThanOrEqual":"2.0.7.post1","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T15:10:54.765258Z","id":"CVE-2026-85685","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-22"}]}],"references":[{"url":"https://github.com/agentscope-ai/agentscope","source":"disclosure@vulncheck.com"},{"url":"https://github.com/agentscope-ai/agentscope/blob/v2.0.7.post1/src/agentscope/workspace/_local_workspace.py","source":"disclosure@vulncheck.com"},{"url":"https://github.com/agentscope-ai/agentscope/issues/2069","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/agentscope-through-2.0.7-post1-arbitrary-directory-copy-via-add-skill","source":"disclosure@vulncheck.com"},{"url":"https://github.com/agentscope-ai/agentscope/issues/2069","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}]}},{"cve":{"id":"CVE-2026-85686","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-04T15:17:46.360","lastModified":"2026-09-04T15:17:46.360","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"ms-swift 4.5.2 contains a server-side request forgery vulnerability in the swift deploy OpenAI-compatible API that fetches multimodal media URLs without validation or redirect filtering. Unauthenticated attackers can supply arbitrary image_url, audio_url, or video_url parameters to make the server issue requests to internal services and cloud metadata endpoints."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"modelscope","product":"ms-swift","defaultStatus":"unaffected","packageURL":"pkg:pypi/ms-swift","versions":[{"version":"0","lessThanOrEqual":"4.5.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Primary","description":[{"lang":"en","value":"CWE-918"}]}],"references":[{"url":"https://github.com/modelscope/ms-swift","source":"disclosure@vulncheck.com"},{"url":"https://github.com/modelscope/ms-swift/blob/v4.5.2/swift/template/vision_utils.py","source":"disclosure@vulncheck.com"},{"url":"https://github.com/modelscope/ms-swift/issues/9740","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/ms-swift-4.5.2-unauthenticated-ssrf-via-multimodal-media-urls","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-85687","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-04T15:17:46.507","lastModified":"2026-09-04T18:18:06.663","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"surya 0.22.1 screenshot server contains an unauthenticated arbitrary file read vulnerability in the /info, /page, and /process routes that accept raw file_path parameters. Attackers can read any image or PDF file on the host by supplying arbitrary file paths to Image.open or pypdfium2.PdfDocument, obtaining rendered contents as base64 and using /info as an existence oracle."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"datalab-to","product":"surya","defaultStatus":"unaffected","packageURL":"pkg:pypi/surya-ocr","versions":[{"version":"0","lessThanOrEqual":"0.22.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T17:44:48.898363Z","id":"CVE-2026-85687","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-73"}]}],"references":[{"url":"https://github.com/datalab-to/surya","source":"disclosure@vulncheck.com"},{"url":"https://github.com/datalab-to/surya/blob/v0.22.1/surya/scripts/screenshot_app.py","source":"disclosure@vulncheck.com"},{"url":"https://github.com/datalab-to/surya/issues/518","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/surya-0.22.1-unauthenticated-arbitrary-file-read-via-screenshot-server","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-85688","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-04T15:17:46.657","lastModified":"2026-09-04T15:17:46.657","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"TEN Framework 0.11.71 contains unauthenticated arbitrary file read and write vulnerabilities in the TMAN Designer file-content API endpoints. Attackers can submit POST and PUT requests to the /api/designer/v1/file-content endpoints to read arbitrary files or write malicious content to system paths, enabling code execution through authorized_keys, cron files, or executable graph files."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"TEN-framework","product":"ten-framework","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"0.11.71","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":9.3,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Primary","description":[{"lang":"en","value":"CWE-306"}]}],"references":[{"url":"https://github.com/TEN-framework/ten-framework","source":"disclosure@vulncheck.com"},{"url":"https://github.com/TEN-framework/ten-framework/blob/0.11.71/core/src/ten_manager/src/designer/file_content/mod.rs","source":"disclosure@vulncheck.com"},{"url":"https://github.com/TEN-framework/ten-framework/issues/2187","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/ten-framework-0.11.71-unauthenticated-file-read-write-via-tman-designer","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-85689","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-04T15:17:46.803","lastModified":"2026-09-04T15:17:46.803","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"llmware 0.4.6 contains an SQL injection vulnerability in the collection-database layer (llmware/resources.py) where filter and lookup values are directly string-interpolated into SQL WHERE clauses without parameterization or escaping, in both the SQLite and PostgreSQL backends. The filter validator only checks keys against an allow-list and never sanitizes values. Attacker-controlled filter values reaching the public API via Library.block_lookup and Query.text_query_with_custom_filter / text_query_by_author_or_speaker can neutralize the intended filter to disclose rows the caller was scoped out of (cross-document/cross-collection disclosure); on PostgreSQL the flaw permits boolean- and UNION-based SQL injection."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"llmware-ai","product":"llmware","defaultStatus":"unaffected","packageURL":"pkg:pypi/llmware","versions":[{"version":"0","lessThanOrEqual":"0.4.6","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Primary","description":[{"lang":"en","value":"CWE-89"}]}],"references":[{"url":"https://github.com/llmware-ai/llmware","source":"disclosure@vulncheck.com"},{"url":"https://github.com/llmware-ai/llmware/blob/v0.4.6/llmware/resources.py","source":"disclosure@vulncheck.com"},{"url":"https://github.com/llmware-ai/llmware/issues/1304","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/llmware-0.4.6-sql-injection-via-unescaped-filter-values","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-85690","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-04T15:17:46.947","lastModified":"2026-09-04T16:18:22.967","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Plandex 2.2.1 contains a path traversal vulnerability in the ApplyFiles function that allows attackers to write files outside the project directory. Attackers can influence model output through poisoned repository files or attacker-controlled context to write to arbitrary locations like shell rc or cron files, achieving code execution."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"plandex-ai","product":"plandex","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"2.2.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.5,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"PASSIVE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T15:08:37.586518Z","id":"CVE-2026-85690","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-22"}]}],"references":[{"url":"https://github.com/plandex-ai/plandex","source":"disclosure@vulncheck.com"},{"url":"https://github.com/plandex-ai/plandex/blob/cli/v2.2.1/app/cli/lib/apply.go","source":"disclosure@vulncheck.com"},{"url":"https://github.com/plandex-ai/plandex/issues/352","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/plandex-2.2.1-path-traversal-via-applyfiles","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-85691","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-04T15:17:47.097","lastModified":"2026-09-04T15:17:47.097","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"MegaParse 0.0.55 contains an unauthenticated server-side request forgery vulnerability in the POST /v1/url endpoint that fetches caller-supplied URLs server-side. Attackers can supply internal service URLs or metadata endpoints without authentication to read their responses directly from the JSON response."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"The-Vibe-Company","product":"megaparse","defaultStatus":"unaffected","packageURL":"pkg:pypi/megaparse","versions":[{"version":"0","lessThanOrEqual":"0.0.55","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Primary","description":[{"lang":"en","value":"CWE-918"}]}],"references":[{"url":"https://github.com/The-Vibe-Company/megaparse","source":"disclosure@vulncheck.com"},{"url":"https://github.com/The-Vibe-Company/megaparse/blob/megaparse-v0.0.55/libs/megaparse/src/megaparse/api/app.py","source":"disclosure@vulncheck.com"},{"url":"https://github.com/The-Vibe-Company/megaparse/issues/259","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/megaparse-0.0.55-server-side-request-forgery-via-post-v1-url","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-85692","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-04T15:17:47.243","lastModified":"2026-09-04T18:18:06.787","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Nightingale (n9e), as of commit 8362cbe (main branch, confirmed 2026-08-27), contains a server-side request forgery vulnerability in the isPublicIP function in aiagent/tools/http.go, the SSRF guard for the http_fetch AI-agent tool. The function only unwraps standard IPv4-mapped (::ffff:a.b.c.d) IPv6 addresses before checking them against the forbidden-range list, and does not classify 6to4 (2002::/16), NAT64 (64:ff9b::/96, 64:ff9b:1::/48), or deprecated site-local (fec0::/10) addresses. On a dual-stack or NAT64-enabled host, an attacker able to supply a URL to the http_fetch tool can bypass the guard by encoding a forbidden IPv4 address (such as the cloud instance-metadata endpoint 169.254.169.254) in one of these IPv6 forms to reach internal or metadata services."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"ccfos","product":"nightingale","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"9.1.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T17:43:27.970361Z","id":"CVE-2026-85692","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-918"}]}],"references":[{"url":"https://github.com/ccfos/nightingale","source":"disclosure@vulncheck.com"},{"url":"https://github.com/ccfos/nightingale/blob/v9.1.1/aiagent/tools/http.go","source":"disclosure@vulncheck.com"},{"url":"https://github.com/ccfos/nightingale/issues/3363","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/nightingale-9.1.1-ssrf-guard-bypass-via-ipv6-encoding","source":"disclosure@vulncheck.com"},{"url":"https://github.com/ccfos/nightingale/issues/3363","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}]}},{"cve":{"id":"CVE-2026-85693","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-04T15:17:47.397","lastModified":"2026-09-04T15:17:47.397","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Chatbot UI contains an authorization bypass vulnerability in the retrieval endpoint that allows authenticated attackers to access private file content belonging to other users by supplying arbitrary file UUIDs. The endpoint uses a service-role Supabase client that bypasses row-level security and fails to validate file ownership, enabling attackers to retrieve indexed content chunks from victim files through crafted POST requests."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"mckaywrigley","product":"chatbot-ui","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"81328b61d2a4ab597a7a057be70e785cf756d9f8","versionType":"git","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Primary","description":[{"lang":"en","value":"CWE-639"}]}],"references":[{"url":"https://github.com/mckaywrigley/chatbot-ui","source":"disclosure@vulncheck.com"},{"url":"https://github.com/mckaywrigley/chatbot-ui/blob/81328b61d2a4ab597a7a057be70e785cf756d9f8/app/api/retrieval/retrieve/route.ts","source":"disclosure@vulncheck.com"},{"url":"https://github.com/mckaywrigley/chatbot-ui/issues/2028","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/chatbot-ui-cross-user-private-file-content-disclosure-via-retrieval-api","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-85694","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-04T15:17:47.540","lastModified":"2026-09-04T15:17:47.540","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"LaVague 0.2.35 contains a remote code execution vulnerability in PythonFromMarkdownExtractor.extract_as_object that evaluates untrusted language model output derived from web page content. Attackers can inject malicious Python code through web pages using indirect prompt injection to execute arbitrary code on the operator's host without review."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"lavague-ai","product":"LaVague","defaultStatus":"unaffected","packageURL":"pkg:pypi/lavague-core","versions":[{"version":"0","lessThanOrEqual":"0.2.35","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":9.2,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"HIGH","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.2,"impactScore":5.9}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Primary","description":[{"lang":"en","value":"CWE-94"}]}],"references":[{"url":"https://github.com/lavague-ai/LaVague","source":"disclosure@vulncheck.com"},{"url":"https://github.com/lavague-ai/LaVague/blob/9024bb83/lavague-core/lavague/core/extractors.py","source":"disclosure@vulncheck.com"},{"url":"https://github.com/lavague-ai/LaVague/issues/650","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/lavague-0.2.35-remote-code-execution-via-eval-extraction","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-85695","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-04T15:17:47.690","lastModified":"2026-09-04T15:17:47.690","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"FastChat contains an authentication bypass vulnerability in the /register_worker endpoint that allows unauthenticated attackers to register arbitrary worker addresses and perform server-side request forgery. Attackers can register malicious workers under victim model names to intercept user prompts, images, and responses, or probe internal network ports across the worker mesh."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"lm-sys","product":"FastChat","defaultStatus":"unaffected","packageURL":"pkg:pypi/fschat","versions":[{"version":"0","lessThanOrEqual":"0.2.36","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":9.3,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"LOW","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L","baseScore":9.4,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":5.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T15:04:53.369519Z","id":"CVE-2026-85695","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Primary","description":[{"lang":"en","value":"CWE-306"}]}],"references":[{"url":"https://github.com/lm-sys/FastChat","source":"disclosure@vulncheck.com"},{"url":"https://github.com/lm-sys/FastChat/blob/v0.2.36/fastchat/serve/controller.py","source":"disclosure@vulncheck.com"},{"url":"https://github.com/lm-sys/FastChat/issues/3886","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/fastchat-unauthenticated-worker-registration-ssrf-and-model-spoofing","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-85696","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-04T15:17:48.523","lastModified":"2026-09-04T15:17:48.523","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"SadTalker contains an OS command injection vulnerability in the video muxing process where uploaded audio filenames are interpolated into ffmpeg commands without proper escaping. Attackers can upload audio files with shell metacharacters in the filename to break out of quoted arguments and execute arbitrary system commands when video generation occurs."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"OpenTalker","product":"SadTalker","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"0.0.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":9.3,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Primary","description":[{"lang":"en","value":"CWE-78"}]}],"references":[{"url":"https://github.com/OpenTalker/SadTalker","source":"disclosure@vulncheck.com"},{"url":"https://github.com/OpenTalker/SadTalker/blob/v0.0.2/src/utils/videoio.py","source":"disclosure@vulncheck.com"},{"url":"https://github.com/OpenTalker/SadTalker/issues/1043","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/sadtalker-os-command-injection-via-audio-filename","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-85697","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-04T15:17:48.670","lastModified":"2026-09-04T18:18:06.913","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Documenso 2.17.0 contains an access control vulnerability in the PDF-serving endpoint that fails to validate document visibility settings. Attackers with low privileges can read restricted documents within their team or cross-tenant by leveraging missing ownership validation on document data identifiers."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"documenso","product":"documenso","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"2.17.0","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T17:42:36.114391Z","id":"CVE-2026-85697","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]}],"references":[{"url":"https://github.com/documenso/documenso","source":"disclosure@vulncheck.com"},{"url":"https://github.com/documenso/documenso/blob/v2.17.0/apps/remix/server/api/files/files.helpers.ts","source":"disclosure@vulncheck.com"},{"url":"https://github.com/documenso/documenso/issues/3112","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/documenso-2.17.0-pdf-route-ignores-document-visibility","source":"disclosure@vulncheck.com"},{"url":"https://github.com/documenso/documenso/issues/3112","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}]}},{"cve":{"id":"CVE-2026-85698","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-04T15:17:48.817","lastModified":"2026-09-04T15:17:48.817","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Turso through 0.8.0-pre.8 contains an out-of-bounds read vulnerability in the table-leaf page reader that uses an attacker-controlled cell-count field without bounds validation. Attackers can craft a malicious database file with a modified cell count value to trigger an index-out-of-bounds panic when querying, causing denial of service in any application that opens untrusted database files."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"tursodatabase","product":"turso","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"0.8.0-pre.8","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":6.8,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"PASSIVE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":3.6}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Primary","description":[{"lang":"en","value":"CWE-125"}]}],"references":[{"url":"https://github.com/tursodatabase/turso","source":"disclosure@vulncheck.com"},{"url":"https://github.com/tursodatabase/turso/blob/v0.8.0-pre.8/core/storage/pager.rs","source":"disclosure@vulncheck.com"},{"url":"https://github.com/tursodatabase/turso/issues/7473","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/turso-through-0.8.0-pre.8-out-of-bounds-read-denial-of-service","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-85699","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-04T15:17:48.967","lastModified":"2026-09-04T15:17:48.967","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"jina-ai reader contains a server-side request forgery vulnerability where URL validation is performed only on the initial request but not re-applied to subsequent redirect hops. Attackers can craft a public URL that redirects to internal network addresses or cloud metadata endpoints, allowing the server to fetch and return the target's response body to the attacker."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"jina-ai","product":"reader","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"1574bfd380d249c86c82db4dace0d9c8fe17e2b1","versionType":"git","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Primary","description":[{"lang":"en","value":"CWE-918"}]}],"references":[{"url":"https://github.com/jina-ai/reader","source":"disclosure@vulncheck.com"},{"url":"https://github.com/jina-ai/reader/blob/1574bfd380d249c86c82db4dace0d9c8fe17e2b1/src/services/curl.ts","source":"disclosure@vulncheck.com"},{"url":"https://github.com/jina-ai/reader/blob/1574bfd380d249c86c82db4dace0d9c8fe17e2b1/src/services/puppeteer.ts","source":"disclosure@vulncheck.com"},{"url":"https://github.com/jina-ai/reader/issues/1252","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/jina-ai-reader-server-side-request-forgery-via-redirect-validation-bypass","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-85700","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-04T15:17:49.110","lastModified":"2026-09-04T15:17:49.110","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Onyx 4.6.6 fails to properly restrict access to custom tool credentials stored in custom_headers, allowing any authenticated user to read admin-defined API keys. Attackers with basic authentication can call GET /tool/{tool_id} or GET /tool endpoints to retrieve plaintext authorization headers and third-party API credentials, then use them to directly access upstream APIs."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"onyx-dot-app","product":"onyx","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"4.6.6","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T14:53:05.820690Z","id":"CVE-2026-85700","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Primary","description":[{"lang":"en","value":"CWE-522"}]}],"references":[{"url":"https://github.com/onyx-dot-app/onyx","source":"disclosure@vulncheck.com"},{"url":"https://github.com/onyx-dot-app/onyx/blob/v4.6.6/backend/onyx/server/features/tool/api.py","source":"disclosure@vulncheck.com"},{"url":"https://github.com/onyx-dot-app/onyx/blob/v4.6.6/backend/onyx/server/features/tool/models.py","source":"disclosure@vulncheck.com"},{"url":"https://github.com/onyx-dot-app/onyx/issues/13165","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/onyx-4.6.6-custom-tool-secret-header-disclosure-via-tool-endpoints","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-8447","sourceIdentifier":"psirt@us.ibm.com","published":"2026-09-04T15:17:49.930","lastModified":"2026-09-04T15:17:49.930","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"IBM Langflow OSS 1.0.0 through 1.11.2 suffer from a stored cross-site scripting vulnerability in the Playground chat interface."}],"affected":[{"source":"psirt@us.ibm.com","affectedData":[{"vendor":"IBM","product":"Langflow OSS","cpes":["cpe:2.3:a:ibm:langflow_oss:1.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:langflow_oss:1.11.2:*:*:*:*:*:*:*"],"versions":[{"version":"1.0.0","lessThanOrEqual":"1.11.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T14:41:32.969483Z","id":"CVE-2026-8447","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"psirt@us.ibm.com","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7285646","source":"psirt@us.ibm.com"}]}},{"cve":{"id":"CVE-2026-9138","sourceIdentifier":"psirt@us.ibm.com","published":"2026-09-04T15:17:50.717","lastModified":"2026-09-04T15:17:50.717","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"IBM Langflow OSS 1.0.0 through 1.11.2 Langflow could allow an authenticated attacker to write arbitrary files to the server due to improper input validation in the SaveToFileComponent. The application constructs local file paths using attacker‑controlled input without sufficient sanitization when handling requests to the /api/v1/run/{flow_id} endpoint. An attacker with low‑privileged authenticated access (such as a valid API key or user session) can supply crafted path values, including absolute paths or path traversal sequences, allowing arbitrary file writes to locations writable by the Langflow process. Successful exploitation may lead to unauthorized file creation or modification, potentially resulting in further compromise depending on the deployment environment."}],"affected":[{"source":"psirt@us.ibm.com","affectedData":[{"vendor":"IBM","product":"Langflow OSS","cpes":["cpe:2.3:a:ibm:langflow_oss:1.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:langflow_oss:1.11.2:*:*:*:*:*:*:*"],"versions":[{"version":"1.0.0","lessThanOrEqual":"1.11.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}]},"weaknesses":[{"source":"psirt@us.ibm.com","type":"Primary","description":[{"lang":"en","value":"CWE-22"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7285643","source":"psirt@us.ibm.com"}]}},{"cve":{"id":"CVE-2026-9186","sourceIdentifier":"psirt@us.ibm.com","published":"2026-09-04T15:17:50.860","lastModified":"2026-09-04T15:17:50.860","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"IBM Langflow OSS 1.0.0 through 1.11.2 allows remote authenticated attackers to bypass localhost-only MCP configuration installation by spoofing X-Forwarded-For: 127.0.0.1 header, enabling arbitrary writes to IDE config files (~/.cursor/mcp.json, etc.)."}],"affected":[{"source":"psirt@us.ibm.com","affectedData":[{"vendor":"IBM","product":"Langflow OSS","cpes":["cpe:2.3:a:ibm:langflow_oss:1.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:langflow_oss:1.11.2:*:*:*:*:*:*:*"],"versions":[{"version":"1.0.0","lessThanOrEqual":"1.11.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}]},"weaknesses":[{"source":"psirt@us.ibm.com","type":"Primary","description":[{"lang":"en","value":"CWE-284"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7285646","source":"psirt@us.ibm.com"}]}},{"cve":{"id":"CVE-2022-35497","sourceIdentifier":"cve@mitre.org","published":"2026-09-04T16:17:19.570","lastModified":"2026-09-04T16:17:19.570","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In Trimble TM4WEB 21.4.0.4 due to security misconfiguration with session identifiers, it is possible to recover valid session cookies via reflected cross-site scripting affecting the external document viewer endpoint."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{},"references":[{"url":"http://tm4web.com","source":"cve@mitre.org"},{"url":"http://trimble.com","source":"cve@mitre.org"},{"url":"https://github.com/PN-Tester/CVE-2022-35497/tree/main","source":"cve@mitre.org"}]}},{"cve":{"id":"CVE-2022-35499","sourceIdentifier":"cve@mitre.org","published":"2026-09-04T16:17:19.963","lastModified":"2026-09-04T18:17:44.527","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In Trimble TM4WEB 21.4.0.4, the external bill viewer endpoint is vulnerable to reflected cross-site scripting via injection in a arbitrary parameter appended to the URL."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":3.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T17:02:14.102021Z","id":"CVE-2022-35499","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"http://tm4web.com","source":"cve@mitre.org"},{"url":"http://trimble.com","source":"cve@mitre.org"},{"url":"https://github.com/PN-Tester/CVE-2022-35499","source":"cve@mitre.org"},{"url":"https://github.com/PN-Tester/CVE-2022-35499","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}]}},{"cve":{"id":"CVE-2026-18567","sourceIdentifier":"psirt@us.ibm.com","published":"2026-09-04T16:17:20.970","lastModified":"2026-09-04T18:17:50.530","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a local attacker to obtain information due to a race condition involving a predictable Unix domain socket path in a world-writable directory."}],"affected":[{"source":"psirt@us.ibm.com","affectedData":[{"vendor":"IBM","product":"Db2 Mirror for i","cpes":["cpe:2.3:a:ibm:db2_mirror_for_i:7.4:*:*:*:*:*:*:*","cpe:2.3:a:ibm:db2_mirror_for_i:7.4.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:db2_mirror_for_i:7.5:*:*:*:*:*:*:*","cpe:2.3:a:ibm:db2_mirror_for_i:7.5.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:db2_mirror_for_i:7.6:*:*:*:*:*:*:*","cpe:2.3:a:ibm:db2_mirror_for_i:7.6.0:*:*:*:*:*:*:*"],"versions":[{"version":"7.4","status":"affected"},{"version":"7.5","status":"affected"},{"version":"7.6","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L","baseScore":4.4,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":1.8,"impactScore":2.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T17:29:29.141115Z","id":"CVE-2026-18567","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"psirt@us.ibm.com","type":"Secondary","description":[{"lang":"en","value":"CWE-367"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7285904","source":"psirt@us.ibm.com"}]}},{"cve":{"id":"CVE-2026-18658","sourceIdentifier":"psirt@us.ibm.com","published":"2026-09-04T16:17:21.133","lastModified":"2026-09-04T16:17:21.133","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"IBM Operational Decision Manager 9.6.0.0, 9.5.0.0, 8.11.1.0, 8.11.0.1, 8.12.0.1, 9.5.0.1, and 9.0.0.1 is vulnerable to SQL injection. An unauthenticated attacker can execute arbitrary SQL statements and leverage database functionality to write a web shell to the application web root, resulting in remote code execution."}],"affected":[{"source":"psirt@us.ibm.com","affectedData":[{"vendor":"IBM","product":"Operational Decision Manager","cpes":["cpe:2.3:a:ibm:operational_decision_manager:9.6.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:operational_decision_manager:9.5.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:operational_decision_manager:8.11.1.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:operational_decision_manager:8.11.0.1:*:*:*:*:*:*:*","cpe:2.3:a:ibm:operational_decision_manager:8.12.0.1:*:*:*:*:*:*:*","cpe:2.3:a:ibm:operational_decision_manager:9.5.0.1:*:*:*:*:*:*:*","cpe:2.3:a:ibm:operational_decision_manager:9.0.0.1:*:*:*:*:*:*:*"],"versions":[{"version":"9.6.0.0","status":"affected"},{"version":"9.5.0.0","status":"affected"},{"version":"8.11.1.0","status":"affected"},{"version":"8.11.0.1","status":"affected"},{"version":"8.12.0.1","status":"affected"},{"version":"9.5.0.1","status":"affected"},{"version":"9.0.0.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}]},"weaknesses":[{"source":"psirt@us.ibm.com","type":"Primary","description":[{"lang":"en","value":"CWE-89"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7286196","source":"psirt@us.ibm.com"}]}},{"cve":{"id":"CVE-2026-18858","sourceIdentifier":"psirt@us.ibm.com","published":"2026-09-04T16:17:21.270","lastModified":"2026-09-04T16:17:21.270","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"IBM i 7.6, and 7.5 could allow a local authenticated attacker to obtain information from a privileged file when using SSH."}],"affected":[{"source":"psirt@us.ibm.com","affectedData":[{"vendor":"IBM","product":"i","cpes":["cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*"],"versions":[{"version":"7.6","status":"affected"},{"version":"7.5","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":3.3,"baseSeverity":"LOW","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.8,"impactScore":1.4}]},"weaknesses":[{"source":"psirt@us.ibm.com","type":"Primary","description":[{"lang":"en","value":"CWE-267"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7285938","source":"psirt@us.ibm.com"}]}},{"cve":{"id":"CVE-2026-18887","sourceIdentifier":"psirt@us.ibm.com","published":"2026-09-04T16:17:21.393","lastModified":"2026-09-04T17:16:56.690","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"IBM i 7.6, 7.5, 7.4, and 7.3 could allow an authenticated attacker to obtain sensitive information in PASE. An attacker could exploit this vulnerability to access information about process they shouldn't be permitted to access."}],"affected":[{"source":"psirt@us.ibm.com","affectedData":[{"vendor":"IBM","product":"i","cpes":["cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*"],"versions":[{"version":"7.6","status":"affected"},{"version":"7.5","status":"affected"},{"version":"7.4","status":"affected"},{"version":"7.3","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T16:44:24.309823Z","id":"CVE-2026-18887","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"psirt@us.ibm.com","type":"Secondary","description":[{"lang":"en","value":"CWE-200"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7285940","source":"psirt@us.ibm.com"}]}},{"cve":{"id":"CVE-2026-18905","sourceIdentifier":"psirt@us.ibm.com","published":"2026-09-04T16:17:21.517","lastModified":"2026-09-04T19:17:24.637","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"IBM ContextForge MCP Gateway (`mcp-contextforge-gateway`) <= v1.0.6 MCP Context Forge could allow a remote authenticated attacker to obtain sensitive information due to a DNS rebinding vulnerability during tool invocation."}],"affected":[{"source":"psirt@us.ibm.com","affectedData":[{"vendor":"IBM","product":"ContextForge MCP Gateway (`mcp-contextforge-gateway`)","cpes":["cpe:2.3:a:ibm:contextforge-mcp-gateway:*:*:*:*:*:*:*:*"],"versions":[{"version":"<= v1.0.6","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","baseScore":7.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":4.0}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T17:39:59.136548Z","id":"CVE-2026-18905","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"psirt@us.ibm.com","type":"Secondary","description":[{"lang":"en","value":"CWE-918"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7286053","source":"psirt@us.ibm.com"}]}},{"cve":{"id":"CVE-2026-19274","sourceIdentifier":"psirt@us.ibm.com","published":"2026-09-04T16:17:21.650","lastModified":"2026-09-04T18:17:51.260","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated Kubernetes tenant to hijack or permanently destroy another tenant's cluster-level RBAC permissions, caused by cluster-scoped RBAC objects being keyed solely by the bare CR name with no namespace disambiguation, allowing a same-named `InstanaAgent` CR in an attacker-controlled namespace to silently overwrite the shared `ClusterRoleBinding` or delete it outright and revoke the victim agent's cluster monitoring access."}],"affected":[{"source":"psirt@us.ibm.com","affectedData":[{"vendor":"IBM","product":"Observability with Instana (Agent)","cpes":["cpe:2.3:a:ibm:observability_with_instana_agent:build:*:*:*:*:*:*:*","cpe:2.3:a:ibm:observability_with_instana_agent:1.0.323:*:*:*:*:*:*:*"],"versions":[{"version":"Build 1.0.303","lessThanOrEqual":"1.0.323","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H","baseScore":9.6,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.1,"impactScore":5.8}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T17:28:42.625868Z","id":"CVE-2026-19274","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"psirt@us.ibm.com","type":"Secondary","description":[{"lang":"en","value":"CWE-284"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7286070","source":"psirt@us.ibm.com"}]}},{"cve":{"id":"CVE-2026-19283","sourceIdentifier":"psirt@us.ibm.com","published":"2026-09-04T16:17:21.777","lastModified":"2026-09-04T16:17:21.777","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated remote attacker to obtain sensitive information, caused by missing destination namespace validation when copying etcd mTLS client credentials from the openshift-etcd system namespace into an attacker-controlled namespace."}],"affected":[{"source":"psirt@us.ibm.com","affectedData":[{"vendor":"IBM","product":"Observability with Instana (Agent)","cpes":["cpe:2.3:a:ibm:observability_with_instana_agent:build:*:*:*:*:*:*:*","cpe:2.3:a:ibm:observability_with_instana_agent:1.0.323:*:*:*:*:*:*:*"],"versions":[{"version":"Build 1.0.303","lessThanOrEqual":"1.0.323","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","baseScore":7.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":4.0}]},"weaknesses":[{"source":"psirt@us.ibm.com","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7286070","source":"psirt@us.ibm.com"}]}},{"cve":{"id":"CVE-2026-19298","sourceIdentifier":"psirt@us.ibm.com","published":"2026-09-04T16:17:21.900","lastModified":"2026-09-04T16:17:21.900","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to execute arbitrary code due to an authorization bypass in the flow build process."}],"affected":[{"source":"psirt@us.ibm.com","affectedData":[{"vendor":"IBM","product":"Langflow OSS","cpes":["cpe:2.3:a:ibm:langflow_oss:1.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:langflow_oss:1.11.2:*:*:*:*:*:*:*"],"versions":[{"version":"1.0.0","lessThanOrEqual":"1.11.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}]},"weaknesses":[{"source":"psirt@us.ibm.com","type":"Primary","description":[{"lang":"en","value":"CWE-94"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7285640","source":"psirt@us.ibm.com"}]}},{"cve":{"id":"CVE-2026-19299","sourceIdentifier":"psirt@us.ibm.com","published":"2026-09-04T16:17:22.027","lastModified":"2026-09-04T16:17:22.027","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to path traversal."}],"affected":[{"source":"psirt@us.ibm.com","affectedData":[{"vendor":"IBM","product":"Langflow OSS","cpes":["cpe:2.3:a:ibm:langflow_oss:1.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:langflow_oss:1.11.2:*:*:*:*:*:*:*"],"versions":[{"version":"1.0.0","lessThanOrEqual":"1.11.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}]},"weaknesses":[{"source":"psirt@us.ibm.com","type":"Primary","description":[{"lang":"en","value":"CWE-22"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7285641","source":"psirt@us.ibm.com"}]}},{"cve":{"id":"CVE-2026-19300","sourceIdentifier":"psirt@us.ibm.com","published":"2026-09-04T16:17:22.167","lastModified":"2026-09-04T17:16:56.800","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to incomplete scrubbing of sensitive credential fields."}],"affected":[{"source":"psirt@us.ibm.com","affectedData":[{"vendor":"IBM","product":"Langflow OSS","cpes":["cpe:2.3:a:ibm:langflow_oss:1.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:langflow_oss:1.11.2:*:*:*:*:*:*:*"],"versions":[{"version":"1.0.0","lessThanOrEqual":"1.11.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T16:45:52.703626Z","id":"CVE-2026-19300","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"psirt@us.ibm.com","type":"Secondary","description":[{"lang":"en","value":"CWE-200"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7285642","source":"psirt@us.ibm.com"}]}},{"cve":{"id":"CVE-2026-19301","sourceIdentifier":"psirt@us.ibm.com","published":"2026-09-04T16:17:22.650","lastModified":"2026-09-04T18:17:51.383","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to server-side request forgery."}],"affected":[{"source":"psirt@us.ibm.com","affectedData":[{"vendor":"IBM","product":"Langflow OSS","cpes":["cpe:2.3:a:ibm:langflow_oss:1.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:langflow_oss:1.11.2:*:*:*:*:*:*:*"],"versions":[{"version":"1.0.0","lessThanOrEqual":"1.11.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N","baseScore":5.0,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T17:29:05.566668Z","id":"CVE-2026-19301","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"psirt@us.ibm.com","type":"Secondary","description":[{"lang":"en","value":"CWE-918"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7285639","source":"psirt@us.ibm.com"}]}},{"cve":{"id":"CVE-2026-19302","sourceIdentifier":"psirt@us.ibm.com","published":"2026-09-04T16:17:23.960","lastModified":"2026-09-04T19:17:24.753","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of symbolic links."}],"affected":[{"source":"psirt@us.ibm.com","affectedData":[{"vendor":"IBM","product":"Langflow OSS","cpes":["cpe:2.3:a:ibm:langflow_oss:1.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:langflow_oss:1.11.2:*:*:*:*:*:*:*"],"versions":[{"version":"1.0.0","lessThanOrEqual":"1.11.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T17:39:57.016840Z","id":"CVE-2026-19302","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"psirt@us.ibm.com","type":"Secondary","description":[{"lang":"en","value":"CWE-22"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7285641","source":"psirt@us.ibm.com"}]}},{"cve":{"id":"CVE-2026-19303","sourceIdentifier":"psirt@us.ibm.com","published":"2026-09-04T16:17:24.077","lastModified":"2026-09-04T16:17:24.077","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to delete arbitrary local files or directories due to improper limitation of a pathname to a restricted directory."}],"affected":[{"source":"psirt@us.ibm.com","affectedData":[{"vendor":"IBM","product":"Langflow OSS","cpes":["cpe:2.3:a:ibm:langflow_oss:1.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:langflow_oss:1.11.2:*:*:*:*:*:*:*"],"versions":[{"version":"1.0.0","lessThanOrEqual":"1.11.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.2}]},"weaknesses":[{"source":"psirt@us.ibm.com","type":"Primary","description":[{"lang":"en","value":"CWE-22"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7285643","source":"psirt@us.ibm.com"}]}},{"cve":{"id":"CVE-2026-19304","sourceIdentifier":"psirt@us.ibm.com","published":"2026-09-04T16:17:24.200","lastModified":"2026-09-04T16:17:24.200","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information from internal services due to a URL parser discrepancy."}],"affected":[{"source":"psirt@us.ibm.com","affectedData":[{"vendor":"IBM","product":"Langflow OSS","cpes":["cpe:2.3:a:ibm:langflow_oss:1.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:langflow_oss:1.11.2:*:*:*:*:*:*:*"],"versions":[{"version":"1.0.0","lessThanOrEqual":"1.11.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","baseScore":7.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":4.0}]},"weaknesses":[{"source":"psirt@us.ibm.com","type":"Primary","description":[{"lang":"en","value":"CWE-918"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7285639","source":"psirt@us.ibm.com"}]}},{"cve":{"id":"CVE-2026-19305","sourceIdentifier":"psirt@us.ibm.com","published":"2026-09-04T16:17:24.323","lastModified":"2026-09-04T16:17:24.323","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to server-side request forgery."}],"affected":[{"source":"psirt@us.ibm.com","affectedData":[{"vendor":"IBM","product":"Langflow OSS","cpes":["cpe:2.3:a:ibm:langflow_oss:1.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:langflow_oss:1.11.2:*:*:*:*:*:*:*"],"versions":[{"version":"1.0.0","lessThanOrEqual":"1.11.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N","baseScore":8.6,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":4.0}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T15:46:27.322288Z","id":"CVE-2026-19305","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"psirt@us.ibm.com","type":"Primary","description":[{"lang":"en","value":"CWE-918"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7285639","source":"psirt@us.ibm.com"}]}},{"cve":{"id":"CVE-2026-19306","sourceIdentifier":"psirt@us.ibm.com","published":"2026-09-04T16:17:24.793","lastModified":"2026-09-04T18:17:51.513","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"IBM Langflow OSS 1.0.0 through 1.11.2 allows an authenticated attacker to read arbitrary files from the server filesystem — including server secret material (secret_key, JWT signing keys, the application database, /proc/self/environ, and other tenants' upload directories) — by supplying absolute paths or traversal sequences in the files parameter of an authenticated build request. The file contents were embedded as text attachments in the language model prompt and transmitted to the configured model endpoint, resulting in confidential data exfiltration. This bypassed the LANGFLOW_RESTRICT_LOCAL_FILE_ACCESS=true containment boundary, which was enforced for other file-reading components but not for the Chat Input to Message attachment pipeline."}],"affected":[{"source":"psirt@us.ibm.com","affectedData":[{"vendor":"IBM","product":"Langflow OSS","cpes":["cpe:2.3:a:ibm:langflow_oss:1.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:langflow_oss:1.11.2:*:*:*:*:*:*:*"],"versions":[{"version":"1.0.0","lessThanOrEqual":"1.11.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","baseScore":7.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":4.0}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T17:41:09.327462Z","id":"CVE-2026-19306","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"psirt@us.ibm.com","type":"Secondary","description":[{"lang":"en","value":"CWE-22"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7285641","source":"psirt@us.ibm.com"}]}},{"cve":{"id":"CVE-2026-19645","sourceIdentifier":"psirt@us.ibm.com","published":"2026-09-04T16:17:24.923","lastModified":"2026-09-04T16:17:24.923","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"IBM MQ Agent CD: v1.0.0, v1.0.1, v2.0.0, v2.0.1 An authenticated user with a valid session cookie can submit arbitrarily large or computationallyexpensive requests that cause the LLM agent workers to be held for extended periods — rangingfrom tens of seconds to over ten minutes per request. When multiple such requests are sentconcurrently, the agent worker pool becomes exhausted, causing all other IBM MQ Console users toexperience degraded performance or complete unavailability of the AI Agent feature."}],"affected":[{"source":"psirt@us.ibm.com","affectedData":[{"vendor":"IBM","product":"MQ Agent","cpes":["cpe:2.3:a:ibm:mq_agent:cd:*:*:*:*:*:*:*"],"versions":[{"version":"CD: v1.0.0, v1.0.1, v2.0.0, v2.0.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}]},"weaknesses":[{"source":"psirt@us.ibm.com","type":"Primary","description":[{"lang":"en","value":"CWE-400"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7285394","source":"psirt@us.ibm.com"}]}},{"cve":{"id":"CVE-2026-19649","sourceIdentifier":"psirt@us.ibm.com","published":"2026-09-04T16:17:25.100","lastModified":"2026-09-04T16:17:25.100","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to obtain sensitive information due to improper logging of database credentials."}],"affected":[{"source":"psirt@us.ibm.com","affectedData":[{"vendor":"IBM","product":"App Connect Enterprise","cpes":["cpe:2.3:a:ibm:app_connect_enterprise:13.0.1.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:app_connect_enterprise:13.0.8.1:*:*:*:*:*:*:*","cpe:2.3:a:ibm:app_connect_enterprise:12.0.1.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:app_connect_enterprise:12.0.12.28:*:*:*:*:*:*:*"],"versions":[{"version":"13.0.1.0","lessThanOrEqual":"13.0.8.1","versionType":"semver","status":"affected"},{"version":"12.0.1.0","lessThanOrEqual":"12.0.12.28","versionType":"semver","status":"affected"}]},{"vendor":"IBM","product":"Integration Bus for z/OS","cpes":["cpe:2.3:a:ibm:integration_bus_for_zos:10.1.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:integration_bus_for_zos:10.1.0.7:*:*:*:*:*:*:*"],"versions":[{"version":"10.1.0.0","lessThanOrEqual":"10.1.0.7","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":6.2,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.5,"impactScore":3.6}]},"weaknesses":[{"source":"psirt@us.ibm.com","type":"Primary","description":[{"lang":"en","value":"CWE-532"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7286372","source":"psirt@us.ibm.com"}]}},{"cve":{"id":"CVE-2026-44402","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-04T16:17:25.250","lastModified":"2026-09-04T18:17:52.080","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Voltronic Power SNMP Web Pro 1.1 contains an unauthenticated remote code execution vulnerability in the upload.cgi firmware update endpoint that allows remote attackers to execute arbitrary commands as root by uploading a crafted tar archive without valid credentials. Attackers can supply a malicious tar archive containing arbitrary executable files that are extracted to a privileged directory and executed as root, achieving full system compromise."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"Voltronic Power","product":"SNMP Web Pro","defaultStatus":"unaffected","versions":[{"version":"1.1","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":9.3,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T17:39:52.858365Z","id":"CVE-2026-44402","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-434"}]}],"references":[{"url":"https://github.com/Virgula0/CVE-2026-44402","source":"disclosure@vulncheck.com"},{"url":"https://voltronicpower.com/","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/voltronic-power-snmp-web-pro-unauthenticated-rce-via-upload-cgi","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-5522","sourceIdentifier":"psirt@us.ibm.com","published":"2026-09-04T16:17:25.870","lastModified":"2026-09-04T16:17:25.870","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 005 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data."}],"affected":[{"source":"psirt@us.ibm.com","affectedData":[{"vendor":"IBM","product":"QRadar","cpes":["cpe:2.3:a:ibm:qradar:7.5.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:qradar:7.5.0up15:interim_fix_005:*:*:*:*:*:*"],"versions":[{"version":"7.5.0","lessThanOrEqual":"7.5.0 UP15 Interim Fix 005","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N","baseScore":6.7,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.5,"impactScore":4.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T15:54:43.419028Z","id":"CVE-2026-5522","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"psirt@us.ibm.com","type":"Primary","description":[{"lang":"en","value":"CWE-798"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7285277","source":"psirt@us.ibm.com"}]}},{"cve":{"id":"CVE-2026-75160","sourceIdentifier":"cve@mitre.org","published":"2026-09-04T16:17:57.827","lastModified":"2026-09-04T20:17:26.533","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"An issue in X-Serie Gateway Firmware V6_00_05 allows a remote attacker to escalate privileges via the endpoints /cgi-bin/wwwugw.cgi and /cgi-bin/ugwdownload.cgi."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","baseScore":9.1,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T19:26:16.574075Z","id":"CVE-2026-75160","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-269"}]}],"references":[{"url":"https://en.mbs-solutions.de/mbs","source":"cve@mitre.org"},{"url":"https://en.mbs-solutions.de/xserie","source":"cve@mitre.org"},{"url":"https://github.com/SilviaMun/vulnerability-research/tree/main/CVE-2026-75160","source":"cve@mitre.org"}]}},{"cve":{"id":"CVE-2026-75161","sourceIdentifier":"cve@mitre.org","published":"2026-09-04T16:17:57.960","lastModified":"2026-09-04T16:17:57.960","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"An issue in the ugw-restart method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with the low-privileged Standard role to inject arbitrary code into the dpcheck system utility executed as root."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://en.mbs-solutions.de/mbs","source":"cve@mitre.org"},{"url":"https://en.mbs-solutions.de/xserie","source":"cve@mitre.org"},{"url":"https://github.com/SilviaMun/vulnerability-research/tree/main/CVE-2026-75161","source":"cve@mitre.org"}]}},{"cve":{"id":"CVE-2026-75162","sourceIdentifier":"cve@mitre.org","published":"2026-09-04T16:17:58.097","lastModified":"2026-09-04T16:17:58.097","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"An information disclosure vulnerability in the opcua-configuration method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows any remote authenticated user, including users with the low-privileged Standard role, to retrieve the configured OPC-UA authentication credentials in cleartext via the JSON API response."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://en.mbs-solutions.de/mbs","source":"cve@mitre.org"},{"url":"https://en.mbs-solutions.de/xserie","source":"cve@mitre.org"},{"url":"https://github.com/SilviaMun/vulnerability-research/tree/main/CVE-2026-75162","source":"cve@mitre.org"}]}},{"cve":{"id":"CVE-2026-75163","sourceIdentifier":"cve@mitre.org","published":"2026-09-04T16:17:58.220","lastModified":"2026-09-04T17:16:57.450","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"An information disclosure vulnerability in the ugw-deviceinfo method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_05 returns detailed system version fields (operatingsystem, gatewayversion) to any authenticated user, including users with the low-privileged Standard role."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T16:57:53.586683Z","id":"CVE-2026-75163","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-200"}]}],"references":[{"url":"https://en.mbs-solutions.de/mbs","source":"cve@mitre.org"},{"url":"https://en.mbs-solutions.de/xserie","source":"cve@mitre.org"},{"url":"https://github.com/SilviaMun/vulnerability-research/tree/main/CVE-2026-75163","source":"cve@mitre.org"}]}},{"cve":{"id":"CVE-2026-75164","sourceIdentifier":"cve@mitre.org","published":"2026-09-04T16:17:58.330","lastModified":"2026-09-04T20:17:26.717","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"An arbitrary file read vulnerability in /cgi-bin/ugwdownload.cgi of MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with the low-privileged Standard role to retrieve arbitrary files from the device filesystem via the file query string parameter."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T19:24:39.393514Z","id":"CVE-2026-75164","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-552"}]}],"references":[{"url":"https://en.mbs-solutions.de/mbs","source":"cve@mitre.org"},{"url":"https://en.mbs-solutions.de/xserie","source":"cve@mitre.org"},{"url":"https://github.com/SilviaMun/vulnerability-research/tree/main/CVE-2026-75164","source":"cve@mitre.org"}]}},{"cve":{"id":"CVE-2026-75165","sourceIdentifier":"cve@mitre.org","published":"2026-09-04T16:17:58.450","lastModified":"2026-09-04T16:17:58.450","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"An issue in /cgi-bin/wwwugw.cgi of MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with the low-privileged Standard role to invoke hidden network diagnostic methods (ugw-ping, ugw-traceroute) that are not exposed in the web UI, allowing attackers to obtain sensitive information."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://en.mbs-solutions.de/mbs","source":"cve@mitre.org"},{"url":"https://en.mbs-solutions.de/xserie","source":"cve@mitre.org"},{"url":"https://github.com/SilviaMun/vulnerability-research/tree/main/CVE-2026-75165","source":"cve@mitre.org"}]}},{"cve":{"id":"CVE-2026-75166","sourceIdentifier":"cve@mitre.org","published":"2026-09-04T16:17:58.570","lastModified":"2026-09-04T16:17:58.570","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Insecure Permission vulnerability in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows the low-privileged service user to execute /usr/bin/tcpdump as root without a password. By leveraging the tcpdump -z option, an authenticated attacker can achieve arbitrary command execution."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://en.mbs-solutions.de/mbs","source":"cve@mitre.org"},{"url":"https://en.mbs-solutions.de/xserie","source":"cve@mitre.org"},{"url":"https://github.com/SilviaMun/vulnerability-research/tree/main/CVE-2026-75166","source":"cve@mitre.org"}]}},{"cve":{"id":"CVE-2026-75167","sourceIdentifier":"cve@mitre.org","published":"2026-09-04T16:17:58.690","lastModified":"2026-09-04T16:17:58.690","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"A broken access control vulnerability in the ugw-usr-edit method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with the low-privileged Standard role to change the password of arbitrary accounts."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://en.mbs-solutions.de/mbs","source":"cve@mitre.org"},{"url":"https://en.mbs-solutions.de/xserie","source":"cve@mitre.org"},{"url":"https://github.com/SilviaMun/vulnerability-research/tree/main/CVE-2026-75167","source":"cve@mitre.org"}]}},{"cve":{"id":"CVE-2026-75168","sourceIdentifier":"cve@mitre.org","published":"2026-09-04T16:17:58.813","lastModified":"2026-09-04T17:16:57.610","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"An issue in the ugw-editfile method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with the low-privileged Standard role to write arbitrary content to files within /uxx/config/ and /ugw/config/."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","baseScore":6.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":3.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T16:54:17.757073Z","id":"CVE-2026-75168","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-284"}]}],"references":[{"url":"https://en.mbs-solutions.de/mbs","source":"cve@mitre.org"},{"url":"https://en.mbs-solutions.de/xserie","source":"cve@mitre.org"},{"url":"https://github.com/SilviaMun/vulnerability-research/tree/main/CVE-2026-75168","source":"cve@mitre.org"}]}},{"cve":{"id":"CVE-2026-75169","sourceIdentifier":"cve@mitre.org","published":"2026-09-04T16:17:58.937","lastModified":"2026-09-04T16:17:58.937","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"An arbitrary file upload vulnerability in /cgi-bin/ugwupload.cgi of MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with Admin role to upload files with arbitrary content to hardcoded paths."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://en.mbs-solutions.de/mbs","source":"cve@mitre.org"},{"url":"https://en.mbs-solutions.de/xserie","source":"cve@mitre.org"},{"url":"https://github.com/SilviaMun/vulnerability-research/tree/main/CVE-2026-75169","source":"cve@mitre.org"}]}},{"cve":{"id":"CVE-2026-75170","sourceIdentifier":"cve@mitre.org","published":"2026-09-04T16:17:59.050","lastModified":"2026-09-04T16:17:59.050","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in the /loginController/doLogin endpoint of the HubCore platform (version 14.1.1) allows a remote unauthenticated attacker to inject arbitrary JavaScript into the application's response via the language POST parameter."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://github.com/SilviaMun/vulnerability-research/tree/main/CVE-2026-75170","source":"cve@mitre.org"},{"url":"https://hubcore.ai/","source":"cve@mitre.org"}]}},{"cve":{"id":"CVE-2026-75171","sourceIdentifier":"cve@mitre.org","published":"2026-09-04T16:17:59.173","lastModified":"2026-09-04T16:17:59.173","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"An issue in HubCore v.14.1.1 allows a remote attacker to escalate privileges via the HUBCOREID session cookie handling component."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://github.com/SilviaMun/vulnerability-research/tree/main/CVE-2026-75171","source":"cve@mitre.org"},{"url":"https://hubcore.ai/","source":"cve@mitre.org"}]}},{"cve":{"id":"CVE-2026-75429","sourceIdentifier":"cve@mitre.org","published":"2026-09-04T16:17:59.290","lastModified":"2026-09-04T16:17:59.290","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"PowerJob versions 4.x through 5.1.2 contain an unauthenticated remote code execution vulnerability in the /friend/process endpoint of the Server-Worker transport layer"}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://gist.github.com/unpredictable21/dbd1791294c9a77ad0ee3d4827073966","source":"cve@mitre.org"},{"url":"https://github.com/PowerJob/PowerJob","source":"cve@mitre.org"},{"url":"https://github.com/PowerJob/PowerJob/blob/master/docker-compose.yml","source":"cve@mitre.org"}]}},{"cve":{"id":"CVE-2026-75431","sourceIdentifier":"cve@mitre.org","published":"2026-09-04T16:17:59.413","lastModified":"2026-09-04T19:17:27.110","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"PowerJob Server version 5.1.2 (and likely earlier) uses a predictable JWT signing key for HS256-based authentication. This allows a remote attacker to execute arbitrary code."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@mitre.org","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","baseScore":9.1,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T18:23:42.524319Z","id":"CVE-2026-75431","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-321"}]}],"references":[{"url":"https://gist.github.com/unpredictable21/39e6ce22e4bc45b0e553d0fa6a6e4d1c","source":"cve@mitre.org"},{"url":"https://github.com/PowerJob/PowerJob/blob/master/docker-compose.yml","source":"cve@mitre.org"},{"url":"https://github.com/PowerJob/PowerJob/blob/master/powerjob-server/powerjob-server-auth/src/main/java/tech/powerjob/server/auth/jwt/impl/DefaultSecretProvider.java","source":"cve@mitre.org"},{"url":"https://github.com/PowerJob/PowerJob/blob/master/powerjob-server/powerjob-server-auth/src/main/java/tech/powerjob/server/auth/jwt/impl/JwtServiceImpl.java","source":"cve@mitre.org"},{"url":"https://github.com/PowerJob/PowerJob/blob/master/powerjob-server/powerjob-server-openapi/src/main/java/tech/powerjob/server/openapi/service/impl/OpenApiSecurityServiceImpl.java","source":"cve@mitre.org"},{"url":"https://github.com/PowerJob/PowerJob/blob/master/powerjob-server/powerjob-server-starter/src/main/resources/application-daily.properties","source":"cve@mitre.org"}]}},{"cve":{"id":"CVE-2026-77822","sourceIdentifier":"psirt@us.ibm.com","published":"2026-09-04T16:17:59.550","lastModified":"2026-09-04T19:17:27.240","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"IBM ContextForge MCP Gateway could allow a remote authenticated attacker to obtain sensitive information due to server-side request forgery via DNS rebinding."}],"affected":[{"source":"psirt@us.ibm.com","affectedData":[{"vendor":"IBM","product":"ContextForge MCP Gateway","cpes":["cpe:2.3:a:ibm:contextforge-mcp-gateway:*:*:*:*:*:*:*:*"],"versions":[{"version":"<= v1.0.8","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N","baseScore":8.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.8,"impactScore":5.8}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T17:09:15.348543Z","id":"CVE-2026-77822","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"psirt@us.ibm.com","type":"Secondary","description":[{"lang":"en","value":"CWE-918"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7286055","source":"psirt@us.ibm.com"}]}},{"cve":{"id":"CVE-2026-78543","sourceIdentifier":"psirt@us.ibm.com","published":"2026-09-04T16:17:59.690","lastModified":"2026-09-04T18:17:56.203","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a remote attacker to cause a denial of service due to an infinite loop."}],"affected":[{"source":"psirt@us.ibm.com","affectedData":[{"vendor":"IBM","product":"App Connect Enterprise","cpes":["cpe:2.3:a:ibm:app_connect_enterprise:13.0.1.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:app_connect_enterprise:13.0.8.1:*:*:*:*:*:*:*","cpe:2.3:a:ibm:app_connect_enterprise:12.0.1.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:app_connect_enterprise:12.0.12.28:*:*:*:*:*:*:*"],"versions":[{"version":"13.0.1.0","lessThanOrEqual":"13.0.8.1","versionType":"semver","status":"affected"},{"version":"12.0.1.0","lessThanOrEqual":"12.0.12.28","versionType":"semver","status":"affected"}]},{"vendor":"IBM","product":"Integration Bus for z/OS","cpes":["cpe:2.3:a:ibm:integration_bus_for_zos:10.1.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:integration_bus_for_zos:10.1.0.7:*:*:*:*:*:*:*"],"versions":[{"version":"10.1.0.0","lessThanOrEqual":"10.1.0.7","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T17:41:36.354396Z","id":"CVE-2026-78543","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"psirt@us.ibm.com","type":"Secondary","description":[{"lang":"en","value":"CWE-835"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7286372","source":"psirt@us.ibm.com"}]}},{"cve":{"id":"CVE-2026-78658","sourceIdentifier":"psirt@us.ibm.com","published":"2026-09-04T16:17:59.823","lastModified":"2026-09-04T16:17:59.823","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.25, and 7.3 through 7.3.2.20 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.15, 8.1 through 8.1.2.8, and 8.2 through 8.2.2.1 IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptible to an formation disclosure vulnerability when processing redacted property values. If a deployment is configured with a secure property that starts with certain non-ASCII characters, the redaction engine may fail to mask subsequent ASCII secure values embedded inside unsecure properties. An authenticated user with permissions to view deployment request details could exploit this flaw via the UI or API to view sensitive values in plain text that should otherwise be redacted."}],"affected":[{"source":"psirt@us.ibm.com","affectedData":[{"vendor":"IBM","product":"UCD - IBM UrbanCode Deploy","cpes":["cpe:2.3:a:ibm:ucd_ibm_urbancode_deploy:7.2:*:*:*:*:*:*:*","cpe:2.3:a:ibm:ucd_ibm_urbancode_deploy:7.2.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:ucd_ibm_urbancode_deploy:7.2.3.25:*:*:*:*:*:*:*","cpe:2.3:a:ibm:ucd_ibm_urbancode_deploy:7.3:*:*:*:*:*:*:*","cpe:2.3:a:ibm:ucd_ibm_urbancode_deploy:7.3.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:ucd_ibm_urbancode_deploy:7.3.2.20:*:*:*:*:*:*:*"],"versions":[{"version":"7.2.0","lessThanOrEqual":"7.2.3.25","versionType":"semver","status":"affected"},{"version":"7.3.0","lessThanOrEqual":"7.3.2.20","versionType":"semver","status":"affected"}]},{"vendor":"IBM","product":"UCD - IBM DevOps Deploy","cpes":["cpe:2.3:a:ibm:ucd_ibm_devops_deploy:8.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:ucd_ibm_devops_deploy:8.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:ucd_ibm_devops_deploy:8.0.1.15:*:*:*:*:*:*:*","cpe:2.3:a:ibm:ucd_ibm_devops_deploy:8.1:*:*:*:*:*:*:*","cpe:2.3:a:ibm:ucd_ibm_devops_deploy:8.1.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:ucd_ibm_devops_deploy:8.1.2.8:*:*:*:*:*:*:*","cpe:2.3:a:ibm:ucd_ibm_devops_deploy:8.2:*:*:*:*:*:*:*","cpe:2.3:a:ibm:ucd_ibm_devops_deploy:8.2.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:ucd_ibm_devops_deploy:8.2.2.1:*:*:*:*:*:*:*"],"versions":[{"version":"8.0","lessThanOrEqual":"8.0.1.15","versionType":"semver","status":"affected"},{"version":"8.1.0","lessThanOrEqual":"8.1.2.8","versionType":"semver","status":"affected"},{"version":"8.2.0","lessThanOrEqual":"8.2.2.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}]},"weaknesses":[{"source":"psirt@us.ibm.com","type":"Primary","description":[{"lang":"en","value":"CWE-212"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7286256","source":"psirt@us.ibm.com"}]}},{"cve":{"id":"CVE-2026-78970","sourceIdentifier":"cve@mitre.org","published":"2026-09-04T16:17:59.973","lastModified":"2026-09-04T18:17:56.320","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"JeecgBoot 3.9.2 and earlier contains an authorization bypass vulnerability in the SystemApiController component. An authenticated attacker with any valid JWT token can access multiple API endpoints (including queryAllUser, queryUsersByUsernames, queryUserById, and queryUsersByIds) to retrieve sensitive information of all users, including real names, phone numbers, email addresses, employee numbers, and role definitions, due to missing fine-grained permission checks and incomplete data desensitization."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T17:40:42.451339Z","id":"CVE-2026-78970","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]}],"references":[{"url":"https://github.com/jeecgboot/JeecgBoot/issues/9670","source":"cve@mitre.org"},{"url":"https://github.com/jeecgboot/JeecgBoot/issues/9674","source":"cve@mitre.org"},{"url":"https://github.com/jeecgboot/JeecgBoot/issues/9674","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}]}},{"cve":{"id":"CVE-2026-79418","sourceIdentifier":"cve@mitre.org","published":"2026-09-04T16:18:00.103","lastModified":"2026-09-04T16:18:00.103","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"EMX Tecnologia Gestao X version <= 8.4 contains a Stored Cross-Site Scripting (XSS) vulnerability in the Help Chat functionality. Improper neutralization of user-controlled input during web page generation allows authenticated attackers to execute arbitrary JavaScript in the context of other authenticated users, potentially resulting in session hijacking, account takeover, and unauthorized actions."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://drive.google.com/file/d/1mp-uS-tAthH9FAObfx1D3lOM7IIjRsmE/view?usp=sharing","source":"cve@mitre.org"},{"url":"https://emxtecnologia.com.br/gestao-x-business-suite/","source":"cve@mitre.org"}]}},{"cve":{"id":"CVE-2026-79419","sourceIdentifier":"cve@mitre.org","published":"2026-09-04T16:18:00.250","lastModified":"2026-09-05T02:17:17.550","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"A reflected cross-site scripting (XSS) vulnerability exists in EMX Tecnologia Gestao X Business Suite 8.4 and earlier. The vulnerability is caused by insufficient validation and sanitization of the mensagem parameter in the /Configuracao/Imagens.aspx endpoint, allowing an authenticated attacker to inject arbitrary JavaScript code that is reflected and executed in the context of a victim's browser."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://drive.google.com/file/d/1QVH1MRo3G4KqmBORkhXITzcYmO_BDjWc/view","source":"cve@mitre.org"},{"url":"https://emxtecnologia.com.br/gestao-x-business-suite/","source":"cve@mitre.org"}]}},{"cve":{"id":"CVE-2026-80758","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:00.830","lastModified":"2026-09-04T16:18:00.830","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfutex: Avoid private hash use-after-free on final put\n\nfutex_private_hash_put() drops the reference to fph before evaluating\nfph->mm for wake_up_var(). futex_ref_put() enables preemption again before\nreturning. If that put drops the final reference and the task is preempted,\nanother task can pivot to the replacement hash and free the old hash after\nan RCU grace period. The first task then reads fph->mm from the freed\nallocation when it resumes.\n\nKASAN reports a slab-use-after-free in futex_private_hash_put(), with the\nread at offset 24 in a freed kmalloc-512 allocation. The allocation and\nfree stacks point to futex_hash_allocate() and the RCU free path,\nrespectively.\n\nLoad the mm pointer while the fph reference is still held and pass the\nsaved value to wake_up_var(). wake_up_var() uses the pointer as a waitqueue\nkey and does not dereference the mm through it."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["kernel/futex/core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"bd54df5ea7cadac520e346d5f0fe5d58e635b6ba","lessThan":"dba60d26e9dda3e157ad6b0934d4232f6c6904ee","versionType":"git","status":"affected"},{"version":"bd54df5ea7cadac520e346d5f0fe5d58e635b6ba","lessThan":"12cd315a7b6a7d7db3f69d98bfe3909275e9451d","versionType":"git","status":"affected"},{"version":"bd54df5ea7cadac520e346d5f0fe5d58e635b6ba","lessThan":"25408c62ed4ebcd491d0e9e4b4a5b512547512e4","versionType":"git","status":"affected"},{"version":"bd54df5ea7cadac520e346d5f0fe5d58e635b6ba","lessThan":"1c7efabfbaf796f11000a46094a69955a01ec6cc","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["kernel/futex/core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.16","status":"affected"},{"version":"0","lessThan":"6.16","versionType":"semver","status":"unaffected"},{"version":"6.18.47","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.11","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.1","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/12cd315a7b6a7d7db3f69d98bfe3909275e9451d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1c7efabfbaf796f11000a46094a69955a01ec6cc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/25408c62ed4ebcd491d0e9e4b4a5b512547512e4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dba60d26e9dda3e157ad6b0934d4232f6c6904ee","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80759","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:00.950","lastModified":"2026-09-04T16:18:00.950","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_aml: validate firmware segment lengths\n\naml_download_firmware() reads two lengths from the firmware header and\nuses them to build pointers before checking that the header and segment\ndata are present. A truncated or inconsistent firmware image can make\nthe driver read past firmware->data while constructing TCI commands.\n\nReject images shorter than the header and ensure that the ICCM and DCCM\nranges fit within the loaded firmware before downloading either segment."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/bluetooth/hci_aml.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"37bac77e4649e8158698a60addc22ec4faf5649a","lessThan":"7733b01ed13685773ccda91035a46f87d4cfef7c","versionType":"git","status":"affected"},{"version":"37bac77e4649e8158698a60addc22ec4faf5649a","lessThan":"e1534d49a7b8ba728e84b020f6d802aa1cb759d9","versionType":"git","status":"affected"},{"version":"37bac77e4649e8158698a60addc22ec4faf5649a","lessThan":"6c70253462902d835e843b470f74aa816d60af80","versionType":"git","status":"affected"},{"version":"37bac77e4649e8158698a60addc22ec4faf5649a","lessThan":"2763b8bcb504e30ec955474f51b99ce42fc62f3b","versionType":"git","status":"affected"},{"version":"37bac77e4649e8158698a60addc22ec4faf5649a","lessThan":"2bf6b9baca9372ea51b6d0f2820dc9bf29a83ef4","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/bluetooth/hci_aml.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.12","status":"affected"},{"version":"0","lessThan":"6.12","versionType":"semver","status":"unaffected"},{"version":"6.12.106","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.47","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.11","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.1","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2763b8bcb504e30ec955474f51b99ce42fc62f3b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2bf6b9baca9372ea51b6d0f2820dc9bf29a83ef4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6c70253462902d835e843b470f74aa816d60af80","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7733b01ed13685773ccda91035a46f87d4cfef7c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e1534d49a7b8ba728e84b020f6d802aa1cb759d9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80760","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:01.070","lastModified":"2026-09-04T16:18:01.070","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: MGMT: reject HCI_CMD_SYNC params_len above 255\n\nmgmt_hci_cmd_sync() checks that the message length agrees with params_len\nbut puts no upper bound on it. params_len is __le16 while the parameter\nlength in the HCI command header is a u8:\n\n\tstruct hci_command_hdr {\n\t\t__le16\topcode;\n\t\t__u8\tplen;\n\t} __packed;\n\nhci_cmd_sync_alloc() assigns one to the other:\n\n\thdr->plen = plen;\n\n\tif (plen)\n\t\tskb_put_data(skb, param, plen);\n\nso a params_len of 256 leaves plen at 0 while all 256 bytes are still\nappended. The frame handed to the driver then declares no parameters and\ncarries 256 of them. On a length framed transport such as H:4 the\ncontroller takes the trailing bytes as the start of the next packet.\n\nThe mgmt socket MTU is HCI_MAX_FRAME_SIZE, so params_len can reach about\n1KB this way. Commit 03f1700b9b4d (\"Bluetooth: MGMT: reject malformed\nHCI_CMD_SYNC commands\") only made params_len agree with the message\nlength, a value that fits the message but not the header field is still\naccepted.\n\nReject params_len that does not fit the header field."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/bluetooth/mgmt.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"827af4787e74e8df9e8e0677a69fbb15e0856d2f","lessThan":"b7d9edcf9fe6e9ec3a2e80ef9e8d44ef9b4f2894","versionType":"git","status":"affected"},{"version":"827af4787e74e8df9e8e0677a69fbb15e0856d2f","lessThan":"0bd0195ce25737cbdd0eabc54319ee0ddf3a0ad2","versionType":"git","status":"affected"},{"version":"827af4787e74e8df9e8e0677a69fbb15e0856d2f","lessThan":"6e1c44878aa3ee7336efeaf01414b030b0a5c273","versionType":"git","status":"affected"},{"version":"827af4787e74e8df9e8e0677a69fbb15e0856d2f","lessThan":"5d95286b6d6e8f1d304da7522bfa6860fc017e48","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/bluetooth/mgmt.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.13","status":"affected"},{"version":"0","lessThan":"6.13","versionType":"semver","status":"unaffected"},{"version":"6.18.47","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.11","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.1","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0bd0195ce25737cbdd0eabc54319ee0ddf3a0ad2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5d95286b6d6e8f1d304da7522bfa6860fc017e48","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6e1c44878aa3ee7336efeaf01414b030b0a5c273","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b7d9edcf9fe6e9ec3a2e80ef9e8d44ef9b4f2894","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80761","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:01.190","lastModified":"2026-09-04T16:18:01.190","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: ISO: zero the sockaddr before returning it in getname\n\niso_sock_getname() fills a struct sockaddr_iso in place and returns its\nsize without clearing it first, so bytes it does not write are copied to\nuser space from the kernel stack. The getsockname(2) and getpeername(2)\npaths both run through do_getsockname(), which hands getname() an\nuninitialized sockaddr_storage on the stack and copies back up to the\nnumber of bytes getname() returns, so the driver has to initialize every\nbyte it accounts for.\n\nTwo ranges are left uninitialized:\n\n  - struct sockaddr_iso is 10 bytes but only 9 are written (family,\n    iso_bdaddr, iso_bdaddr_type), leaking the trailing pad byte on every\n    call.\n\n  - for a broadcast peer (BIS_LINK or PA_LINK) the returned length grows\n    by sizeof(struct sockaddr_iso_bc), but only bc_sid, bc_num_bis and\n    bc_bis are filled; bc_bdaddr and bc_bdaddr_type, the first 7 bytes of\n    that structure, are never written.\n\nAn unprivileged process can open a BTPROTO_ISO socket and reach the pad\nleak with getsockname(); the broadcast leak needs an established BIS/PA\nconnection. l2cap and rfcomm already memset their sockaddr in getname\nfor the same reason; do the same here."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/bluetooth/iso.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"ccf74f2390d60a2f9a75ef496d2564abb478f46a","lessThan":"1f6d1f2611af0eb36b133a41d29ffd2cc2601615","versionType":"git","status":"affected"},{"version":"ccf74f2390d60a2f9a75ef496d2564abb478f46a","lessThan":"9069be87c67f290783b332c4284e09fb89cb9ea7","versionType":"git","status":"affected"},{"version":"ccf74f2390d60a2f9a75ef496d2564abb478f46a","lessThan":"190b719b787eb4ca6c25b12fab224806f9108b06","versionType":"git","status":"affected"},{"version":"ccf74f2390d60a2f9a75ef496d2564abb478f46a","lessThan":"884cf2cc957da7ac178a0e6c6c69ddfec0481cc8","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/bluetooth/iso.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.0","status":"affected"},{"version":"0","lessThan":"6.0","versionType":"semver","status":"unaffected"},{"version":"6.18.47","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.11","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.1","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/190b719b787eb4ca6c25b12fab224806f9108b06","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1f6d1f2611af0eb36b133a41d29ffd2cc2601615","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/884cf2cc957da7ac178a0e6c6c69ddfec0481cc8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9069be87c67f290783b332c4284e09fb89cb9ea7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80762","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:01.313","lastModified":"2026-09-04T16:18:01.313","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_sync: Fix accept list UAF during suspend\n\nhci_update_event_filter_sync() walks hdev->accept_list while sending a\nsynchronous HCI command for each remote-wakeup device.  The suspend path\nholds hdev->req_lock, but accept-list updates are serialized by hdev->lock.\nConsequently, remove_device() can free the current list entry during the\ncontroller wait.\n\nThe following interleaving causes the use-after-free:\n\n  hci_update_event_filter_sync()    remove_device()\n  fetch accept-list entry\n  hci_set_event_filter_sync()\n    wait for controller response    hci_dev_lock()\n                                    list_del()\n                                    kfree()\n                                    hci_dev_unlock()\n  read the freed list.next\n\nKASAN reported:\n\n  BUG: KASAN: slab-use-after-free in hci_suspend_sync+0x835/0x910\n  Read of size 8 at addr ffff88810bec8440 by task kworker/0:1/10\n  Workqueue: events vhci_suspend_work\n  Call Trace:\n   hci_suspend_sync+0x835/0x910\n   hci_suspend_dev+0x182/0x450\n   process_one_work+0x661/0x1090\n   worker_thread+0x45b/0xd10\n\n  Allocated by task 86:\n   hci_bdaddr_list_add_with_flags+0x1a8/0x400\n   add_device+0x381/0x820\n   hci_sock_sendmsg+0x1033/0x1ea0\n\n  Freed by task 91:\n   kfree+0x131/0x3c0\n   remove_device+0x429/0xb70\n   hci_sock_sendmsg+0x1033/0x1ea0\n\nSnapshot the remote-wakeup addresses under hdev->lock.  Release the lock\nbefore sending HCI commands.  Clear the controller event filter before\nbuilding the snapshot, and skip allocation and the second list traversal\nwhen there are no matching entries.  This preserves the original filter\nand scan-state updates without retaining an accept-list node across a\ncontroller wait."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/bluetooth/hci_sync.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"182ee45da083db4e3e621541ccf255bfa9652214","lessThan":"bb5f5414d1a6272a16f68684e998f4063dd19f57","versionType":"git","status":"affected"},{"version":"182ee45da083db4e3e621541ccf255bfa9652214","lessThan":"b5181516a9f5c2fdb3271cdad72a5b16c6963a44","versionType":"git","status":"affected"},{"version":"182ee45da083db4e3e621541ccf255bfa9652214","lessThan":"87ad116ac3abc6f2ce2b5b6c488f633003581eee","versionType":"git","status":"affected"},{"version":"182ee45da083db4e3e621541ccf255bfa9652214","lessThan":"fe93a697a7a92fa9adf78c9ff67a10db3193290c","versionType":"git","status":"affected"},{"version":"182ee45da083db4e3e621541ccf255bfa9652214","lessThan":"95bb57bc11a91caf042ad00fca85e480d3fda37f","versionType":"git","status":"affected"},{"version":"182ee45da083db4e3e621541ccf255bfa9652214","lessThan":"29c59212a507804d7616b8abf491d30b4ab8e75f","versionType":"git","status":"affected"},{"version":"182ee45da083db4e3e621541ccf255bfa9652214","lessThan":"f57b399c4fa1501b2d5451f52d861ece86bcf3db","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/bluetooth/hci_sync.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.17","status":"affected"},{"version":"0","lessThan":"5.17","versionType":"semver","status":"unaffected"},{"version":"6.1.187","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.156","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.108","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.47","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.11","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.1","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/29c59212a507804d7616b8abf491d30b4ab8e75f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/87ad116ac3abc6f2ce2b5b6c488f633003581eee","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/95bb57bc11a91caf042ad00fca85e480d3fda37f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b5181516a9f5c2fdb3271cdad72a5b16c6963a44","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bb5f5414d1a6272a16f68684e998f4063dd19f57","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f57b399c4fa1501b2d5451f52d861ece86bcf3db","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fe93a697a7a92fa9adf78c9ff67a10db3193290c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80763","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:01.487","lastModified":"2026-09-04T16:18:01.487","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_event: validate LE Set CIG Parameters response\n\nThe Command Complete dispatch validates only the fixed part of the LE Set\nCIG Parameters response. After that part is pulled from the skb,\nhci_cc_le_set_cig_params() trusts num_handles and reads each entry in the\ntrailing handle array.\n\nMatching num_handles against the command's num_cis does not guarantee\nthat the response contains the advertised handles. A truncated response\nfrom a malfunctioning controller can therefore make the handler read\nbeyond the skb data.\n\nValidate that the remaining skb data contains all advertised handles.\nInclude this in the existing response validation so malformed responses\nalso follow the established CIG failure handling."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/bluetooth/hci_event.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"26afbd826ee326e63a334c37fd45e82e50a615ec","lessThan":"9e05783d0bb96a7b853cc058a7c7de2dc4a62154","versionType":"git","status":"affected"},{"version":"26afbd826ee326e63a334c37fd45e82e50a615ec","lessThan":"26741d178f31932c9018b36b7953e6dc391436a4","versionType":"git","status":"affected"},{"version":"26afbd826ee326e63a334c37fd45e82e50a615ec","lessThan":"a34df5c4a439cfc04565fa5be608ed1e53134f1f","versionType":"git","status":"affected"},{"version":"26afbd826ee326e63a334c37fd45e82e50a615ec","lessThan":"e3f82e8f2a5915f533b57a065e9a045aa2ee03bc","versionType":"git","status":"affected"},{"version":"26afbd826ee326e63a334c37fd45e82e50a615ec","lessThan":"d83ecb7b96105d932dabaa56ccd7418c25fb7cbb","versionType":"git","status":"affected"},{"version":"26afbd826ee326e63a334c37fd45e82e50a615ec","lessThan":"6fc540e835dddb518cef3ff522b780f701cd03df","versionType":"git","status":"affected"},{"version":"26afbd826ee326e63a334c37fd45e82e50a615ec","lessThan":"0acd4eeb4b225b9bebbf9ef96cc10cdd79b94899","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/bluetooth/hci_event.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.0","status":"affected"},{"version":"0","lessThan":"6.0","versionType":"semver","status":"unaffected"},{"version":"6.1.187","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.154","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.106","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.47","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.11","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.1","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0acd4eeb4b225b9bebbf9ef96cc10cdd79b94899","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/26741d178f31932c9018b36b7953e6dc391436a4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6fc540e835dddb518cef3ff522b780f701cd03df","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9e05783d0bb96a7b853cc058a7c7de2dc4a62154","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a34df5c4a439cfc04565fa5be608ed1e53134f1f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d83ecb7b96105d932dabaa56ccd7418c25fb7cbb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e3f82e8f2a5915f533b57a065e9a045aa2ee03bc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80764","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:01.617","lastModified":"2026-09-04T16:18:01.617","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_event: fix LE list UAF on reset\n\nhci_cc_reset() clears the LE accept and resolving lists without taking\nhdev->lock. Other command-complete handlers serialize updates to these\nlists with that lock, and the debugfs readers hold it while walking them.\n\nThis permits the reset completion and a debugfs read to interleave as\nfollows:\n\n  hci_rx_work                 debugfs reader\n  -----------                 --------------\n                              lock hdev->lock\n                              fetch current entry\n  list_del(entry)\n  kfree(entry)\n                              read entry fields\n\nThe reader then dereferences a freed list entry and may follow its stale\nnext pointer.\n\nKASAN reported:\n\n  BUG: KASAN: slab-use-after-free in white_list_show+0x15f/0x180\n  Read of size 1 at addr ffff8881015dab16 by task poc/95\n\n  Call Trace:\n   white_list_show+0x15f/0x180\n   seq_read_iter+0x3ff/0x1190\n   seq_read+0x267/0x3d0\n   vfs_read+0x177/0xa20\n   ksys_read+0xf7/0x1c0\n\n  Allocated by task 91:\n   hci_bdaddr_list_add+0x1a6/0x3a0\n   hci_cc_le_add_to_accept_list+0xab/0x140\n   hci_cmd_complete_evt+0x26c/0x9a0\n   hci_event_packet+0x454/0xb20\n   hci_rx_work+0x293/0x730\n\n  Freed by task 90:\n   kfree+0x131/0x3c0\n   hci_bdaddr_list_clear+0xd8/0x160\n   hci_cc_reset+0x28a/0x370\n   hci_cmd_complete_evt+0x26c/0x9a0\n   hci_event_packet+0x454/0xb20\n   hci_rx_work+0x293/0x730\n\nTake hdev->lock around both list clears. This matches the existing\nmutation and traversal locking convention."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/bluetooth/hci_event.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"a4d5504d5c39cc84f1f828e19967595597a8136e","lessThan":"8e68c380290b1dd64a0a512ce66d0264130c46ed","versionType":"git","status":"affected"},{"version":"a4d5504d5c39cc84f1f828e19967595597a8136e","lessThan":"0628cc9b2fa29985a7b8c774741f8a736b0f5e7c","versionType":"git","status":"affected"},{"version":"a4d5504d5c39cc84f1f828e19967595597a8136e","lessThan":"d57702d4c55633c243da5a2fec37ae2ad4adb621","versionType":"git","status":"affected"},{"version":"a4d5504d5c39cc84f1f828e19967595597a8136e","lessThan":"39a3afb91be3cb465f46ce7a8e5696d9e33edf93","versionType":"git","status":"affected"},{"version":"a4d5504d5c39cc84f1f828e19967595597a8136e","lessThan":"b55e83a4ba31d40deae22d4e4dc8c84083e953c6","versionType":"git","status":"affected"},{"version":"a4d5504d5c39cc84f1f828e19967595597a8136e","lessThan":"25b05e3ce31d954540e99954bcc66cbceb27ab35","versionType":"git","status":"affected"},{"version":"a4d5504d5c39cc84f1f828e19967595597a8136e","lessThan":"33af47e847fe4a28b109673affb5874015d54f5a","versionType":"git","status":"affected"},{"version":"0de8cd646b0152c9ddd10257d8284938d0df0181","versionType":"git","status":"affected"},{"version":"3.18.3","lessThan":"3.19","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/bluetooth/hci_event.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.19","status":"affected"},{"version":"0","lessThan":"3.19","versionType":"semver","status":"unaffected"},{"version":"6.1.185","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.154","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.106","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.47","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.11","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.1","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0628cc9b2fa29985a7b8c774741f8a736b0f5e7c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/25b05e3ce31d954540e99954bcc66cbceb27ab35","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/33af47e847fe4a28b109673affb5874015d54f5a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/39a3afb91be3cb465f46ce7a8e5696d9e33edf93","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8e68c380290b1dd64a0a512ce66d0264130c46ed","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b55e83a4ba31d40deae22d4e4dc8c84083e953c6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d57702d4c55633c243da5a2fec37ae2ad4adb621","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80765","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:01.770","lastModified":"2026-09-04T16:18:01.770","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nHID: hyperv: validate initial device info bounds\n\nThe Hyper-V synthetic HID host supplies SYNTH_HID_INITIAL_DEVICE_INFO\nmessages that contain a HID descriptor followed by the report descriptor\nbytes. mousevsc_on_receive_device_info() trusts bLength and\nwDescriptorLength without checking that the received packet contains both\nbyte ranges.\n\nA malformed host or backend message can therefore make the guest read\npast the received VMBus packet while copying the report descriptor. Pass\nthe received initial-device-info size into the parser and reject\ndescriptor lengths that exceed the packet.\n\nImpact: A malicious Hyper-V host or backend can crash a guest by sending\na short initial device-info message with an oversized HID report\ndescriptor length."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/hid/hid-hyperv.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"b95f5bcb811e3905b5376f87789da8d097fee682","lessThan":"e0d5d3e45e142b7ef7525654aaa54d3e986002a6","versionType":"git","status":"affected"},{"version":"b95f5bcb811e3905b5376f87789da8d097fee682","lessThan":"390d3d9c52a710fdc9de95a537747397c0c671d1","versionType":"git","status":"affected"},{"version":"b95f5bcb811e3905b5376f87789da8d097fee682","lessThan":"8614c043b11cc35ffebd35542ab4da275f8f923d","versionType":"git","status":"affected"},{"version":"b95f5bcb811e3905b5376f87789da8d097fee682","lessThan":"334271d3812ab3197c95b4593bc6745f8d189114","versionType":"git","status":"affected"},{"version":"b95f5bcb811e3905b5376f87789da8d097fee682","lessThan":"f84d777574b748b1a488723ca7be9d87a301a872","versionType":"git","status":"affected"},{"version":"b95f5bcb811e3905b5376f87789da8d097fee682","lessThan":"608f8fd8c0f7b6268da43509447802955f210aac","versionType":"git","status":"affected"},{"version":"b95f5bcb811e3905b5376f87789da8d097fee682","lessThan":"2529737763cb4bcfcaf397beeea2664656c865b4","versionType":"git","status":"affected"},{"version":"b95f5bcb811e3905b5376f87789da8d097fee682","lessThan":"c894143c508a7e063aab9f73c9e835ab40121283","versionType":"git","status":"affected"},{"version":"b95f5bcb811e3905b5376f87789da8d097fee682","lessThan":"934b7778aa7b7c8f6bb073d2a73ba3674885bae0","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/hid/hid-hyperv.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.3","status":"affected"},{"version":"0","lessThan":"3.3","versionType":"semver","status":"unaffected"},{"version":"5.10.267","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.218","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.185","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.154","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.106","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.47","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.11","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.1","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2529737763cb4bcfcaf397beeea2664656c865b4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/334271d3812ab3197c95b4593bc6745f8d189114","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/390d3d9c52a710fdc9de95a537747397c0c671d1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/608f8fd8c0f7b6268da43509447802955f210aac","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8614c043b11cc35ffebd35542ab4da275f8f923d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/934b7778aa7b7c8f6bb073d2a73ba3674885bae0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c894143c508a7e063aab9f73c9e835ab40121283","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e0d5d3e45e142b7ef7525654aaa54d3e986002a6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f84d777574b748b1a488723ca7be9d87a301a872","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80766","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:01.923","lastModified":"2026-09-04T16:18:01.923","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nHID: uclogic: fix use-after-free of inrange_timer on remove\n\nuclogic_remove() cancels the pen in-range timer and then stops the\ndevice:\n\n\ttimer_delete_sync(&drvdata->inrange_timer);\n\thid_hw_stop(hdev);\n\ntimer_delete_sync() only guarantees the timer is idle at that instant.\nuclogic_raw_event_pen() keeps delivering pen reports until hid_hw_stop()\nstops the transport several lines later, and every report with\npen->inrange == UCLOGIC_PARAMS_PEN_INRANGE_NONE re-arms the timer:\n\n\tmod_timer(&drvdata->inrange_timer, jiffies + msecs_to_jiffies(100));\n\nA report landing between the timer_delete_sync() call and the transport\nteardown in hid_hw_stop() re-arms inrange_timer after it was cancelled.\nuclogic_remove() then returns and the devm drvdata is freed, while\nhid_hw_stop() has already freed the input device drvdata->pen_input\npoints at, so when the timer fires ~100 ms later\nuclogic_inrange_timeout() dereferences freed memory -- a use-after-free\nin timer-softirq context.\n\nSwapping the two calls is not a fix: stopping the device first frees\ndrvdata->pen_input via hidinput_disconnect() while the timer may still\nbe pending, so a timer already armed before removal fires on the freed\ninput device in the window before timer_delete_sync() runs.\n\nUse timer_shutdown_sync() before hid_hw_stop() instead. It cancels the\ntimer, waits for a running callback while pen_input is still valid, and\nprevents any further re-arming -- a later mod_timer() from an in-flight\nreport is silently ignored -- so the timer is provably dead before\nhid_hw_stop() frees the inputs. This is the ordering the timer core\ndocuments for this \"timer re-armed from another path\" teardown case."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/hid/hid-uclogic-core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"01309e29eb95c16bd48984f2589fad0cbf5e27d1","lessThan":"f40243358b407aec362fe305fabfcdc94a3abd89","versionType":"git","status":"affected"},{"version":"01309e29eb95c16bd48984f2589fad0cbf5e27d1","lessThan":"dc5108f18f58870a8dd4203a02a47e571a2be7f0","versionType":"git","status":"affected"},{"version":"01309e29eb95c16bd48984f2589fad0cbf5e27d1","lessThan":"9d77ac82e57ead056cf3f71d347083ed9244ad90","versionType":"git","status":"affected"},{"version":"01309e29eb95c16bd48984f2589fad0cbf5e27d1","lessThan":"e750cdb6de009aace3c77f37fe2173f96175e8e4","versionType":"git","status":"affected"},{"version":"01309e29eb95c16bd48984f2589fad0cbf5e27d1","lessThan":"849e537160bbb77fe419ecc3944bfe125dcd441b","versionType":"git","status":"affected"},{"version":"01309e29eb95c16bd48984f2589fad0cbf5e27d1","lessThan":"f1b3ca06380531f49f988f4721d3ed30b0d7a5d2","versionType":"git","status":"affected"},{"version":"01309e29eb95c16bd48984f2589fad0cbf5e27d1","lessThan":"f13d0a00204b05e62336da0ab72ea0d87b56690c","versionType":"git","status":"affected"},{"version":"01309e29eb95c16bd48984f2589fad0cbf5e27d1","lessThan":"506fd50a9027340f0e9dcc587d10ccb03312dba6","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/hid/hid-uclogic-core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.1","status":"affected"},{"version":"0","lessThan":"5.1","versionType":"semver","status":"unaffected"},{"version":"5.15.220","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.187","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.156","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.108","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.47","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.11","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.1","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/506fd50a9027340f0e9dcc587d10ccb03312dba6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/849e537160bbb77fe419ecc3944bfe125dcd441b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9d77ac82e57ead056cf3f71d347083ed9244ad90","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dc5108f18f58870a8dd4203a02a47e571a2be7f0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e750cdb6de009aace3c77f37fe2173f96175e8e4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f13d0a00204b05e62336da0ab72ea0d87b56690c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f1b3ca06380531f49f988f4721d3ed30b0d7a5d2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f40243358b407aec362fe305fabfcdc94a3abd89","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80767","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:02.080","lastModified":"2026-09-04T16:18:02.080","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nHID: sensor: custom: Fix use-after-free in enable_sensor\n\nenable_sensor_store() can call set_power_report_state(), which\ndereferences sensor_inst->power_state and sensor_inst->report_state.\nThese pointers refer to entries in sensor_inst->fields.\n\nCreate the field attributes before exposing the enable_sensor sysfs\nattribute, so enable_sensor cannot be accessed before the state it\ndepends on has been initialized.\n\nOn remove, delete enable_sensor before freeing the field attributes,\nso a concurrent sysfs write cannot dereference freed memory through\npower_state or report_state."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/hid/hid-sensor-custom.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4a7de0519df5e8fb89cef6ee062330ffe4b50a4d","lessThan":"c2be74b0272b7f8f60739e7aaf0d36c0befe7136","versionType":"git","status":"affected"},{"version":"4a7de0519df5e8fb89cef6ee062330ffe4b50a4d","lessThan":"d7cbea1d342a16ec96d9eb3d7bd0ba2d4b2f2855","versionType":"git","status":"affected"},{"version":"4a7de0519df5e8fb89cef6ee062330ffe4b50a4d","lessThan":"d37ff4e3635c18af907f25712596f8ccec323751","versionType":"git","status":"affected"},{"version":"4a7de0519df5e8fb89cef6ee062330ffe4b50a4d","lessThan":"2ce90cfc6646a32100feabd7110ae0352aa01167","versionType":"git","status":"affected"},{"version":"4a7de0519df5e8fb89cef6ee062330ffe4b50a4d","lessThan":"244a1cb638370490ed74a8adb5cc3f1212602e32","versionType":"git","status":"affected"},{"version":"4a7de0519df5e8fb89cef6ee062330ffe4b50a4d","lessThan":"8406d4b69d48bc72fb6f8812a65a17a1f903440b","versionType":"git","status":"affected"},{"version":"4a7de0519df5e8fb89cef6ee062330ffe4b50a4d","lessThan":"c0757f10610542d763bd0bf9bda455b78afeef0b","versionType":"git","status":"affected"},{"version":"4a7de0519df5e8fb89cef6ee062330ffe4b50a4d","lessThan":"7bb79a3cf45e0805aef74457e19deb77e18cf196","versionType":"git","status":"affected"},{"version":"4a7de0519df5e8fb89cef6ee062330ffe4b50a4d","lessThan":"ad8fb82b04422f49530d2aa2753cc81d1c60102c","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/hid/hid-sensor-custom.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.1","status":"affected"},{"version":"0","lessThan":"4.1","versionType":"semver","status":"unaffected"},{"version":"5.10.267","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.218","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.185","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.154","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.106","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.47","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.11","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.1","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/244a1cb638370490ed74a8adb5cc3f1212602e32","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2ce90cfc6646a32100feabd7110ae0352aa01167","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7bb79a3cf45e0805aef74457e19deb77e18cf196","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8406d4b69d48bc72fb6f8812a65a17a1f903440b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ad8fb82b04422f49530d2aa2753cc81d1c60102c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c0757f10610542d763bd0bf9bda455b78afeef0b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c2be74b0272b7f8f60739e7aaf0d36c0befe7136","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d37ff4e3635c18af907f25712596f8ccec323751","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d7cbea1d342a16ec96d9eb3d7bd0ba2d4b2f2855","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80768","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:02.227","lastModified":"2026-09-04T16:18:02.227","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nHID: ft260: fix stack-use-after-return write in I2C read race\n\nft260_i2c_read() points dev->read_buf at a caller-supplied buffer\n(often an on-stack variable), arms a completion and waits up to five\nseconds for the device to return the data. The HID input callback\nft260_raw_event() runs in the input/IRQ path, independent of the\ndev->lock mutex held by the read path, and copies the device-supplied\npayload into dev->read_buf after a plain NULL check.\n\nThese two paths share read_buf, read_idx and read_len with no\nserialization. If the device delays its response until the read\ntimes out, ft260_i2c_read() resets the controller, clears read_buf\nand returns, unwinding the stack frame the buffer lived in. A\nresponse that arrives at that moment lets ft260_raw_event() pass the\nNULL check and then memcpy() the device-controlled payload into the\nnow-freed stack location, a bounded but attacker-influenced\nstack-use-after-return write triggerable by malicious or\nmalfunctioning hardware.\n\nAdd a dedicated spinlock that serializes every access to read_buf,\nread_idx and read_len. ft260_raw_event() now holds it across the\nNULL check, the memcpy and the index update, while the read path\ntakes it when arming and when clearing the buffer, so the teardown\ncan no longer slip between the check and the copy."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/hid/hid-ft260.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6a82582d9fa438045191074856f47165334f2777","lessThan":"2b907001e8a83cdb71e899fd3d77ab51e2c03f10","versionType":"git","status":"affected"},{"version":"6a82582d9fa438045191074856f47165334f2777","lessThan":"90e9298f2e4336a0e1ca7eeb173403df78056164","versionType":"git","status":"affected"},{"version":"6a82582d9fa438045191074856f47165334f2777","lessThan":"460514d46e8892189fc933a1b4433811cfa5c309","versionType":"git","status":"affected"},{"version":"6a82582d9fa438045191074856f47165334f2777","lessThan":"5aa5a1b7cc4b4bec5497ad9ef113fdfe37b232f3","versionType":"git","status":"affected"},{"version":"6a82582d9fa438045191074856f47165334f2777","lessThan":"a8e1f970f9040294cfd9100c681c32af6c2aeec0","versionType":"git","status":"affected"},{"version":"6a82582d9fa438045191074856f47165334f2777","lessThan":"d7ffbdc076675c84128d5b904e4d5167fe9f3a7f","versionType":"git","status":"affected"},{"version":"6a82582d9fa438045191074856f47165334f2777","lessThan":"77832d8f1c81d9f84b6b54807fb278586001d754","versionType":"git","status":"affected"},{"version":"6a82582d9fa438045191074856f47165334f2777","lessThan":"bf3e39df3a397fd82967a31d17c4e02c7feab221","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/hid/hid-ft260.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.13","status":"affected"},{"version":"0","lessThan":"5.13","versionType":"semver","status":"unaffected"},{"version":"5.15.220","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.187","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.156","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.108","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.49","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.11","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.1","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2b907001e8a83cdb71e899fd3d77ab51e2c03f10","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/460514d46e8892189fc933a1b4433811cfa5c309","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5aa5a1b7cc4b4bec5497ad9ef113fdfe37b232f3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/77832d8f1c81d9f84b6b54807fb278586001d754","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/90e9298f2e4336a0e1ca7eeb173403df78056164","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a8e1f970f9040294cfd9100c681c32af6c2aeec0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bf3e39df3a397fd82967a31d17c4e02c7feab221","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d7ffbdc076675c84128d5b904e4d5167fe9f3a7f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80769","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:02.373","lastModified":"2026-09-04T16:18:02.373","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nHID: rapoo: fix missing hid_is_usb() check\n\nto_usb_interface() can only be used on a hid_device whose parent is really\nUSB; uhid can create devices that identify as being on BUS_USB, but don't\nactually have a USB parent.\nFix the use of to_usb_interface() without a hid_is_usb() check.\n\nAdd a dependency on USB_HID for hid_is_usb(), as other HID drivers do; the\nalternative would be to provide a simple stub implementation on !USB_HID\nbuilds.\n\nI have verified that it is currently possible to trigger a kernel splat due\nto this bug in an ASAN build, and that this commit fixes the issue."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/hid/Kconfig","drivers/hid/hid-rapoo.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"b3b1c68fb726907ea35ac172906705fe62c7fdaf","lessThan":"99ed3febafe0452994620a4d819f595583289bec","versionType":"git","status":"affected"},{"version":"b3b1c68fb726907ea35ac172906705fe62c7fdaf","lessThan":"49b6fd28fbcc0b6457e16e25c7617f63449d4808","versionType":"git","status":"affected"},{"version":"b3b1c68fb726907ea35ac172906705fe62c7fdaf","lessThan":"b57af2448268c30c25509a832b6ff6dc27176b28","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/hid/Kconfig","drivers/hid/hid-rapoo.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.0","status":"affected"},{"version":"0","lessThan":"7.0","versionType":"semver","status":"unaffected"},{"version":"7.1.11","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.1","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/49b6fd28fbcc0b6457e16e25c7617f63449d4808","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/99ed3febafe0452994620a4d819f595583289bec","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b57af2448268c30c25509a832b6ff6dc27176b28","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80770","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:02.483","lastModified":"2026-09-04T16:18:02.483","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nHID: nintendo: stop device IO before hid_hw_stop on probe failure\n\nnintendo_hid_probe() calls hid_device_io_start() before joycon_init()\nand joycon_leds_create().  If either fails, the error path jumps to\nerr_close which calls hid_hw_close()/hid_hw_stop() without first calling\nhid_device_io_stop().\n\nhid_hw_stop() does not stop device IO, so hid_input_report() may still\nrun and access driver data that is being torn down, resulting in a\nuse-after-free.\n\nAdd an err_io_stop label that calls hid_device_io_stop() before\nhid_hw_close(), and point the two post-io_start error paths at it."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/hid/hid-nintendo.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2af16c1f846bd60240745bbd3afa13d5f040c61a","lessThan":"c2f3d51c7f5222f5b51e0c90f02258d82e1b44dd","versionType":"git","status":"affected"},{"version":"2af16c1f846bd60240745bbd3afa13d5f040c61a","lessThan":"c023443f0e6cfd257846b6515c93c1ea08026593","versionType":"git","status":"affected"},{"version":"2af16c1f846bd60240745bbd3afa13d5f040c61a","lessThan":"03a84f9f88b42cd49752ec0259922b67e4b88598","versionType":"git","status":"affected"},{"version":"2af16c1f846bd60240745bbd3afa13d5f040c61a","lessThan":"5efcd7bbfaaec67d137c99aa0940fa34375db27f","versionType":"git","status":"affected"},{"version":"2af16c1f846bd60240745bbd3afa13d5f040c61a","lessThan":"13a3edf96568a0b7aacadea07c2adec53ac8f630","versionType":"git","status":"affected"},{"version":"2af16c1f846bd60240745bbd3afa13d5f040c61a","lessThan":"2e0d98dc8a6dea5fc2b72bf66e0dcbd5488644b4","versionType":"git","status":"affected"},{"version":"2af16c1f846bd60240745bbd3afa13d5f040c61a","lessThan":"1f74d3bff6fe04a64e02ab3661d2e0d554565aa6","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/hid/hid-nintendo.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.16","status":"affected"},{"version":"0","lessThan":"5.16","versionType":"semver","status":"unaffected"},{"version":"6.1.187","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.156","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.106","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.47","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.11","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.1","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/03a84f9f88b42cd49752ec0259922b67e4b88598","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/13a3edf96568a0b7aacadea07c2adec53ac8f630","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1f74d3bff6fe04a64e02ab3661d2e0d554565aa6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2e0d98dc8a6dea5fc2b72bf66e0dcbd5488644b4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5efcd7bbfaaec67d137c99aa0940fa34375db27f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c023443f0e6cfd257846b6515c93c1ea08026593","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c2f3d51c7f5222f5b51e0c90f02258d82e1b44dd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80771","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:02.620","lastModified":"2026-09-04T16:18:02.620","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nHID: nintendo: register input device after capabilities are set\n\ninput_register_device() exposes the device to userspace immediately.\nIn joycon_input_create() it was called before joycon_config_rumble()\nconfigures the FF_RUMBLE capability and the memless force-feedback\ndevice, so a concurrent EVIOCSFF could dereference a NULL dev->ff.\n\nRegistering early also means the initial udev event lacks button and\naxis information, which can make input managers ignore the device.\n\nMove input_register_device() to the end of joycon_input_create(), after\nall capabilities, the IMU input device and the force-feedback callbacks\nhave been configured."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/hid/hid-nintendo.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2af16c1f846bd60240745bbd3afa13d5f040c61a","lessThan":"3288bec1a21d582b504344380139cdc0e88ebe4d","versionType":"git","status":"affected"},{"version":"2af16c1f846bd60240745bbd3afa13d5f040c61a","lessThan":"268679f501386ad46405d42c2bcf89384cb5e256","versionType":"git","status":"affected"},{"version":"2af16c1f846bd60240745bbd3afa13d5f040c61a","lessThan":"a9fc7547f911ada09da33c5e204e5acda38e765a","versionType":"git","status":"affected"},{"version":"2af16c1f846bd60240745bbd3afa13d5f040c61a","lessThan":"27dc4b8eadac73b3c3cc526c8547d8b4ae8528be","versionType":"git","status":"affected"},{"version":"2af16c1f846bd60240745bbd3afa13d5f040c61a","lessThan":"d723bc1fe2e72b9252234e94c11af644ec477bf7","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/hid/hid-nintendo.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.16","status":"affected"},{"version":"0","lessThan":"5.16","versionType":"semver","status":"unaffected"},{"version":"6.12.106","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.47","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.11","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.1","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/268679f501386ad46405d42c2bcf89384cb5e256","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/27dc4b8eadac73b3c3cc526c8547d8b4ae8528be","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3288bec1a21d582b504344380139cdc0e88ebe4d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a9fc7547f911ada09da33c5e204e5acda38e765a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d723bc1fe2e72b9252234e94c11af644ec477bf7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80772","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:02.743","lastModified":"2026-09-04T16:18:02.743","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nHID: nintendo: fix out-of-bounds read in joycon_ctlr_read_handler()\n\njoycon_ctlr_read_handler() casts an incoming HID input report to\nstruct joycon_input_report and parses it, guarding the cast only with a\n12-byte length check:\n\n\tif (size >= 12) /* make sure it contains the input report */\n\t\tjoycon_parse_report(ctlr, (struct joycon_input_report *)data);\n\nstruct joycon_input_report is 49 bytes: a 13-byte header followed by a\nunion whose IMU arm is 36 bytes. For an IMU report joycon_parse_report()\n-> joycon_parse_imu_report() walks that union (struct offsets 13..48),\nso a report of exactly 12 bytes with data[0] == JC_INPUT_IMU_DATA passes\nthe guard yet is read up to 37 bytes past its declared length. The\nover-read bytes are decoded into accelerometer/gyroscope values and\nforwarded to userspace through the \"(IMU)\" input device, leaking\ndriver-internal memory. data[0] and size are fully controlled by a\nmalicious or spoofed Joy-Con/Pro Controller.\n\nReceive buffers are sized to the maximum report length, so this is an\nover-read within the allocation rather than a slab OOB, but the decoded\nbytes still reach userspace.\n\nThe sibling subcmd path in joycon_ctlr_handle_event() already bounds the\nsame cast correctly:\n\n\tif (size < sizeof(struct joycon_input_report) ||\n\t    data[0] != JC_INPUT_SUBCMD_REPLY)\n\t\tbreak;\n\nUse the same sizeof(struct joycon_input_report) bound here."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/hid/hid-nintendo.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2af16c1f846bd60240745bbd3afa13d5f040c61a","lessThan":"33ea29f8b6141f2d265de807e110a6435b355cb0","versionType":"git","status":"affected"},{"version":"2af16c1f846bd60240745bbd3afa13d5f040c61a","lessThan":"bd397c4123a4bc084913d8c7fdb40ef94e9f8172","versionType":"git","status":"affected"},{"version":"2af16c1f846bd60240745bbd3afa13d5f040c61a","lessThan":"addca61f9a23c0d20a387c2040e70479f54518e1","versionType":"git","status":"affected"},{"version":"2af16c1f846bd60240745bbd3afa13d5f040c61a","lessThan":"51cfd1adbe7a46bb08af162abb3ab3b6820e2d15","versionType":"git","status":"affected"},{"version":"2af16c1f846bd60240745bbd3afa13d5f040c61a","lessThan":"d4cabd4089adb59cf7974915737c52cc47a9bb1b","versionType":"git","status":"affected"},{"version":"2af16c1f846bd60240745bbd3afa13d5f040c61a","lessThan":"34725ed4719da424113db8449fb5485aaf71a913","versionType":"git","status":"affected"},{"version":"2af16c1f846bd60240745bbd3afa13d5f040c61a","lessThan":"27b376b945c0aac46fcdfcc950b14a85b874b557","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/hid/hid-nintendo.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.16","status":"affected"},{"version":"0","lessThan":"5.16","versionType":"semver","status":"unaffected"},{"version":"6.1.185","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.154","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.106","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.47","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.11","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.1","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/27b376b945c0aac46fcdfcc950b14a85b874b557","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/33ea29f8b6141f2d265de807e110a6435b355cb0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/34725ed4719da424113db8449fb5485aaf71a913","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/51cfd1adbe7a46bb08af162abb3ab3b6820e2d15","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/addca61f9a23c0d20a387c2040e70479f54518e1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bd397c4123a4bc084913d8c7fdb40ef94e9f8172","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d4cabd4089adb59cf7974915737c52cc47a9bb1b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80773","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:02.890","lastModified":"2026-09-04T16:18:02.890","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nHID: huawei: fix missing hid_is_usb() check\n\nto_usb_interface() can only be used on a hid_device whose parent is really\nUSB; uhid can create devices that identify as being on BUS_USB, but don't\nactually have a USB parent.\nFix the use of to_usb_interface() without a hid_is_usb() check.\n\nI have verified that it is currently possible to trigger a kernel splat due\nto this bug in an ASAN build, and that this commit fixes the issue."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/hid/hid-huawei.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"e93faaca84b73431ccef029b2c8e902e5be83006","lessThan":"66805454c01ffefc40d08a962d606cdb73644c5d","versionType":"git","status":"affected"},{"version":"e93faaca84b73431ccef029b2c8e902e5be83006","lessThan":"9acc2463991cdb0856fdbd63fd7178102c1ed73d","versionType":"git","status":"affected"},{"version":"e93faaca84b73431ccef029b2c8e902e5be83006","lessThan":"4cdb6b4b34d7823254f6e1b22faf56c96ac57fb9","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/hid/hid-huawei.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1","status":"affected"},{"version":"0","lessThan":"7.1","versionType":"semver","status":"unaffected"},{"version":"7.1.11","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.1","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/4cdb6b4b34d7823254f6e1b22faf56c96ac57fb9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/66805454c01ffefc40d08a962d606cdb73644c5d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9acc2463991cdb0856fdbd63fd7178102c1ed73d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80774","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:03.000","lastModified":"2026-09-04T16:18:03.000","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nHID: asus: fix missing hid_is_usb() check\n\nto_usb_interface() can only be used on a hid_device whose parent is really\nUSB; uhid can create devices that identify as being on BUS_USB, but don't\nactually have a USB parent.\nFix the use of to_usb_interface() without a hid_is_usb() check.\n\nI have verified that it is currently possible to trigger a kernel splat due\nto this bug in an ASAN build, and that this commit fixes the issue."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/hid/hid-asus.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"ff38cf0bd888fe15789a7193d07c4a876388d520","lessThan":"bdb2e0a2a359e473ca5619e35adee89028697239","versionType":"git","status":"affected"},{"version":"00e005c952f74f50a3f86af96f56877be4685e14","lessThan":"8b5debb6252cd1e2b6c7adf8f95761a0e743d2cf","versionType":"git","status":"affected"},{"version":"00e005c952f74f50a3f86af96f56877be4685e14","lessThan":"1ddc2f5913bec7a846544d51a8f7a8119573b2a1","versionType":"git","status":"affected"},{"version":"00e005c952f74f50a3f86af96f56877be4685e14","lessThan":"ee883906cf6685d753af9c2d2ca9fd6f63197726","versionType":"git","status":"affected"},{"version":"00e005c952f74f50a3f86af96f56877be4685e14","lessThan":"02bf61dfb44f17ec187d1da1a82495951bbd12df","versionType":"git","status":"affected"},{"version":"02d5431198f10e7c6e31f4138c14cfe400ec55a7","versionType":"git","status":"affected"},{"version":"6.12.35","lessThan":"6.12.108","versionType":"semver","status":"affected"},{"version":"6.15.4","lessThan":"6.16","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/hid/hid-asus.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.16","status":"affected"},{"version":"0","lessThan":"6.16","versionType":"semver","status":"unaffected"},{"version":"6.12.108","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.49","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.11","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.1","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/02bf61dfb44f17ec187d1da1a82495951bbd12df","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1ddc2f5913bec7a846544d51a8f7a8119573b2a1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8b5debb6252cd1e2b6c7adf8f95761a0e743d2cf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bdb2e0a2a359e473ca5619e35adee89028697239","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ee883906cf6685d753af9c2d2ca9fd6f63197726","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80775","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:03.123","lastModified":"2026-09-04T16:18:03.123","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfutex: Fix race on the initial mm->futex.phash.ref allocation\n\nfutex_hash_allocate() allocates mm->futex.phash.ref without any locking.\nCommit d9b05321e21e (\"futex: Move futex_hash_free() back to __mmput()\")\nmoved the allocation here and assumed that the process has just a single\nthread at this point.\n\nCommit ee9dce44362b (\"futex: Drop CLONE_THREAD requirement for private\ndefault hash alloc\") widened need_futex_hash_allocate_default() to cover\nany CLONE_VM clone, but left out vfork because the parent is suspended and\ncannot race.\n\nThat no longer holds once vfork is nested. If a vfork child calls vfork\nagain and is then killed with SIGKILL, the parent is released from its\nvfork wait and runs concurrently with the grandchild in the same mm.\nNeither of them went through futex_hash_allocate_default().\n\nWhen both call prctl(PR_FUTEX_HASH, PR_FUTEX_HASH_SET_SLOTS) at the same\ntime, each one sees mm->futex.phash.ref as NULL and stores its own percpu\ncounter. Only the last store survives. The counter stored first is no\nlonger reachable from the mm, so the references on it are not seen by\n__futex_ref_atomic_end(). A private hash that still has references is then\nconsidered dead and freed, and a task that still holds one of its buckets\nwrites into freed memory in futex_q_lock().\n\nStore the counter once with cmpxchg() and let the loser free_percpu() its\nown. The initial reference has to be taken before the store, otherwise\nanother task can install a private hash while the counter is still 0."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["kernel/futex/core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"d9b05321e21e4b218de4ce8a590bf375f58b6346","lessThan":"86d12b34bafc9a4c271a9edefea88855a934d6e5","versionType":"git","status":"affected"},{"version":"d9b05321e21e4b218de4ce8a590bf375f58b6346","lessThan":"ff252ed45c8263525f2f54d81c5fa6d547fba344","versionType":"git","status":"affected"},{"version":"d9b05321e21e4b218de4ce8a590bf375f58b6346","lessThan":"c4b4972d8edcdf50b6518f55119e129d2f668a10","versionType":"git","status":"affected"},{"version":"d9b05321e21e4b218de4ce8a590bf375f58b6346","lessThan":"bde0238083647381d4747355c5a19115a3422b96","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["kernel/futex/core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.17","status":"affected"},{"version":"0","lessThan":"6.17","versionType":"semver","status":"unaffected"},{"version":"6.18.47","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.11","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.1","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/86d12b34bafc9a4c271a9edefea88855a934d6e5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bde0238083647381d4747355c5a19115a3422b96","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c4b4972d8edcdf50b6518f55119e129d2f668a10","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ff252ed45c8263525f2f54d81c5fa6d547fba344","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80776","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:03.250","lastModified":"2026-09-04T16:18:03.250","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfutex: Fix race in futex_pivot_pending() during private hash resize\n\nA task performing a custom private hash resize can remain blocked in\nuninterruptible sleep indefinitely.  The hung-task detector reports:\n\n  INFO: task futex-resizer:314 blocked for more than 10 seconds.\n  task:futex-resizer state:D stack:14824 pid:314 tgid:312 ppid:311\n\n  Call Trace:\n   __schedule+0x521/0xf30\n   schedule+0x22/0xa0\n   futex_hash_allocate+0x3db/0x490\n   __do_sys_prctl+0x6f5/0xbd0\n   do_syscall_64+0xf9/0x530\n   entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\n  Kernel panic - not syncing: hung_task: blocked tasks\n\nfutex_pivot_pending() allows the resize request to continue when\neither no replacement hash is pending (hash_new == NULL) or the current\nhash reference count has reached zero.\n\nAfter the final-reference wake, another futex task can complete the\npivot between the two observations:\n\n  T1                                  T2\n\n  futex_hash_allocate()\n    wait_var_event(mm, ...)\n      futex_pivot_pending(mm)\n        hash_new != NULL\n                                      futex_hash()\n                                        futex_ref_get(old) -> false\n                                        futex_pivot_hash(mm)\n                                          hash_new = NULL\n                                          __futex_pivot_hash(mm, new)\n                                            rcu_assign_pointer(hash, new)\n        fph = rcu_dereference(hash) /* new */\n        futex_ref_is_dead(fph) -> false\n      schedule()\n\nThe pivot changes the state from hash_new != NULL with a dead current\nhash to hash_new == NULL with a live current hash.  Because\nfutex_pivot_pending() reads hash_new and hash without serialization,\nthe resize task can observe hash_new in the pre-pivot state and hash in\nthe post-pivot state, causing futex_pivot_pending() to return false even\nthough the pivot has completed.  The task then goes to sleep after the\nwakeup has already been consumed.\n\nSerialize state reads in futex_pivot_pending() using futex_mm_phash::lock.\nThis guarantees that futex_pivot_pending() observes hash_new and hash\natomically, eliminating the race condition."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["kernel/futex/core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"bd54df5ea7cadac520e346d5f0fe5d58e635b6ba","lessThan":"4a7e941ca29a608c6244cbd028d3599ecaef7207","versionType":"git","status":"affected"},{"version":"bd54df5ea7cadac520e346d5f0fe5d58e635b6ba","lessThan":"19b4be0717fa83265d66aea836b7022d898422cf","versionType":"git","status":"affected"},{"version":"bd54df5ea7cadac520e346d5f0fe5d58e635b6ba","lessThan":"8e7ff730dd96519a333d1570edf1c3fabb6d3629","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["kernel/futex/core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.16","status":"affected"},{"version":"0","lessThan":"6.16","versionType":"semver","status":"unaffected"},{"version":"6.18.46","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.11","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/19b4be0717fa83265d66aea836b7022d898422cf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4a7e941ca29a608c6244cbd028d3599ecaef7207","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8e7ff730dd96519a333d1570edf1c3fabb6d3629","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80777","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:03.373","lastModified":"2026-09-04T16:18:03.373","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfutex/pi: Plug private futex exec() race\n\nThe check for private futexes whether the waiter's mm, which is stored in\nthe futex_key and copied into the pi_state, is the same as the owner's mm\nis not sufficient for exec(). exec() has a gap where the mm check fails to\ngive the correct answer:\n\n  exec()\n  ...\n    exec_release_mm()\n      futex_exec_release()\n        tsk::futex::exit_state = EXITING;\n        cleanup_robust_list();\n1)      tsk::futex::exit_state = OK;\n    ...\n    old_mm = tsk::mm;\n2)  tsk::mm = ->mm;\n\nBetween #1 and #2 the check for the mm is wrong as that mm is about to be\nswapped out and eventually freed.\n\nPlug this gap by:\n\n  1) Setting tsk::futex::exit_state to FUTEX_STATE_DEAD in\n     futex_exec_release()\n\n  2) Setting tsk::futex::exit_state to FUTEX_STATE_OK after\n     the mm has been switched.\n\nFrom a futex point of view the task is dead after it finished the robust\nlist cleanup up to the point where it sets the state to OK again."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/exec.c","include/linux/futex.h","kernel/futex/core.c","kernel/futex/pi.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"80367ad01d93ac781b0e1df246edaf006928002f","lessThan":"fdf538b2e69653ff740e84042245018e5680cd7b","versionType":"git","status":"affected"},{"version":"80367ad01d93ac781b0e1df246edaf006928002f","lessThan":"0478bc6bf197629fea0331d65b39eeea043c6cf0","versionType":"git","status":"affected"},{"version":"80367ad01d93ac781b0e1df246edaf006928002f","lessThan":"d7944cee62ec6cca1c90780a766960a57d3b4bb8","versionType":"git","status":"affected"},{"version":"80367ad01d93ac781b0e1df246edaf006928002f","lessThan":"c5f0bc9fd1cec4a00400cc727fcde03e0fde17cc","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/exec.c","include/linux/futex.h","kernel/futex/core.c","kernel/futex/pi.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.16","status":"affected"},{"version":"0","lessThan":"6.16","versionType":"semver","status":"unaffected"},{"version":"6.18.47","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.11","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.1","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0478bc6bf197629fea0331d65b39eeea043c6cf0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c5f0bc9fd1cec4a00400cc727fcde03e0fde17cc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d7944cee62ec6cca1c90780a766960a57d3b4bb8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fdf538b2e69653ff740e84042245018e5680cd7b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80778","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:03.490","lastModified":"2026-09-04T16:18:03.490","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfutex/pi: Reject cross-mm private futex owners\n\nA private futex key borrows the waiter's mm without taking an mm_users\nreference. Nevertheless, attach_to_pi_owner() currently accepts an owner\nfrom a different address space and copies the private key into the owner's\nPI state.\n\nWhen that owner exits, exit_pi_state_list() uses the saved key to find the\nhash bucket and acquires a reference to the waiter's private hash. If the\nlast user of the waiter's mm exits concurrently, futex_hash_free() frees\nthe hash while the owner still uses its bucket and reference.\n\nPrevent this by validating in attach_to_pi_owner() that, for private\nfutexes, the owner mm and waiter mm are the same. Perform the check with\nthe owner's pi_lock held and after validating owner::futex::state to\nserialize against a concurrent PI-state exit cleanup.\n\n[ tglx: Amended comment ]"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["kernel/futex/pi.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"80367ad01d93ac781b0e1df246edaf006928002f","lessThan":"2b92e5562653b5293529f63b0300837d9dcedbd7","versionType":"git","status":"affected"},{"version":"80367ad01d93ac781b0e1df246edaf006928002f","lessThan":"f7fb3e07752688842cbe0b85cf0d98c2fbf76b68","versionType":"git","status":"affected"},{"version":"80367ad01d93ac781b0e1df246edaf006928002f","lessThan":"43b148d796aa338858792d0167cebdc12b8cb4b9","versionType":"git","status":"affected"},{"version":"80367ad01d93ac781b0e1df246edaf006928002f","lessThan":"59b3732f95dda1fbd2234514d35f4fb6b5bb6d85","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["kernel/futex/pi.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.16","status":"affected"},{"version":"0","lessThan":"6.16","versionType":"semver","status":"unaffected"},{"version":"6.18.47","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.11","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.1","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2b92e5562653b5293529f63b0300837d9dcedbd7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/43b148d796aa338858792d0167cebdc12b8cb4b9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/59b3732f95dda1fbd2234514d35f4fb6b5bb6d85","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f7fb3e07752688842cbe0b85cf0d98c2fbf76b68","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80779","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:03.607","lastModified":"2026-09-04T16:18:03.607","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/ionic: avoid OOB TX partner lookup for hwstamp RXQ\n\nThe dedicated hardware timestamp RX queue is allocated with q->index\nequal to lif->ionic->nrxqs_per_lif. The normal txqcqs array only\ncontains the regular queue pairs, so using that index to set rxq->partner\ncan read one entry past txqcqs[] and then write through the derived\npointer.\nOnly link RX/TX partners for normal queue-pair indexes. Leave the hwstamp\nRX queue unpaired, and make the XDP_TX path abort cleanly if an RX queue\nhas no TX partner."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/ethernet/pensando/ionic/ionic_lif.c","drivers/net/ethernet/pensando/ionic/ionic_txrx.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"8eeed8373e1cca836799bf8e4a05cffa8e444908","lessThan":"881a805a8029ba48c0ce81c6674910f8d83f7afb","versionType":"git","status":"affected"},{"version":"8eeed8373e1cca836799bf8e4a05cffa8e444908","lessThan":"39fc615e355b65b8d43be30da57aa95ae6eaf688","versionType":"git","status":"affected"},{"version":"8eeed8373e1cca836799bf8e4a05cffa8e444908","lessThan":"f3868046e8e2e761d4d943a232bd109ff22a7d5b","versionType":"git","status":"affected"},{"version":"8eeed8373e1cca836799bf8e4a05cffa8e444908","lessThan":"ea081b4435515ac7177eb598a3c0678d1b9e7911","versionType":"git","status":"affected"},{"version":"8eeed8373e1cca836799bf8e4a05cffa8e444908","lessThan":"d92255b405fb6f5acca408239ccd742e0a42c9cb","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/ethernet/pensando/ionic/ionic_lif.c","drivers/net/ethernet/pensando/ionic/ionic_txrx.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.9","status":"affected"},{"version":"0","lessThan":"6.9","versionType":"semver","status":"unaffected"},{"version":"6.12.106","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.47","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.11","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.1","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/39fc615e355b65b8d43be30da57aa95ae6eaf688","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/881a805a8029ba48c0ce81c6674910f8d83f7afb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d92255b405fb6f5acca408239ccd742e0a42c9cb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ea081b4435515ac7177eb598a3c0678d1b9e7911","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f3868046e8e2e761d4d943a232bd109ff22a7d5b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80780","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:03.723","lastModified":"2026-09-04T16:18:03.723","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nHID: pidff: fix OOB write when hid->inputs is empty\n\nhid_pidff_init_with_quirks() derives its input_dev from\n\n\tlist_entry(hid->inputs.next, struct hid_input, list)\n\nwithout first checking that hid->inputs is non-empty.  The list member\nof struct hid_input is at offset 0, so on an empty list list_entry()\nyields &hid->inputs itself and the following hidinput->input load reads\nan unrelated member of struct hid_device.  dev is then a type-confused\npointer, and force-feedback init writes through it: each\nset_bit(FF_*, dev->ffbit) stores 8 bytes at dev + 192, past the end of\nthe object dev actually aliases, and input_ff_create() adds further\nwrites of a heap pointer and two function pointers.\n\nUntil hid-universal-pidff the only caller was hid_pidff_init() from\nusbhid, which runs under HID_CLAIMED_INPUT and therefore always has at\nleast one hid_input.  universal_pidff_probe() starts the device with\nHID_CONNECT_DEFAULT & ~HID_CONNECT_FF and then calls\nhid_pidff_init_with_quirks() directly whenever the descriptor carries a\nPID usage page, bypassing that gate.  A report descriptor whose only\napplication collection is on HID_UP_PID leaves hid->inputs empty while\nhid_connect() still succeeds through the hidraw claim, so probe reaches\nthe unguarded list_entry().\n\nThe write happens in the USB probe path, on the hotplug workqueue, so\nplugging in a malicious device is enough to trigger it; no attacker\nsoftware and no logged-in user are required.  KASAN reports an 8-byte\nout-of-bounds write in hid_pidff_init_with_quirks() reached from\nuniversal_pidff_probe().\n\nCheck for an empty list before deriving dev and return -ENODEV, as the\nother HID force-feedback drivers already do.  universal_pidff_probe()\npropagates the error and unwinds.\n\nDiscovered by XBOW, triaged by Baul Lee <baul.lee@xbow.com>"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/hid/usbhid/hid-pidff.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"c1fde337b317f0a226de92803288741c30799eb0","lessThan":"2e0471bf3ab2a6b7eedcc3b8a2a17286b6a9ae1a","versionType":"git","status":"affected"},{"version":"f45f26a6b3e7260c129c7c6bb0ace63aeb7b3868","lessThan":"ad9330f7e74a97842815a291a0d7389ed2f34504","versionType":"git","status":"affected"},{"version":"f06bf8d94fffbb544b1cb5402c92e0a075f0d420","lessThan":"4529c03c3da8f91392cd630453452f569973f4cd","versionType":"git","status":"affected"},{"version":"f06bf8d94fffbb544b1cb5402c92e0a075f0d420","lessThan":"d416eeb7d016d82af67c149d884bc6a9323c4ac7","versionType":"git","status":"affected"},{"version":"f06bf8d94fffbb544b1cb5402c92e0a075f0d420","lessThan":"86b63adfa5e132beac4be72668fdf9128fe51d2e","versionType":"git","status":"affected"},{"version":"f06bf8d94fffbb544b1cb5402c92e0a075f0d420","lessThan":"67bb1074e3d2d12fa059a9cc707e89398a4e4704","versionType":"git","status":"affected"},{"version":"af9f2471dfe5a48384f5b7f021a673fbc741465e","versionType":"git","status":"affected"},{"version":"b797352954eee6dc084cfaed0659dea60adfb484","versionType":"git","status":"affected"},{"version":"6.6.88","lessThan":"6.6.156","versionType":"semver","status":"affected"},{"version":"6.12.24","lessThan":"6.12.108","versionType":"semver","status":"affected"},{"version":"6.13.12","lessThan":"6.14","versionType":"semver","status":"affected"},{"version":"6.14.3","lessThan":"6.15","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/hid/usbhid/hid-pidff.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.15","status":"affected"},{"version":"0","lessThan":"6.15","versionType":"semver","status":"unaffected"},{"version":"6.6.156","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.108","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.47","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.11","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.1","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2e0471bf3ab2a6b7eedcc3b8a2a17286b6a9ae1a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4529c03c3da8f91392cd630453452f569973f4cd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/67bb1074e3d2d12fa059a9cc707e89398a4e4704","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/86b63adfa5e132beac4be72668fdf9128fe51d2e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ad9330f7e74a97842815a291a0d7389ed2f34504","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d416eeb7d016d82af67c149d884bc6a9323c4ac7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80781","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:03.867","lastModified":"2026-09-04T16:18:03.867","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nHID: core: fix OOB read of field->usage in hid_set_field()\n\nhid_set_field() hands field->usage + offset to hid_dump_input() before\nthe guard that bounds offset:\n\n\thid_dump_input(field->report->device, field->usage + offset, value);\n\n\tif (offset >= field->report_count) {\n\t\thid_err(...);\n\t\treturn -1;\n\t}\n\nUnder CONFIG_DEBUG_FS hid_dump_input() dereferences that pointer, with\nbuf = hid_resolv_usage(usage->hid, NULL).  The usage[] array is\nallocated inline with the hid_field in hid_register_field() and holds\nfield->maxusage entries, so an offset past it reads off the end of the\nkvzalloc()ed allocation and into a neighbouring object.  Had the guard\nrun first, offset < report_count <= maxusage would already have confined\nthe pointer to the array.\n\nA caller supplies such an offset today.  picolcd_fb_send_tile()\nvalidates only report->maxfield before issuing\nhid_set_field(report->field[0], 11 + i, ...) for i = 0..31, so its\noffsets are fixed at 11..42 and are never checked against the bound\nfield.  When the device registers that field with fewer usages, the\nframebuffer deferred-io work drives the read on every tile.  KASAN\nreports a 4-byte slab-out-of-bounds read in hid_dump_input() below\nhid_set_field(), and the same boot logs \"offset (1) exceeds\nreport_count (1)\" from the guard that runs only afterwards.\n\nMove the hid_dump_input() call below the guard.  Because\nfield->maxusage >= field->report_count, the guard then establishes that\nfield->usage + offset lies inside the array before it is dereferenced,\nfor every caller and without changing behaviour on the valid path.\n\nDiscovered by XBOW, triaged by Baul Lee <baul.lee@xbow.com>"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/hid/hid-core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"465544b3d6602cfbdc2305d5cbfb7f4954353b63","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"4993e1ab85d7d3f4a40d81852170f9665483bbd8","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"313ead1abed945544703b100a12c5a10fdf78409","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"c1d9c16af51cc6ff92a5a062617d3b022dd01078","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"a38212687519f2a72f43e62dec1348a690412404","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"9a1d7c5f0d82e8665715d5e47c9410c6a97e3748","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"5215ea00a747eca34cb2f603cfef91fef76c2558","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"cbcc0e8dea499e5ca86b583372ccb1815cccc570","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"a13cdb19fcb223ed41bdab3bab42b98dba87e90b","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/hid/hid-core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.12","status":"affected"},{"version":"0","lessThan":"2.6.12","versionType":"semver","status":"unaffected"},{"version":"5.10.267","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.218","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.185","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.154","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.106","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.47","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.11","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.1","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/313ead1abed945544703b100a12c5a10fdf78409","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/465544b3d6602cfbdc2305d5cbfb7f4954353b63","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4993e1ab85d7d3f4a40d81852170f9665483bbd8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5215ea00a747eca34cb2f603cfef91fef76c2558","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9a1d7c5f0d82e8665715d5e47c9410c6a97e3748","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a13cdb19fcb223ed41bdab3bab42b98dba87e90b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a38212687519f2a72f43e62dec1348a690412404","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c1d9c16af51cc6ff92a5a062617d3b022dd01078","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cbcc0e8dea499e5ca86b583372ccb1815cccc570","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80782","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:04.030","lastModified":"2026-09-04T16:18:04.030","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nHID: magicmouse: do not keep a stale msc->input if no input is claimed\n\nmagicmouse_input_mapping() caches the first hid_input's input_dev in\nmsc->input while the report descriptor is parsed, and the rest of the\ndriver treats a non-NULL msc->input as proof that an input device was\nregistered.\n\nThat does not hold on the hid-input error path. If hidinput_connect()\nfails -- for instance because input_register_device() returns an error --\nit unwinds through hidinput_disconnect(), which frees every input_dev it\ncreated, including the one cached in msc->input.\n\nThe failure does not abort the probe. hid_connect() only skips the claim:\n\n\tif ((connect_mask & HID_CONNECT_HIDINPUT) && !hidinput_connect(hdev,\n\t\t\t\tconnect_mask & HID_CONNECT_HIDINPUT_FORCE))\n\t\thdev->claimed |= HID_CLAIMED_INPUT;\n\nand the \"device has no listeners\" bailout below it does not fire for this\ndriver, which sets ->raw_event; on the USB Magic Mouse 2 / Magic Trackpad\n2 paths hidraw and hiddev are claimed as well. hid_hw_start() therefore\nreturns 0 and magicmouse_probe() continues with msc->input pointing at\nfreed memory. Being non-NULL, it passes the \"input not registered\" check\nin probe and the NULL checks in ->raw_event and ->event, so the next\ninput report dereferences freed memory.\n\nClear msc->input when the HID core did not claim an input device, so the\nexisting NULL checks cover this case as well."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/hid/hid-magicmouse.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"f1a9a149abc86903e81dd1b2e720f3f89874384b","lessThan":"c3597923932bb90d4fc2186aef552f6677175e4a","versionType":"git","status":"affected"},{"version":"f1a9a149abc86903e81dd1b2e720f3f89874384b","lessThan":"e0c224c93d10ee38854fdf24c815108aedd3dcb3","versionType":"git","status":"affected"},{"version":"f1a9a149abc86903e81dd1b2e720f3f89874384b","lessThan":"403cc9bd6ccb9fbe68d501c3236e5a6dd5504e14","versionType":"git","status":"affected"},{"version":"f1a9a149abc86903e81dd1b2e720f3f89874384b","lessThan":"3d7a7bac4c75f25b2513505a0ac5ba909588ed2b","versionType":"git","status":"affected"},{"version":"f1a9a149abc86903e81dd1b2e720f3f89874384b","lessThan":"9bdf8c7bfd79f1090e61d28f969b32880fd77bb3","versionType":"git","status":"affected"},{"version":"f1a9a149abc86903e81dd1b2e720f3f89874384b","lessThan":"15b60ade825c8ce9ec560048a4ae3747e4572be3","versionType":"git","status":"affected"},{"version":"f1a9a149abc86903e81dd1b2e720f3f89874384b","lessThan":"0bf253e9ac994cb5329bc87b00bb4eeca9136791","versionType":"git","status":"affected"},{"version":"f1a9a149abc86903e81dd1b2e720f3f89874384b","lessThan":"2ef16934e069d5f771e989d6ee5c3ece5042f3cd","versionType":"git","status":"affected"},{"version":"f1a9a149abc86903e81dd1b2e720f3f89874384b","lessThan":"0af3b89705688af01aa06025b84fa7a1e06ba6cc","versionType":"git","status":"affected"},{"version":"0e55072e7c63a6569cab1447e9025d160abd9dd9","versionType":"git","status":"affected"},{"version":"3.8.7","lessThan":"3.9","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/hid/hid-magicmouse.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.9","status":"affected"},{"version":"0","lessThan":"3.9","versionType":"semver","status":"unaffected"},{"version":"5.10.269","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.218","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.185","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.154","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.106","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.47","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.11","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.1","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0af3b89705688af01aa06025b84fa7a1e06ba6cc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/0bf253e9ac994cb5329bc87b00bb4eeca9136791","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/15b60ade825c8ce9ec560048a4ae3747e4572be3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2ef16934e069d5f771e989d6ee5c3ece5042f3cd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3d7a7bac4c75f25b2513505a0ac5ba909588ed2b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/403cc9bd6ccb9fbe68d501c3236e5a6dd5504e14","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9bdf8c7bfd79f1090e61d28f969b32880fd77bb3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c3597923932bb90d4fc2186aef552f6677175e4a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e0c224c93d10ee38854fdf24c815108aedd3dcb3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80783","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:04.183","lastModified":"2026-09-04T16:18:04.183","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nHID: magicmouse: prevent unbounded recursion in magicmouse_raw_event()\n\nmagicmouse_raw_event() handles DOUBLE_REPORT_ID (0xf7) packets, which pack\ntwo touch reports into one, by splitting the packet and calling itself on\neach half. The only guard against runaway recursion is a \"size < 1\" check,\nwhich stops zero-sized calls but does not bound the recursion depth.\n\nA malicious HID device that matches this driver can send a report starting\nwith DOUBLE_REPORT_ID and filled with the sequence [0xf7, 0x00]. Each level\nconsumes two bytes and recurses on the remainder, so an incoming report of\nup to HID_MAX_BUFFER_SIZE (16 KiB) drives roughly 8000 nested calls. That\neasily exhausts the 16 KiB kernel stack, leading to a stack overflow: a\npanic with CONFIG_VMAP_STACK, or memory corruption without it.\n\nA double report only ever wraps two normal reports; it is never\nlegitimately nested. Refuse to re-enter the DOUBLE_REPORT_ID case from a\nrecursive call so the recursion depth is bounded to two, while all valid\npackets keep being parsed exactly as before."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/hid/hid-magicmouse.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"a462230e16acc8664145216da3c928d03556691a","lessThan":"26c45abed62536aabf4033fb6d64cf72e93374e9","versionType":"git","status":"affected"},{"version":"a462230e16acc8664145216da3c928d03556691a","lessThan":"8a10a624996f16628234306b46f0cf36707d78bd","versionType":"git","status":"affected"},{"version":"a462230e16acc8664145216da3c928d03556691a","lessThan":"d16df755b4493b6d37803c628b2c621d096796a8","versionType":"git","status":"affected"},{"version":"a462230e16acc8664145216da3c928d03556691a","lessThan":"bec338b07beb883726b32192c8f01c601bc76fda","versionType":"git","status":"affected"},{"version":"a462230e16acc8664145216da3c928d03556691a","lessThan":"70589b0c005db003f6d8ae4db3c4d54fed7b83e4","versionType":"git","status":"affected"},{"version":"a462230e16acc8664145216da3c928d03556691a","lessThan":"a33a596d3ad8dfe6c96a368097a028abeee16c17","versionType":"git","status":"affected"},{"version":"a462230e16acc8664145216da3c928d03556691a","lessThan":"d095de37f78c5f32a4252ef0f99b84ba76550b86","versionType":"git","status":"affected"},{"version":"a462230e16acc8664145216da3c928d03556691a","lessThan":"db8d634128d2ba88d79c0b601e983ebe14bb0519","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/hid/hid-magicmouse.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.37","status":"affected"},{"version":"0","lessThan":"2.6.37","versionType":"semver","status":"unaffected"},{"version":"5.15.220","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.187","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.156","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.108","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.49","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.11","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.1","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/26c45abed62536aabf4033fb6d64cf72e93374e9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/70589b0c005db003f6d8ae4db3c4d54fed7b83e4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8a10a624996f16628234306b46f0cf36707d78bd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a33a596d3ad8dfe6c96a368097a028abeee16c17","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bec338b07beb883726b32192c8f01c601bc76fda","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d095de37f78c5f32a4252ef0f99b84ba76550b86","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d16df755b4493b6d37803c628b2c621d096796a8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/db8d634128d2ba88d79c0b601e983ebe14bb0519","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80784","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:04.333","lastModified":"2026-09-04T16:18:04.333","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: pm: fix memory leak from alloc-during-teardown race\n\nmptcp_pm_destroy() empties msk->pm.anno_list and\nmsk->pm.userspace_pm_local_addr_list under msk->pm.lock during socket\nteardown, dropping the lock between the two.\n\nA concurrent userspace PM genl ANNOUNCE on the same msk holds a sock\nreference via mptcp_token_get_sock() and, in\nmptcp_pm_nl_announce_doit(), calls\nmptcp_userspace_pm_append_new_local_addr() and\nmptcp_pm_announced_alloc(). Both take msk->pm.lock briefly to add to\ntheir respective lists. Because the genl handler holds a sock reference,\nmptcp_pm_destroy() may run on the same msk via mptcp_disconnect(), which\ninvokes mptcp_destroy_common() without dropping the sock refcount,\nbefore the handler completes.\n\nIf the lock acquisitions interleave such that mptcp_pm_destroy() empties\na list first, the later alloc adds its entry to a list head that nothing\nelse iterates for this msk, and the entry leaks. kmemleak reports both\nmptcp_pm_add_addr objects (from mptcp_pm_announced_alloc()) and\nmptcp_pm_addr_entry objects (from\nmptcp_userspace_pm_append_new_local_addr()) under sustained concurrent\nANNOUNCE + close load against the userspace PM.\n\nAdd an MPTCP_PM_DESTROYING bit in msk->pm.status, set by\nmptcp_pm_destroy() under pm.lock before the lists are emptied and\nchecked under pm.lock by the alloc paths. Either the alloc takes pm.lock\nfirst, in which case its entry is on the list when mptcp_pm_destroy()\nfrees it; or mptcp_pm_destroy() takes pm.lock first, in which case the\nlater alloc observes the bit and refuses.\n\nFound by an MPTCP protocol-flow harness extending BRF (arXiv:2305.08782)."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/mptcp/pm.c","net/mptcp/pm_userspace.c","net/mptcp/protocol.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"9ab4807c84a4aacfc9b4f79cc81254035e0ec361","lessThan":"f48341830e4202db3fe884b819b2db6740f0537d","versionType":"git","status":"affected"},{"version":"9ab4807c84a4aacfc9b4f79cc81254035e0ec361","lessThan":"bb32e9a6a9a9f99eeda16c4efe443400f3e43892","versionType":"git","status":"affected"},{"version":"9ab4807c84a4aacfc9b4f79cc81254035e0ec361","lessThan":"b2a0b55bf613bd3e81ed26a847b0f6b8e6b7f804","versionType":"git","status":"affected"},{"version":"9ab4807c84a4aacfc9b4f79cc81254035e0ec361","lessThan":"9fe5eebb664ecdba88f3fde18062d94b1d1c465f","versionType":"git","status":"affected"},{"version":"9ab4807c84a4aacfc9b4f79cc81254035e0ec361","lessThan":"6c290915a03fc8228b473641025cf762b256dbd2","versionType":"git","status":"affected"},{"version":"9ab4807c84a4aacfc9b4f79cc81254035e0ec361","lessThan":"efc33b5102ff859bacd390a5f30112d8e0c084c0","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/mptcp/pm.c","net/mptcp/pm_userspace.c","net/mptcp/protocol.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.19","status":"affected"},{"version":"0","lessThan":"5.19","versionType":"semver","status":"unaffected"},{"version":"6.1.187","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.154","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.106","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.47","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.11","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/6c290915a03fc8228b473641025cf762b256dbd2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9fe5eebb664ecdba88f3fde18062d94b1d1c465f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b2a0b55bf613bd3e81ed26a847b0f6b8e6b7f804","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bb32e9a6a9a9f99eeda16c4efe443400f3e43892","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/efc33b5102ff859bacd390a5f30112d8e0c084c0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f48341830e4202db3fe884b819b2db6740f0537d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80785","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:04.470","lastModified":"2026-09-04T16:18:04.470","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: serialize mode sysfs access with lock_fb_info()\n\nshow_mode(), show_modes(), and store_mode() access fb_info->modelist\nand fb_info->mode without holding lock_fb_info(). store_modes() takes\nlock_fb_info() while replacing the modelist and freeing the old one.\n\nA concurrent reader or writer can load a pointer to an old modelist\nentry before store_modes() frees it, then dereference freed memory or\nstore a stale freed pointer in fb_info->mode.\n\nTake lock_fb_info() in show_mode(), show_modes(), and store_mode() to\nserialize with store_modes(). In show_mode(), copy the mode to the\nstack and format after dropping the lock. In store_mode(), split\nactivate() into a _locked variant to avoid double-locking, and hold\nthe locks for the modelist walk, mode conversion, activation, and\nfb_info->mode assignment together."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/video/fbdev/core/fbsysfs.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"26135631ed8e487bc6aef70cc41934e258d09bbe","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"061db6b7a910b8378f3b2df64f8c0a3ddc6e85f2","versionType":"git","status":"affected"},{"version":"0","lessThan":"7.1.11","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/video/fbdev/core/fbsysfs.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1.11","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/061db6b7a910b8378f3b2df64f8c0a3ddc6e85f2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/26135631ed8e487bc6aef70cc41934e258d09bbe","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80786","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:04.580","lastModified":"2026-09-04T16:18:04.580","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: Wrap user-invoked calls to fb_set_var() in helper\n\nHandle fbcon during display updates in fb_set_var_from_user(). Check\nwith fbcon if the mode change is possible, update hardware state and\nfinally update fbcon. Update all callers.\n\nOnly the FBIOPUT_VSCREENINFO ioctl currently does all steps. Other\nmode-changes callers in sysfs and driver code are missing fbcon-related\nsteps.\n\nWith the new helper, ps3fb and sh_mobile_lcdcfb no longer maintain\nfbcon state themselves."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/video/fbdev/core/fb_chrdev.c","drivers/video/fbdev/core/fbcon.c","drivers/video/fbdev/core/fbmem.c","drivers/video/fbdev/core/fbsysfs.c","drivers/video/fbdev/ps3fb.c","drivers/video/fbdev/sh_mobile_lcdcfb.c","include/linux/fb.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"07f7e46833f71472e30da54a50dacdf48521bdd3","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"6f611e5e5f3327cf2e2daabe6ee5acac58cc784e","versionType":"git","status":"affected"},{"version":"0","lessThan":"7.1.11","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/video/fbdev/core/fb_chrdev.c","drivers/video/fbdev/core/fbcon.c","drivers/video/fbdev/core/fbmem.c","drivers/video/fbdev/core/fbsysfs.c","drivers/video/fbdev/ps3fb.c","drivers/video/fbdev/sh_mobile_lcdcfb.c","include/linux/fb.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1.11","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/07f7e46833f71472e30da54a50dacdf48521bdd3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6f611e5e5f3327cf2e2daabe6ee5acac58cc784e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80787","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:04.710","lastModified":"2026-09-04T16:18:04.710","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet: pci-epf: fix use-after-free in nvmet_pci_epf_exec_iod_work()\n\nnvmet_pci_epf_exec_iod_work() submits an I/O command with req->execute()\nand then waits for the command to complete and transfers the data back\nto the host. This wait is not needed for commands that do not transfer\ndata from the device to the host. To decide whether that wait is needed,\nit reads iod->data_len and iod->dma_dir after calling req->execute().\n\nHowever, once req->execute() is called, the command may complete\nasynchronously on another CPU. For commands that do not require a\ndevice-to-host data transfer, nvmet_pci_epf_queue_response() calls\nnvmet_pci_epf_complete_iod() directly, which can free the iod before it\nreads iod->data_len and iod->dma_dir, resulting in the KFENCE use-after-\nfree:\n\n BUG: KFENCE: use-after-free read in nvmet_pci_epf_exec_iod_work+0x288/0x798 [nvmet_pci_epf]\n\n Use-after-free read at 0x00000000fdfa6d03 (in kfence-#63):\n  nvmet_pci_epf_exec_iod_work+0x288/0x798 [nvmet_pci_epf]\n  process_one_work+0x15c/0x4f0\n  worker_thread+0x18c/0x30c\n  kthread+0x130/0x140\n  ret_from_fork+0x10/0x20\n\n kfence-#63: 0x00000000e3de0e71-0x00000000c938ad62, size=712, cache=kmalloc-1k\n\n allocated by task 10 on cpu 0 at 73.995480s (0.005122s ago):\n  mempool_kmalloc+0x1c/0x28\n  mempool_alloc_noprof+0x40/0x9c\n  nvmet_pci_epf_poll_sqs_work+0xd4/0x344 [nvmet_pci_epf]\n  process_one_work+0x15c/0x4f0\n  worker_thread+0x18c/0x30c\n  kthread+0x130/0x140\n  ret_from_fork+0x10/0x20\n\n freed by task 131 on cpu 3 at 73.995521s (0.008385s ago):\n  mempool_kfree+0x10/0x20\n  mempool_free+0x44/0x64\n  nvmet_pci_epf_free_iod+0x88/0x98 [nvmet_pci_epf]\n  nvmet_pci_epf_cq_work+0xfc/0x280 [nvmet_pci_epf]\n  process_one_work+0x15c/0x4f0\n  worker_thread+0x18c/0x30c\n  kthread+0x130/0x140\n  ret_from_fork+0x10/0x20\n\nFix this by referring to iod->data_len and iod->dma_dir before calling\nreq->execute(). The remaining iod accesses such as iod->status are only\nreached on the device-to-host read path. In this case,\nnvmet_pci_epf_queue_response() signals iod->done instead of freeing the\niod, so the iod stays valid."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/nvme/target/pci-epf.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"0faa0fe6f90ea59b10d1b0f15ce0eb0c18eff186","lessThan":"20be486d1c225402b067391e72ff5b0dd8ebff76","versionType":"git","status":"affected"},{"version":"0faa0fe6f90ea59b10d1b0f15ce0eb0c18eff186","lessThan":"1ed1eeaef55cebf2d74b3ef104c20bdab719b165","versionType":"git","status":"affected"},{"version":"0faa0fe6f90ea59b10d1b0f15ce0eb0c18eff186","lessThan":"cede8d2852570c79b9bbb9527255ae9ed3317b82","versionType":"git","status":"affected"},{"version":"0faa0fe6f90ea59b10d1b0f15ce0eb0c18eff186","lessThan":"c9e9bb757971485b4e8414b1744507af186d72c9","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/nvme/target/pci-epf.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.14","status":"affected"},{"version":"0","lessThan":"6.14","versionType":"semver","status":"unaffected"},{"version":"6.18.47","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.11","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.1","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1ed1eeaef55cebf2d74b3ef104c20bdab719b165","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/20be486d1c225402b067391e72ff5b0dd8ebff76","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c9e9bb757971485b4e8414b1744507af186d72c9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cede8d2852570c79b9bbb9527255ae9ed3317b82","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80788","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:04.857","lastModified":"2026-09-04T16:18:04.857","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet-tcp: Do not WARN on remotely-controlled oversized SGL allocations\n\nWhen fuzzing the nvme target code, I tripped a kernel warning in\nnvmet_tcp_map_data() because the length passed into the allocator is\ncontrolled by the remote initiator.\n\nA remote initiator that sends a command with an SGL claiming a huge\nnumber, can create a scatterlist and iovec allocation of over 1 million\nentries, which causes the backing kmalloc call to exceed MAX_PAGE_ORDER\nand then the page allocator will trip on a WARN_ON_ONCE_GFP() message:\n\n  WARNING: mm/page_alloc.c:5280 __alloc_frozen_pages_noprof\n  Workqueue: nvmet_tcp_wq nvmet_tcp_io_work\n  ...\n  sgl_alloc_order\n  nvmet_tcp_map_data\n  nvmet_tcp_try_recv_pdu\n\nAs it's never good to trip a kernel warning remotely due to many systems\nhaving panic-on-warn enabled, let's silence it by just add GFP_NOWARN to\nthe allocation flags."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/nvme/target/tcp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"8d01f0d0e96485e39ad89b859ef85e1dc3020465","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"7b6a54d4e7b0da423c2b53ed293fd36b16c0b19e","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"e7077e6c45423dd2bb7de7b5fc4b018a8e6c4741","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"86cc450022473c4a29b43a09f3ec22a9ef566dac","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"c509f20be1cabda3087810bb2d658d66b3f31f35","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"9c95f7e66c62ee6c6abedcf1c04311f430ff5833","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"7fd6da0f28932442b51658bac4ff55565ca9b377","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"9b770e40bc00381e5ebf53653de5776773415be3","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"737a3b535247226f6e1a7988fd9d6e63e7d6fc71","versionType":"git","status":"affected"},{"version":"0","lessThan":"5.10.267","versionType":"semver","status":"affected"},{"version":"0","lessThan":"5.15.218","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.1.185","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.6.154","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.12.106","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.18.47","versionType":"semver","status":"affected"},{"version":"0","lessThan":"7.1.11","versionType":"semver","status":"affected"},{"version":"0","lessThan":"7.2.1","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/nvme/target/tcp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.10.267","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.218","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.185","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.154","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.106","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.47","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.11","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.1","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/737a3b535247226f6e1a7988fd9d6e63e7d6fc71","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7b6a54d4e7b0da423c2b53ed293fd36b16c0b19e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7fd6da0f28932442b51658bac4ff55565ca9b377","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/86cc450022473c4a29b43a09f3ec22a9ef566dac","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8d01f0d0e96485e39ad89b859ef85e1dc3020465","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9b770e40bc00381e5ebf53653de5776773415be3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9c95f7e66c62ee6c6abedcf1c04311f430ff5833","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c509f20be1cabda3087810bb2d658d66b3f31f35","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e7077e6c45423dd2bb7de7b5fc4b018a8e6c4741","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80789","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:05.010","lastModified":"2026-09-04T16:18:05.010","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet-tcp: bound SGL data length before allocating command buffers\n\nnvmet_tcp_map_data() reads the host-controlled 32-bit sgl->length\nand, for the in-capsule offset descriptor (type 0x01), checks it\nagainst port->inline_data_size before use. Any other SGL descriptor\ntype -- including the non-inline transport SGL data-block descriptor\n(type (NVME_TRANSPORT_SGL_DATA_DESC << 4) | NVME_SGL_FMT_TRANSPORT_A,\nthe type a real host uses for out-of-capsule writes) skips that check\nentirely and falls straight through to:\n\n\tcmd->req.sg = sgl_alloc(len, GFP_KERNEL, &cmd->req.sg_cnt);\n\nwith len taken directly from the wire, unbounded up to 4 GiB.\n\nnvmet_req_init() only parses the command and never inspects\nsgl->length, and nvmet_check_transfer_len() -- the only other place\ntransfer_len is validated -- runs later, from req->execute(), after\nthe allocation has already happened. For a write command the target\nresponds with an R2T and parks the command waiting for the host to\nsend the data; if the host (or an unauthenticated peer that simply\nnever follows up) never does, the sgl_alloc() buffer stays resident\nfor the life of the command. NVMe/TCP has no mandatory authentication\nin the default configuration, so any peer able to reach the target\nportal and complete a Fabrics connect can drive this with a single\ncrafted command, repeatable across queues and connections for\namplification. This is unbounded kernel memory allocation\ntriggered by a remote, effectively unauthenticated peer.\n\nValidate len against the same NVMET_TCP_MAXH2CDATA ceiling this file\nalready uses to bound per-PDU H2C data, for every SGL descriptor type,\nbefore doing any allocation. This closes the gap for the non-inline\ndescriptor while leaving the existing, tighter inline_data_size check\nin place for the in-capsule case.\n\nRuntime-verified on a v6.19 KASAN stand: with this bound in place, a\ncrafted write command carrying an oversized non-inline SGL length is\nrejected before sgl_alloc() runs, where the same request previously\ndrove an unbounded ~256 MiB kernel allocation (up to 4 GiB) that\nstayed resident pending an R2T the host never satisfies."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/nvme/target/tcp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"872d26a391da92ed8f0c0f5cb5fef428067b7f30","lessThan":"f6e51b09cbaa5f6f6e6a3a9dafa666f76c37aab5","versionType":"git","status":"affected"},{"version":"872d26a391da92ed8f0c0f5cb5fef428067b7f30","lessThan":"f63e89a0310264264923f84406dea05fe752de62","versionType":"git","status":"affected"},{"version":"872d26a391da92ed8f0c0f5cb5fef428067b7f30","lessThan":"0952541b153e258b99d39cdb03ea6919fdeb41d0","versionType":"git","status":"affected"},{"version":"872d26a391da92ed8f0c0f5cb5fef428067b7f30","lessThan":"25ad03d5c0e858c4b63f1e4b6d461d2af1b30b22","versionType":"git","status":"affected"},{"version":"872d26a391da92ed8f0c0f5cb5fef428067b7f30","lessThan":"d2acc96c528d589f5827cfb90e8e9229dd9d8cb4","versionType":"git","status":"affected"},{"version":"872d26a391da92ed8f0c0f5cb5fef428067b7f30","lessThan":"6d27199ebe8cb223022150f74be13f154a964474","versionType":"git","status":"affected"},{"version":"872d26a391da92ed8f0c0f5cb5fef428067b7f30","lessThan":"14dbe37681a6a7e346fc147bb363ec7cca3180a0","versionType":"git","status":"affected"},{"version":"872d26a391da92ed8f0c0f5cb5fef428067b7f30","lessThan":"d895e66628f939edbb98608f6e033d3d39e6e546","versionType":"git","status":"affected"},{"version":"872d26a391da92ed8f0c0f5cb5fef428067b7f30","lessThan":"4a3f00262a044e8e15064b1a6860968bf0500bf4","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/nvme/target/tcp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.0","status":"affected"},{"version":"0","lessThan":"5.0","versionType":"semver","status":"unaffected"},{"version":"5.10.269","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.220","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.187","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.156","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.106","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.47","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.11","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.1","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0952541b153e258b99d39cdb03ea6919fdeb41d0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/14dbe37681a6a7e346fc147bb363ec7cca3180a0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/25ad03d5c0e858c4b63f1e4b6d461d2af1b30b22","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4a3f00262a044e8e15064b1a6860968bf0500bf4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6d27199ebe8cb223022150f74be13f154a964474","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d2acc96c528d589f5827cfb90e8e9229dd9d8cb4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d895e66628f939edbb98608f6e033d3d39e6e546","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f63e89a0310264264923f84406dea05fe752de62","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f6e51b09cbaa5f6f6e6a3a9dafa666f76c37aab5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80790","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:05.167","lastModified":"2026-09-04T16:18:05.167","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet-fc: fix invalid free in LS IOD error path\n\nnvmet_fc_alloc_ls_iodlist() advances iod while initializing the LS IOD\narray. If an rqstbuf allocation or response buffer DMA mapping fails,\nthe unwind loop decrements iod past the start of the array. The final\nkfree(iod) therefore frees an address before the allocated object.\n\nThis can be reproduced with nvme-fcloop and failslab by setting\nfail-nth to 6 before creating a target port. KASAN reports:\n\n  BUG: KASAN: invalid-free in nvmet_fc_register_targetport\n  Free of addr ffff88816cf8ff48 by task nvmet_fail_nth/9552\n\nFree the original allocation base stored in tgtport->iod instead. With\nthis fix applied, the same sysfs write with fail-nth=6 returns -ENOMEM\nwithout any KASAN report."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/nvme/target/fc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"c53432030d86429dc9fe5adc3d68cb9d1343b0b2","lessThan":"b189c6e408896ccc23d2e76d7738847cdebf1532","versionType":"git","status":"affected"},{"version":"c53432030d86429dc9fe5adc3d68cb9d1343b0b2","lessThan":"449e9c4f8db84ad9d9bb288029b230bcf590faa2","versionType":"git","status":"affected"},{"version":"c53432030d86429dc9fe5adc3d68cb9d1343b0b2","lessThan":"1a8f007faefe8c226ec65896589f8d59b0a8d5a5","versionType":"git","status":"affected"},{"version":"c53432030d86429dc9fe5adc3d68cb9d1343b0b2","lessThan":"d094582cce9c08516d714e7436a8f3b9211dda90","versionType":"git","status":"affected"},{"version":"c53432030d86429dc9fe5adc3d68cb9d1343b0b2","lessThan":"371fb1bf902adaa59be32bd7e904a5317e604fd0","versionType":"git","status":"affected"},{"version":"c53432030d86429dc9fe5adc3d68cb9d1343b0b2","lessThan":"8bce9cd08aae4283badf8ddc11fbb6f57b75a81e","versionType":"git","status":"affected"},{"version":"c53432030d86429dc9fe5adc3d68cb9d1343b0b2","lessThan":"bb9489f0dce58da730d3479588d6710d7a2c1b45","versionType":"git","status":"affected"},{"version":"c53432030d86429dc9fe5adc3d68cb9d1343b0b2","lessThan":"94334ea92f4d7535f66f86e33681efa94827eddc","versionType":"git","status":"affected"},{"version":"c53432030d86429dc9fe5adc3d68cb9d1343b0b2","lessThan":"ba98d6796d12258e837ece065d2ecb59d76ce4ff","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/nvme/target/fc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.10","status":"affected"},{"version":"0","lessThan":"4.10","versionType":"semver","status":"unaffected"},{"version":"5.10.267","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.218","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.185","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.154","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.106","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.47","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.11","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.1","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1a8f007faefe8c226ec65896589f8d59b0a8d5a5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/371fb1bf902adaa59be32bd7e904a5317e604fd0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/449e9c4f8db84ad9d9bb288029b230bcf590faa2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8bce9cd08aae4283badf8ddc11fbb6f57b75a81e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/94334ea92f4d7535f66f86e33681efa94827eddc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b189c6e408896ccc23d2e76d7738847cdebf1532","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ba98d6796d12258e837ece065d2ecb59d76ce4ff","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bb9489f0dce58da730d3479588d6710d7a2c1b45","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d094582cce9c08516d714e7436a8f3b9211dda90","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80791","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:05.327","lastModified":"2026-09-04T16:18:05.327","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet-auth: zero the AUTH_RECEIVE response buffer\n\nnvmet_execute_auth_receive() allocates the response buffer with kmalloc()\nsized by the host-supplied AUTH_RECEIVE allocation length, but the\nDH-HMAC-CHAP builders write only a fixed-size message into it. The full\nallocation length is then copied to the wire by nvmet_copy_to_sgl(), so a\nremote initiator receives the bytes past the built message -- up to nearly\na page of uninitialized slab -- during the pre-authentication handshake.\n\nAllocate the buffer with kzalloc() so the unwritten tail is zeroed before\nit is sent; conforming responses are unaffected."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/nvme/target/fabrics-cmd-auth.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"db1312dd95488b5e6ff362ff66fcf953a46b1821","lessThan":"447b668faa14710f611e714031e3739ac3ec3a4f","versionType":"git","status":"affected"},{"version":"db1312dd95488b5e6ff362ff66fcf953a46b1821","lessThan":"8f6363c8d54dde95982f0ab45e77cf57ec0efd62","versionType":"git","status":"affected"},{"version":"db1312dd95488b5e6ff362ff66fcf953a46b1821","lessThan":"dfcf013f77709ebdb282767edc2795a37cab5b57","versionType":"git","status":"affected"},{"version":"db1312dd95488b5e6ff362ff66fcf953a46b1821","lessThan":"b26189d28442183a8b5edb754f4a6918f77ca84e","versionType":"git","status":"affected"},{"version":"db1312dd95488b5e6ff362ff66fcf953a46b1821","lessThan":"2dcc9226203da7275a9c29d20007da278d73d5e9","versionType":"git","status":"affected"},{"version":"db1312dd95488b5e6ff362ff66fcf953a46b1821","lessThan":"1d6837d98bf966a041af65de5f78de7409ff83bc","versionType":"git","status":"affected"},{"version":"db1312dd95488b5e6ff362ff66fcf953a46b1821","lessThan":"3ddcfb013322aa37eaa7a0d344b73079c38dfa21","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/nvme/target/fabrics-cmd-auth.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.0","status":"affected"},{"version":"0","lessThan":"6.0","versionType":"semver","status":"unaffected"},{"version":"6.1.185","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.154","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.106","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.47","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.11","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.1","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1d6837d98bf966a041af65de5f78de7409ff83bc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2dcc9226203da7275a9c29d20007da278d73d5e9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3ddcfb013322aa37eaa7a0d344b73079c38dfa21","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/447b668faa14710f611e714031e3739ac3ec3a4f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8f6363c8d54dde95982f0ab45e77cf57ec0efd62","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b26189d28442183a8b5edb754f4a6918f77ca84e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dfcf013f77709ebdb282767edc2795a37cab5b57","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80792","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:05.460","lastModified":"2026-09-04T16:18:05.460","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: fix use-after-free in ip6_finish_output2()\n\nip6_finish_output2() caches a pointer to the IPv6 destination\naddress (daddr) before invoking lwtunnel_xmit().  The LWT-BPF\ntransmit path or other encapsulation operations within\nlwtunnel_xmit() can reallocate the skb head, freeing the memory\nthat daddr points to.  When lwtunnel_xmit() returns\nLWTUNNEL_XMIT_CONTINUE, the function continues to use the stale\ndaddr pointer to compute the nexthop and to look up or create the\nneighbour entry.  This results in a use-after-free read, which can\nleak sensitive kernel data, pollute the neighbour table with\narbitrary values, misdirect traffic, or crash the system.\n\nFix this by re-fetching the IPv6 header and the destination\naddress pointer after lwtunnel_xmit() returns\nLWTUNNEL_XMIT_CONTINUE, ensuring that the subsequent nexthop\ncomputation and neighbour lookup operate on valid memory."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/ipv6/ip6_output.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4132c4ad00ddbf3a175ea0d2c775b662a32f4c85","lessThan":"75e0a544ebe9af663ef53ca21e9e9185c51fb54a","versionType":"git","status":"affected"},{"version":"e415ed3a4b8b246ee5e9d109ff5153efcf96b9f2","lessThan":"c95f01b78266828a57060d754fcbfc92123a98ed","versionType":"git","status":"affected"},{"version":"e415ed3a4b8b246ee5e9d109ff5153efcf96b9f2","lessThan":"d960881b9312e781a3429aabceb223ce6b7c882f","versionType":"git","status":"affected"},{"version":"e415ed3a4b8b246ee5e9d109ff5153efcf96b9f2","lessThan":"087ee0d914aaae929f1660c9ca878e367655ba1a","versionType":"git","status":"affected"},{"version":"e415ed3a4b8b246ee5e9d109ff5153efcf96b9f2","lessThan":"3c770ac4e6f07af7c7b40c474a3efc61ffed7862","versionType":"git","status":"affected"},{"version":"e415ed3a4b8b246ee5e9d109ff5153efcf96b9f2","lessThan":"3dc98e5fe82d069dd29b124ffbdb679331dfea43","versionType":"git","status":"affected"},{"version":"e415ed3a4b8b246ee5e9d109ff5153efcf96b9f2","lessThan":"99219c82804f266189388e8bf1cf5135d10d5515","versionType":"git","status":"affected"},{"version":"e415ed3a4b8b246ee5e9d109ff5153efcf96b9f2","lessThan":"73a187384a8c8b983c7fea046d716b6752a1e7a3","versionType":"git","status":"affected"},{"version":"e415ed3a4b8b246ee5e9d109ff5153efcf96b9f2","lessThan":"d0d48d999b0eee6bb176ef4e39d9be868fa80f7e","versionType":"git","status":"affected"},{"version":"1598154fd28ffa4a55beae1970475fd6776554b6","versionType":"git","status":"affected"},{"version":"5.10.233","lessThan":"5.10.267","versionType":"semver","status":"affected"},{"version":"5.4.289","lessThan":"5.5","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/ipv6/ip6_output.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.15","status":"affected"},{"version":"0","lessThan":"5.15","versionType":"semver","status":"unaffected"},{"version":"5.10.267","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.218","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.185","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.154","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.106","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.47","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.11","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.1","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/087ee0d914aaae929f1660c9ca878e367655ba1a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3c770ac4e6f07af7c7b40c474a3efc61ffed7862","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3dc98e5fe82d069dd29b124ffbdb679331dfea43","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/73a187384a8c8b983c7fea046d716b6752a1e7a3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/75e0a544ebe9af663ef53ca21e9e9185c51fb54a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/99219c82804f266189388e8bf1cf5135d10d5515","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c95f01b78266828a57060d754fcbfc92123a98ed","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d0d48d999b0eee6bb176ef4e39d9be868fa80f7e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d960881b9312e781a3429aabceb223ce6b7c882f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80793","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:05.613","lastModified":"2026-09-04T16:18:05.613","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nipv4: reject undersized MTUs in ip_do_fragment()\n\nip_do_fragment() subtracts the IPv4 header length from the effective\nMTU and passes the resulting payload MTU to ip_frag_next().\n\nIf the effective MTU is smaller than hlen + 8, ip_frag_next() rounds\nthe fragment payload length down to zero. The fragmentation state then\nnever makes forward progress: state->left, state->ptr and state->offset\nstay unchanged while ip_do_fragment() keeps allocating and transmitting\nheader-only fragments until the softlockup detector fires.\n\nThis is reproducible with a route installed using \"mtu lock 20\", but it\nis also reproducible without route MTU lock, for example by forwarding a\npacket to a device whose MTU is 20.\n\nFix it in ip_do_fragment() by rejecting mtu < hlen + 8 with -EMSGSIZE,\nmatching the existing IPv6 fragmentation check."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/ipv4/ip_output.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"a716a64a4ba68cd46f2745fba2b1099fe8e0aa59","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"515b6816ba0c12d8415c88e5f41e6ec029e35cfa","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"74ce7389f8f562d39015f59a00ef7ad6acd37803","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"b0ea911453ce7210e8200a07a94d2458bd1e6430","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"36e0741833bd823866f8cb9f112f37cea1a70b60","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"d9d1a676b033acabf8e5645f730486d1f8204a3f","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"3556beb8ca86677af2aca5bfbed6f8e790fccc83","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"c8a74adccaf028223054633b532593101dfcc581","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"c0726f0caf8c6b3208552949e17d23634a2f3129","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/ipv4/ip_output.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.12","status":"affected"},{"version":"0","lessThan":"2.6.12","versionType":"semver","status":"unaffected"},{"version":"5.10.267","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.218","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.185","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.154","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.106","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.47","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.11","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.1","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3556beb8ca86677af2aca5bfbed6f8e790fccc83","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/36e0741833bd823866f8cb9f112f37cea1a70b60","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/515b6816ba0c12d8415c88e5f41e6ec029e35cfa","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/74ce7389f8f562d39015f59a00ef7ad6acd37803","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a716a64a4ba68cd46f2745fba2b1099fe8e0aa59","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b0ea911453ce7210e8200a07a94d2458bd1e6430","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c0726f0caf8c6b3208552949e17d23634a2f3129","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c8a74adccaf028223054633b532593101dfcc581","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d9d1a676b033acabf8e5645f730486d1f8204a3f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80794","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:05.767","lastModified":"2026-09-04T16:18:05.767","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: nci: fix uninit-value in the RF discover/activated NTF handlers\n\nnci_rf_discover_ntf_packet() and nci_rf_intf_activated_ntf_packet() each\nparse a notification into an on-stack struct (nci_rf_discover_ntf /\nnci_rf_intf_activated_ntf) that is not initialised. The RF\ntechnology-specific parameters are only extracted when\nrf_tech_specific_params_len is non-zero, so a notification that reports a\nzero length leaves the rf_tech_specific_params union uninitialised - and\nboth handlers then pass it to nci_add_new_protocol(), which reads it:\n\n - discover:  nci_add_new_target() -> nci_add_new_protocol();\n - activated: nci_target_auto_activated() -> nci_add_new_protocol().\n\nnci_add_new_protocol() uses nfca_poll->nfcid1_len as both a branch\ncondition and a memcpy() length and copies nfcid1/sens_res/sel_res into\nndev->targets, which is later exposed to user space via NFC_CMD_GET_TARGET.\n\n  BUG: KMSAN: uninit-value in nci_add_new_protocol+0x624/0x6c0\n   nci_add_new_protocol+0x624/0x6c0\n   nci_ntf_packet+0x25b2/0x3c30\n   nci_rx_work+0x318/0x5d0\n   process_scheduled_works+0x84b/0x17a0\n   worker_thread+0xc10/0x11b0\n   kthread+0x376/0x500\n  Local variable ntf.i created at:\n   nci_ntf_packet+0xbc2/0x3c30\n\nZero-initialise both on-stack notifications so the union reads back as\nzero when no technology-specific parameters are present."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/nfc/nci/ntf.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20","lessThan":"1007a6b429d756513abd25bd00290908f2e89a4a","versionType":"git","status":"affected"},{"version":"e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20","lessThan":"4bda9ef8392710f21e99027467f3f4afdfb5c99a","versionType":"git","status":"affected"},{"version":"e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20","lessThan":"fe69fed3495f676578d49414a069ad7d8468e2ce","versionType":"git","status":"affected"},{"version":"e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20","lessThan":"7489f59d1ea2d3298aa41de7baf193e5e6e132f6","versionType":"git","status":"affected"},{"version":"e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20","lessThan":"7086dab72b3ed95df96842801e10e935cfeb27a3","versionType":"git","status":"affected"},{"version":"e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20","lessThan":"0d4b5cfab6891a5ca0f6aef209beebba4bd7c095","versionType":"git","status":"affected"},{"version":"e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20","lessThan":"5bd00c0e1470d90d77a7c60242854257ddf14e00","versionType":"git","status":"affected"},{"version":"e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20","lessThan":"d6f743d3d388913135681cde051c08823730194f","versionType":"git","status":"affected"},{"version":"e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20","lessThan":"8cbe06c1e699c0a165dae5093a2550e65f914818","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/nfc/nci/ntf.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.3","status":"affected"},{"version":"0","lessThan":"3.3","versionType":"semver","status":"unaffected"},{"version":"5.10.269","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.218","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.185","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.154","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.106","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.47","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.11","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.1","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0d4b5cfab6891a5ca0f6aef209beebba4bd7c095","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1007a6b429d756513abd25bd00290908f2e89a4a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4bda9ef8392710f21e99027467f3f4afdfb5c99a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5bd00c0e1470d90d77a7c60242854257ddf14e00","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7086dab72b3ed95df96842801e10e935cfeb27a3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7489f59d1ea2d3298aa41de7baf193e5e6e132f6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8cbe06c1e699c0a165dae5093a2550e65f914818","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d6f743d3d388913135681cde051c08823730194f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fe69fed3495f676578d49414a069ad7d8468e2ce","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80795","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:06.020","lastModified":"2026-09-04T16:18:06.020","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: nci: fix out-of-bounds write in nci_target_auto_activated()\n\nnci_target_auto_activated() appends a target to the fixed-size array\nndev->targets[NCI_MAX_DISCOVERED_TARGETS] and increments ndev->n_targets\nwithout first checking the array is full; unlike its sibling\nnci_add_new_target(), which bails out when n_targets already equals\nNCI_MAX_DISCOVERED_TARGETS.\n\nndev->n_targets is only cleared by nci_clear_target_list(), so an NFCC\nthat repeatedly re-runs discovery (RF_DISCOVER_RSP, which re-enters\nNCI_DISCOVERY without clearing the target list) and reports an\nauto-activated target (RF_INTF_ACTIVATED_NTF) drives n_targets past the\nlimit. The append then writes a struct nfc_target past the end of the\narray (a slab out-of-bounds write), and nfc_targets_found() goes on to\nwalk the array with the inflated count:\n\n  BUG: KASAN: slab-out-of-bounds in nci_add_new_protocol+0x94/0x2ac [nci]\n  Write of size 2 at addr ffff0000c7299a18 by task kworker/u8:0/12\n  Workqueue: nfc0_nci_rx_wq nci_rx_work [nci]\n  Call trace:\n   nci_add_new_protocol+0x94/0x2ac [nci]\n   nci_ntf_packet+0xddc/0x11a0 [nci]\n   nci_rx_work+0x15c/0x1e0 [nci]\n   process_one_work+0x2dc/0x500\n   worker_thread+0x240/0x460\n   kthread+0x1c0/0x1d0\n   ret_from_fork+0x10/0x20\n\n  The buggy address belongs to the cache kmalloc-2k of size 2048\n  The buggy address is located 1024 bytes to the right of\n  allocated 1560-byte region [ffff0000c7299000, ffff0000c7299618)\n\nGuard nci_target_auto_activated() with the same check used by\nnci_add_new_target()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/nfc/nci/ntf.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"019c4fbaa790e2b3f11dab0c8b7d9896d77db3e5","lessThan":"0dc59de0075f88404a0f4a2b5233104ef459fbb2","versionType":"git","status":"affected"},{"version":"019c4fbaa790e2b3f11dab0c8b7d9896d77db3e5","lessThan":"94530ffabfca57e9bff1d207106010014cc84032","versionType":"git","status":"affected"},{"version":"019c4fbaa790e2b3f11dab0c8b7d9896d77db3e5","lessThan":"afd8605fb43becb892311102844955c3b127fc7e","versionType":"git","status":"affected"},{"version":"019c4fbaa790e2b3f11dab0c8b7d9896d77db3e5","lessThan":"24761d3a5f692df5f7d848caeabcb2afd10917aa","versionType":"git","status":"affected"},{"version":"019c4fbaa790e2b3f11dab0c8b7d9896d77db3e5","lessThan":"50e87e1c0e18d791dcd7dccf30f9a2f3e2cf3951","versionType":"git","status":"affected"},{"version":"019c4fbaa790e2b3f11dab0c8b7d9896d77db3e5","lessThan":"2f08dbce3b37624ec6b424d759336a99586170ec","versionType":"git","status":"affected"},{"version":"019c4fbaa790e2b3f11dab0c8b7d9896d77db3e5","lessThan":"d7083f41c21b30582e91b2e6de4d54dce74f6f9c","versionType":"git","status":"affected"},{"version":"019c4fbaa790e2b3f11dab0c8b7d9896d77db3e5","lessThan":"129032c0616d83a5e3e304f6ebf88f14ba01e5f7","versionType":"git","status":"affected"},{"version":"019c4fbaa790e2b3f11dab0c8b7d9896d77db3e5","lessThan":"ac200079db50af81e6b04d058b33ec92901d8edd","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/nfc/nci/ntf.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.4","status":"affected"},{"version":"0","lessThan":"3.4","versionType":"semver","status":"unaffected"},{"version":"5.10.267","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.218","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.185","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.154","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.106","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.47","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.11","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.1","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0dc59de0075f88404a0f4a2b5233104ef459fbb2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/129032c0616d83a5e3e304f6ebf88f14ba01e5f7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/24761d3a5f692df5f7d848caeabcb2afd10917aa","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2f08dbce3b37624ec6b424d759336a99586170ec","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/50e87e1c0e18d791dcd7dccf30f9a2f3e2cf3951","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/94530ffabfca57e9bff1d207106010014cc84032","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ac200079db50af81e6b04d058b33ec92901d8edd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/afd8605fb43becb892311102844955c3b127fc7e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d7083f41c21b30582e91b2e6de4d54dce74f6f9c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80796","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:06.180","lastModified":"2026-09-04T16:18:06.180","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: nci: add data_len bound checks to activation parameter extractors\n\nnci_extract_activation_params_iso_dep() and\nnci_extract_activation_params_nfc_dep() read an inner length byte from\nthe NCI RF_INTF_ACTIVATED_NTF payload and use it to memcpy() into fixed\nkernel buffers, but neither function receives the caller-validated\nactivation_params_len.  A crafted NCI notification with\nactivation_params_len=1 and an inner length byte of up to 20 (NFC-A) or\n50 (NFC-B) causes memcpy() to read that many bytes past the one valid\nbyte in the activation params region -- a slab out-of-bounds read of\nkernel memory adjacent to the NCI skb.\n\nThe sibling nci_extract_rf_params_*() family was given equivalent\nprotection by commit 571dcbeb8e63 (\"net: nfc: nci: Fix parameter\nvalidation for packet data\"), but the two activation parameter\nextractors were not updated at that time.\n\nAdd a data_len parameter to both functions, guard against an empty\nregion before consuming the inner length byte, decrement the remaining\ncount after consuming it, and clamp the copy length to what is actually\navailable.  Update both call sites to pass ntf.activation_params_len,\nwhich is already validated against the skb at ntf.c:801."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/nfc/nci/ntf.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20","lessThan":"1168484fe2b3828bf24a46f3c42a8719fade679b","versionType":"git","status":"affected"},{"version":"e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20","lessThan":"be311c0cfeadfbe815ea22d2914a98d06e3fab0e","versionType":"git","status":"affected"},{"version":"e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20","lessThan":"04e51353cb9fa321caaeeed8331d4cd041fbaca7","versionType":"git","status":"affected"},{"version":"e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20","lessThan":"e25b44bd8b8cc666b49a3fe0ef547e64d5b1e300","versionType":"git","status":"affected"},{"version":"e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20","lessThan":"9b01f5af0dc59263b59391b148bc78d83c0354a9","versionType":"git","status":"affected"},{"version":"e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20","lessThan":"9620a91f8d643b680f417a435db399a04d1e06d8","versionType":"git","status":"affected"},{"version":"e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20","lessThan":"cf9d44be50b9074a5abdc301b4a3ba3e283591df","versionType":"git","status":"affected"},{"version":"e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20","lessThan":"f5c534b53f8c424a8e7633c9b585475c4bf4ee18","versionType":"git","status":"affected"},{"version":"e8c0dacd9836dc2dcb28d236c9cc3cfaa9965a20","lessThan":"0428fa2c22e2ba0cff766d3b80d461e149102045","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/nfc/nci/ntf.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.3","status":"affected"},{"version":"0","lessThan":"3.3","versionType":"semver","status":"unaffected"},{"version":"5.10.269","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.220","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.187","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.156","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.108","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.47","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.11","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.1","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0428fa2c22e2ba0cff766d3b80d461e149102045","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/04e51353cb9fa321caaeeed8331d4cd041fbaca7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1168484fe2b3828bf24a46f3c42a8719fade679b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9620a91f8d643b680f417a435db399a04d1e06d8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9b01f5af0dc59263b59391b148bc78d83c0354a9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/be311c0cfeadfbe815ea22d2914a98d06e3fab0e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cf9d44be50b9074a5abdc301b4a3ba3e283591df","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e25b44bd8b8cc666b49a3fe0ef547e64d5b1e300","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f5c534b53f8c424a8e7633c9b585475c4bf4ee18","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80797","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:06.333","lastModified":"2026-09-04T16:18:06.333","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: pn533: purge fragmented skbs during cleanup\n\npn53x_common_clean() purges resp_q before freeing the common PN533 state,\nbut it leaves fragment_skb untouched.  The fragmentation helpers queue\ntransmit fragments there while sending large initiator or target-mode\nframes, and those skbs remain owned by the driver until they are sent or\ndiscarded.\n\nIf the device is removed while fragments are still queued, the common\ncleanup path frees the PN533 state without releasing the queued fragment\nskbs, leaking them.\n\nPurge fragment_skb during cleanup alongside resp_q."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/nfc/pn533/pn533.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"963a82e07d4e1f95fc423d53912ac0a7fe643b1c","lessThan":"130b5ad4492f8e53d0398ee3af2b0e2388504d11","versionType":"git","status":"affected"},{"version":"963a82e07d4e1f95fc423d53912ac0a7fe643b1c","lessThan":"9319c3c4962efc8697246b563ea31c6d47f085aa","versionType":"git","status":"affected"},{"version":"963a82e07d4e1f95fc423d53912ac0a7fe643b1c","lessThan":"d63e85c5d5555fe6aa65155d3a09452597e163c3","versionType":"git","status":"affected"},{"version":"963a82e07d4e1f95fc423d53912ac0a7fe643b1c","lessThan":"4a52ec2457ff8c26206fcc20fa1972cc35a678c4","versionType":"git","status":"affected"},{"version":"963a82e07d4e1f95fc423d53912ac0a7fe643b1c","lessThan":"e169277281373818ae1cedf976aa1e99118fb77d","versionType":"git","status":"affected"},{"version":"963a82e07d4e1f95fc423d53912ac0a7fe643b1c","lessThan":"2f5d093194ec24d7c29b91bf7df014924e0f4ea1","versionType":"git","status":"affected"},{"version":"963a82e07d4e1f95fc423d53912ac0a7fe643b1c","lessThan":"e7ed2ea5590fbe2d3be39ee4fb0c758a12e31d0c","versionType":"git","status":"affected"},{"version":"963a82e07d4e1f95fc423d53912ac0a7fe643b1c","lessThan":"e95beff58b38c871c557bf84e528408283c2c0ad","versionType":"git","status":"affected"},{"version":"963a82e07d4e1f95fc423d53912ac0a7fe643b1c","lessThan":"5718fc62198c38c2de5316020a90506f9e75e0bb","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/nfc/pn533/pn533.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.12","status":"affected"},{"version":"0","lessThan":"3.12","versionType":"semver","status":"unaffected"},{"version":"5.10.267","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.218","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.185","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.154","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.106","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.47","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.11","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.1","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/130b5ad4492f8e53d0398ee3af2b0e2388504d11","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2f5d093194ec24d7c29b91bf7df014924e0f4ea1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4a52ec2457ff8c26206fcc20fa1972cc35a678c4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5718fc62198c38c2de5316020a90506f9e75e0bb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9319c3c4962efc8697246b563ea31c6d47f085aa","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d63e85c5d5555fe6aa65155d3a09452597e163c3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e169277281373818ae1cedf976aa1e99118fb77d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e7ed2ea5590fbe2d3be39ee4fb0c758a12e31d0c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e95beff58b38c871c557bf84e528408283c2c0ad","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80798","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:06.487","lastModified":"2026-09-04T16:18:06.487","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: llcp: reject PDUs shorter than the LLCP header\n\nEvery LLCP PDU begins with a two-byte header (DSAP/SSAP + PTYPE), but the\nreceive path never checked that a frame is at least LLCP_HEADER_SIZE bytes\nbefore parsing it.\n\nnfc_llcp_rx_skb() reads the header via nfc_llcp_ptype()/nfc_llcp_dsap()/\nnfc_llcp_ssap(), which dereference pdu->data[0] and pdu->data[1], and a\nCONNECT or CC PDU then computes\n\n\ttlv_array_len = skb->len - LLCP_HEADER_SIZE;\n\nas a size_t and hands it to the TLV walk. When the frame is shorter than\nthe header the subtraction wraps to a huge value and the walk runs far\npast the buffer, an out-of-bounds read.\n\nA nearby NFC device can reach this without authentication; LLCP link\nactivation happens automatically after NFC-DEP.\n\nGuard the common receive choke point __nfc_llcp_recv(), shared by both the\ntarget (nfc_llcp_data_received()) and initiator (nfc_llcp_recv()) paths, so\na short skb is dropped before the rx_work worker parses it. Use\npskb_may_pull() rather than a skb->len test so the two header bytes are\nguaranteed to sit in the skb linear area even for a non-linear skb,\nmatching how the sibling NCI and HCI receive paths validate their headers.\n\nReproduced with a KFENCE out-of-bounds read via /dev/virtual_nci on\nlinux-next.\n\nFound by 0sec automated security-research tooling (https://0sec.ai)."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/nfc/llcp_core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"d646960f7986fefb460a2b062d5ccc8ccfeacc3a","lessThan":"e6ec76a68dce04884dfeccfe5a5f0e9f67c0ec82","versionType":"git","status":"affected"},{"version":"d646960f7986fefb460a2b062d5ccc8ccfeacc3a","lessThan":"f36cffea24bf3e2cc29a00d4b51dbcadc087d810","versionType":"git","status":"affected"},{"version":"d646960f7986fefb460a2b062d5ccc8ccfeacc3a","lessThan":"a7b9b449f5a5132221fff6adc11a9431ab8cd914","versionType":"git","status":"affected"},{"version":"d646960f7986fefb460a2b062d5ccc8ccfeacc3a","lessThan":"3793d768b40f38bb97265dd5b9a8b8655c4e1b1d","versionType":"git","status":"affected"},{"version":"d646960f7986fefb460a2b062d5ccc8ccfeacc3a","lessThan":"eab47618e282602197db287ecbd1b09d356a2515","versionType":"git","status":"affected"},{"version":"d646960f7986fefb460a2b062d5ccc8ccfeacc3a","lessThan":"e969e98410051b1ef8cc318bfe0c7e3f24ec766d","versionType":"git","status":"affected"},{"version":"d646960f7986fefb460a2b062d5ccc8ccfeacc3a","lessThan":"ae5f20f5842f440b72d030e3a34fe182dd8eae42","versionType":"git","status":"affected"},{"version":"d646960f7986fefb460a2b062d5ccc8ccfeacc3a","lessThan":"d3d90243393c48146911c67fd3792b549d21d9e6","versionType":"git","status":"affected"},{"version":"d646960f7986fefb460a2b062d5ccc8ccfeacc3a","lessThan":"95674f506c6376d6722a23144c9acd26609771ed","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/nfc/llcp_core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.3","status":"affected"},{"version":"0","lessThan":"3.3","versionType":"semver","status":"unaffected"},{"version":"5.10.267","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.218","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.185","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.154","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.106","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.47","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.11","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.1","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3793d768b40f38bb97265dd5b9a8b8655c4e1b1d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/95674f506c6376d6722a23144c9acd26609771ed","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a7b9b449f5a5132221fff6adc11a9431ab8cd914","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ae5f20f5842f440b72d030e3a34fe182dd8eae42","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d3d90243393c48146911c67fd3792b549d21d9e6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e6ec76a68dce04884dfeccfe5a5f0e9f67c0ec82","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e969e98410051b1ef8cc318bfe0c7e3f24ec766d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/eab47618e282602197db287ecbd1b09d356a2515","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f36cffea24bf3e2cc29a00d4b51dbcadc087d810","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80799","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:06.637","lastModified":"2026-09-04T16:18:06.637","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: llcp: fix OOB read and u8 offset wrap in TLV parsers\n\nnfc_llcp_parse_gb_tlv() and nfc_llcp_parse_connection_tlv() contain\nthree related bugs in their TLV parsing loops:\n\n1. 'offset' is declared u8 but tlv_array_len is u16. When TLV data\n   advances offset past 255 it silently wraps to zero, causing\n   infinite loops or double-processing of buffer data.\n\n2. Before reading tlv[0] (type) and tlv[1] (length) there is no\n   check that offset+2 <= tlv_array_len. A truncated TLV causes\n   an OOB read of one byte past the buffer end.\n\n3. After reading the length field, the value bytes are accessed\n   without checking offset+2+length <= tlv_array_len. A crafted\n   length=0xFF on a short buffer causes up to 255 bytes of OOB\n   read past the buffer end.\n\nBoth functions are reachable without authentication via\nnfc_llcp_set_remote_gb() which feeds remote LLCP general bytes\ndirectly into nfc_llcp_parse_gb_tlv() with no additional\nvalidation.\n\nFix all three issues by widening offset from u8 to u16 and adding\nbounds checks for both the TLV header and value field before each\naccess."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/nfc/llcp_commands.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"0be9de2ea01e8d52646e7310a7eef5459cf07ea8","lessThan":"2c1456fe09ab1a5a9fe1d8339ca6d509589b56e1","versionType":"git","status":"affected"},{"version":"3df40eb3a2ea58bf404a38f15a7a2768e4762cb0","lessThan":"7f6f3d087c67a4346189ef2c36481455bbc59a74","versionType":"git","status":"affected"},{"version":"3df40eb3a2ea58bf404a38f15a7a2768e4762cb0","lessThan":"9c47d667963542c3cf8e3007b7f10c0904d08238","versionType":"git","status":"affected"},{"version":"3df40eb3a2ea58bf404a38f15a7a2768e4762cb0","lessThan":"a209334ed929941b20810c17c3a507445b0a7c85","versionType":"git","status":"affected"},{"version":"3df40eb3a2ea58bf404a38f15a7a2768e4762cb0","lessThan":"382eaa770335acf4f16a5a55524500f2bb4207df","versionType":"git","status":"affected"},{"version":"3df40eb3a2ea58bf404a38f15a7a2768e4762cb0","lessThan":"2d239590d1845a706304833d40dd6d4fec20ad88","versionType":"git","status":"affected"},{"version":"3df40eb3a2ea58bf404a38f15a7a2768e4762cb0","lessThan":"e84cdfdc4a6c88e8b751144458f2e04e24415a28","versionType":"git","status":"affected"},{"version":"3df40eb3a2ea58bf404a38f15a7a2768e4762cb0","lessThan":"875285a165fd3b402de2ab3be0deb355d6f4caf5","versionType":"git","status":"affected"},{"version":"3df40eb3a2ea58bf404a38f15a7a2768e4762cb0","lessThan":"78b20c8eeacd2e44a2d8a4cb5316d3c521d90911","versionType":"git","status":"affected"},{"version":"1deacb5e031e289ca5636f2db4fcae6612c05d34","versionType":"git","status":"affected"},{"version":"66a1be74230bbe098e651766c9a0cf4038db8442","versionType":"git","status":"affected"},{"version":"5.10.188","lessThan":"5.10.267","versionType":"semver","status":"affected"},{"version":"4.19.291","lessThan":"4.20","versionType":"semver","status":"affected"},{"version":"5.4.251","lessThan":"5.5","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/nfc/llcp_commands.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.15","status":"affected"},{"version":"0","lessThan":"5.15","versionType":"semver","status":"unaffected"},{"version":"5.10.267","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.218","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.185","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.154","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.106","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.47","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.11","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.1","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2c1456fe09ab1a5a9fe1d8339ca6d509589b56e1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2d239590d1845a706304833d40dd6d4fec20ad88","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/382eaa770335acf4f16a5a55524500f2bb4207df","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/78b20c8eeacd2e44a2d8a4cb5316d3c521d90911","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7f6f3d087c67a4346189ef2c36481455bbc59a74","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/875285a165fd3b402de2ab3be0deb355d6f4caf5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9c47d667963542c3cf8e3007b7f10c0904d08238","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a209334ed929941b20810c17c3a507445b0a7c85","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e84cdfdc4a6c88e8b751144458f2e04e24415a28","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80800","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:06.797","lastModified":"2026-09-04T16:18:06.797","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: llcp: bound the connect_sn TLV walk to the skb\n\nCommit 27256cdb290e (\"nfc: llcp: bound SNL TLV parsing to the skb and\nadd length checks\") fixed the unbounded TLV walk in nfc_llcp_recv_snl(),\nand commit d8bd2dedbde5 (\"nfc: llcp: fix OOB read and u8 offset wrap in\nTLV parsers\") subsequently bounded nfc_llcp_parse_gb_tlv() and\nnfc_llcp_parse_connection_tlv(). One sibling parser sharing the same\npattern remains unbounded: nfc_llcp_connect_sn().\n\nnfc_llcp_connect_sn() walks a TLV list, reading a two-byte header\n(type, length) followed by length bytes of value, without checking that\nthe two header bytes or the declared length stay within the buffer. It\nreturns a pointer to a service name of up to 255 bytes that may point\npast the end of the skb; it is subsequently consumed by memcmp() in\nnfc_llcp_sock_from_sn(). In addition tlv_array_len was computed as\n\"skb->len - LLCP_HEADER_SIZE\" in size_t, so a CONNECT/CC frame shorter\nthan the LLCP header underflows to a huge length and the walk runs far\npast the buffer.\n\nnfc_llcp_connect_sn() is reachable from nfc_llcp_recv_connect() and\nnfc_llcp_recv_cc(), i.e. from received CONNECT and CC PDUs. A nearby\nNFC device can reach this without authentication; LLCP link activation\nhappens automatically after NFC-DEP, and the nfc_llcp_rx_skb()\ndispatcher applies no minimum-length guard.\n\nWalk the TLV list by pointer, bounded by skb_tail_pointer(skb), and\nvalidate each declared length before use, matching the approach already\nused for nfc_llcp_recv_snl(). Starting the walk at\n&skb->data[LLCP_HEADER_SIZE] against the tail pointer also removes the\nsize_t underflow for short frames.\n\nFound by 0sec automated security-research tooling (https://0sec.ai)."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/nfc/llcp_core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"d646960f7986fefb460a2b062d5ccc8ccfeacc3a","lessThan":"b2ebdfe3d5b76e91f267a61cbc3f9a0e3f77071e","versionType":"git","status":"affected"},{"version":"d646960f7986fefb460a2b062d5ccc8ccfeacc3a","lessThan":"e18d044bab6d3d0280639098c3fe6621692cbfe2","versionType":"git","status":"affected"},{"version":"d646960f7986fefb460a2b062d5ccc8ccfeacc3a","lessThan":"65a0ec7783b06068dda6745dd689bf4a91ee64aa","versionType":"git","status":"affected"},{"version":"d646960f7986fefb460a2b062d5ccc8ccfeacc3a","lessThan":"1964addc8dd535a05d5d3b55b4d1ac19ae31aa65","versionType":"git","status":"affected"},{"version":"d646960f7986fefb460a2b062d5ccc8ccfeacc3a","lessThan":"389986fd79e4d43f971a03b512645a1bb63c982f","versionType":"git","status":"affected"},{"version":"d646960f7986fefb460a2b062d5ccc8ccfeacc3a","lessThan":"e87527b506c40db9af528714b7b1240918eb80fc","versionType":"git","status":"affected"},{"version":"d646960f7986fefb460a2b062d5ccc8ccfeacc3a","lessThan":"22e5177ba1196a0b272a6a46c2575eb940a939c4","versionType":"git","status":"affected"},{"version":"d646960f7986fefb460a2b062d5ccc8ccfeacc3a","lessThan":"0cfbdb0e13ab5b0765d77f96af67eb879cbc9736","versionType":"git","status":"affected"},{"version":"d646960f7986fefb460a2b062d5ccc8ccfeacc3a","lessThan":"55c68ac93e7dacc0f5f608b9c39dd4ff48cf28e8","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/nfc/llcp_core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.3","status":"affected"},{"version":"0","lessThan":"3.3","versionType":"semver","status":"unaffected"},{"version":"5.10.267","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.218","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.185","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.154","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.106","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.47","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.11","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.1","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0cfbdb0e13ab5b0765d77f96af67eb879cbc9736","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1964addc8dd535a05d5d3b55b4d1ac19ae31aa65","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/22e5177ba1196a0b272a6a46c2575eb940a939c4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/389986fd79e4d43f971a03b512645a1bb63c982f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/55c68ac93e7dacc0f5f608b9c39dd4ff48cf28e8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/65a0ec7783b06068dda6745dd689bf4a91ee64aa","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b2ebdfe3d5b76e91f267a61cbc3f9a0e3f77071e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e18d044bab6d3d0280639098c3fe6621692cbfe2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e87527b506c40db9af528714b7b1240918eb80fc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80801","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:06.960","lastModified":"2026-09-04T16:18:06.960","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: microread: validate target discovery payload lengths\n\nmicroread_target_discovered() parses target discovery payloads from\nskb->data according to the HCI gate. The fixed field offsets and UID\ncopies were checked only against the destination nfc_target buffers, not\nagainst the actual skb length.\n\nValidate that each gate-specific payload contains the fixed fields and\nUID bytes before reading or copying them."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/nfc/microread/microread.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"cfad1ba87150e198be9ea32367a24e500e59de2c","lessThan":"c6de4241f2efbbab286efbb84a9c7190298b3052","versionType":"git","status":"affected"},{"version":"cfad1ba87150e198be9ea32367a24e500e59de2c","lessThan":"92a6f0201bb68391b5eba1b3f330af007d7323b6","versionType":"git","status":"affected"},{"version":"cfad1ba87150e198be9ea32367a24e500e59de2c","lessThan":"cb298672282421159e53ab311fe49d204c8a52da","versionType":"git","status":"affected"},{"version":"cfad1ba87150e198be9ea32367a24e500e59de2c","lessThan":"18f02354ed229b8e4561b580812d026e7eb29c85","versionType":"git","status":"affected"},{"version":"cfad1ba87150e198be9ea32367a24e500e59de2c","lessThan":"e6397fe7b8b5ef18e051f49612d40ff476c5f7d9","versionType":"git","status":"affected"},{"version":"cfad1ba87150e198be9ea32367a24e500e59de2c","lessThan":"d0902a7c454326c6384c614226ab8987f3fd425d","versionType":"git","status":"affected"},{"version":"cfad1ba87150e198be9ea32367a24e500e59de2c","lessThan":"dabfa26a208e56f4d8dbf26fddc48f188bdb0649","versionType":"git","status":"affected"},{"version":"cfad1ba87150e198be9ea32367a24e500e59de2c","lessThan":"953963b9ac5eecbb316617d337bfaa3d731e3c5e","versionType":"git","status":"affected"},{"version":"cfad1ba87150e198be9ea32367a24e500e59de2c","lessThan":"25519469972ef57c3edb1805dabd6c5612b90211","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/nfc/microread/microread.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.9","status":"affected"},{"version":"0","lessThan":"3.9","versionType":"semver","status":"unaffected"},{"version":"5.10.267","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.218","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.185","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.154","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.106","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.47","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.11","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.1","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/18f02354ed229b8e4561b580812d026e7eb29c85","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/25519469972ef57c3edb1805dabd6c5612b90211","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/92a6f0201bb68391b5eba1b3f330af007d7323b6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/953963b9ac5eecbb316617d337bfaa3d731e3c5e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c6de4241f2efbbab286efbb84a9c7190298b3052","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cb298672282421159e53ab311fe49d204c8a52da","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d0902a7c454326c6384c614226ab8987f3fd425d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dabfa26a208e56f4d8dbf26fddc48f188bdb0649","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e6397fe7b8b5ef18e051f49612d40ff476c5f7d9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80802","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:07.103","lastModified":"2026-09-04T16:18:07.103","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: fdp: bound the device-reported read length and fix an skb leak\n\nfdp_nci_i2c_read() takes the next packet length from two device-supplied\nbytes and never validates it. The value is a u16 used as the\ni2c_master_recv() count into a 261-byte on-stack buffer: a malicious,\ncounterfeit or malfunctioning controller (or an i2c bus interposer) can\ndrive it far past the buffer for a stack out-of-bounds write that\nclobbers the canary and return address, or below the minimum frame size\n(directly, or by truncating the computed sum) so the header/LRC strip\nand the next length read run past a short receive. Reject a length\noutside [FDP_NCI_I2C_MIN_PAYLOAD, FDP_NCI_I2C_MAX_PAYLOAD], as a\ncorrupted packet already is, and force resynchronization.\n\nThe same loop allocates one data skb per iteration and assumes a length\npacket followed by a data packet; a device that sends two data packets\nin one call leaks the first skb when the second allocation overwrites\nit. Free a previously allocated skb before allocating the next."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/nfc/fdp/i2c.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"a06347c04c13e380afce0c9816df51f00b83faf1","lessThan":"d9498ab9a78cb63d78dbe4f221d8cc6c91f285ee","versionType":"git","status":"affected"},{"version":"a06347c04c13e380afce0c9816df51f00b83faf1","lessThan":"1fc32327b927a6e2cde086f82575c29880844228","versionType":"git","status":"affected"},{"version":"a06347c04c13e380afce0c9816df51f00b83faf1","lessThan":"8d2c243b79854628ff076c38748c020042f02f57","versionType":"git","status":"affected"},{"version":"a06347c04c13e380afce0c9816df51f00b83faf1","lessThan":"fc3c2bd5b1ec6c7cbc8a50e32d9bcec114f25463","versionType":"git","status":"affected"},{"version":"a06347c04c13e380afce0c9816df51f00b83faf1","lessThan":"0d723090645b82c1cb27cfd7ebf81f0e7c96bcae","versionType":"git","status":"affected"},{"version":"a06347c04c13e380afce0c9816df51f00b83faf1","lessThan":"db7e464b350969c6ea8340de00d9796e5fd5123b","versionType":"git","status":"affected"},{"version":"a06347c04c13e380afce0c9816df51f00b83faf1","lessThan":"e5eec121f2c3bc4c7022613bedd9121a8aa4c949","versionType":"git","status":"affected"},{"version":"a06347c04c13e380afce0c9816df51f00b83faf1","lessThan":"1aa3fc769b0c45bd19f8dab1697084c2b3f6d706","versionType":"git","status":"affected"},{"version":"a06347c04c13e380afce0c9816df51f00b83faf1","lessThan":"7ad21dcfeb5181af0c3ee2608808c0c0a5283aa1","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/nfc/fdp/i2c.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.4","status":"affected"},{"version":"0","lessThan":"4.4","versionType":"semver","status":"unaffected"},{"version":"5.10.267","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.218","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.185","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.154","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.106","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.47","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.11","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.1","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0d723090645b82c1cb27cfd7ebf81f0e7c96bcae","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1aa3fc769b0c45bd19f8dab1697084c2b3f6d706","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1fc32327b927a6e2cde086f82575c29880844228","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7ad21dcfeb5181af0c3ee2608808c0c0a5283aa1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8d2c243b79854628ff076c38748c020042f02f57","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d9498ab9a78cb63d78dbe4f221d8cc6c91f285ee","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/db7e464b350969c6ea8340de00d9796e5fd5123b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e5eec121f2c3bc4c7022613bedd9121a8aa4c949","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fc3c2bd5b1ec6c7cbc8a50e32d9bcec114f25463","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80803","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:07.250","lastModified":"2026-09-04T16:18:07.250","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: digital: clamp SENSF_RES length to the destination buffer\n\ndigital_in_recv_sensf_res() memcpy()s resp->len bytes from a remote\nNFC-F device response into the NFC_SENSF_RES_MAXSIZE-byte target.sensf_res\nfield without an upper-bound check. A nearby malicious NFC-F device can\nsend an oversized SENSF_RES response to overflow the stack-local struct\nnfc_target.\n\nClamp resp->len to NFC_SENSF_RES_MAXSIZE before the copy.\n\nFound by 0sec automated security-research tooling (https://0sec.ai)."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/nfc/digital_technology.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"8c0695e4998dd268ff2a05951961247b7e015651","lessThan":"6afb29751ee731e7f7a96feb8a15f91441e552ba","versionType":"git","status":"affected"},{"version":"8c0695e4998dd268ff2a05951961247b7e015651","lessThan":"e886c63d2ca7108826076989103a1ffa8a0bb8f4","versionType":"git","status":"affected"},{"version":"8c0695e4998dd268ff2a05951961247b7e015651","lessThan":"4e942da2869bcd646353eef706b7dd82efeb9db5","versionType":"git","status":"affected"},{"version":"8c0695e4998dd268ff2a05951961247b7e015651","lessThan":"d0756a98277e383c26fead988a96c91f0781cd7f","versionType":"git","status":"affected"},{"version":"8c0695e4998dd268ff2a05951961247b7e015651","lessThan":"af4c0606f743e009254a8d252096855335ade85d","versionType":"git","status":"affected"},{"version":"8c0695e4998dd268ff2a05951961247b7e015651","lessThan":"a56773e649ea99b344d6bbaf90f34c8e3fadef5d","versionType":"git","status":"affected"},{"version":"8c0695e4998dd268ff2a05951961247b7e015651","lessThan":"a1ef9bddfbb3ae42b036c5aa16cf386d78db70b6","versionType":"git","status":"affected"},{"version":"8c0695e4998dd268ff2a05951961247b7e015651","lessThan":"31aa28ed732f66ab83c40ef53d99791be69b85c4","versionType":"git","status":"affected"},{"version":"8c0695e4998dd268ff2a05951961247b7e015651","lessThan":"344a56d7c8e0f3cbaff0bcb1bcd95a1a1db24b16","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/nfc/digital_technology.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.13","status":"affected"},{"version":"0","lessThan":"3.13","versionType":"semver","status":"unaffected"},{"version":"5.10.267","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.218","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.185","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.154","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.106","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.47","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.11","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.1","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/31aa28ed732f66ab83c40ef53d99791be69b85c4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/344a56d7c8e0f3cbaff0bcb1bcd95a1a1db24b16","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4e942da2869bcd646353eef706b7dd82efeb9db5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6afb29751ee731e7f7a96feb8a15f91441e552ba","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a1ef9bddfbb3ae42b036c5aa16cf386d78db70b6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a56773e649ea99b344d6bbaf90f34c8e3fadef5d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/af4c0606f743e009254a8d252096855335ade85d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d0756a98277e383c26fead988a96c91f0781cd7f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e886c63d2ca7108826076989103a1ffa8a0bb8f4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80804","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:07.397","lastModified":"2026-09-04T16:18:07.397","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nxfs: restore nofs context unconditionally in xfs_trans_roll\n\nWhen __xfs_trans_commit() fails in xfs_trans_roll(), the NOFS context\nis cleared but only restored in the success path.  This leaves the\nerror path without nofs protection, causing a circular lock dependency\nbetween xfs_nondir_ilock_class and fs_reclaim:\n\n       CPU0                    CPU1\n       ----                    ----\n  lock(&xfs_nondir_ilock_class);\n                               lock(fs_reclaim);\n                               lock(&xfs_nondir_ilock_class);\n  lock(fs_reclaim);\n\nFix this by moving xfs_trans_set_context() before the error check so\nthat nofs context is always restored on the new transaction."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/xfs/xfs_trans.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"a1ca658d649a4d8972e2e21ac2625b633217e327","lessThan":"b09198cf90ccf296970b774beea1c1ddb260f94c","versionType":"git","status":"affected"},{"version":"a1ca658d649a4d8972e2e21ac2625b633217e327","lessThan":"4d00a39c676274f4071b467e630565ac1e3ae0f2","versionType":"git","status":"affected"},{"version":"a1ca658d649a4d8972e2e21ac2625b633217e327","lessThan":"0241ea5fb0fe86d2a673163b2f5815111aadc7f7","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/xfs/xfs_trans.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.0","status":"affected"},{"version":"0","lessThan":"7.0","versionType":"semver","status":"unaffected"},{"version":"7.1.11","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.1","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0241ea5fb0fe86d2a673163b2f5815111aadc7f7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4d00a39c676274f4071b467e630565ac1e3ae0f2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b09198cf90ccf296970b774beea1c1ddb260f94c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80805","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:07.510","lastModified":"2026-09-04T16:18:07.510","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nxfs: validate attr entry pointer before field access\n\nxfs_attr3_leaf_verify_entry() accesses lentry/rentry fields (namelen,\nvaluelen) before checking if the entry pointer itself is within bounds.\nIf nameidx is crafted to point near the end of the buffer, these field\naccesses can read out-of-bounds before the bounds check at\nname_end > buf_end is performed.\n\nAdd explicit bounds checks for entry pointers before accessing their\nfields. Use offsetof() to check that the start of the flexible array\nmember (nameval/name) is within bounds, which ensures all preceding\nfields are safe to access."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/xfs/libxfs/xfs_attr_leaf.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"c84760659dcf237902d4cc997cd5f55cb3b2807f","lessThan":"0f82586741e39926542f621bafa424e237a04fa4","versionType":"git","status":"affected"},{"version":"c84760659dcf237902d4cc997cd5f55cb3b2807f","lessThan":"134d82a2b5e3eba3ebf58753a1387b22f26ca1de","versionType":"git","status":"affected"},{"version":"c84760659dcf237902d4cc997cd5f55cb3b2807f","lessThan":"03a12253dd2a036545bdb0110a4e0b8dc70f8e7c","versionType":"git","status":"affected"},{"version":"c84760659dcf237902d4cc997cd5f55cb3b2807f","lessThan":"e99120b5944a16d0bc27e52b33de78bcdaaabf5c","versionType":"git","status":"affected"},{"version":"c84760659dcf237902d4cc997cd5f55cb3b2807f","lessThan":"98a42bb9d60d42898c3494de351a1bf508348cde","versionType":"git","status":"affected"},{"version":"c84760659dcf237902d4cc997cd5f55cb3b2807f","lessThan":"184c1a80421a5b5ddcd262e47980ce2e67fee211","versionType":"git","status":"affected"},{"version":"c84760659dcf237902d4cc997cd5f55cb3b2807f","lessThan":"9f92e749fc08b7ff3d9da190c4d1b2273745b282","versionType":"git","status":"affected"},{"version":"c84760659dcf237902d4cc997cd5f55cb3b2807f","lessThan":"c35da2bac6f7cb9a9be73f188b4fcc324615c327","versionType":"git","status":"affected"},{"version":"c84760659dcf237902d4cc997cd5f55cb3b2807f","lessThan":"b7eea80be25f3334f131d52982b3131aba77b97d","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/xfs/libxfs/xfs_attr_leaf.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.5","status":"affected"},{"version":"0","lessThan":"5.5","versionType":"semver","status":"unaffected"},{"version":"5.10.267","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.218","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.185","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.154","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.106","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.47","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.11","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.1","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/03a12253dd2a036545bdb0110a4e0b8dc70f8e7c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/0f82586741e39926542f621bafa424e237a04fa4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/134d82a2b5e3eba3ebf58753a1387b22f26ca1de","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/184c1a80421a5b5ddcd262e47980ce2e67fee211","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/98a42bb9d60d42898c3494de351a1bf508348cde","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9f92e749fc08b7ff3d9da190c4d1b2273745b282","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b7eea80be25f3334f131d52982b3131aba77b97d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c35da2bac6f7cb9a9be73f188b4fcc324615c327","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e99120b5944a16d0bc27e52b33de78bcdaaabf5c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80806","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:07.647","lastModified":"2026-09-04T16:18:07.647","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\next4: don't enable DAX on new encrypted files\n\nCurrently, when a new encrypted regular file is created, the call to\next4_set_inode_flags(inode, init=true) in __ext4_new_inode() is made\nbefore EXT4_INODE_ENCRYPT is set.  As a result, it can set S_DAX if the\nfilesystem is mounted with \"-o dax=always\".\n\nEXT4_INODE_ENCRYPT then actually gets set a bit later in\n__ext4_new_inode(), when it calls fscrypt_set_context() which calls\next4_set_context().  ext4_set_context() sets EXT4_INODE_ENCRYPT and\ncalls ext4_set_inode_flags(inode, init=false) to set S_ENCRYPTED too.\n\nThis was intended to clear S_DAX as well.  However, this was broken by\ncommit 043546e46dc7 (\"fs/ext4: Only change S_DAX on inode load\").  This\ncauses data written to the file to bypass encryption, also causing\nxfstests failures such as generic/548 (when \"-o dax=always\" is used).\n\nFix this by simplifying the flow by making __ext4_new_inode() set\nEXT4_INODE_ENCRYPT earlier.  This makes it take effect in\next4_set_inode_flags(inode, init=true), making S_DAX never be set.\n\nSimilarly, make EXT4_STATE_MAY_INLINE_DATA never be set in the first\nplace on new encrypted inodes.  Then it doesn't need to be cleared.\n\nAs a result of these simplifications, ext4_set_context() no longer needs\nto change inode flags or state when 'handle != NULL'.  Remove that too."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/ext4/crypto.c","fs/ext4/ialloc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"043546e46dc70c25ff7e2cf6d09cbb0424fc9978","lessThan":"add98959b220935b243170214c787bc03044a44d","versionType":"git","status":"affected"},{"version":"043546e46dc70c25ff7e2cf6d09cbb0424fc9978","lessThan":"f53b325068bca0b238c3e0d2eb7de9b1f2268cab","versionType":"git","status":"affected"},{"version":"043546e46dc70c25ff7e2cf6d09cbb0424fc9978","lessThan":"5959cad3cfa852ec07bbdaf9c17f4838a94a8e6c","versionType":"git","status":"affected"},{"version":"043546e46dc70c25ff7e2cf6d09cbb0424fc9978","lessThan":"a13f61ba9b2a7a4ff1f140949ccfad23c5313757","versionType":"git","status":"affected"},{"version":"043546e46dc70c25ff7e2cf6d09cbb0424fc9978","lessThan":"ed1cd834da65db127f1c30ff67e78f14825a06c1","versionType":"git","status":"affected"},{"version":"043546e46dc70c25ff7e2cf6d09cbb0424fc9978","lessThan":"458776af0061afec1014cb3cd0061e282e482e83","versionType":"git","status":"affected"},{"version":"043546e46dc70c25ff7e2cf6d09cbb0424fc9978","lessThan":"3392391b363a63ebb531d45318a729b1c998565b","versionType":"git","status":"affected"},{"version":"043546e46dc70c25ff7e2cf6d09cbb0424fc9978","lessThan":"e27bae352158c007143d5bb50f3af33a177c0a37","versionType":"git","status":"affected"},{"version":"043546e46dc70c25ff7e2cf6d09cbb0424fc9978","lessThan":"da32af420d6d466e247c43ac0b829edeac7ae0ad","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/ext4/crypto.c","fs/ext4/ialloc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.8","status":"affected"},{"version":"0","lessThan":"5.8","versionType":"semver","status":"unaffected"},{"version":"5.10.269","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.220","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.187","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.156","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.108","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.47","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.11","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.1","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3392391b363a63ebb531d45318a729b1c998565b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/458776af0061afec1014cb3cd0061e282e482e83","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5959cad3cfa852ec07bbdaf9c17f4838a94a8e6c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a13f61ba9b2a7a4ff1f140949ccfad23c5313757","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/add98959b220935b243170214c787bc03044a44d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/da32af420d6d466e247c43ac0b829edeac7ae0ad","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e27bae352158c007143d5bb50f3af33a177c0a37","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ed1cd834da65db127f1c30ff67e78f14825a06c1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f53b325068bca0b238c3e0d2eb7de9b1f2268cab","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80807","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:07.810","lastModified":"2026-09-04T16:18:07.810","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: reject invalid block index in GC ioctl\n\nSyzbot reported list corruption caused by a double list_add_tail() call on\nbh->b_assoc_buffers within nilfs_lookup_dirty_data_buffers().\n\nAnalysis revealed that the root cause was the insertion of a page/folio\nwith a page index of ULONG_MAX into the page cache via the GC ioctl.\nfilemap_get_folios_tag(), called by nilfs_lookup_dirty_data_buffers(),\nrepeatedly detects a dirty folio with a page index of ULONG_MAX due to\nindex wrap-around, leading to duplicate processing of dirty buffers.\n\nAs a preparatory step, the GC ioctl loads the page/folio of the block to\nbe moved during GC and inserts it into the page cache based on information\nin the nilfs_vdesc structure passed as an argument.  Normally, this does\nnot cause issues because the user-space GC library configures the\nnilfs_vdesc structure properly.  However, since there is no range check on\nthe parameters determining the page index, a request with artificially\ncrafted parameters -- such as those generated by Syzbot -- can result in a\npage/folio being inserted with a page index of ULONG_MAX, triggering the\nabove problem.\n\nThis resolves the issue by checking the ranges of 'vd_offset' and\n'vd_vblocknr' in the nilfs_vdesc structure that determine the page index,\nthereby preventing the invalid page/folio insertions."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/nilfs2/ioctl.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7942b919f7321f95a777d396ff7894a7a83dc9b0","lessThan":"898404cdf882d7b54f1132f75570984ca3214796","versionType":"git","status":"affected"},{"version":"7942b919f7321f95a777d396ff7894a7a83dc9b0","lessThan":"ba8a8b563a28d358c45c62a306d421434a058648","versionType":"git","status":"affected"},{"version":"7942b919f7321f95a777d396ff7894a7a83dc9b0","lessThan":"3bd064ccc70b85f9a3d53aece29dc8473be5a226","versionType":"git","status":"affected"},{"version":"7942b919f7321f95a777d396ff7894a7a83dc9b0","lessThan":"a5e776e2937581d67ec5b9b4d27b0f70d7baa6b1","versionType":"git","status":"affected"},{"version":"7942b919f7321f95a777d396ff7894a7a83dc9b0","lessThan":"68aa9ab6f8f2895713aa6ddf781463ed8ea5ba44","versionType":"git","status":"affected"},{"version":"7942b919f7321f95a777d396ff7894a7a83dc9b0","lessThan":"e447f7edb99bd00cec63d6f3049e2e5074946f71","versionType":"git","status":"affected"},{"version":"7942b919f7321f95a777d396ff7894a7a83dc9b0","lessThan":"ec6ddf271dfa4c7e3147bc2c8b2bad4315f316a1","versionType":"git","status":"affected"},{"version":"7942b919f7321f95a777d396ff7894a7a83dc9b0","lessThan":"fbcfb75c20d71a5b542ad4ac3b79d10b997c8152","versionType":"git","status":"affected"},{"version":"7942b919f7321f95a777d396ff7894a7a83dc9b0","lessThan":"a1735eae55448bc79c2da6593455791e886f6ed8","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/nilfs2/ioctl.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.30","status":"affected"},{"version":"0","lessThan":"2.6.30","versionType":"semver","status":"unaffected"},{"version":"5.10.269","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.220","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.187","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.156","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.108","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.47","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.11","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.1","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3bd064ccc70b85f9a3d53aece29dc8473be5a226","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/68aa9ab6f8f2895713aa6ddf781463ed8ea5ba44","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/898404cdf882d7b54f1132f75570984ca3214796","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a1735eae55448bc79c2da6593455791e886f6ed8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a5e776e2937581d67ec5b9b4d27b0f70d7baa6b1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ba8a8b563a28d358c45c62a306d421434a058648","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e447f7edb99bd00cec63d6f3049e2e5074946f71","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ec6ddf271dfa4c7e3147bc2c8b2bad4315f316a1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fbcfb75c20d71a5b542ad4ac3b79d10b997c8152","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80808","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:07.993","lastModified":"2026-09-04T16:18:07.993","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\next4: stop retrying saturated xattr cache entries\n\next4_xattr_block_set() retries when a cache entry selected for reuse\nhas a saturated reference count after taking the buffer lock. The retry\nreturns to the mbcache lookup without making that entry ineligible, so\nit can select the same unusable entry indefinitely. A task spinning\nthere can hold the parent directory's i_rwsem and leave concurrent\nrmdir callers blocked.\n\nNormally a reusable entry has a reference count below\nEXT4_XATTR_REFCOUNT_MAX because the count and MBE_REUSABLE_B are\nupdated under the same buffer lock. A corrupted filesystem can violate\nthat invariant. The syzbot reproducer reports allocator and xattr\ncorruption before triggering this retry loop.\n\nCheck the untrusted on-disk count before incrementing it, avoiding\noverflow, and clear MBE_REUSABLE_B when it is already saturated. The\nnext lookup then skips the entry that was just proven unusable. This\nmirrors the normal transition at EXT4_XATTR_REFCOUNT_MAX; the release\npath marks the entry reusable again on the exact 1024-to-1023\ntransition.\n\nUsing the same QEMU harness and guest parameters, current unpatched\nLinux hung in 6 of 8 420-second trials with the do_rmdir signature;\nrepresentative NMI backtraces caught the owner spinning in\next4_xattr_block_set(). The patched kernel completed 28 of 28 trials\nwithout a hung-task report; the final twelve trials exercised the\nreviewed overflow-safe form of the change. syzbot's patch testing also\ncompleted without reproducing the hang."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/ext4/xattr.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1a56cd972ce121b6cf2517a47a578782bbd2ec95","lessThan":"119a2f053242ed75bdd2ebc95baf3ae7db6ccacf","versionType":"git","status":"affected"},{"version":"1be97463696c7291a3e1547614e96432b0bd3add","lessThan":"61631352a5b405c89be579de00903b72e6888aa4","versionType":"git","status":"affected"},{"version":"65f8b80053a1b2fd602daa6814e62d6fa90e5e9b","lessThan":"8865cd664484517703df5c18a965dc3227572b87","versionType":"git","status":"affected"},{"version":"65f8b80053a1b2fd602daa6814e62d6fa90e5e9b","lessThan":"a40c45268f4358207aa9c53764fed2e05f62986a","versionType":"git","status":"affected"},{"version":"65f8b80053a1b2fd602daa6814e62d6fa90e5e9b","lessThan":"889ec86464d261f026f6c334040cfc6c58c99d58","versionType":"git","status":"affected"},{"version":"65f8b80053a1b2fd602daa6814e62d6fa90e5e9b","lessThan":"4902a5cba21aeaf91e6b29e20e0967a5f6abdcd9","versionType":"git","status":"affected"},{"version":"65f8b80053a1b2fd602daa6814e62d6fa90e5e9b","lessThan":"55ee6533c1db7f7656fa8dd19637f3f8b8c08dc5","versionType":"git","status":"affected"},{"version":"65f8b80053a1b2fd602daa6814e62d6fa90e5e9b","lessThan":"dbd4aea175ad3c46436acb251e817b4374628072","versionType":"git","status":"affected"},{"version":"65f8b80053a1b2fd602daa6814e62d6fa90e5e9b","lessThan":"54b6bd40898de7906acb2bccc9a96d1b8e6b4323","versionType":"git","status":"affected"},{"version":"98953044b3cdb2cb7d82e7365b659e2ed4f4ca4d","versionType":"git","status":"affected"},{"version":"af8ecc8d20e72130771cc076bce7fcf17ccda6c4","versionType":"git","status":"affected"},{"version":"c6fac5cf5a5098732623bcd00a8a3eb9f5465144","versionType":"git","status":"affected"},{"version":"96fa141fa295ae9428da73c56c9852053b575c04","versionType":"git","status":"affected"},{"version":"5.10.163","lessThan":"5.10.267","versionType":"semver","status":"affected"},{"version":"5.15.61","lessThan":"5.15.218","versionType":"semver","status":"affected"},{"version":"4.19.270","lessThan":"4.20","versionType":"semver","status":"affected"},{"version":"5.4.229","lessThan":"5.5","versionType":"semver","status":"affected"},{"version":"5.18.18","lessThan":"5.19","versionType":"semver","status":"affected"},{"version":"5.19.2","lessThan":"5.20","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/ext4/xattr.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.0","status":"affected"},{"version":"0","lessThan":"6.0","versionType":"semver","status":"unaffected"},{"version":"5.10.267","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.218","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.185","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.154","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.106","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.47","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.11","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.1","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/119a2f053242ed75bdd2ebc95baf3ae7db6ccacf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4902a5cba21aeaf91e6b29e20e0967a5f6abdcd9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/54b6bd40898de7906acb2bccc9a96d1b8e6b4323","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/55ee6533c1db7f7656fa8dd19637f3f8b8c08dc5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/61631352a5b405c89be579de00903b72e6888aa4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8865cd664484517703df5c18a965dc3227572b87","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/889ec86464d261f026f6c334040cfc6c58c99d58","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a40c45268f4358207aa9c53764fed2e05f62986a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dbd4aea175ad3c46436acb251e817b4374628072","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80809","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:08.190","lastModified":"2026-09-04T16:18:08.190","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: fix missing metadata reservation for large xattrs\n\n[BUG]\nlsetxattr() panics the kernel when setting a large xattr value on a\nfragmented filesystem where the file already has an external xattr\nblock.\n\n[CAUSE]\nocfs2_calc_xattr_set_need() never reserves metadata blocks for a new\nxattr value's extent tree when the file already has an external xattr\nblock. The not_found path leaves meta_add at zero, so meta_ac is NULL\nwhen ocfs2_xattr_extend_allocation() runs.\n\nA new value root has room for a single extent record. On a fragmented\nfilesystem, the allocator cannot satisfy the xattr value in one\ncontiguous run, so each non-contiguous run requires its own extent\nrecord. When the value root's extent list is full and meta_ac is NULL,\nocfs2_add_clusters_in_btree() returns RESTART_META, and\nocfs2_xattr_extend_allocation() hits BUG_ON(why == RESTART_META).\n\n[FIX]\nThe case where no xattr block exists yet already calls\nocfs2_extend_meta_needed(&def_xv.xv.xr_list) to reserve value tree\nmetadata. Add the same reservation to the case where an xattr block\nalready exists, making the two cases consistent.\n\nReplace the BUG_ON with a -ENOSPC return so that if RESTART_META is\nreturned despite the reservation, the error propagates to userspace\ninstead of panicking the kernel."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/ocfs2/xattr.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"a78f9f4668949a6588b8872f162e86685c63d023","lessThan":"743ac908282ac97ef6e73ac3a92df2cc8ecb7479","versionType":"git","status":"affected"},{"version":"a78f9f4668949a6588b8872f162e86685c63d023","lessThan":"04ba24bce61c917b5b3009f0db470cbb72e26a0d","versionType":"git","status":"affected"},{"version":"a78f9f4668949a6588b8872f162e86685c63d023","lessThan":"b4663405ae29d36011cd712d243456f3f9ab700d","versionType":"git","status":"affected"},{"version":"a78f9f4668949a6588b8872f162e86685c63d023","lessThan":"6a009f1e61b11d9e23d3c5aa1dacfb010945da45","versionType":"git","status":"affected"},{"version":"a78f9f4668949a6588b8872f162e86685c63d023","lessThan":"b9eb5c9fdd81d82976d4d5be2b2458eb7d7e46ec","versionType":"git","status":"affected"},{"version":"a78f9f4668949a6588b8872f162e86685c63d023","lessThan":"6176313622e34fa3e2b66b9d0682d1e1c6b365c5","versionType":"git","status":"affected"},{"version":"a78f9f4668949a6588b8872f162e86685c63d023","lessThan":"a3ccb57086dd7652d5ecb826486144198a98a8e9","versionType":"git","status":"affected"},{"version":"a78f9f4668949a6588b8872f162e86685c63d023","lessThan":"50f0cbec45b0f3fd7e1263d01916518dbf31eb3f","versionType":"git","status":"affected"},{"version":"a78f9f4668949a6588b8872f162e86685c63d023","lessThan":"0cdc7dde00ec63ac714271fa8b2918d630b8da1a","versionType":"git","status":"affected"},{"version":"92f61d8a31e270f9391e7bcc0ac638bd4262a8e0","versionType":"git","status":"affected"},{"version":"2.6.34.2","lessThan":"2.6.35","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/ocfs2/xattr.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.35","status":"affected"},{"version":"0","lessThan":"2.6.35","versionType":"semver","status":"unaffected"},{"version":"5.10.267","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.218","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.185","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.154","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.106","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.47","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.11","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.1","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/04ba24bce61c917b5b3009f0db470cbb72e26a0d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/0cdc7dde00ec63ac714271fa8b2918d630b8da1a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/50f0cbec45b0f3fd7e1263d01916518dbf31eb3f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6176313622e34fa3e2b66b9d0682d1e1c6b365c5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6a009f1e61b11d9e23d3c5aa1dacfb010945da45","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/743ac908282ac97ef6e73ac3a92df2cc8ecb7479","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a3ccb57086dd7652d5ecb826486144198a98a8e9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b4663405ae29d36011cd712d243456f3f9ab700d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b9eb5c9fdd81d82976d4d5be2b2458eb7d7e46ec","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80810","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:08.360","lastModified":"2026-09-04T16:18:08.360","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nio_uring/rsrc: fix folio size overflow in io_vec_fill_bvec()\n\nio_vec_fill_bvec() computes the folio size with a plain int 1:\n\n\tunsigned long folio_size = 1 << imu->folio_shift;\n\nimu->folio_shift is unsigned int and comes from folio_shift() of the\nfolio backing the registered buffer, so it can be 32 or more on a 64 bit\nkernel. Shifting int 1 that far is undefined, and on x86 and arm64 the\ncount is taken modulo 32, so a shift of 34 yields 4 rather than 16G.\nEvery other folio_shift shift in this file already uses 1UL.\n\nThe result is that the segment estimate and the fill loop disagree.\nio_estimate_bvec_size() sizes the bvec array with the real shift:\n\n\tmax_segs += (iov[i].iov_len >> shift) + 2;\n\nso a 1M iovec on a 16G folio is charged 2 segments, while\nio_vec_fill_bvec() then walks the same iovec in folio_size chunks of 4\nbytes and writes res_bvec[bvec_idx] a quarter of a million times, past\nthe end of the array it was given. src_bvec is advanced once per\niteration as well, so imu->bvec is read past its end at the same time.\nvalidate_fixed_range() only checks that the range is inside the\nregistered buffer and does not bound the segment count.\n\nReaching it needs a folio with a shift of at least 32, which means a\ngigantic hugetlb page: 16G on arm64 with 64K pages, where\nCONT_PMD_SHIFT is 34 and hugetlb_add_hstate(CONT_PMD_SHIFT - PAGE_SHIFT)\nregisters that size, and likewise on powerpc. x86_64 tops out at 1G, so\na shift of 30, which still fits in int and is unaffected.\n\nUse 1UL, as the rest of the file does."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["io_uring/rsrc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"9ef4cbbcb4ac3786a1a4164507511b76b2a572c5","lessThan":"45c945107e007b1fb73e21cd220277652a45521a","versionType":"git","status":"affected"},{"version":"9ef4cbbcb4ac3786a1a4164507511b76b2a572c5","lessThan":"6b308c37fbeba3aa8c634fb1ed53e2f63a5d5a5c","versionType":"git","status":"affected"},{"version":"9ef4cbbcb4ac3786a1a4164507511b76b2a572c5","lessThan":"3267d7c8ba51642117f7bdd1ece02b2540668476","versionType":"git","status":"affected"},{"version":"9ef4cbbcb4ac3786a1a4164507511b76b2a572c5","lessThan":"3f3a6a16bbe8bde76532d9415438f8cdef439e5d","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["io_uring/rsrc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.15","status":"affected"},{"version":"0","lessThan":"6.15","versionType":"semver","status":"unaffected"},{"version":"6.18.47","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.11","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.1","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3267d7c8ba51642117f7bdd1ece02b2540668476","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3f3a6a16bbe8bde76532d9415438f8cdef439e5d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/45c945107e007b1fb73e21cd220277652a45521a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6b308c37fbeba3aa8c634fb1ed53e2f63a5d5a5c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80811","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:08.497","lastModified":"2026-09-04T16:18:08.497","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nio_uring/cmd: fix iovec leak when the async cmd is not recycled\n\nAn io_async_cmd carries an iovec array in ->vec.iovec, allocated when the\nvec has to grow and kept across recycling through ctx->cmd_cache.  On two\npaths nothing frees it and io_clean_op()'s kfree(req->async_data) drops\nthe io_async_cmd without it.\n\nio_req_uring_cleanup() clears the async data flags only when\nio_alloc_cache_put() succeeds, and the cache holds IO_ALLOC_CACHE_MAX ==\n128 entries, so once it is full the put fails and the vec is left behind.\nAn NVMe passthrough workload gets there without doing anything unusual:\nnvme_uring_cmd_io() returns -EIOCBQUEUED, so the io_async_cmd stays\nattached for the lifetime of the command and the live object count tracks\nthe queue depth.  Above 128 the puts start failing.\n\n->cleanup is the last chance to free an inherited vec, since\nio_req_uring_cleanup() returns early for an io-wq issued command and is\nnot called at all for one completed without ever being issued.  But\nio_clean_op() calls ->cleanup only if REQ_F_NEED_CLEANUP is set, and for\nuring_cmd that happens only where the vec has to grow, so a command\nreusing a large enough cached vec never sets it.  io_rw_alloc_async() and\nio_msg_alloc_async() flag an inherited vec for exactly this reason;\nio_uring_cmd_prep() does not.\n\nFlag an inherited vec in io_uring_cmd_prep(), and free the vec when the\ncache put fails, as io_req_rw_cleanup() does.\n\nThe leak is invisible under KASAN, where io_alloc_cache_vec_kasan() frees\nthe vec unconditionally."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["io_uring/uring_cmd.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3a4689ac109f18f23ea0d0c1c79e055142796858","lessThan":"b6a768aa975b9ca81b92f028bdd975d1f8237894","versionType":"git","status":"affected"},{"version":"3a4689ac109f18f23ea0d0c1c79e055142796858","lessThan":"b290de4d16d75b6c1ef42025b47f5d94eb1ec09f","versionType":"git","status":"affected"},{"version":"3a4689ac109f18f23ea0d0c1c79e055142796858","lessThan":"7068d3587a64a24943a7c9e232976da2c9e0e303","versionType":"git","status":"affected"},{"version":"3a4689ac109f18f23ea0d0c1c79e055142796858","lessThan":"bb34ae5da3365699d53a756f4c96b6ea9f8ba0c1","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["io_uring/uring_cmd.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.15","status":"affected"},{"version":"0","lessThan":"6.15","versionType":"semver","status":"unaffected"},{"version":"6.18.47","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.11","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.1","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/7068d3587a64a24943a7c9e232976da2c9e0e303","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b290de4d16d75b6c1ef42025b47f5d94eb1ec09f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b6a768aa975b9ca81b92f028bdd975d1f8237894","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bb34ae5da3365699d53a756f4c96b6ea9f8ba0c1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80812","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:08.633","lastModified":"2026-09-04T16:18:08.633","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: dummy: Check card index validity at probe\n\nsnd_dummy_probe() blindly trusts that the given devptr->id value is\nwithin the proper card index range.  It's OK for the devices the\ndriver itself creates at the module probe time, but if the device is\nbound manually via sysfs interface, this could be -1 as \"none\", and\nthis leads to OOB access for index[] and other parameters.\n\nAdd a sanity check for the card index and warn/correct it if it's a\nvalue out of the range."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["sound/drivers/dummy.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"b7579e86afcec932e169d10e2d603abed8dd2fdf","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"4d0892a90b57f0e89b274c3f3c51c2fa17937c88","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"b20eb7ecbdaa3e649023fe41b177d90983ffb487","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"c9f10a001c243d1f069ebb0e2f4999ad4043a254","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"f20c2c32ec1c5c3526f29a03b487c55a5890996c","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"3dba0e92e18980cb5a4d70a9a263539ae4f0c7ec","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"690b721b9595f9a43395fd4047a832c42b5b6078","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"02442d5fe8ee365a084b055d4fa81a0c1abfc3fd","versionType":"git","status":"affected"},{"version":"0","lessThan":"5.15.218","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.1.185","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.6.154","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.12.106","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.18.47","versionType":"semver","status":"affected"},{"version":"0","lessThan":"7.1.11","versionType":"semver","status":"affected"},{"version":"0","lessThan":"7.2.1","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["sound/drivers/dummy.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.15.218","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.185","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.154","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.106","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.47","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.11","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.1","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/02442d5fe8ee365a084b055d4fa81a0c1abfc3fd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3dba0e92e18980cb5a4d70a9a263539ae4f0c7ec","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4d0892a90b57f0e89b274c3f3c51c2fa17937c88","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/690b721b9595f9a43395fd4047a832c42b5b6078","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b20eb7ecbdaa3e649023fe41b177d90983ffb487","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b7579e86afcec932e169d10e2d603abed8dd2fdf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c9f10a001c243d1f069ebb0e2f4999ad4043a254","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f20c2c32ec1c5c3526f29a03b487c55a5890996c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80813","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:08.793","lastModified":"2026-09-04T16:18:08.793","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet: fix NULL pointer dereference in nvmet_execute_identify_nslist()\n\nWhen a host issues an Identify command with CNS 07h (Active Namespace ID\nList for a specific I/O Command Set), nvmet_execute_identify_nslist() is\ncalled with match_css set. The command-set filter dereferences req->ns,\nbut this handler never calls nvmet_req_find_ns(), so req->ns is always\nNULL (nvmet_req_init() resets it to NULL). As soon as an enabled\nnamespace with an NSID greater than the requested value exists,\nreq->ns->csi dereferences a NULL pointer and oopses.\n\nBesides the crash, the comparison is logically wrong: to filter the list\nby command set it must test the command set of the namespace being\niterated, not a single fixed value. Use the loop variable ns->csi."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/nvme/target/admin-cmd.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"61c9967cd63448292a64f9ee9aeb6e2053e3a624","lessThan":"61dc1a37e04d4003a19095f54883358330034a39","versionType":"git","status":"affected"},{"version":"61c9967cd63448292a64f9ee9aeb6e2053e3a624","lessThan":"2bc1e33ff6a558c8ceef7c0077f3ef70a15fcba2","versionType":"git","status":"affected"},{"version":"61c9967cd63448292a64f9ee9aeb6e2053e3a624","lessThan":"123d664ac98d6f3464462ad4a530474b91ba9890","versionType":"git","status":"affected"},{"version":"61c9967cd63448292a64f9ee9aeb6e2053e3a624","lessThan":"79aba4c9403419d822972d2851f2a96a2c0531cf","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/nvme/target/admin-cmd.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.13","status":"affected"},{"version":"0","lessThan":"6.13","versionType":"semver","status":"unaffected"},{"version":"6.18.47","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.11","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.1","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/123d664ac98d6f3464462ad4a530474b91ba9890","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2bc1e33ff6a558c8ceef7c0077f3ef70a15fcba2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/61dc1a37e04d4003a19095f54883358330034a39","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/79aba4c9403419d822972d2851f2a96a2c0531cf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80814","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:08.913","lastModified":"2026-09-04T16:18:08.913","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nrndis_host: add overflow check in rndis_rx_fixup()\n\nAdd an overflow check to ensure that data_offset + data_len + 8 does not\nwrap, which would enable an OOB read of the USB data buffer."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/usb/rndis_host.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"2140db1232af04b92faa6c4a2a40df6371ea89ff","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"8ca3bd404d076495ed0b274b65971c57b6fd5ac0","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"f8e6fde5db87f855e99b200e392467274f0eb9d7","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"10a6b99079697c5027b25352e882bdf54fef702a","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"c5398ce6db7647b7004d73a3102ccc25fb4bb596","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"e971d956353d382ee2185d71c47b538501a43f76","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"be7dc3650f799a253df4edd4fe230fc9ea4be063","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"2ded89ca77fae1da6886fe94831acfe4d6aa80b1","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"965a251f23ff69cfb4486974d4532e9bb551c7fc","versionType":"git","status":"affected"},{"version":"0","lessThan":"5.10.267","versionType":"semver","status":"affected"},{"version":"0","lessThan":"5.15.218","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.1.185","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.6.154","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.12.106","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.18.47","versionType":"semver","status":"affected"},{"version":"0","lessThan":"7.1.11","versionType":"semver","status":"affected"},{"version":"0","lessThan":"7.2.1","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/usb/rndis_host.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.10.267","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.218","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.185","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.154","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.106","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.47","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.11","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.1","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/10a6b99079697c5027b25352e882bdf54fef702a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2140db1232af04b92faa6c4a2a40df6371ea89ff","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2ded89ca77fae1da6886fe94831acfe4d6aa80b1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8ca3bd404d076495ed0b274b65971c57b6fd5ac0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/965a251f23ff69cfb4486974d4532e9bb551c7fc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/be7dc3650f799a253df4edd4fe230fc9ea4be063","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c5398ce6db7647b7004d73a3102ccc25fb4bb596","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e971d956353d382ee2185d71c47b538501a43f76","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f8e6fde5db87f855e99b200e392467274f0eb9d7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80815","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:09.057","lastModified":"2026-09-04T16:18:09.057","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: scarlett2: Use a private URB for the notification endpoint\n\nscarlett2_init_notify() used mixer->urb, which\nsnd_usb_mixer_status_create() allocates for the UAC2 status interrupt\nendpoint and mixer.c manages. On a device with that endpoint, the\n\"already in use\" check fires on the status URB and returns 0 for\nsuccess without doing anything. No notification URB is submitted, and\ncmd_done is left zeroed because it is initialised past that check and\nnowhere else. scarlett2_usb_init() then issues SCARLETT2_USB_INIT_1\nand wait_for_completion_timeout() would crash adding to the zeroed\nwait.head.\n\nUse a separate URB in scarlett2_data, as done for FCP, and initialise\ncmd_done in scarlett2_init_private(). mixer.c was also freeing the URB\nin snd_usb_mixer_free() and resubmitting it in\nsnd_usb_mixer_activate(), so scarlett2 must now do both: add\nscarlett2_cleanup_urb(), called from private_free and private_suspend,\nand a private_resume callback to re-establish the URB after resume.\nscarlett2_init_notify() is reached from there, and the URB kill path\nin scarlett2_notify() completes cmd_done, leaving a stale count that\nwould satisfy the next command's wait before the device ACKs. Use\nreinit_completion() to clear it.\n\nAlso free the URB if the transfer buffer allocation fails, and both if\nusb_submit_urb() fails. Move scarlett2_init_notify() up next to\nscarlett2_cleanup_urb() so scarlett2_init_private() can reference it\nwithout a forward declaration."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["sound/usb/mixer.c","sound/usb/mixer.h","sound/usb/mixer_scarlett2.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1b65088958cadab04d5d34a8615e2466b1b48ecb","lessThan":"013448eb7b0d0b91d6168685dab10e9b41baa825","versionType":"git","status":"affected"},{"version":"1b65088958cadab04d5d34a8615e2466b1b48ecb","lessThan":"4305e4b52acc0ca67dcfdf8f73dd943dab508ae8","versionType":"git","status":"affected"},{"version":"1b65088958cadab04d5d34a8615e2466b1b48ecb","lessThan":"04df0232a6976845cd9c9e83b6c26215759be667","versionType":"git","status":"affected"},{"version":"1b65088958cadab04d5d34a8615e2466b1b48ecb","lessThan":"ecd2f83a4ddc078901e7104144cb6c5e5db3b7cf","versionType":"git","status":"affected"},{"version":"1b65088958cadab04d5d34a8615e2466b1b48ecb","lessThan":"cd17d6ff7b7d2b1dd9bcc80ae7b4a83773f918c6","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["sound/usb/mixer.c","sound/usb/mixer.h","sound/usb/mixer_scarlett2.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.10","status":"affected"},{"version":"0","lessThan":"6.10","versionType":"semver","status":"unaffected"},{"version":"6.12.106","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.47","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.11","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.1","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/013448eb7b0d0b91d6168685dab10e9b41baa825","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/04df0232a6976845cd9c9e83b6c26215759be667","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4305e4b52acc0ca67dcfdf8f73dd943dab508ae8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cd17d6ff7b7d2b1dd9bcc80ae7b4a83773f918c6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ecd2f83a4ddc078901e7104144cb6c5e5db3b7cf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80816","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:09.190","lastModified":"2026-09-04T16:18:09.190","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: FCP: Use a private URB for the notification endpoint\n\nfcp_init_notify() used mixer->urb, which snd_usb_mixer_status_create()\nallocates for the optional UAC2 status interrupt endpoint and mixer.c\nkills, resubmits and frees. On a device with that endpoint,\nfcp_init_notify()'s \"already set up\" early return fires on the status\nURB and returns success without doing anything. No FCP notification\nURB is submitted, and cmd_done is left zeroed because it is\ninitialised past that early return and nowhere else. fcp_init() then\nissues init1_opcode and wait_for_completion_timeout() would crash\nadding to the zeroed wait.head. fcp_cleanup_urb() would also kill and\nfree mixer.c's status URB.\n\nUse a separate URB in fcp_data, and initialise cmd_done in\nfcp_init_private() where fcp_data is allocated. fcp_init_notify() is\nreached again after suspend via fcp_reinit(), and the URB kill path in\nfcp_notify() completes cmd_done, leaving a stale count that would\nsatisfy the next command's wait before the device ACKs. Use\nreinit_completion() to clear it."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["sound/usb/fcp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"46757a3e7d50dac923888e7fbe68377736f13c70","lessThan":"65aceb45ca91ddb7f7ed178821f481b34da35543","versionType":"git","status":"affected"},{"version":"46757a3e7d50dac923888e7fbe68377736f13c70","lessThan":"5da21a434171e8ecf1d992c6f1d84c0c706fd395","versionType":"git","status":"affected"},{"version":"46757a3e7d50dac923888e7fbe68377736f13c70","lessThan":"6db3c1d7e2872c9904e05ca8e0515920776a3c9c","versionType":"git","status":"affected"},{"version":"46757a3e7d50dac923888e7fbe68377736f13c70","lessThan":"918b8d231c571c50a00efe92ffc8404a537a0490","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["sound/usb/fcp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.14","status":"affected"},{"version":"0","lessThan":"6.14","versionType":"semver","status":"unaffected"},{"version":"6.18.47","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.11","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.1","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/5da21a434171e8ecf1d992c6f1d84c0c706fd395","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/65aceb45ca91ddb7f7ed178821f481b34da35543","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6db3c1d7e2872c9904e05ca8e0515920776a3c9c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/918b8d231c571c50a00efe92ffc8404a537a0490","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80817","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:09.303","lastModified":"2026-09-04T16:18:09.303","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\niommu/iommufd: Fix NULL pointer deref in iommufd_ioas_change_process when racing with iopt_map_file_pages\n\niommufd_ioas_change_process() iterates every IOAS area while only\nholding every IOAS iova_rwsem, so it assumes every area has a non-NULL\npages pointer. That assumption can be false when it runs concurrently\nwith iopt_map_file_pages().\n\niopt_map_pages() executes in two phases. It first creates the area and\ninserts it into the interval tree under iova_rwsem, with area->pages\nstill NULL. It then drops iova_rwsem and later fills area->pages\nunder domains_rwsem. This leaves a window between area creation and\narea->pages fill where a concurrent iommufd_ioas_change_process()\ncan observe the area and dereference a NULL area->pages pointer,\nleading to a NULL pointer dereference:\n\nBUG: kernel NULL pointer dereference, address: 00000000000000c0\n#PF: supervisor read access in kernel mode\n#PF: error_code(0x0000) - not-present page\nPGD 4b655067 P4D 4b655067 PUD 0\nOops: Oops: 0000 [#1] SMP NOPTI\nCPU: 0 UID: 0 PID: 11841 Comm: syz.1.628 Not tainted 7.1.0 #3 PREEMPT(full)\nHardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_caps fix, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014\nRIP: 0010:iommufd_ioas_change_process+0x419/0xd50 drivers/iommu/iommufd/ioas.c:538\nCode: 48 89 c3 48 85 c0 0f 84 cc 00 00 00 e8 10 f5 cb fd 48 8d 7b 68 e8 a7 b5 eb fd 48 8b 6b 68 48 8d bd c0 00 00 00 e8 17 b2 eb fd <8b> ad c0 00 00 00 bf 01 00 00 00 89 ee e8 85 ef cb fd 83 fd 01 74\nRSP: 0018:ffffc90015c17d28 EFLAGS: 00010246\nRAX: ffff8880186d5328 RBX: ffff88801d25e240 RCX: 0000000080000000\nRDX: 00000000000002d7 RSI: ffffffff83ba9e10 RDI: 00000000000000c0\nRBP: 0000000000000000 R08: ffffffff8e781eb8 R09: 0000000000000000\nR10: 00000000000000c0 R11: ffffffff83ba9e29 R12: ffff88802e216008\nR13: ffff88802e216000 R14: 0000000000000001 R15: 0000000000000000\nFS:  00007f4aea3f66c0(0000) GS:ffff8880b1fa1000(0000) knlGS:0000000000000000\nCS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00000000000000c0 CR3: 000000004b75c000 CR4: 0000000000350ef0\nCall Trace:\n <TASK>\n iommufd_fops_ioctl+0x287/0x400 drivers/iommu/iommufd/main.c:533\n vfs_ioctl fs/ioctl.c:51 [inline]\n __do_sys_ioctl fs/ioctl.c:597 [inline]\n __se_sys_ioctl fs/ioctl.c:583 [inline]\n __x64_sys_ioctl+0x120/0x170 fs/ioctl.c:583\n x64_sys_call+0x1092/0x1fb0 arch/x86/include/generated/asm/syscalls_64.h:17\n do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]\n do_syscall_64+0x10a/0x680 arch/x86/entry/syscall_64.c:94\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\nRIP: 0033:0x7f4aec1a82bd\nCode: ff c3 66 2e 0f 1f 84 00 00 00 00 00 90 f3 0f 1e fa 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b0 ff ff ff f7 d8 64 89 01 48\nRSP: 002b:00007f4aea3f6018 EFLAGS: 00000246 ORIG_RAX: 0000000000000010\nRAX: ffffffffffffffda RBX: 00007f4aec436090 RCX: 00007f4aec1a82bd\nRDX: 0000200000000180 RSI: 0000000000003b92 RDI: 0000000000000003\nRBP: 00007f4aec250295 R08: 0000000000000000 R09: 0000000000000000\nR10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000\nR13: 00007f4aec436128 R14: 00007f4aec436090 R15: 00007ffd04ef23e0\n </TASK>\nModules linked in:\nCR2: 00000000000000c0\n---[ end trace 0000000000000000 ]---\nRIP: 0010:iommufd_ioas_change_process+0x419/0xd50 drivers/iommu/iommufd/ioas.c:538\nCode: 48 89 c3 48 85 c0 0f 84 cc 00 00 00 e8 10 f5 cb fd 48 8d 7b 68 e8 a7 b5 eb fd 48 8b 6b 68 48 8d bd c0 00 00 00 e8 17 b2 eb fd <8b> ad c0 00 00 00 bf 01 00 00 00 89 ee e8 85 ef cb fd 83 fd 01 74\nRSP: 0018:ffffc90015c17d28 EFLAGS: 00010246\nRAX: ffff8880186d5328 RBX: ffff88801d25e240 RCX: 0000000080000000\nRDX: 00000000000002d7 RSI: ffffffff83ba9e10 RDI: 00000000000000c0\nRBP: 0000000000000000 R08: ffffffff8e781eb8 R09: 0000000000000000\nR10: 00000000000000c0 R11: ffffffff83ba9e29 R12: ffff88802e216008\nR13: ffff88802e216000 R14: 0000000000000001 R15: 0000000000000000\nFS:  00007f4aea3f66c0(000\n---truncated---"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/iommu/iommufd/ioas.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"829ed626499c11c9d11c65e93febc1e0da7cd61b","lessThan":"7596354148c5aa12dfaa17992d1aef1aa2ea831a","versionType":"git","status":"affected"},{"version":"829ed626499c11c9d11c65e93febc1e0da7cd61b","lessThan":"d9635e2507dc8260b9ba9992a4198e84f9340a15","versionType":"git","status":"affected"},{"version":"829ed626499c11c9d11c65e93febc1e0da7cd61b","lessThan":"ffe6d379be20df013e19a4c63dd80bc6b683106d","versionType":"git","status":"affected"},{"version":"829ed626499c11c9d11c65e93febc1e0da7cd61b","lessThan":"d616de490ec0242dcf78f02f1adf7baa035c4d0d","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/iommu/iommufd/ioas.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.13","status":"affected"},{"version":"0","lessThan":"6.13","versionType":"semver","status":"unaffected"},{"version":"6.18.47","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.11","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.1","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/7596354148c5aa12dfaa17992d1aef1aa2ea831a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d616de490ec0242dcf78f02f1adf7baa035c4d0d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d9635e2507dc8260b9ba9992a4198e84f9340a15","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ffe6d379be20df013e19a4c63dd80bc6b683106d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80818","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:09.453","lastModified":"2026-09-04T16:18:09.453","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\niommu/tegra241-cmdqv: Fix CMD_SYNC use-after-free on teardown\n\narm_smmu_impl_remove() is registered as a devres action in\narm_smmu_impl_probe(), before arm_smmu_init_queues() allocates\nsmmu->cmdq.q.base. On a devres unwind, whether a failed probe or an\nunbind, the queue is freed first and arm_smmu_impl_remove() then runs\ntegra241_cmdqv_remove_vintf(), whose VINTF deinit issues a CMD_SYNC on\nthe freed memory.\n\nObserved during testing with a QEMU hack that makes the VCMDQ fail to\nenable, so the impl reset fails and probe aborts into the devres unwind:\n\n platform NVDA200C:00: tegra241_cmdqv: VINTF0: VCMDQ0/LVCMDQ0: failed to enable, STATUS=0x00000000\n platform NVDA200C:00: tegra241_cmdqv: VINTF0: VCMDQ0/LVCMDQ0: GERRORN=0x0, GERROR=0x4, CONS=0x0\n platform NVDA200C:00: tegra241_cmdqv: VINTF0: VCMDQ0/LVCMDQ0: uncleared error detected, resetting\n arm-smmu-v3 arm-smmu-v3.0.auto: failed to reset impl\n arm-smmu-v3 arm-smmu-v3.0.auto: probe with driver arm-smmu-v3 failed with error -110\n Unable to handle kernel paging request at virtual address ffff8000891e0098\n ...\n Internal error: Oops: 0000000096000047 [#1] SMP\n ...\n Call trace:\n  arm_smmu_cmdq_issue_cmdlist+0x320/0x6fc (P)\n  tegra241_vcmdq_hw_deinit+0x98/0x168\n  tegra241_vintf_hw_deinit+0x5c/0x1b0\n  tegra241_cmdqv_remove_vintf+0x34/0xec\n  tegra241_cmdqv_remove+0x40/0x9c\n  arm_smmu_impl_remove+0x20/0x30\n  devm_action_release+0x14/0x20\n  devres_release_all+0xa8/0x110\n  device_unbind_cleanup+0x18/0x84\n  really_probe+0x1f0/0x29c\n\nDrop the VINTF deinit from tegra241_cmdqv_remove_vintf() so the unwind no\nlonger touches the freed queue. Quiesce the VINTFs earlier instead. Add a\ndevice_disable() impl op and run it from arm_smmu_disable_action() while\nthe CMDQ is still up. That handles a live unbind. A failed reset is already\nhandled because tegra241_vintf_hw_init() deinits the VINTF on its own error\npath. tegra241_cmdqv_remove_vintf() is also used by the iommufd viommu\ndestroy path, so quiesce there too."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3.c","drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3.h","drivers/iommu/arm/arm-smmu-v3/tegra241-cmdqv.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4dc0d12474f9d4833c3dd96b73d61e406d3f5dc7","lessThan":"d2ab08437e913d9e4dda4dfd0d327446ec8717fc","versionType":"git","status":"affected"},{"version":"4dc0d12474f9d4833c3dd96b73d61e406d3f5dc7","lessThan":"a94309bb99eaf0c6a2ace4927864486d19458eb5","versionType":"git","status":"affected"},{"version":"4dc0d12474f9d4833c3dd96b73d61e406d3f5dc7","lessThan":"5994617e09ee6016c1b094f29d9c85cac944b477","versionType":"git","status":"affected"},{"version":"4dc0d12474f9d4833c3dd96b73d61e406d3f5dc7","lessThan":"9ff145a25c5c8a26b06ef7cf558fb536b18bba6d","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3.c","drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3.h","drivers/iommu/arm/arm-smmu-v3/tegra241-cmdqv.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.17","status":"affected"},{"version":"0","lessThan":"6.17","versionType":"semver","status":"unaffected"},{"version":"6.18.47","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.11","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.1","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/5994617e09ee6016c1b094f29d9c85cac944b477","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9ff145a25c5c8a26b06ef7cf558fb536b18bba6d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a94309bb99eaf0c6a2ace4927864486d19458eb5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d2ab08437e913d9e4dda4dfd0d327446ec8717fc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80819","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:09.583","lastModified":"2026-09-04T16:18:09.583","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: RFCOMM: take rfcomm_mutex for the deferred setup accept\n\nrfcomm_sock_recvmsg() completes a deferred setup by calling\nrfcomm_dlc_accept() without holding any RFCOMM lock:\n\n\tif (test_and_clear_bit(RFCOMM_DEFER_SETUP, &d->flags)) {\n\t\trfcomm_dlc_accept(d);\n\t\treturn 0;\n\t}\n\nand rfcomm_dlc_accept() dereferences the session on its first line:\n\n\tstruct sock *sk = d->session->sock->sk;\n\nEvery other path that touches d->session runs under rfcomm_mutex:\nrfcomm_dlc_open(), rfcomm_dlc_close(), rfcomm_dlc_exists(),\nrfcomm_dlc_send_rpn(), and the RFCOMM thread through\nrfcomm_process_sessions(). rfcomm_connect_ind() is even documented as\n\"called under rfcomm_lock()\". This call site is the only one that skips\nit.\n\nThe RFCOMM_DEFER_SETUP bit looks like it serialises the accept against\nteardown, since __rfcomm_dlc_close() returns early when it wins the\ntest_and_clear. But rfcomm_recv_disc() forces the state first:\n\n\td->state = BT_CLOSED;\n\t__rfcomm_dlc_close(d, err);\n\nand the early return only covers BT_CONNECT, BT_CONFIG, BT_OPEN and\nBT_CONNECT2. With the state already BT_CLOSED that switch does not\nmatch, the bit is never consulted, and __rfcomm_dlc_close() falls\nthrough to rfcomm_dlc_unlink(), which sets d->session = NULL.\n\nSo a remote DISC on a deferred dlc clears the session while leaving\nRFCOMM_DEFER_SETUP set. The next recvmsg() then passes the\ntest_and_clear and dereferences a NULL session. No timing window is\nneeded: once the DISC has been processed, the dereference is\nunconditional.\n\nGive rfcomm_dlc_accept() the same shape as rfcomm_dlc_open() and\nrfcomm_dlc_close(): an exported wrapper that takes rfcomm_mutex and\nre-checks the session, around a __rfcomm_dlc_accept() that the two\nin-core callers, which already hold the mutex, keep using.\n\nReproduced on a KASAN + PROVE_LOCKING kernel with a BR/EDR peer emulated\nover /dev/vhci: the peer brings up an ACL link, opens L2CAP on the\nRFCOMM PSM, starts a session, opens a dlc on a channel bound with\nBT_DEFER_SETUP, and sends DISC after the socket is accepted. recv() on\nthe accepted socket then hits:\n\n  Oops: general protection fault\n  KASAN: null-ptr-deref in range [0x0000000000000010-0x0000000000000017]\n  RIP: 0010:rfcomm_dlc_accept+0x54/0x350\n  Call Trace:\n    rfcomm_sock_recvmsg+0x1cd/0x230\n    sock_recvmsg+0x166/0x1c0\n    __sys_recvfrom+0x20d/0x300\n\n0x10 is the offset of sock in struct rfcomm_session. With this patch the\nsame run completes with recv() returning 0 and no report, and lockdep\nstays quiet, confirming rfcomm_mutex is still taken before lock_sock on\nthis path as it is on the thread side."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/bluetooth/rfcomm/core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"bb23c0ab824653be4aa7dfca15b07b3059717004","lessThan":"d8d686dd5662a7c4745e4515f1237a9f3b7df181","versionType":"git","status":"affected"},{"version":"bb23c0ab824653be4aa7dfca15b07b3059717004","lessThan":"eb71d5a1ea8ff2683e394b48ae3cd676037ab4c2","versionType":"git","status":"affected"},{"version":"bb23c0ab824653be4aa7dfca15b07b3059717004","lessThan":"56f0aa75c7640e46397ef73bea251fcbef9150c0","versionType":"git","status":"affected"},{"version":"bb23c0ab824653be4aa7dfca15b07b3059717004","lessThan":"362726c9c6e56eea4262109183e49868c39ccd3a","versionType":"git","status":"affected"},{"version":"bb23c0ab824653be4aa7dfca15b07b3059717004","lessThan":"825b95561d7b7c393df9e7bc295451aaeadc3d18","versionType":"git","status":"affected"},{"version":"bb23c0ab824653be4aa7dfca15b07b3059717004","lessThan":"d4b1a13b1eff2e80925c7368ffdeaaa50cba93df","versionType":"git","status":"affected"},{"version":"bb23c0ab824653be4aa7dfca15b07b3059717004","lessThan":"355bfd57ca4ca881c6eb03ca813b440a094b1f44","versionType":"git","status":"affected"},{"version":"bb23c0ab824653be4aa7dfca15b07b3059717004","lessThan":"b405c2f96ae2e37375105881890f7738833b1d62","versionType":"git","status":"affected"},{"version":"bb23c0ab824653be4aa7dfca15b07b3059717004","lessThan":"43a556b2fd43f2df6dded59c2e26560a27874c24","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/bluetooth/rfcomm/core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.30","status":"affected"},{"version":"0","lessThan":"2.6.30","versionType":"semver","status":"unaffected"},{"version":"5.10.267","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.218","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.185","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.154","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.106","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.47","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.11","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.1","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/355bfd57ca4ca881c6eb03ca813b440a094b1f44","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/362726c9c6e56eea4262109183e49868c39ccd3a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/43a556b2fd43f2df6dded59c2e26560a27874c24","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/56f0aa75c7640e46397ef73bea251fcbef9150c0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/825b95561d7b7c393df9e7bc295451aaeadc3d18","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b405c2f96ae2e37375105881890f7738833b1d62","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d4b1a13b1eff2e80925c7368ffdeaaa50cba93df","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d8d686dd5662a7c4745e4515f1237a9f3b7df181","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/eb71d5a1ea8ff2683e394b48ae3cd676037ab4c2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80820","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:09.743","lastModified":"2026-09-04T16:18:09.743","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nxfs: don't livelock in scrub on a circular unlinked list\n\nLOLLM points out that online fsck can livelock if an unlinked inode list\ncontains a loop.  Use a bitmap to detect cycles."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/xfs/scrub/agheader.c","fs/xfs/scrub/agheader_repair.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"a12890aebb895951720ff884eab1c99a30645b29","lessThan":"599453f83458b57995290a1d31200c263e2c2691","versionType":"git","status":"affected"},{"version":"a12890aebb895951720ff884eab1c99a30645b29","lessThan":"159d162fe80bd56573cafde5801bd5a90a3dd1ac","versionType":"git","status":"affected"},{"version":"a12890aebb895951720ff884eab1c99a30645b29","lessThan":"56407a61a8bb85b884de802d39635abdb0ea7408","versionType":"git","status":"affected"},{"version":"a12890aebb895951720ff884eab1c99a30645b29","lessThan":"527eaaefddb6ec5c83a06c9a1559960dd6361753","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/xfs/scrub/agheader.c","fs/xfs/scrub/agheader_repair.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.15","status":"affected"},{"version":"0","lessThan":"4.15","versionType":"semver","status":"unaffected"},{"version":"6.12.106","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.47","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.11","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/159d162fe80bd56573cafde5801bd5a90a3dd1ac","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/527eaaefddb6ec5c83a06c9a1559960dd6361753","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/56407a61a8bb85b884de802d39635abdb0ea7408","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/599453f83458b57995290a1d31200c263e2c2691","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80821","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:09.857","lastModified":"2026-09-04T16:18:09.857","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet: pci-epf: put CQ ref on create_cq mapping failure\n\nnvmet_pci_epf_create_cq() calls nvmet_cq_create(), which takes a\nreference on the controller and installs the completion queue. If the\nsubsequent PCI address-space mapping fails or returns a too-small partial\nmapping, the function jumps to err_internal / err_unmap_queue without\ncalling nvmet_cq_put(). The matching put in nvmet_pci_epf_delete_cq() is\ngated on NVMET_PCI_EPF_Q_LIVE, which is only set after the mapping\nsucceeds, so teardown never releases these references. A remote PCI host\nthat drives Create IO CQ commands with a failing PRP1/pci_addr therefore\nleaks the CQ and a controller reference on each attempt.\n\nDrop the CQ reference on the mapping-failure paths. The err_internal and\nerr_unmap_queue labels are only reachable after nvmet_cq_create() has\nsucceeded, so this pairs the create/put correctly."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/nvme/target/pci-epf.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"0faa0fe6f90ea59b10d1b0f15ce0eb0c18eff186","lessThan":"f31650243c1ab32394077f234685e89ed8dece84","versionType":"git","status":"affected"},{"version":"0faa0fe6f90ea59b10d1b0f15ce0eb0c18eff186","lessThan":"b5f97fae2503a763fa0f953abf5f121b0fef7d0d","versionType":"git","status":"affected"},{"version":"0faa0fe6f90ea59b10d1b0f15ce0eb0c18eff186","lessThan":"56a7b6a6880dbabe28214ff88df8d229ca3a944a","versionType":"git","status":"affected"},{"version":"0faa0fe6f90ea59b10d1b0f15ce0eb0c18eff186","lessThan":"659ae9d02cb5d72c76f74fff7441eb8fb64d8f5c","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/nvme/target/pci-epf.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.14","status":"affected"},{"version":"0","lessThan":"6.14","versionType":"semver","status":"unaffected"},{"version":"6.18.47","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.11","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.1","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/56a7b6a6880dbabe28214ff88df8d229ca3a944a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/659ae9d02cb5d72c76f74fff7441eb8fb64d8f5c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b5f97fae2503a763fa0f953abf5f121b0fef7d0d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f31650243c1ab32394077f234685e89ed8dece84","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80822","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:09.970","lastModified":"2026-09-04T16:18:09.970","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmailbox: mchp-ipc-sbi: Add null check for devm_kasprintf()\n\nAdd a check to see if devm_kasprintf() is not NULL in\nmchp_ipc_get_cluster_aggr_irq(), returning -ENOMEM if the function\nfailed."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/mailbox/mailbox-mchp-ipc-sbi.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"364edaedf4125825781a12c84c77699780d52a16","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"df5c9816986b2f4d754ef3aa65a92382e9b39c4a","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"b233e7836d98d1790e71f5f3734a86409664f341","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"b37c4d0a2fd90c0c31223acd37f763eb8953ed1a","versionType":"git","status":"affected"},{"version":"0","lessThan":"6.18.47","versionType":"semver","status":"affected"},{"version":"0","lessThan":"7.1.11","versionType":"semver","status":"affected"},{"version":"0","lessThan":"7.2.1","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/mailbox/mailbox-mchp-ipc-sbi.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.18.47","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.11","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.1","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/364edaedf4125825781a12c84c77699780d52a16","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b233e7836d98d1790e71f5f3734a86409664f341","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b37c4d0a2fd90c0c31223acd37f763eb8953ed1a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/df5c9816986b2f4d754ef3aa65a92382e9b39c4a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80823","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:10.080","lastModified":"2026-09-04T16:18:10.080","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: st21nfca: validate ATR_REQ length against the received frame\n\nst21nfca_tm_recv_atr_req() checks that the received ATR_REQ frame is at\nleast ST21NFCA_ATR_REQ_MIN_SIZE and that the self-declared atr_req->length\nis at least sizeof(struct st21nfca_atr_req), but never checks that\natr_req->length does not exceed the actual received length (skb->len).\n\nst21nfca_tm_send_atr_res() then trusts the declared length:\n\n\tgb_len = atr_req->length - sizeof(struct st21nfca_atr_req);\n\t...\n\tmemcpy(atr_res->gbi, atr_req->gbi, gb_len);\n\nso an RF peer that sends a short frame but sets atr_req->length larger\nthan the frame makes gb_len exceed the general bytes actually present,\nand the memcpy reads out of bounds past the received skb. Those bytes are\nplaced in the ATR_RES and sent back to the peer (kernel-memory disclosure\nto a proximity attacker); a larger declared length is an out-of-bounds\nread (DoS).\n\nReject frames whose declared length exceeds the received length. The\nadjacent nfc_tm_activated() path in the same function already derives its\ngeneral-bytes length from skb->len rather than the declared field.\n\nFound by 0sec (https://0sec.ai) using automated source analysis; the\nmissing bound is evident from source. Compile-tested."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/nfc/st21nfca/dep.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1892bf844ea0261736bd5e75546fc996e9daeedf","lessThan":"785df00bb3ae3206674a43284eb06dac575b5c64","versionType":"git","status":"affected"},{"version":"1892bf844ea0261736bd5e75546fc996e9daeedf","lessThan":"2c1ad291f4cdc357f9527b688c6fda9c6ffa7890","versionType":"git","status":"affected"},{"version":"1892bf844ea0261736bd5e75546fc996e9daeedf","lessThan":"dd26d30f40c43ad9cfe2f25c6ea0ead1dd51d5aa","versionType":"git","status":"affected"},{"version":"1892bf844ea0261736bd5e75546fc996e9daeedf","lessThan":"9635507fe82949e429b3cd938876a9917125b151","versionType":"git","status":"affected"},{"version":"1892bf844ea0261736bd5e75546fc996e9daeedf","lessThan":"0f344944c506b4f02d2b098489f7268b438c369e","versionType":"git","status":"affected"},{"version":"1892bf844ea0261736bd5e75546fc996e9daeedf","lessThan":"bfcca5f42c9aa4eadef1e5fe7bb23783d7fcc96d","versionType":"git","status":"affected"},{"version":"1892bf844ea0261736bd5e75546fc996e9daeedf","lessThan":"304f5b414f4051d324b8c4a3ab0e79f7dc7e150e","versionType":"git","status":"affected"},{"version":"1892bf844ea0261736bd5e75546fc996e9daeedf","lessThan":"f33cecf69095c43be88567fef92b180b858f7369","versionType":"git","status":"affected"},{"version":"1892bf844ea0261736bd5e75546fc996e9daeedf","lessThan":"5cdcca5d62a66eda6b774110a44cba67bc1a8d1d","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/nfc/st21nfca/dep.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.17","status":"affected"},{"version":"0","lessThan":"3.17","versionType":"semver","status":"unaffected"},{"version":"5.10.267","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.218","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.185","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.154","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.106","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.47","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.11","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.1","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0f344944c506b4f02d2b098489f7268b438c369e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2c1ad291f4cdc357f9527b688c6fda9c6ffa7890","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/304f5b414f4051d324b8c4a3ab0e79f7dc7e150e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5cdcca5d62a66eda6b774110a44cba67bc1a8d1d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/785df00bb3ae3206674a43284eb06dac575b5c64","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9635507fe82949e429b3cd938876a9917125b151","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bfcca5f42c9aa4eadef1e5fe7bb23783d7fcc96d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dd26d30f40c43ad9cfe2f25c6ea0ead1dd51d5aa","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f33cecf69095c43be88567fef92b180b858f7369","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80824","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:10.233","lastModified":"2026-09-04T16:18:10.233","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: usbfs: fix use-after-free of usb_device in usbdev_release()\n\nusbdev_release() drops its reference to the struct usb_device before\ndraining the list of completed async URBs, but that drain path reads back\nthrough the same object: free_async() calls dec_usb_memory_use_count()\nfor any URB whose buffer came from the usbfs mmap() region, and its first\nstatement is bus_to_hcd(ps->dev->bus).\n\nAfter a disconnect the usbfs reference can be the last one, in which case\nusb_put_dev() frees the device and the subsequent loop reads offset 80 of\nfreed memory and uses the result as a struct usb_hcd *, which\nhcd_buffer_free_pages() then dereferences.\n\nThis is reachable by an unprivileged process that has read/write access to\na /dev/bus/usb node: mmap() the fd, submit one URB with a buffer inside the\nmapping, wait for the device to be unplugged, then munmap() and close().\nIt reproduces on every attempt rather than being a race, because a live\nMAP_SHARED vma holds a reference on the struct file, so usbdev_release()\ncannot run until the last vma is gone and the freeing branch of\ndec_usb_memory_use_count() is always taken.\n\n  BUG: KASAN: slab-use-after-free in dec_usb_memory_use_count+0x3ae/0x410\n  Read of size 8 at addr ffff8880122ee050 by task poc/769\n  CPU: 1 UID: 1000 PID: 769 Comm: poc Tainted: G    B    6.12.94 #3\n\n  Call Trace:\n   dec_usb_memory_use_count+0x3ae/0x410\n   free_async+0x2aa/0x4f0\n   usbdev_release+0x375/0x460\n   __fput+0x3ea/0xb50\n   __x64_sys_close+0x86/0x100\n\n  Allocated by task 11:\n   usb_alloc_dev+0x55/0xd90\n   hub_event+0x2524/0x43d0\n\n  Freed by task 769:\n   kfree+0x121/0x360\n   device_release+0xd2/0x280\n   usb_put_dev+0x23/0x30\n   usbdev_release+0x2d8/0x460\n\nRelease the device reference after the drain loop instead. Nothing between\nthe two points requires it to have been dropped."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/usb/core/devio.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"f7d34b445abc00e979b7cf36b9580ac3d1a47cd8","lessThan":"0a960b88c5979f853019d4dc4957dfbeeb193440","versionType":"git","status":"affected"},{"version":"f7d34b445abc00e979b7cf36b9580ac3d1a47cd8","lessThan":"96f5520fc9a5e4bbf77ac93c9d5ce502f597e6cf","versionType":"git","status":"affected"},{"version":"f7d34b445abc00e979b7cf36b9580ac3d1a47cd8","lessThan":"bd4bffc621a8cb2f4d9ed9b6447415de524a3bef","versionType":"git","status":"affected"},{"version":"f7d34b445abc00e979b7cf36b9580ac3d1a47cd8","lessThan":"65879e0a452ca2a234b9475e0c11aff7a4343738","versionType":"git","status":"affected"},{"version":"f7d34b445abc00e979b7cf36b9580ac3d1a47cd8","lessThan":"b3cde26a66b04f1d90ed0b675899c88b4e49d424","versionType":"git","status":"affected"},{"version":"f7d34b445abc00e979b7cf36b9580ac3d1a47cd8","lessThan":"5f08c45bdcfd28d1171de38c5ef29fc89a76eedc","versionType":"git","status":"affected"},{"version":"f7d34b445abc00e979b7cf36b9580ac3d1a47cd8","lessThan":"7f0278e474c4d1c4457974ff1137cc385c944ab3","versionType":"git","status":"affected"},{"version":"f7d34b445abc00e979b7cf36b9580ac3d1a47cd8","lessThan":"47a7f98fbb5006d46d15a3a210ffdc61448a4f19","versionType":"git","status":"affected"},{"version":"f7d34b445abc00e979b7cf36b9580ac3d1a47cd8","lessThan":"0dd68b5d01d022fc9c5e71c82a82b0a94d3d0671","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/usb/core/devio.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.6","status":"affected"},{"version":"0","lessThan":"4.6","versionType":"semver","status":"unaffected"},{"version":"5.10.269","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.220","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.187","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.156","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.108","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.49","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.13","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.3","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0a960b88c5979f853019d4dc4957dfbeeb193440","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/0dd68b5d01d022fc9c5e71c82a82b0a94d3d0671","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/47a7f98fbb5006d46d15a3a210ffdc61448a4f19","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5f08c45bdcfd28d1171de38c5ef29fc89a76eedc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/65879e0a452ca2a234b9475e0c11aff7a4343738","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7f0278e474c4d1c4457974ff1137cc385c944ab3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/96f5520fc9a5e4bbf77ac93c9d5ce502f597e6cf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b3cde26a66b04f1d90ed0b675899c88b4e49d424","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bd4bffc621a8cb2f4d9ed9b6447415de524a3bef","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80825","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:10.410","lastModified":"2026-09-04T16:18:10.410","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: mt7925: ensure tx headroom in usb_sdio_tx_prepare_skb\n\nmt7925_usb_sdio_tx_prepare_skb() pushes a TX descriptor and a USB\nheader onto every skb and assumes the headroom for them is already\nthere. That holds for locally generated traffic, where mac80211\nreserves hw->extra_tx_headroom, but forwarded frames are sent through\nieee80211_8023_xmit(), which does not reserve it. Bridge a wired\ninterface to an mt7925u AP and the first forwarded frame that arrives\nshort panics the kernel:\n\n skbuff: skb_under_panic: len:415 put:4 tail:0x19b end:0x640 dev:wlan1\n kernel BUG at net/core/skbuff.c:212!\n Call trace:\n  skb_panic+0x58/0x60 (P)\n  skb_push+0x58/0x60\n  mt7925_usb_sdio_tx_prepare_skb+0xf8/0x1b8 [mt7925_common]\n  mt76u_tx_queue_skb+0xa0/0x1f8 [mt76_usb]\n  __mt76_tx_queue_skb+0x54/0xe8 [mt76]\n  mt76_txq_schedule.part.0+0x204/0x478 [mt76]\n  mt76_txq_schedule_all+0x50/0x80 [mt76]\n  mt792x_tx_worker+0x68/0x100 [mt792x_lib]\n  __mt76_worker_fn+0x84/0x150 [mt76]\n\nWhether a given setup hits it depends on how much headroom the ingress\nnetdev leaves in its rx skbs. Reproduced on a Raspberry Pi 5 bridging\nonboard ethernet to a Netgear A9000; originally reported on an MT7986\nrouter running OpenWrt. Nick Morrow's testing on a Pi 4 (bcmgenet),\nwhich leaves more headroom, helped narrow the trigger to the ingress\npath.\n\nThe same bug was fixed on mt7921 by commit 98c4d0abf5c4 (\"mt76:\nmt7921: don't assume adequate headroom for SDIO headers\"), but mt7925\nwas copied from mt7921 without the fix. Add the same guard here."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/wireless/mediatek/mt76/mt7925/mac.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"c948b5da6bbec742b433138e3e3f9537a85af2e5","lessThan":"9a72b180f0575e41471e088e09bddc4b73d6dee2","versionType":"git","status":"affected"},{"version":"c948b5da6bbec742b433138e3e3f9537a85af2e5","lessThan":"22edb6786127271aeba7abd30f152977c605c6a3","versionType":"git","status":"affected"},{"version":"c948b5da6bbec742b433138e3e3f9537a85af2e5","lessThan":"8d481f93588932a95f657671d4e1601b90d130cc","versionType":"git","status":"affected"},{"version":"c948b5da6bbec742b433138e3e3f9537a85af2e5","lessThan":"e5e8fc11a7ac578f16079f855b7fffc1649d053c","versionType":"git","status":"affected"},{"version":"c948b5da6bbec742b433138e3e3f9537a85af2e5","lessThan":"ef3e34874d2332d0f63e72c2c35ce5c93568c125","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/wireless/mediatek/mt76/mt7925/mac.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.7","status":"affected"},{"version":"0","lessThan":"6.7","versionType":"semver","status":"unaffected"},{"version":"6.12.108","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.49","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.13","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.3","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/22edb6786127271aeba7abd30f152977c605c6a3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8d481f93588932a95f657671d4e1601b90d130cc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9a72b180f0575e41471e088e09bddc4b73d6dee2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e5e8fc11a7ac578f16079f855b7fffc1649d053c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ef3e34874d2332d0f63e72c2c35ce5c93568c125","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80826","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:10.543","lastModified":"2026-09-04T16:18:10.543","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: c67x00: fix use-after-free in c67x00_add_iso_urb()\n\nWhen TD creation fails for the last packet of an isochronous URB,\nc67x00_add_iso_urb() gives the URB back before updating the endpoint\nscheduling state.\n\nc67x00_giveback_urb() frees the URB private data, and the completion\ncallback may release the final URB reference. The following accesses to\nurbp->ep_data, urb->interval, and urbp->cnt can therefore use freed\nmemory.\n\nUpdate next_frame and cnt before giving back the failed final packet,\nmaking the giveback the last operation that uses the URB and its private\ndata."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/usb/c67x00/c67x00-sched.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"e9b29ffc519b9e63d4e1c0b1278bb951bb418a9d","lessThan":"e4039e9bebb528dd9cd7ac72aeaec529c26c355a","versionType":"git","status":"affected"},{"version":"e9b29ffc519b9e63d4e1c0b1278bb951bb418a9d","lessThan":"ade18b4ce78a16558f4f435aece80082f6f7b64c","versionType":"git","status":"affected"},{"version":"e9b29ffc519b9e63d4e1c0b1278bb951bb418a9d","lessThan":"bb572801290e25ec1c4753d14af35777303f5d6b","versionType":"git","status":"affected"},{"version":"e9b29ffc519b9e63d4e1c0b1278bb951bb418a9d","lessThan":"62cd519ab74cac499036cd88c11692f8f0d53e14","versionType":"git","status":"affected"},{"version":"e9b29ffc519b9e63d4e1c0b1278bb951bb418a9d","lessThan":"ff172092cba7ec990ecc7b610ce703e19570b8f0","versionType":"git","status":"affected"},{"version":"e9b29ffc519b9e63d4e1c0b1278bb951bb418a9d","lessThan":"b4cb8081cf80f82e48fbe9c021a8f6d0fa2ed421","versionType":"git","status":"affected"},{"version":"e9b29ffc519b9e63d4e1c0b1278bb951bb418a9d","lessThan":"7983daa159981fac125db2457437723f38ea1472","versionType":"git","status":"affected"},{"version":"e9b29ffc519b9e63d4e1c0b1278bb951bb418a9d","lessThan":"f24dcc61bd0ecf7639fac5bf700450b398d793a7","versionType":"git","status":"affected"},{"version":"e9b29ffc519b9e63d4e1c0b1278bb951bb418a9d","lessThan":"b1e24de475bf2d66fffc9103f3444b783527d55a","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/usb/c67x00/c67x00-sched.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.26","status":"affected"},{"version":"0","lessThan":"2.6.26","versionType":"semver","status":"unaffected"},{"version":"5.10.269","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.220","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.187","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.156","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.108","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.49","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.13","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.3","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/62cd519ab74cac499036cd88c11692f8f0d53e14","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7983daa159981fac125db2457437723f38ea1472","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ade18b4ce78a16558f4f435aece80082f6f7b64c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b1e24de475bf2d66fffc9103f3444b783527d55a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b4cb8081cf80f82e48fbe9c021a8f6d0fa2ed421","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bb572801290e25ec1c4753d14af35777303f5d6b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e4039e9bebb528dd9cd7ac72aeaec529c26c355a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f24dcc61bd0ecf7639fac5bf700450b398d793a7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ff172092cba7ec990ecc7b610ce703e19570b8f0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80827","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:10.683","lastModified":"2026-09-04T16:18:10.683","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: serial: option: fix slab OOB read in interrupt URB callback\n\nThe interrupt URB buffer is allocated in setup_port_interrupt_in() based\non the endpoint's wMaxPacketSize:\n\n    buffer_size = usb_endpoint_maxp(epd);\n    port->interrupt_in_buffer = kmalloc(buffer_size, GFP_KERNEL);\n\nWhen a USB device declares wMaxPacketSize = 8 on its interrupt IN\nendpoint, the buffer is allocated from kmalloc-8 cache (exactly\n8 bytes).\n\nIf the device sends a short packet (actual_length < wMaxPacketSize),\nthe URB completes with status == 0 and the callback proceeds to read:\n\n    data[sizeof(struct usb_ctrlrequest)]\n\nwhich evaluates to data[8], accessing 1 byte beyond the allocated 8-byte\nbuffer. This results in a slab out-of-bounds read.\n\nFix this by adding the missing bounds check: first verify that the\nactual length is large enough to contain the struct usb_ctrlrequest\nheader before accessing req_pkt->bRequestType and req_pkt->bRequest,\nand then verify that there is an additional byte for the modem signal\nstate before reading data[sizeof(struct usb_ctrlrequest)] inside the\nconditional.  Use sizeof(*req_pkt) instead of sizeof(struct\nusb_ctrlrequest) for consistency.\n\n[ johan: use dev_err(); split signals declaration and initialisation ]"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/usb/serial/option.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"58cfe9113e485f7e04bd0eac4fc4251b330af501","lessThan":"fbe60fd2abc8a5561f39719a41ad9a01b5d8e567","versionType":"git","status":"affected"},{"version":"58cfe9113e485f7e04bd0eac4fc4251b330af501","lessThan":"94e5525697b9e91ddc4071129874120a50a4f342","versionType":"git","status":"affected"},{"version":"58cfe9113e485f7e04bd0eac4fc4251b330af501","lessThan":"6b8cf5422c7e96ed5b22a8368eff663f3f98b8ec","versionType":"git","status":"affected"},{"version":"58cfe9113e485f7e04bd0eac4fc4251b330af501","lessThan":"030e3a73d3c3aa67c44454649e984d6383cdb7d3","versionType":"git","status":"affected"},{"version":"58cfe9113e485f7e04bd0eac4fc4251b330af501","lessThan":"060db7d48af1e650643c8b8319111a9ea2ce4486","versionType":"git","status":"affected"},{"version":"58cfe9113e485f7e04bd0eac4fc4251b330af501","lessThan":"2ef5560387f2c0713cee975be2b24b281bd90f3e","versionType":"git","status":"affected"},{"version":"58cfe9113e485f7e04bd0eac4fc4251b330af501","lessThan":"a72a13c83a652516a0e469d275b81d29a7429049","versionType":"git","status":"affected"},{"version":"58cfe9113e485f7e04bd0eac4fc4251b330af501","lessThan":"d762aef4eba354066be21a5d88eb2066e282f4c9","versionType":"git","status":"affected"},{"version":"58cfe9113e485f7e04bd0eac4fc4251b330af501","lessThan":"885d802f544ca7bfa8f3984d94233cce715bb6b3","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/usb/serial/option.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.12","status":"affected"},{"version":"0","lessThan":"2.6.12","versionType":"semver","status":"unaffected"},{"version":"5.10.269","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.220","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.187","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.156","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.108","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.49","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.13","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.3","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/030e3a73d3c3aa67c44454649e984d6383cdb7d3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/060db7d48af1e650643c8b8319111a9ea2ce4486","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2ef5560387f2c0713cee975be2b24b281bd90f3e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6b8cf5422c7e96ed5b22a8368eff663f3f98b8ec","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/885d802f544ca7bfa8f3984d94233cce715bb6b3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/94e5525697b9e91ddc4071129874120a50a4f342","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a72a13c83a652516a0e469d275b81d29a7429049","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d762aef4eba354066be21a5d88eb2066e282f4c9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fbe60fd2abc8a5561f39719a41ad9a01b5d8e567","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80828","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:10.833","lastModified":"2026-09-04T16:18:10.833","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: usb-audio: Complete cleanup after system-resume errors\n\nA failed system resume can leave the card unusable until reboot.\nusb_audio_resume() jumps to err_out when snd_usb_pcm_resume() or\nsnd_usb_mixer_resume() fails. The error path skips the out: block, which\nrestores D0 and decrements chip->num_suspended_intf.\n\nThe card stays in SNDRV_CTL_POWER_D3hot, so later control access blocks in\nsnd_power_ref_and_wait(). USB core logs an interface resume callback error.\nIt does not retry that callback, so a later callback cannot complete the\nskipped cleanup.\n\nusb_audio_suspend() increments num_suspended_intf before returning success.\nA system-resume callback must consume the system-suspend count even if a\ncomponent resume fails. Otherwise, the stranded count skews later suspend\nand resume cycles.\n\nDo not apply this cleanup to runtime-resume errors. Runtime PM can retry\n-EAGAIN or -EBUSY without another suspend callback. The count must continue\nto describe that suspended interface. Other runtime-resume errors latch\nruntime_error in the PM core and do not cause an immediate callback retry.\n\nBoth parts of the system-resume error path are longstanding. Commit\n88a8516a2128a (\"ALSA: usbaudio: implement USB autosuspend\") introduced\nerr_out past the D0 restore. Commit 862b2509d157c (\"ALSA: usb-audio: Fix\ninconsistent card PM state after resume\") later moved\nnum_suspended_intf-- into the out: block. The error path now skips both\noperations.\n\nNo third-party code is needed to reach the error path.\nsnd_usb_mixer_resume() ends in snd_usb_mixer_activate(), which returns the\nresult of usb_submit_urb() for devices that have a mixer status URB. Its\nmixer->private_resume hook can also fail through scarlett2_init_notify().\nsnd_usb_pcm_resume() issues a SET_CUR request to a UAC3 power domain. It\ncan return -EPIPE or -EIO when the device stalls the request.\n\nRoute a component error through out: only when system_suspend is nonzero.\nContinue to return runtime-resume errors through err_out. Later component\nresume stages remain skipped. The original error still reaches USB core.\nA later transfer can fail if the device did not recover.\n\nI reproduced the system-resume failure on an Audient iD14 MkI with an\nout-of-tree diagnostic mixer resume hook. An injected -EIO on the unpatched\ncore left control readers in uninterruptible sleep in\nsnd_power_ref_and_wait() until a reboot. With this patch, the same failure\nrestored control access. A second system suspend and resume also succeeded\nafter I disabled fault injection."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["sound/usb/card.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"88a8516a2128a6d078a106ead48092240e8a138f","lessThan":"3fa521c3c54b42e16cad8ade76551113a783752b","versionType":"git","status":"affected"},{"version":"88a8516a2128a6d078a106ead48092240e8a138f","lessThan":"3f06f3f5b16212f180764654a9398ff5f7a855c8","versionType":"git","status":"affected"},{"version":"88a8516a2128a6d078a106ead48092240e8a138f","lessThan":"f1c05c41d07b874635d681ae328d13ec550470c5","versionType":"git","status":"affected"},{"version":"88a8516a2128a6d078a106ead48092240e8a138f","lessThan":"5a625fc2284e35f33693efd9534aebaca3b005d4","versionType":"git","status":"affected"},{"version":"88a8516a2128a6d078a106ead48092240e8a138f","lessThan":"6d3e202670b819c414076a5d07dffac8a39274ad","versionType":"git","status":"affected"},{"version":"88a8516a2128a6d078a106ead48092240e8a138f","lessThan":"6c94877b6bab9185898bcad4b082ff5592558921","versionType":"git","status":"affected"},{"version":"88a8516a2128a6d078a106ead48092240e8a138f","lessThan":"d1f643b1c0258bd519146f7a342bbb394d413912","versionType":"git","status":"affected"},{"version":"88a8516a2128a6d078a106ead48092240e8a138f","lessThan":"1739a976312e110c93a8dee66a1cdf893a1b187e","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["sound/usb/card.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.39","status":"affected"},{"version":"0","lessThan":"2.6.39","versionType":"semver","status":"unaffected"},{"version":"5.15.220","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.187","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.156","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.108","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.49","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.13","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.3","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1739a976312e110c93a8dee66a1cdf893a1b187e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3f06f3f5b16212f180764654a9398ff5f7a855c8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3fa521c3c54b42e16cad8ade76551113a783752b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5a625fc2284e35f33693efd9534aebaca3b005d4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6c94877b6bab9185898bcad4b082ff5592558921","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6d3e202670b819c414076a5d07dffac8a39274ad","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d1f643b1c0258bd519146f7a342bbb394d413912","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f1c05c41d07b874635d681ae328d13ec550470c5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80829","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:10.997","lastModified":"2026-09-04T16:18:10.997","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output()\n\nsnd_usbmidi_novation_output() lays out a two-byte header at\ntransfer_buffer[0..1] and passes &transfer_buffer[2] together with a\nlength of ep->max_transfer - 2 to snd_rawmidi_transmit():\n\n\tcount = snd_rawmidi_transmit(ep->ports[0].substream,\n\t\t\t\t     &transfer_buffer[2],\n\t\t\t\t     ep->max_transfer - 2);\n\nep->max_transfer comes from the output endpoint's wMaxPacketSize via\nusb_maxpacket(). A malformed or malicious device can advertise a bulk\nOUT endpoint with a wMaxPacketSize of 1 - the USB core only clamps this\nvalue downwards - so ep->max_transfer becomes 1 and the count argument\nbecomes -1.\n\nsnd_rawmidi_transmit() passes the negative count on to\n__snd_rawmidi_transmit_peek(), where \"if (count1 > count) count1 = count\"\nleaves count1 negative; get_aligned_size() keeps it negative for a\nbyte-stream substream, so the following memcpy(buffer, ..., count1) runs\nwith a (size_t)-1 length and writes far past the transfer buffer, which\nwas allocated with usb_alloc_coherent(ep->max_transfer).\n\nThis is the same class of bug that was fixed for snd_usbmidi_akai_output()\nin commit 0970274613fb (\"ALSA: usb-audio: fix OOB write in\nsnd_usbmidi_akai_output()\"); the novation output routine was left\nunguarded. Bail out when the endpoint cannot hold the two-byte header\nplus at least one payload byte."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["sound/usb/midi.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"558fc4485ecc704edfe7876d6cebae4738ff7ef8","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"9c8212436631b0063cb021e9f58df438e3db84d0","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"e9c00d7533f99aa9833c4b598f47e3b3202fdb9a","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"94e4562fcc81badd1d467ddfb88c27e4fae974c2","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"7639ec9755d3ec0ec8cd7c0fdd2c3d3997434870","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"91919b3b99ab7ce3d7dbb39fcf7c6c742a663c0c","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"7f00dbddb51f4f74325cdc7c3f6b19fb3392481a","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"1074c2306901b44ebcb83855583c6776e1e392ea","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"1035a8f63bae28e498b0e7b5ac91d749844a7158","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["sound/usb/midi.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.12","status":"affected"},{"version":"0","lessThan":"2.6.12","versionType":"semver","status":"unaffected"},{"version":"5.10.269","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.220","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.187","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.156","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.108","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.49","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.13","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.3","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1035a8f63bae28e498b0e7b5ac91d749844a7158","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1074c2306901b44ebcb83855583c6776e1e392ea","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/558fc4485ecc704edfe7876d6cebae4738ff7ef8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7639ec9755d3ec0ec8cd7c0fdd2c3d3997434870","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7f00dbddb51f4f74325cdc7c3f6b19fb3392481a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/91919b3b99ab7ce3d7dbb39fcf7c6c742a663c0c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/94e4562fcc81badd1d467ddfb88c27e4fae974c2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9c8212436631b0063cb021e9f58df438e3db84d0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e9c00d7533f99aa9833c4b598f47e3b3202fdb9a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80830","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:11.143","lastModified":"2026-09-04T16:18:11.143","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: core: Add lock to usb_wakeup_notification()\n\nAdd a spin lock to usb_wakeup notification to prevent a race condition\nwith dereferencing freed memory. This could be hit by the xHCI driver as\nit calls this function from an IRQ and could race with the\nhub_disconnect() function, which properly grabs this lock to protect the\nstate of the device."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/usb/core/hub.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"a7a16167991c88016acef720927400404039d850","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"975ef630393c07fcbebf94f4d97043161b77a6ce","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"71cfda2fdf78041a01e9d94143baa79feabbdbf6","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"04ab260407972e631c86f2bc576cd8e64d65b325","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"bf2288583b4e072bdff17a233963619e4bc7a8b5","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"d80b946804674069db7ce6657319a71cf8eeaa5a","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"960ca456faf61824b178f47967340300b24183db","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"7c48aa0c1e79116b8af4b988d16ee29b427d6491","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"e263e18a9e7b1ff3e7301f0801c6ff87c31adfb6","versionType":"git","status":"affected"},{"version":"0","lessThan":"5.10.269","versionType":"semver","status":"affected"},{"version":"0","lessThan":"5.15.220","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.1.187","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.6.156","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.12.108","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.18.49","versionType":"semver","status":"affected"},{"version":"0","lessThan":"7.1.13","versionType":"semver","status":"affected"},{"version":"0","lessThan":"7.2.3","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/usb/core/hub.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.10.269","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.220","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.187","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.156","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.108","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.49","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.13","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.3","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/04ab260407972e631c86f2bc576cd8e64d65b325","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/71cfda2fdf78041a01e9d94143baa79feabbdbf6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7c48aa0c1e79116b8af4b988d16ee29b427d6491","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/960ca456faf61824b178f47967340300b24183db","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/975ef630393c07fcbebf94f4d97043161b77a6ce","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a7a16167991c88016acef720927400404039d850","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bf2288583b4e072bdff17a233963619e4bc7a8b5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d80b946804674069db7ce6657319a71cf8eeaa5a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e263e18a9e7b1ff3e7301f0801c6ff87c31adfb6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80831","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:11.287","lastModified":"2026-09-04T16:18:11.287","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: mxs-dcp - fix source scatterlist length access\n\nmxs_dcp_aes_block_crypt() uses sg_dma_len() without mapping the source\nscatterlist with dma_map_sg() first. Therefore, sg_dma_len() is invalid\nand could return zero or a stale DMA length, causing encryption and\ndecryption to process the wrong number of bytes when\nCONFIG_NEED_SG_DMA_LENGTH=y.\n\nUse the original scatterlist length instead."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/crypto/mxs-dcp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"15b59e7c3733f90ff1f7dd66ad77ae1c90bcdff5","lessThan":"fd0f211b27a6ec2ebd8c315683401b43adcc5511","versionType":"git","status":"affected"},{"version":"15b59e7c3733f90ff1f7dd66ad77ae1c90bcdff5","lessThan":"04201dcc88b26eac52f736e39727fc5c420b7257","versionType":"git","status":"affected"},{"version":"15b59e7c3733f90ff1f7dd66ad77ae1c90bcdff5","lessThan":"e72a795df521cb65b7c4705cc11078cdacfaa2f4","versionType":"git","status":"affected"},{"version":"15b59e7c3733f90ff1f7dd66ad77ae1c90bcdff5","lessThan":"1537bd55b4f842565068c54b47cd2ae1777d5f8f","versionType":"git","status":"affected"},{"version":"15b59e7c3733f90ff1f7dd66ad77ae1c90bcdff5","lessThan":"da14fae5203b72ca71ccfa9af8de9249e40d533a","versionType":"git","status":"affected"},{"version":"15b59e7c3733f90ff1f7dd66ad77ae1c90bcdff5","lessThan":"182f16a20d329a1c818d51dad57d9bf43d356c7c","versionType":"git","status":"affected"},{"version":"15b59e7c3733f90ff1f7dd66ad77ae1c90bcdff5","lessThan":"0e9edb108a63bbbef952dfcbc597e34ed9c1fb74","versionType":"git","status":"affected"},{"version":"15b59e7c3733f90ff1f7dd66ad77ae1c90bcdff5","lessThan":"6ef9a4afb52cb102ab038cd42352c142d8505d09","versionType":"git","status":"affected"},{"version":"15b59e7c3733f90ff1f7dd66ad77ae1c90bcdff5","lessThan":"c5bcb084a9871e5b62afb5f48b60adfa13b5d9f8","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/crypto/mxs-dcp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.14","status":"affected"},{"version":"0","lessThan":"3.14","versionType":"semver","status":"unaffected"},{"version":"5.10.269","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.220","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.187","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.156","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.108","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.49","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.13","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.3","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/04201dcc88b26eac52f736e39727fc5c420b7257","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/0e9edb108a63bbbef952dfcbc597e34ed9c1fb74","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1537bd55b4f842565068c54b47cd2ae1777d5f8f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/182f16a20d329a1c818d51dad57d9bf43d356c7c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6ef9a4afb52cb102ab038cd42352c142d8505d09","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c5bcb084a9871e5b62afb5f48b60adfa13b5d9f8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/da14fae5203b72ca71ccfa9af8de9249e40d533a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e72a795df521cb65b7c4705cc11078cdacfaa2f4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fd0f211b27a6ec2ebd8c315683401b43adcc5511","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80832","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:11.433","lastModified":"2026-09-04T16:18:11.433","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: qce - fix CCM AAD buffer underallocation\n\nThe AAD buffer allocated in qce_aead_ccm_prepare_buf_assoclen()\ncan be smaller than the length later programmed into the DMA\nscatterlist.\n\nThe allocation size is currently calculated as:\n\n  ALIGN(assoclen, 16) + MAX_CCM_ADATA_HEADER_LEN\n\nwhile the DMA length is set to:\n\n  ALIGN(assoclen + adata_header_len, 16)\n\nSince ALIGN() does not distribute over addition, the allocation\ncan be smaller than the DMA length. For example, when\nassoclen = 32 and adata_header_len = 2:\n\n  allocation = ALIGN(32, 16) + 6 = 38\n  DMA length = ALIGN(32 + 2, 16) = 48\n\nAs a result, the QCE hardware can read beyond the allocated\nbuffer while computing the CBC-MAC over the associated data.\nThe extra bytes are folded into the authentication tag,\nresulting in an incorrect tag and causing CCM self-test\nfailures such as:\n\n  alg: aead: ccm-aes-qce encryption test failed (wrong result)\n  on test vector 8\n\nFix the allocation by adding the maximum possible AAD header\nlength before alignment:\n\n  ALIGN(assoclen + MAX_CCM_ADATA_HEADER_LEN, 16)\n\nThis guarantees that the allocated buffer is large enough\nfor the fully padded AAD data for all supported header sizes."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/crypto/qce/aead.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"9363efb4181c5e0fbf86bdfa759262aa29f0eb50","lessThan":"11775b35ce9f27e73d62188d7d38aa0dc0a219aa","versionType":"git","status":"affected"},{"version":"9363efb4181c5e0fbf86bdfa759262aa29f0eb50","lessThan":"c9e0f06a023107694698a7930616aeb460d91816","versionType":"git","status":"affected"},{"version":"9363efb4181c5e0fbf86bdfa759262aa29f0eb50","lessThan":"cc56d2b0d77cfeea061e98114992ee687d5eb4dd","versionType":"git","status":"affected"},{"version":"9363efb4181c5e0fbf86bdfa759262aa29f0eb50","lessThan":"002f1f99aef7ea631cb687fc17bce64e4963f6aa","versionType":"git","status":"affected"},{"version":"9363efb4181c5e0fbf86bdfa759262aa29f0eb50","lessThan":"2f65718b9c1095eef1ae9b374aa0384b1b083f3c","versionType":"git","status":"affected"},{"version":"9363efb4181c5e0fbf86bdfa759262aa29f0eb50","lessThan":"46a84efe2dbaddde89073a3c00c694486937c34b","versionType":"git","status":"affected"},{"version":"9363efb4181c5e0fbf86bdfa759262aa29f0eb50","lessThan":"4839f4c21f9c577eedef2919ced878a3057c7fc3","versionType":"git","status":"affected"},{"version":"9363efb4181c5e0fbf86bdfa759262aa29f0eb50","lessThan":"7f2345f47dd189625f657cd72437179ab4170ee1","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/crypto/qce/aead.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.14","status":"affected"},{"version":"0","lessThan":"5.14","versionType":"semver","status":"unaffected"},{"version":"5.15.220","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.187","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.156","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.108","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.49","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.13","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.3","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/002f1f99aef7ea631cb687fc17bce64e4963f6aa","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/11775b35ce9f27e73d62188d7d38aa0dc0a219aa","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2f65718b9c1095eef1ae9b374aa0384b1b083f3c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/46a84efe2dbaddde89073a3c00c694486937c34b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4839f4c21f9c577eedef2919ced878a3057c7fc3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7f2345f47dd189625f657cd72437179ab4170ee1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c9e0f06a023107694698a7930616aeb460d91816","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cc56d2b0d77cfeea061e98114992ee687d5eb4dd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80833","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:11.577","lastModified":"2026-09-04T16:18:11.577","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: sun8i-ss - Remove crypto_rng interface\n\nSince the crypto_rng interface for hardware PRNGs is unused and is\nredundant with hwrng and the actual Linux RNG, it's being phased out.\nMost drivers for it were already removed.  Go ahead and remove the\nsun8i-ss support which is one of the only remaining ones.\n\nAs usual for crypto_rng, this driver was also buggy: its ->generate()\nfunction had a use-after-free vulnerability due to using\nwait_for_completion_interruptible_timeout() without handling shutting\ndown the DMA operation if a signal is sent.  Also, it had a buffer\noverread bug in the line 'memcpy(ctx->seed, d + dlen, ctx->slen);'.\nThere's no point in fixing these bugs separately only to remove the code\nanyway, so this commit is marked with Fixes and Cc stable."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/crypto/allwinner/Kconfig","drivers/crypto/allwinner/sun8i-ss/Makefile","drivers/crypto/allwinner/sun8i-ss/sun8i-ss-core.c","drivers/crypto/allwinner/sun8i-ss/sun8i-ss-prng.c","drivers/crypto/allwinner/sun8i-ss/sun8i-ss.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"ac2614d721dea2ff273af19c6c5d508d58a2bb3e","lessThan":"8ab58786b4c63b8f1b6c522f33bb67a3c8c2791f","versionType":"git","status":"affected"},{"version":"ac2614d721dea2ff273af19c6c5d508d58a2bb3e","lessThan":"a78446ee6fae86ac8733f120e3ffce2e5d9384f5","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/crypto/allwinner/Kconfig","drivers/crypto/allwinner/sun8i-ss/Makefile","drivers/crypto/allwinner/sun8i-ss/sun8i-ss-core.c","drivers/crypto/allwinner/sun8i-ss/sun8i-ss-prng.c","drivers/crypto/allwinner/sun8i-ss/sun8i-ss.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.10","status":"affected"},{"version":"0","lessThan":"5.10","versionType":"semver","status":"unaffected"},{"version":"7.2.3","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/8ab58786b4c63b8f1b6c522f33bb67a3c8c2791f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a78446ee6fae86ac8733f120e3ffce2e5d9384f5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80834","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:11.683","lastModified":"2026-09-04T16:18:11.683","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: sun8i-ce - Remove crypto_rng interface\n\nSince the crypto_rng interface for hardware PRNGs is unused and is\nredundant with hwrng and the actual Linux RNG, it's being phased out.\nMost drivers for it were already removed.  Go ahead and remove the\nsun8i-ce support which is one of the only remaining ones.\n\nNote that the sun8i-ce support for hwrng remains in place.  That is the\ninterface that actually matters.\n\nAs usual for crypto_rng, this driver was also buggy: its ->generate()\nfunction had a use-after-free vulnerability due to using\nwait_for_completion_interruptible_timeout() without handling shutting\ndown the DMA operation if a signal is sent.  There's no point in fixing\nthis separately only to remove the code anyway, so this commit is marked\nwith Fixes and Cc stable."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/crypto/allwinner/Kconfig","drivers/crypto/allwinner/sun8i-ce/Makefile","drivers/crypto/allwinner/sun8i-ce/sun8i-ce-core.c","drivers/crypto/allwinner/sun8i-ce/sun8i-ce-prng.c","drivers/crypto/allwinner/sun8i-ce/sun8i-ce.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5eb7e946888493959b1c393144934afcbcd0cfc1","lessThan":"1017f987c5f0841f00408a78f947990c9d84b346","versionType":"git","status":"affected"},{"version":"5eb7e946888493959b1c393144934afcbcd0cfc1","lessThan":"011556f71d094da61379ae3672692cae2795304e","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/crypto/allwinner/Kconfig","drivers/crypto/allwinner/sun8i-ce/Makefile","drivers/crypto/allwinner/sun8i-ce/sun8i-ce-core.c","drivers/crypto/allwinner/sun8i-ce/sun8i-ce-prng.c","drivers/crypto/allwinner/sun8i-ce/sun8i-ce.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.10","status":"affected"},{"version":"0","lessThan":"5.10","versionType":"semver","status":"unaffected"},{"version":"7.2.3","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/011556f71d094da61379ae3672692cae2795304e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1017f987c5f0841f00408a78f947990c9d84b346","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80835","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:11.790","lastModified":"2026-09-04T16:18:11.790","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: qcom-rng - Remove crypto_rng interface\n\nqcom-rng.c exposes the same hardware through two completely separate\ninterfaces, crypto_rng and hwrng.  However, the implementation of this\nis buggy because it permits generation operations from these interfaces\nto run concurrently with each other, accessing the same registers.  That\nis, qcom_rng_generate() synchronizes with itself but not with\nqcom_hwrng_read().  This results in potential repetition of output from\nthe RNG, output of non-random values, etc.\n\nFortunately, there's actually no point in hardware RNG drivers\nimplementing the crypto_rng interface.  It's not actually used by\nanything besides the \"rng\" algorithm type of AF_ALG, which in turn is\nnot actually used in practice.  Other crypto_rng hardware drivers are\nlikewise being phased out, leaving just the hwrng support.\n\nThus, remove it to simplify the code and avoid conflict (and confusion)\nwith the hwrng interface which is the one that actually matters."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/crypto/Kconfig","drivers/crypto/qcom-rng.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"f29cd5bb64c258f29b4c49452532481f50eb43ca","lessThan":"bb474dcd9d0224264a27a60891f00872b879835f","versionType":"git","status":"affected"},{"version":"f29cd5bb64c258f29b4c49452532481f50eb43ca","lessThan":"14d9ee8286460a7b82f3b8610b5c7ebf4550b06b","versionType":"git","status":"affected"},{"version":"f29cd5bb64c258f29b4c49452532481f50eb43ca","lessThan":"843e2bdaf8deb8bc341203094dfe582e38ea4af2","versionType":"git","status":"affected"},{"version":"f29cd5bb64c258f29b4c49452532481f50eb43ca","lessThan":"669d940351eda316b82e24986e2e0e057653ce7d","versionType":"git","status":"affected"},{"version":"f29cd5bb64c258f29b4c49452532481f50eb43ca","lessThan":"2ecdf5c9910e20f73639bc322f0518a3439d17c0","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/crypto/Kconfig","drivers/crypto/qcom-rng.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.7","status":"affected"},{"version":"0","lessThan":"6.7","versionType":"semver","status":"unaffected"},{"version":"6.12.108","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.49","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.13","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.3","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/14d9ee8286460a7b82f3b8610b5c7ebf4550b06b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2ecdf5c9910e20f73639bc322f0518a3439d17c0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/669d940351eda316b82e24986e2e0e057653ce7d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/843e2bdaf8deb8bc341203094dfe582e38ea4af2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bb474dcd9d0224264a27a60891f00872b879835f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80836","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:11.913","lastModified":"2026-09-04T16:18:11.913","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: virtio - bound the akcipher result length\n\nvirtio_crypto_dataq_akcipher_callback() sets the result length from the\ndevice-reported response length without bounding it to the destination\nbuffer, which was allocated for the original request length.\nsg_copy_from_buffer() then reads that many bytes from the destination\nbuffer; a backend reporting a larger length over-reads adjacent kernel\nheap into the caller's scatterlist (an out-of-bounds read).\n\nClamp the reported length to the originally requested destination length.\nA conforming device reports no more than that, so valid results are\nunaffected."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/crypto/virtio/virtio_crypto_akcipher_algs.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"a36bd0ad9fbf69d0d711b1c105954ce8d6cc144a","lessThan":"5545de5050cbc3594506d74f2c392b0716cf8bca","versionType":"git","status":"affected"},{"version":"a36bd0ad9fbf69d0d711b1c105954ce8d6cc144a","lessThan":"3fda114a42f1510a4ec8a0b17a0cfc997952ccc2","versionType":"git","status":"affected"},{"version":"a36bd0ad9fbf69d0d711b1c105954ce8d6cc144a","lessThan":"1f9f877b1ef1fbd4ee95571cddf39c8002cee252","versionType":"git","status":"affected"},{"version":"a36bd0ad9fbf69d0d711b1c105954ce8d6cc144a","lessThan":"f77a956f6a19f9463ef1527c9d0cda50dded6b92","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/crypto/virtio/virtio_crypto_akcipher_algs.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.19","status":"affected"},{"version":"0","lessThan":"5.19","versionType":"semver","status":"unaffected"},{"version":"6.18.49","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.13","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.3","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1f9f877b1ef1fbd4ee95571cddf39c8002cee252","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3fda114a42f1510a4ec8a0b17a0cfc997952ccc2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5545de5050cbc3594506d74f2c392b0716cf8bca","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f77a956f6a19f9463ef1527c9d0cda50dded6b92","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80837","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:12.030","lastModified":"2026-09-04T16:18:12.030","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: don't queue packet path object notifications\n\nAll file:line references below are against v7.2-rc4 (ac5b0e5651b1). The\ntrace was captured on 7.2.0-rc6-kasan72rc6 (075b74841bd0), where the same\nlines apply.\n\nnft_obj_notify() is exported and reached from the packet path. Its only\nin-tree caller is nft_quota_obj_eval() (net/netfilter/nft_quota.c:68),\nwhich notifies with GFP_ATOMIC while evaluating a rule for a transiting\npacket, holding no mutex.\n\nSince commit 67cc570edaa0 (\"netfilter: nf_tables: coalesce multiple\nnotifications into one skbuff\") that notification is no longer sent\nimmediately. __nft_obj_notify() queues it onto nft_net->notify_list via\nnft_notify_enqueue() (net/netfilter/nf_tables_api.c:1211), which is a bare\nlist_add_tail(). notify_list has no lock of its own\n(include/net/netfilter/nf_tables.h:1951), it is serialised by commit_mutex:\nthe six other enqueue sites all run inside a netlink transaction, and the\ndrain in nft_commit_notify() (net/netfilter/nf_tables_api.c:10746) does\nlist_del() + kfree_skb() from nf_tables_commit() with commit_mutex held.\n\nSending packets through a chain that references a depleted quota object\ntherefore races an unlocked list_add_tail() against list_del() +\nkfree_skb() on another CPU. The WRITE_ONCE(prev->next, new) in __list_add()\nthen stores through an sk_buff that has already been freed:\n\n  BUG: KASAN: slab-use-after-free in __nft_obj_notify+0x2c5/0x2d0\n  Write of size 8 at addr ff110001047183c0 by task poc/76\n  CPU: 0 UID: 1000 PID: 76 Comm: poc Tainted: G  W  7.2.0-rc6-kasan72rc6 #4\n  Call Trace:\n   <IRQ>\n   __nft_obj_notify (include/linux/list.h:164 include/linux/list.h:191\n                     net/netfilter/nf_tables_api.c:1211\n                     net/netfilter/nf_tables_api.c:8743)\n   nft_quota_obj_eval (net/netfilter/nft_quota.c:68)\n   nft_do_chain_inet\n   nf_hook_slow\n   __ip_local_out\n   ip_push_pending_frames\n   udp_send_skb\n   udp_sendmsg\n   __x64_sys_sendto\n\n  Allocated by task 77:\n   __alloc_skb (net/core/skbuff.c:704)\n   __nft_obj_notify (include/net/netlink.h:1055\n                     net/netfilter/nf_tables_api.c:8731)\n   nft_quota_obj_eval (net/netfilter/nft_quota.c:68)\n   nft_do_chain\n\n  Freed by task 79:\n   nf_tables_commit (include/linux/skbuff.h:1332\n                     net/netfilter/nf_tables_api.c:10759\n                     net/netfilter/nf_tables_api.c:11185)\n   nfnetlink_rcv_batch (net/netfilter/nfnetlink.c:574)\n   netlink_unicast\n   netlink_sendmsg\n\n  The buggy address belongs to the cache skbuff_head_cache of size 232\n\nQueueing from the packet path is wrong even leaving the race aside:\nnotify_list is only drained by nft_commit_notify() from nf_tables_commit()\n(:11185), so a notification enqueued outside a transaction is not sent\nuntil some later netlink batch commits, if one ever does.\n\nThe gfp argument that nft_obj_notify() still takes is a leftover of the\npre-67cc570edaa0 behaviour, where this path called nfnetlink_send()\ndirectly. Restore that: split the message construction out into\nnft_obj_notify_alloc() and let each caller decide what to do with the skb.\nnft_obj_notify(), the exported one reached from the packet path, sends it\nstraight away; nf_tables_obj_notify(), which runs under commit_mutex, keeps\nqueueing it, so transaction notifications are still coalesced."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/netfilter/nf_tables_api.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"67cc570edaa02016a8685a06a0ee91f05a6277d9","lessThan":"df86c0e84025be8b6dd572a20852698927aa666b","versionType":"git","status":"affected"},{"version":"67cc570edaa02016a8685a06a0ee91f05a6277d9","lessThan":"6fa88d11983c6fe693c13ed7c5b3b75ae9f39de6","versionType":"git","status":"affected"},{"version":"67cc570edaa02016a8685a06a0ee91f05a6277d9","lessThan":"e97e2d6d0b150fd78be573f9fdf193f204d9334e","versionType":"git","status":"affected"},{"version":"67cc570edaa02016a8685a06a0ee91f05a6277d9","lessThan":"68de7f3a38acab355c24114f77bf00d3094ce4da","versionType":"git","status":"affected"},{"version":"67cc570edaa02016a8685a06a0ee91f05a6277d9","lessThan":"7904b94768e983bcb2be34a8d6d1f3450f5b838b","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/netfilter/nf_tables_api.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.9","status":"affected"},{"version":"0","lessThan":"5.9","versionType":"semver","status":"unaffected"},{"version":"6.12.108","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.49","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.13","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.3","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/68de7f3a38acab355c24114f77bf00d3094ce4da","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6fa88d11983c6fe693c13ed7c5b3b75ae9f39de6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7904b94768e983bcb2be34a8d6d1f3450f5b838b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/df86c0e84025be8b6dd572a20852698927aa666b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e97e2d6d0b150fd78be573f9fdf193f204d9334e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80838","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:12.183","lastModified":"2026-09-04T16:18:12.183","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nvxlan: keep the last remote linked during FDB flush\n\nA non-nexthop FDB entry is expected to have at least one remote while it\nremains reachable through the FDB hash table. A filtered bulk flush\nviolates this invariant when every remote matches: It unlinks the last\nremote in vxlan_fdb_dst_destroy() and only afterwards tells vxlan_flush()\nto destroy the parent FDB entry.\n\nAn RCU reader can find the parent during this interval.\nfirst_remote_rcu() then applies list_entry_rcu() to the empty list head,\nproducing an invalid remote pointer that the receive learning path can\nread from and write to.\n\nWhen a matching remote is the sole remaining remote, leave it linked and\nask the caller to destroy the entire FDB entry. vxlan_fdb_destroy() keeps\nthe remote attached while sending the deletion notification and removing\nthe parent from the lookup structures."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/vxlan/vxlan_core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"c499fccb71cb85902b5c5b9ce9c9ae6683e54a8f","lessThan":"2a7c2f00843225d5f037676bca649321f3d024c7","versionType":"git","status":"affected"},{"version":"c499fccb71cb85902b5c5b9ce9c9ae6683e54a8f","lessThan":"a8820c8a7718327e96849782033e7c85a0f6bcfe","versionType":"git","status":"affected"},{"version":"c499fccb71cb85902b5c5b9ce9c9ae6683e54a8f","lessThan":"8ba68fd6cdd1e3c92b92f25c7e48bf7bd51a183c","versionType":"git","status":"affected"},{"version":"c499fccb71cb85902b5c5b9ce9c9ae6683e54a8f","lessThan":"4bbc76ee1b21d3bd045d6d819b2bacd30a6372ab","versionType":"git","status":"affected"},{"version":"c499fccb71cb85902b5c5b9ce9c9ae6683e54a8f","lessThan":"d5d4a7b538b52db63927773a8905fcd9f78a42e2","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/vxlan/vxlan_core.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.7","status":"affected"},{"version":"0","lessThan":"6.7","versionType":"semver","status":"unaffected"},{"version":"6.12.108","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.49","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.13","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.3","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2a7c2f00843225d5f037676bca649321f3d024c7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4bbc76ee1b21d3bd045d6d819b2bacd30a6372ab","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8ba68fd6cdd1e3c92b92f25c7e48bf7bd51a183c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a8820c8a7718327e96849782033e7c85a0f6bcfe","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d5d4a7b538b52db63927773a8905fcd9f78a42e2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80839","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:12.310","lastModified":"2026-09-04T16:18:12.310","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbatman-adv: reject unrepresentable multicast TVLV offsets\n\nThe network and transport header fields in struct sk_buff are 16-bit\noffsets from skb->head, and U16_MAX is reserved as the unset transport\nheader value. batadv_tvlv_call_handler() sets both fields from a received\nmulticast TVLV without checking whether the TVLV end is representable.\n\nIf the end offset exceeds the field's range, skb_set_transport_header()\ntruncates it so that the transport header precedes the network header.\nThe negative difference is then returned by skb_network_header_len() as\na large u32. batadv_mcast_forw_packet() consequently accepts an oversized\nmulticast tracker and accesses memory beyond the skb data.\n\nAdd skb_set_transport_header_careful(), an offset-aware counterpart to\nskb_reset_transport_header_careful(), which validates the final\nhead-relative offset before assigning it. Use the new helper in\nbatadv_tvlv_call_handler() and reject unrepresentable TVLVs before\nsetting the network header."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["include/linux/skbuff.h","net/batman-adv/tvlv.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"07afe1ba288c04280622fa002ed385f1ac0b6fe6","lessThan":"da1f5aa7ec93f2cc17f5cd30efc54f62af433cf2","versionType":"git","status":"affected"},{"version":"07afe1ba288c04280622fa002ed385f1ac0b6fe6","lessThan":"916ec741e65af072b98e475feaad98c063da1b7c","versionType":"git","status":"affected"},{"version":"07afe1ba288c04280622fa002ed385f1ac0b6fe6","lessThan":"1b466746fe109127fd983100a228cdd1f1f6ece2","versionType":"git","status":"affected"},{"version":"07afe1ba288c04280622fa002ed385f1ac0b6fe6","lessThan":"2b46baa591d0a7c16b62f150917187e70d053be6","versionType":"git","status":"affected"},{"version":"07afe1ba288c04280622fa002ed385f1ac0b6fe6","lessThan":"f12c2de4f542e3220e17e0606f492110064f04cb","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["include/linux/skbuff.h","net/batman-adv/tvlv.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.8","status":"affected"},{"version":"0","lessThan":"6.8","versionType":"semver","status":"unaffected"},{"version":"6.12.108","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.49","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.13","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.3","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1b466746fe109127fd983100a228cdd1f1f6ece2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2b46baa591d0a7c16b62f150917187e70d053be6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/916ec741e65af072b98e475feaad98c063da1b7c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/da1f5aa7ec93f2cc17f5cd30efc54f62af433cf2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f12c2de4f542e3220e17e0606f492110064f04cb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80840","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:12.440","lastModified":"2026-09-04T16:18:12.440","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: seg6: clear IPv4 control block on IPIP decapsulation\n\nEnd.DX4 and End.DT4 decapsulate an IPv4 packet through\ndecap_and_validate() and send it directly to IPv4 routing. The inner\npacket therefore bypasses ip_rcv_core(), which normally clears IPCB\nbefore IPv4 interprets skb->cb.\n\nThe skb instead retains IP6CB data from the outer packet. IP6CB and\nIPCB use the same skb->cb storage, so IP6CB(skb)->lastopt overlaps\nIPCB(skb)->opt.optlen and srr, while IP6CB(skb)->nhoff overlaps rr and\nts.\n\nThe sender can make the stale optlen byte nonzero with a valid outer\nextension-header chain. The reproducers put an eight-byte Destination\nOptions header immediately after the 40-byte IPv6 header and before the\nSegment Routing Header. ipv6_destopt_rcv() records the sender-controlled\nDestination Options offset in both lastopt and nhoff, setting them to\n40. On the reproduced little-endian x86-64 kernel, IPv4 therefore sees\noptlen = 40 and rr = 40.\n\nBoth tcp_v4_save_options() and __ip_options_echo() skip option copying\nwhen optlen is zero. Here optlen is 40, so the TCP SYN path allocates\nroom for 40 bytes of option data and calls __ip_options_echo(). The\nstale rr value makes that function read inner packet byte 41 as the\nRecord Route option length. The reproducers set that sender-controlled\nbyte to 255, so __ip_options_echo() copies 255 bytes into the 40-byte\noption-data area.\n\nSeparate End.DX4 and End.DT4 reproducers on the unpatched v7.2-rc5\nkernel both produced:\n\n  BUG: KASAN: slab-out-of-bounds in __ip_options_echo()\n  Write of size 255\n\nThe relevant End.DX4 call path is:\n\n  __ip_options_echo\n  tcp_v4_route_req\n  tcp_conn_request\n  tcp_v4_conn_request\n  tcp_rcv_state_process\n  tcp_v4_do_rcv\n  tcp_v4_rcv\n  ip_protocol_deliver_rcu\n  ip_local_deliver_finish\n  ip_local_deliver\n  input_action_end_dx4_finish\n  input_action_end_dx4\n\nThe relevant End.DT4 call path is:\n\n  __ip_options_echo\n  tcp_v4_route_req\n  tcp_conn_request\n  tcp_v4_conn_request\n  tcp_rcv_state_process\n  tcp_v4_do_rcv\n  tcp_v4_rcv\n  ip_protocol_deliver_rcu\n  ip_local_deliver_finish\n  ip_local_deliver\n  input_action_end_dt4\n\ntcp_v4_save_options() is inlined into the tcp_v4_route_req() path, so\nit does not appear as a separate frame.\n\nWhen decap_and_validate() handles IPPROTO_IPIP, save the ingress\ninterface from IP6CB, clear IPCB, and restore the saved value. Doing\nthis in the common decapsulation path covers End.DX4, End.DT4, and\nEnd.DT46's IPv4 arm.\n\nUse IP6CB(skb)->iif rather than skb->skb_iif. These actions run after\nl3mdev processing, which can replace skb_iif with the L3 master;\nIP6CB iif still records the receiving interface set at IPv6 ingress."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/ipv6/seg6_local.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"891ef8dd2a8d14e4e73a81dcdb135b574c57f556","lessThan":"10fd1a8f58ac619a9e251f2858e2e2c8fd6cd667","versionType":"git","status":"affected"},{"version":"891ef8dd2a8d14e4e73a81dcdb135b574c57f556","lessThan":"eb0f422487228e140f3d609b032ac61aedcab8fa","versionType":"git","status":"affected"},{"version":"891ef8dd2a8d14e4e73a81dcdb135b574c57f556","lessThan":"9039e4f3e1c0ffe2b575b655b3f58fdd10f7e40c","versionType":"git","status":"affected"},{"version":"891ef8dd2a8d14e4e73a81dcdb135b574c57f556","lessThan":"f52f1e75716d2ee49e013edf204ac92337c72fd8","versionType":"git","status":"affected"},{"version":"891ef8dd2a8d14e4e73a81dcdb135b574c57f556","lessThan":"0e3f01fe2e704e76af4385b8a1742641885a191c","versionType":"git","status":"affected"},{"version":"891ef8dd2a8d14e4e73a81dcdb135b574c57f556","lessThan":"3e4476e58343fb8f2fffced9e22d935376b17aaf","versionType":"git","status":"affected"},{"version":"891ef8dd2a8d14e4e73a81dcdb135b574c57f556","lessThan":"bf1c1151560d11036a144d917fa4c131831342d7","versionType":"git","status":"affected"},{"version":"891ef8dd2a8d14e4e73a81dcdb135b574c57f556","lessThan":"f4be3b391265e24c7720fc867c50062b436acf33","versionType":"git","status":"affected"},{"version":"891ef8dd2a8d14e4e73a81dcdb135b574c57f556","lessThan":"44930446dde45a7a90fe1446fa38eb0e2c561646","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/ipv6/seg6_local.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.14","status":"affected"},{"version":"0","lessThan":"4.14","versionType":"semver","status":"unaffected"},{"version":"5.10.269","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.220","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.187","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.156","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.108","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.49","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.13","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.3","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0e3f01fe2e704e76af4385b8a1742641885a191c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/10fd1a8f58ac619a9e251f2858e2e2c8fd6cd667","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3e4476e58343fb8f2fffced9e22d935376b17aaf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/44930446dde45a7a90fe1446fa38eb0e2c561646","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9039e4f3e1c0ffe2b575b655b3f58fdd10f7e40c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bf1c1151560d11036a144d917fa4c131831342d7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/eb0f422487228e140f3d609b032ac61aedcab8fa","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f4be3b391265e24c7720fc867c50062b436acf33","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f52f1e75716d2ee49e013edf204ac92337c72fd8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80841","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:12.607","lastModified":"2026-09-04T16:18:12.607","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/packet: defer vmalloc TX_RING free until skbs finish\n\nAF_PACKET TX_RING skbs keep a raw pointer to their ring frame. The skb\npage references preserve page-backed ring blocks after pg_vec is freed,\nbut they do not preserve a vmalloc mapping.\n\ntpacket_destruct_skb() currently drops the pending reference before\nwriting the timestamp and TP_STATUS_AVAILABLE to the frame. Move the\ndecrement after those stores. The smp_wmb() in __packet_set_status()\norders the frame stores before the decrement.\n\nAlso recheck pending TX frames under pg_vec_lock before non-closing\nring replacement, so a racing send cannot add a pending skb between\nthe initial check and the ring swap.\n\nRing allocation can produce a mixture of page-backed and vmalloc-backed\nblocks. Allocate deferred-work storage during TX ring setup when the\nfirst vmalloc-backed block is encountered, and keep its pointer in the\npg_vec allocation header. If allocation fails, return -ENOMEM from ring\nsetup. On socket close, a non-NULL pointer identifies a vmalloc-backed\nvector without a scan. If TX skbs remain, defer the whole vector to\nsystem_long_wq.\n\nAfter pg_vec is detached, a late destructor can skip the pending\ndecrement. Use socket write-memory accounting as the deferred lifetime\ngate instead: an skb remains charged through its final sock_wfree(),\nafter all ring-frame accesses. The delayed work retains a socket\nreference and reschedules itself until no TX skbs remain.\n\nMove pending_refcnt release to packet_sock_destruct() so late skb\ndestructors and deferred cleanup can safely use it after\npacket_release(). Page-backed teardown remains synchronous, and no lock\nis added to the TX completion hot path."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/packet/af_packet.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"b013840810c221f2b0cf641d01531526052dc1fb","lessThan":"0189dce07db2dc059ae0570e06758ec4233c6e11","versionType":"git","status":"affected"},{"version":"b013840810c221f2b0cf641d01531526052dc1fb","lessThan":"550d00aa58193fb649a09a9c9e338c685adad784","versionType":"git","status":"affected"},{"version":"b013840810c221f2b0cf641d01531526052dc1fb","lessThan":"992cc9f94ca924089a506ba9b327caa9af797529","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/packet/af_packet.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.14","status":"affected"},{"version":"0","lessThan":"3.14","versionType":"semver","status":"unaffected"},{"version":"7.1.13","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.3","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0189dce07db2dc059ae0570e06758ec4233c6e11","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/550d00aa58193fb649a09a9c9e338c685adad784","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/992cc9f94ca924089a506ba9b327caa9af797529","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80842","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:12.727","lastModified":"2026-09-04T16:18:12.727","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: bridge: mcast: fix use-after-free of a master VLAN's multicast context\n\nbr_multicast_toggle_one_vlan() clears BR_VLFLAG_MCAST_ENABLED under\nbr->multicast_lock before stopping a VLAN's multicast context.  That is\nthe teardown handshake: lockless readers gate on the flag through\nbr_multicast_ctx_should_use() -> br_multicast_ctx_vlan_disabled(), so\nonce it is cleared under the lock no reader can arm the context again.\n\nFor a master VLAN the handshake never runs.  __vlan_del() clears\nBRIDGE_VLAN_INFO_BRENTRY before calling br_vlan_put_master(), so\nbr_multicast_toggle_one_vlan(masterv, false) returns early on\n!br_vlan_is_brentry(vlan): the flag stays set and br->multicast_lock is\nnever taken.  br_vlan_put_master() then drains the context in\nbr_multicast_ctx_deinit() and frees the VLAN through call_rcu(), while a\nreader still inside rcu_read_lock() sees the context as enabled and\nre-arms it.  The port and port-VLAN branch of the function has no\nbr_vlan_is_brentry() test and flips the flag under br->multicast_lock,\nso it is not affected.\n\nThe reader is the bridge transmit path.  For a master VLAN\nbr_multicast_rcv() selects brmctx = &vlan->br_mcast_ctx with\npmctx = NULL, so IGMP sent to the bridge device re-arms the context's\ntimers after br_multicast_ctx_deinit() has already stopped them.\n\n  BUG: KASAN: slab-use-after-free in detach_if_pending+0x412/0x4a0\n  Write of size 8 at addr ffff88810ac39918 by task brmc/601\n   __mod_timer+0x51a/0xc50\n   br_multicast_host_join+0x25b/0x390\n   __br_multicast_add_group+0x468/0x530\n   br_ip4_multicast_add_group+0x1a0/0x260\n   br_multicast_rcv+0x2cda/0x61e0\n   br_dev_xmit+0x6c4/0x1540\n  Allocated by task 610:\n   br_vlan_add+0x111/0xb40\n   br_vlan_info+0x370/0x3e0\n  Freed by task 0:\n   kfree+0x1a7/0x4f0\n   rcu_core+0x7dc/0x10a0\n\nOnly test br_vlan_is_brentry() when enabling, like the\nbr_multicast_ctx_vlan_global_disabled() test next to it.  Disabling then\nalways clears BR_VLFLAG_MCAST_ENABLED under br->multicast_lock before\nbr_multicast_ctx_deinit() drains the context."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/bridge/br_multicast.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7b54aaaf53cb784411426c64482af0435f7c845e","lessThan":"3afaaee2f972aec9059110953adb62fa3cf5c4bd","versionType":"git","status":"affected"},{"version":"7b54aaaf53cb784411426c64482af0435f7c845e","lessThan":"22226a2c3b90f15b0925f1464470d3baa6c5677e","versionType":"git","status":"affected"},{"version":"7b54aaaf53cb784411426c64482af0435f7c845e","lessThan":"7c54fd8cfbcf371a5ef50db5c53fe6e85fb76686","versionType":"git","status":"affected"},{"version":"7b54aaaf53cb784411426c64482af0435f7c845e","lessThan":"3a0ad4fcdfa0b7dba1876de14a12cb65c8b5ca50","versionType":"git","status":"affected"},{"version":"7b54aaaf53cb784411426c64482af0435f7c845e","lessThan":"c069f29da72324697aa4b7cab5b3647a7d24a575","versionType":"git","status":"affected"},{"version":"7b54aaaf53cb784411426c64482af0435f7c845e","lessThan":"3f4752996735e0628af559aa8da1d872c2fac13b","versionType":"git","status":"affected"},{"version":"7b54aaaf53cb784411426c64482af0435f7c845e","lessThan":"57f94d3f4dee8b54d63cefddf1112be4656ef9e6","versionType":"git","status":"affected"},{"version":"7b54aaaf53cb784411426c64482af0435f7c845e","lessThan":"50e5c6605cc9c2dd57bd2d1b3459674d19738983","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/bridge/br_multicast.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.15","status":"affected"},{"version":"0","lessThan":"5.15","versionType":"semver","status":"unaffected"},{"version":"5.15.220","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.187","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.156","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.108","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.49","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.13","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.3","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/22226a2c3b90f15b0925f1464470d3baa6c5677e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3a0ad4fcdfa0b7dba1876de14a12cb65c8b5ca50","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3afaaee2f972aec9059110953adb62fa3cf5c4bd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3f4752996735e0628af559aa8da1d872c2fac13b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/50e5c6605cc9c2dd57bd2d1b3459674d19738983","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/57f94d3f4dee8b54d63cefddf1112be4656ef9e6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7c54fd8cfbcf371a5ef50db5c53fe6e85fb76686","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c069f29da72324697aa4b7cab5b3647a7d24a575","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80843","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:12.877","lastModified":"2026-09-04T16:18:12.877","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: fix xfrm_state_construct() auth-trunc leak\n\nattach_auth_trunc() can allocate x->aalg while leaving\nx->props.aalgo at zero when the selected auth algorithm has no\nsadb_alg_id. One real case is cmac(aes).\n\nxfrm_state_construct() then treats !x->props.aalgo as \"no auth\nalgorithm attached yet\" and calls attach_auth(). That overwrites\nx->aalg and loses the first allocation. Any later failure or teardown\nonly frees the replacement pointer.\n\nCheck whether x->aalg is already attached instead of inferring that\nstate from x->props.aalgo."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/xfrm/xfrm_user.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4447bb33f09444920a8f1d89e1540137429351b6","lessThan":"958ae9f261319e1cdc44879886bcda2263258cca","versionType":"git","status":"affected"},{"version":"4447bb33f09444920a8f1d89e1540137429351b6","lessThan":"fb7f3e74789a3c89647f4eb768f6dfaf4a751e72","versionType":"git","status":"affected"},{"version":"4447bb33f09444920a8f1d89e1540137429351b6","lessThan":"ba0c110c205855b3f1e3130d8c0fdb484d704c8c","versionType":"git","status":"affected"},{"version":"4447bb33f09444920a8f1d89e1540137429351b6","lessThan":"c8837bbe792257af547fd1c0252553ce13148795","versionType":"git","status":"affected"},{"version":"4447bb33f09444920a8f1d89e1540137429351b6","lessThan":"71d42da01740ec6557837bebec0bc48cfc3b4c39","versionType":"git","status":"affected"},{"version":"4447bb33f09444920a8f1d89e1540137429351b6","lessThan":"cf67361e78dca488d6e4df8396a53e6745a3a80e","versionType":"git","status":"affected"},{"version":"4447bb33f09444920a8f1d89e1540137429351b6","lessThan":"37426395cb90ef217beec8407a14bd82153793d3","versionType":"git","status":"affected"},{"version":"4447bb33f09444920a8f1d89e1540137429351b6","lessThan":"be19d20e53a239572bb2a28efcc1cd2b069b1ef9","versionType":"git","status":"affected"},{"version":"4447bb33f09444920a8f1d89e1540137429351b6","lessThan":"c12cbf56320fb633484ee0ca1fb7d68d6b64b213","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/xfrm/xfrm_user.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.33","status":"affected"},{"version":"0","lessThan":"2.6.33","versionType":"semver","status":"unaffected"},{"version":"5.10.269","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.220","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.187","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.156","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.108","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.49","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.13","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.3","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/37426395cb90ef217beec8407a14bd82153793d3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/71d42da01740ec6557837bebec0bc48cfc3b4c39","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/958ae9f261319e1cdc44879886bcda2263258cca","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ba0c110c205855b3f1e3130d8c0fdb484d704c8c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/be19d20e53a239572bb2a28efcc1cd2b069b1ef9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c12cbf56320fb633484ee0ca1fb7d68d6b64b213","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c8837bbe792257af547fd1c0252553ce13148795","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cf67361e78dca488d6e4df8396a53e6745a3a80e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fb7f3e74789a3c89647f4eb768f6dfaf4a751e72","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80844","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:13.023","lastModified":"2026-09-04T16:18:13.023","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: ah6: validate routing header segments_left\n\nAH6 rearranges routing-header addresses before computing or verifying the\nICV. ipv6_rearrange_rthdr() assumes that segments_left is not larger than\nthe number of addresses described by the routing header's hdrlen field.\n\nThat assumption does not hold for raw IPv6 HDRINCL packets. A packet with\nhdrlen equal to 2 describes one address, but can carry an arbitrary\nsegments_left value. With segments_left equal to 255, the function moves\nits address pointer 4,064 bytes backwards and passes a 4,064-byte length to\nmemmove(), resulting in an out-of-bounds access.\n\nValidate the invariant locally before modifying the routing header or\nperforming any address-pointer arithmetic, and propagate malformed-header\nerrors to the existing AH6 input and output error paths."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/ipv6/ah6.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"2dc650956e4e163b879b3fb1027f9557abc5c985","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"48b0e36cf54358276ee7aa897034c973097d2bc9","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"1b7e066eabcc7d6d8f476c34739b45932f2f4c31","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"f00df8500e5a36ba70d336fd34bd2152ea074e5f","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"1516e31ac458a738be485620579d8f7fb2700fcb","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"6733ae71268a27d598cfb3f3339a3c950b9b656d","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"0bf11081ad3753938a2b48723ce6298dbac743a1","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"46640c814f25f096b0b0045ca50e1b7030cd8a30","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"7bad4bda74dc4713f398d3b7624ff05478e3a568","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/ipv6/ah6.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.12","status":"affected"},{"version":"0","lessThan":"2.6.12","versionType":"semver","status":"unaffected"},{"version":"5.10.269","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.220","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.187","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.156","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.108","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.49","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.13","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.3","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0bf11081ad3753938a2b48723ce6298dbac743a1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1516e31ac458a738be485620579d8f7fb2700fcb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1b7e066eabcc7d6d8f476c34739b45932f2f4c31","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2dc650956e4e163b879b3fb1027f9557abc5c985","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/46640c814f25f096b0b0045ca50e1b7030cd8a30","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/48b0e36cf54358276ee7aa897034c973097d2bc9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6733ae71268a27d598cfb3f3339a3c950b9b656d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7bad4bda74dc4713f398d3b7624ff05478e3a568","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f00df8500e5a36ba70d336fd34bd2152ea074e5f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80845","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:13.173","lastModified":"2026-09-04T16:18:13.173","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: avoid lock inversion in nat keepalive work\n\nnat_keepalive_work() walks the state table while xfrm_state_walk()\nholds net->xfrm.xfrm_state_lock. Its callback then acquires x->lock,\nwhich conflicts with the delete path taking the same locks in reverse\norder via xfrm_state_delete() and __xfrm_state_delete(). This creates\nan AB-BA deadlock that is reported by lockdep when a NAT keepalive\nworker races with SA deletion.\n\nFix this by splitting the keepalive walk into two phases. First,\ncollect the candidate states while the walk holds xfrm_state_lock and\ntake a reference on each state. Then, after the walk completes, process\neach collected state and acquire x->lock without nesting it under\nxfrm_state_lock."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/xfrm/xfrm_nat_keepalive.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"f531d13bdfe3f4f084aaa8acae2cb0f02295f5ae","lessThan":"ea09210462316e5235a25eccb11ad0708d86615e","versionType":"git","status":"affected"},{"version":"f531d13bdfe3f4f084aaa8acae2cb0f02295f5ae","lessThan":"5c86c895d1cac81a71ead3005084c6265cf6a7a5","versionType":"git","status":"affected"},{"version":"f531d13bdfe3f4f084aaa8acae2cb0f02295f5ae","lessThan":"89ef3a2e1e4682ab82b0455ce113f8c39fb9e50d","versionType":"git","status":"affected"},{"version":"f531d13bdfe3f4f084aaa8acae2cb0f02295f5ae","lessThan":"a9fa05b7a1246797748d15771052639e0d3cabf1","versionType":"git","status":"affected"},{"version":"f531d13bdfe3f4f084aaa8acae2cb0f02295f5ae","lessThan":"763fe700b7c58ad64fe5202c5638848244dd4127","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/xfrm/xfrm_nat_keepalive.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.11","status":"affected"},{"version":"0","lessThan":"6.11","versionType":"semver","status":"unaffected"},{"version":"6.12.108","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.49","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.13","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.3","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/5c86c895d1cac81a71ead3005084c6265cf6a7a5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/763fe700b7c58ad64fe5202c5638848244dd4127","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/89ef3a2e1e4682ab82b0455ce113f8c39fb9e50d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a9fa05b7a1246797748d15771052639e0d3cabf1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ea09210462316e5235a25eccb11ad0708d86615e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80846","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:13.290","lastModified":"2026-09-04T16:18:13.290","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: drop ESP-in-TCP packets with no ingress device\n\nESP-in-TCP receives records through the TCP strparser. handle_esp()\nrestores skb->dev from the saved skb_iif before passing the packet into\nthe XFRM input path.\n\nQueued TCP data can be processed after the original ingress device has\nbeen removed, for example during veth or net namespace teardown. In that\ncase dev_get_by_index_rcu() returns NULL. The XFRM IPv4 and IPv6 input\npaths both expect skb->dev to be valid while building the route lookup,\nso queued ESP-in-TCP data can dereference a NULL device.\n\nDrop the packet if the saved ingress device can no longer be resolved.\nSuch a packet can no longer be routed through the normal XFRM receive\npath, and this preserves the existing behaviour for packets whose ingress\ndevice still exists."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/xfrm/espintcp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"e27cca96cd68fa2c6814c90f9a1cfd36bb68c593","lessThan":"239d0f71af09dc2029fd4d730cb24b8c83aaa43a","versionType":"git","status":"affected"},{"version":"e27cca96cd68fa2c6814c90f9a1cfd36bb68c593","lessThan":"f00235f9d12301183d61f75fbe4105506f3e5140","versionType":"git","status":"affected"},{"version":"e27cca96cd68fa2c6814c90f9a1cfd36bb68c593","lessThan":"6af5cdb03819a5ce6e945992635c6c5e91045367","versionType":"git","status":"affected"},{"version":"e27cca96cd68fa2c6814c90f9a1cfd36bb68c593","lessThan":"2dd1609cadff46c4b20ce53b91ab9cce1380456a","versionType":"git","status":"affected"},{"version":"e27cca96cd68fa2c6814c90f9a1cfd36bb68c593","lessThan":"c296d25efbc840be24de83f56d43bc47e714ace9","versionType":"git","status":"affected"},{"version":"e27cca96cd68fa2c6814c90f9a1cfd36bb68c593","lessThan":"328e40aa774b446969c69b654c52a051a95af8a1","versionType":"git","status":"affected"},{"version":"e27cca96cd68fa2c6814c90f9a1cfd36bb68c593","lessThan":"7911e0236616487b89db6bd3ba3f408abd10eb23","versionType":"git","status":"affected"},{"version":"e27cca96cd68fa2c6814c90f9a1cfd36bb68c593","lessThan":"943d95233b8b4a88994e244fcf466f8c403d63f1","versionType":"git","status":"affected"},{"version":"e27cca96cd68fa2c6814c90f9a1cfd36bb68c593","lessThan":"e1d7c5ac1c246ce5775f604515de0a59fbf2116e","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/xfrm/espintcp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.6","status":"affected"},{"version":"0","lessThan":"5.6","versionType":"semver","status":"unaffected"},{"version":"5.10.269","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.220","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.187","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.156","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.108","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.49","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.13","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.3","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/239d0f71af09dc2029fd4d730cb24b8c83aaa43a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2dd1609cadff46c4b20ce53b91ab9cce1380456a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/328e40aa774b446969c69b654c52a051a95af8a1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6af5cdb03819a5ce6e945992635c6c5e91045367","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7911e0236616487b89db6bd3ba3f408abd10eb23","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/943d95233b8b4a88994e244fcf466f8c403d63f1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c296d25efbc840be24de83f56d43bc47e714ace9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e1d7c5ac1c246ce5775f604515de0a59fbf2116e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f00235f9d12301183d61f75fbe4105506f3e5140","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80847","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:13.430","lastModified":"2026-09-04T16:18:13.430","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: clamp route advmss to TCP_MIN_MSS\n\ntcp_select_initial_window() assumes that callers never pass an MSS\nsmaller than 1, but route-derived advmss values can violate that\nassumption.\n\nA too-small explicit RTAX_ADVMSS is one way to get there, but it is not\nthe only one. The same divide-by-zero can also be reached through the\n\"default advmss\" path when RTAX_ADVMSS is left at 0 and the effective\nadvmss is later driven down by route MTU and min_adv_mss.\n\nIntroduce a tcp_dst_advmss() helper that clamps route advmss to\nTCP_MIN_MSS before TCP consumes it, and use it in the TCP paths that\nderive advmss from dst metrics. This keeps the effective MSS from\ndropping to zero before tcp_select_initial_window() rounds the receive\nwindow."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["include/net/tcp.h","net/ipv4/tcp_ipv4.c","net/ipv4/tcp_minisocks.c","net/ipv4/tcp_output.c","net/ipv6/tcp_ipv6.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"6b8c20bf61924dfc38fefb145c9f7406d73fae53","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"31cf2349361902769dc323e4dbf4b449795ec288","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"870a9e42ecc6fe1b8c25d87af043cb0d9c178fe1","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["include/net/tcp.h","net/ipv4/tcp_ipv4.c","net/ipv4/tcp_minisocks.c","net/ipv4/tcp_output.c","net/ipv6/tcp_ipv6.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.12","status":"affected"},{"version":"0","lessThan":"2.6.12","versionType":"semver","status":"unaffected"},{"version":"7.1.13","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.3","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/31cf2349361902769dc323e4dbf4b449795ec288","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6b8c20bf61924dfc38fefb145c9f7406d73fae53","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/870a9e42ecc6fe1b8c25d87af043cb0d9c178fe1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80848","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:13.540","lastModified":"2026-09-04T16:18:13.540","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: espintcp: fix UAF during close\n\nZDI reported and analyzed a race condition during close for espintcp\nsockets:\n\n    espintcp_close() frees emsg->skb via kfree_skb() without holding\n    any socket lock. Concurrently, the xfrm_trans_reinject work queue\n    invokes esp_output_tcp_finish() -> espintcp_push_skb() ->\n    espintcp_push_msgs() -> skb_send_sock_locked(), which reads the\n    same skb as a data source.\n\nFix this by adding a synchronize_rcu() call after resetting sk_prot,\nsince esp_output_tcp_finish() runs under RCU and won't use a socket\nwith sk_prot == &tcp_prot.  Simply taking the socket lock in\nespintcp_close() could lead to leaks, if esp_output_tcp_finish()\nre-adds an skb in the slot we just freed. After this, the existing\nbarrier() is no longer needed."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/xfrm/espintcp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"e27cca96cd68fa2c6814c90f9a1cfd36bb68c593","lessThan":"29121c5e6591da527e8e36ddac7120dc527f574d","versionType":"git","status":"affected"},{"version":"e27cca96cd68fa2c6814c90f9a1cfd36bb68c593","lessThan":"ed5d9102190c45fc70121c036b0626b740040b75","versionType":"git","status":"affected"},{"version":"e27cca96cd68fa2c6814c90f9a1cfd36bb68c593","lessThan":"4bc0dfa28dca6fc0084203732695968049c44072","versionType":"git","status":"affected"},{"version":"e27cca96cd68fa2c6814c90f9a1cfd36bb68c593","lessThan":"ff8dd7a932f34409a56e1b91a1219340f17457e9","versionType":"git","status":"affected"},{"version":"e27cca96cd68fa2c6814c90f9a1cfd36bb68c593","lessThan":"4b31a875693c480c611519faca46216514e3e052","versionType":"git","status":"affected"},{"version":"e27cca96cd68fa2c6814c90f9a1cfd36bb68c593","lessThan":"24efebecf415ba264adba0f0491cec436463a14f","versionType":"git","status":"affected"},{"version":"e27cca96cd68fa2c6814c90f9a1cfd36bb68c593","lessThan":"eb3bbf29c723fe75c0eb92be14f0ec92971fe272","versionType":"git","status":"affected"},{"version":"e27cca96cd68fa2c6814c90f9a1cfd36bb68c593","lessThan":"54b41ad14da9a981131ab6e4d3f79321a503ea5d","versionType":"git","status":"affected"},{"version":"e27cca96cd68fa2c6814c90f9a1cfd36bb68c593","lessThan":"deb232e884877bf10b4ce2580909eedec986c284","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/xfrm/espintcp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.6","status":"affected"},{"version":"0","lessThan":"5.6","versionType":"semver","status":"unaffected"},{"version":"5.10.269","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.220","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.187","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.156","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.108","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.49","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.13","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.3","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/24efebecf415ba264adba0f0491cec436463a14f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/29121c5e6591da527e8e36ddac7120dc527f574d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4b31a875693c480c611519faca46216514e3e052","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4bc0dfa28dca6fc0084203732695968049c44072","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/54b41ad14da9a981131ab6e4d3f79321a503ea5d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/deb232e884877bf10b4ce2580909eedec986c284","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/eb3bbf29c723fe75c0eb92be14f0ec92971fe272","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ed5d9102190c45fc70121c036b0626b740040b75","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ff8dd7a932f34409a56e1b91a1219340f17457e9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80849","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:13.683","lastModified":"2026-09-04T16:18:13.683","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/tcp-ao: fix use-after-free of current_key on reconnect to another peer\n\ntcp_inbound_ao_hash() is called before bh_lock_sock_nested() is taken,\nwith only rcu_read_lock() held. On the fast path for established\nsockets, if the rnext_keyid sent by the peer differs from\ncurrent_key->sndid, the key the peer asked for is looked up and stored\nin current_key. The lookup is inside the RCU read side, but current_key\noutlives it.\n\nWhen the socket is disconnected and connect() is called again for\nanother peer, tcp_ao_connect_init() unlinks every key that does not\nmatch the new peer and frees it with call_rcu(). If current_key points\nat such a key, it is cleared to NULL.\n\nThe fast path reads sk_state only once on entry, so a softirq that got\ninto it while the socket was still established can update current_key\nafter that loop has already run. The update is inside the RCU read side,\nso it comes before the call_rcu() callback, and once the callback frees\nthe key, current_key is left pointing at freed memory.\n\nThe next transmission picks that pointer up in tcp_get_current_key().\ntcp_ao_transmit_skb() then reads the traffic key from the freed object,\nwhich is the use-after-free.\n\nWait for one grace period before unlinking, and only if a key is going\nto be removed. By the time tcp_connect() runs the socket is already in\nTCP_SYN_SENT, and TCP_AO_ESTABLISHED does not contain TCPF_SYN_SENT, so\na softirq entering after the wait cannot reach the fast path, and the\nones already in it have finished. The existing NULL handling in the loop\nis then enough."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/ipv4/tcp_ao.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"0a3a809089eb1d4a0a2fd0c16b520d603988c859","lessThan":"84a93b4e012587d0a4a84ffb23ec6da18e9d85f9","versionType":"git","status":"affected"},{"version":"0a3a809089eb1d4a0a2fd0c16b520d603988c859","lessThan":"73fde8fe4469f4ed8f0afcc0b9d6413002a9e6b3","versionType":"git","status":"affected"},{"version":"0a3a809089eb1d4a0a2fd0c16b520d603988c859","lessThan":"e54ad693eddb40c595add013f545354c538e325b","versionType":"git","status":"affected"},{"version":"0a3a809089eb1d4a0a2fd0c16b520d603988c859","lessThan":"2857dcbd03cf3354af0fba1b65c6a260fb43811a","versionType":"git","status":"affected"},{"version":"0a3a809089eb1d4a0a2fd0c16b520d603988c859","lessThan":"da4471557f279d0f56605158a625bb6e49ef7d41","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/ipv4/tcp_ao.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.7","status":"affected"},{"version":"0","lessThan":"6.7","versionType":"semver","status":"unaffected"},{"version":"6.12.108","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.49","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.13","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.3","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2857dcbd03cf3354af0fba1b65c6a260fb43811a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/73fde8fe4469f4ed8f0afcc0b9d6413002a9e6b3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/84a93b4e012587d0a4a84ffb23ec6da18e9d85f9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/da4471557f279d0f56605158a625bb6e49ef7d41","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e54ad693eddb40c595add013f545354c538e325b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80850","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:13.813","lastModified":"2026-09-04T16:18:13.813","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: fix AO info use-after-free in tcp_ao_connect_init()\n\ntcp_v4_connect() adds a SYN-SENT socket to the ehash before calling\ntcp_connect().  If TCP-AO is configured, tcp_connect() first verifies that\na key matches the peer and the bound device's current L3 master.\ntcp_ao_connect_init() later resolves the L3 master again and removes keys\nwhich do not match it.\n\nThe socket lock does not stabilize the bound device's VRF membership.\nDetaching the device from its VRF between the initial validation and the\nL3-master calculation in tcp_ao_connect_init() can therefore make the\nvalidation succeed while initialization observes the default L3 domain and\nremoves the only key.  The subsequent AO lookup then fails, so the no-key\npath clears tp->ao_info and frees it directly.\n\nThe receive path can find the socket in the ehash and load tp->ao_info\nunder RCU before acquiring the socket lock.  A reader which loaded the old\npointer can thus continue into tcp_inbound_ao_hash() after the direct free.\n\nThe issue was found during a static audit of TCP-AO object lifetime.  An\nunprivileged reproducer in self-created user and network namespaces raced\nconnect() with detaching a veth from its VRF while sending TCP-AO segments.\nIt triggered the same KASAN report on two fresh boots:\n\n  BUG: KASAN: slab-use-after-free in tcp_inbound_ao_hash+0x585/0x19f0\n  Write of size 8 at addr ffff88800bf88128 by task tcp_ao_vrf_race/232\n\n  Call Trace:\n   tcp_inbound_ao_hash+0x585/0x19f0\n   tcp_inbound_hash+0x677/0xa80\n   tcp_v4_rcv+0x1c3e/0x3ab0\n\n  Allocated by task 235:\n   tcp_ao_alloc_info+0x43/0xf0\n   tcp_ao_add_cmd+0xdf7/0x13b0\n   do_tcp_setsockopt+0x168c/0x2640\n\n  Freed by task 235:\n   kfree+0x1b8/0x550\n   tcp_connect+0x252/0x4f00\n   tcp_v4_connect+0x1114/0x1720\n\nThe bad address is 40 bytes inside the freed 128-byte object, matching the\ntcp_ao_info counters.key_not_found field.  The two runs used 1000 attempts\neach, reached the no-key path 366 and 411 times, and produced one and two\nKASAN reports respectively.  With this change, the same reproducer reached\nthe no-key path 366 times in 1000 attempts without a KASAN report or oops.\n\nUse tcp_ao_destroy_sock() for the no-key path.  It unpublishes the AO info,\nupdates the socket memory and static-key accounting, and defers the free\nuntil after an RCU grace period.\n\nAlso drop the WARN_ON_ONCE() and its stale comment.  The VRF detach race\nmakes the no-key state reachable during normal operation, so it is a\nhandled condition rather than an impossible assertion.  On panic_on_warn\nkernels the WARN would turn this handled race into a kernel panic."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/ipv4/tcp_ao.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"248411b8cb8974a1e1c8e43123c1e682fbd64969","lessThan":"594ba77210a1f065832211851a2d7e14d11fcbdb","versionType":"git","status":"affected"},{"version":"248411b8cb8974a1e1c8e43123c1e682fbd64969","lessThan":"70051a57786d5b23f059fbaf5c8241eca14d42ed","versionType":"git","status":"affected"},{"version":"248411b8cb8974a1e1c8e43123c1e682fbd64969","lessThan":"284d7fd0eec8774bd6214921fbf525cf907c590e","versionType":"git","status":"affected"},{"version":"248411b8cb8974a1e1c8e43123c1e682fbd64969","lessThan":"d17e88b6b60ff4ef64e0dd1444f935cb13dee1cd","versionType":"git","status":"affected"},{"version":"248411b8cb8974a1e1c8e43123c1e682fbd64969","lessThan":"ea30dc5267e367b8a5e1e06cc074f813bcbf18b2","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/ipv4/tcp_ao.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.7","status":"affected"},{"version":"0","lessThan":"6.7","versionType":"semver","status":"unaffected"},{"version":"6.12.108","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.49","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.13","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.3","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/284d7fd0eec8774bd6214921fbf525cf907c590e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/594ba77210a1f065832211851a2d7e14d11fcbdb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/70051a57786d5b23f059fbaf5c8241eca14d42ed","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d17e88b6b60ff4ef64e0dd1444f935cb13dee1cd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ea30dc5267e367b8a5e1e06cc074f813bcbf18b2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80851","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:13.950","lastModified":"2026-09-04T16:18:13.950","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ngtp: serialize PDP context updates\n\nPDP contexts can be deleted through GTP_CMD_DELPDP or while the GTP\nnetwork device is being unregistered. The latter is serialized by RTNL,\nbut the generic-netlink delete path only holds RCU.\n\nRunning both paths concurrently can therefore make both paths delete the\nsame PDP context. The issue was found through static analysis and\nreproduced on a KASAN-enabled kernel by a simple two-thread program\nracing GTP_CMD_DELPDP against RTM_DELLINK:\n\n  Oops: general protection fault, probably for non-canonical address\n  KASAN: maybe wild-memory-access in range\n         [0xdead000000000120-0xdead000000000127]\n  RIP: gtp_genl_del_pdp+0x1c1/0x420 [gtp]\n  RBP: dead000000000122\n\nThe second deletion dereferenced the poisoned hlist pprev pointer.\n\nSerialize gtp_pdp_add(), gtp_genl_del_pdp(), and gtp_dellink() with a\nshared mutex. Keep the mutex held until the final use of a PDP context in\nthe NEWPDP path, and keep the RCU read-side section around the complete\nPDP context use in the DELPDP path."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/gtp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"459aa660eb1d8ce67080da1983bb81d716aa5a69","lessThan":"5f77ddb2756340c1b05381674ca025d52998005e","versionType":"git","status":"affected"},{"version":"459aa660eb1d8ce67080da1983bb81d716aa5a69","lessThan":"3d950e98f74af9611925a5226edced02155f6ed1","versionType":"git","status":"affected"},{"version":"459aa660eb1d8ce67080da1983bb81d716aa5a69","lessThan":"6df4f05bc2991467939d7d80b6f7e121559cc3df","versionType":"git","status":"affected"},{"version":"459aa660eb1d8ce67080da1983bb81d716aa5a69","lessThan":"1e995498d29784a06a2b2899370a1926cfc8410d","versionType":"git","status":"affected"},{"version":"459aa660eb1d8ce67080da1983bb81d716aa5a69","lessThan":"498386b6d402737db1e2eeed4c385acbf0ef9e34","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/gtp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.7","status":"affected"},{"version":"0","lessThan":"4.7","versionType":"semver","status":"unaffected"},{"version":"6.12.108","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.49","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.13","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.3","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1e995498d29784a06a2b2899370a1926cfc8410d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3d950e98f74af9611925a5226edced02155f6ed1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/498386b6d402737db1e2eeed4c385acbf0ef9e34","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5f77ddb2756340c1b05381674ca025d52998005e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6df4f05bc2991467939d7d80b6f7e121559cc3df","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80852","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:14.073","lastModified":"2026-09-04T16:18:14.073","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ntls: device: fix out-of-bounds write in tls_append_frag()\n\nFound with syzkaller and a local syzbot instance running on top of a\nnetdevsim TLS offload emulation; tls_device.c is otherwise only reachable\non a machine with a NIC that implements the offload.\n\ntls_push_data() only checks whether the open record still has room for\nanother frag at the bottom of its loop, and the MSG_MORE early break\nskips that check.  The record survives to the next syscall with the frag\ncount it already had, and tls_append_frag() does not check either, so\nwith TLS_TX_ZEROCOPY_RO every splice(SPLICE_F_MORE) of a byte or two adds\na non-coalescing pipe page and num_frags walks off the end of\ntls_record_info.frags[MAX_SKB_FRAGS].  Once the record is pushed,\ntls_push_record() runs the same index over sg_tx_data[MAX_SKB_FRAGS] and\nthe sg_set_page() writes land on the destruct_work that follows it, which\nthe workqueue then calls.\n\nThe byte limit is fine because copy drops to 0 and the loop falls through\nto the same check; the frag count has no such feedback.\n\nPush the record rather than keep a full one open, which is what a plain\nTCP socket does - tcp_sendmsg_locked() uses tcp_mark_push() and\nnew_segment in both the copy and the MSG_SPLICE_PAGES paths, and tls_sw\nalready sets full_record when the sk_msg ring fills up, MSG_MORE or not.\n\n  BUG: KASAN: slab-out-of-bounds in tls_append_frag ( net/tls/tls_device.c:269)\n  Write of size 8 at addr ffff8881104d1530 by task tls_oob/450\n\n  CPU: 2 UID: 0 PID: 450 Comm: tls_oob Not tainted 7.2.0-rc7+ #329 PREEMPT\n  Call Trace:\n   <TASK>\n   dump_stack_lvl (lib/dump_stack.c:94 lib/dump_stack.c:120)\n   print_report (mm/kasan/report.c:378 mm/kasan/report.c:482)\n   kasan_report (mm/kasan/report.c:595)\n   tls_append_frag (net/tls/tls_device.c:269)\n   tls_push_data (net/tls/tls_device.c:518)\n   tls_device_sendmsg (net/tls/tls_device.c:583)\n   inet_sendmsg (net/ipv4/af_inet.c:865)\n   sock_sendmsg (net/socket.c:775 net/socket.c:790 net/socket.c:813)\n   splice_to_socket (fs/splice.c:884)\n   do_splice (fs/splice.c:936 fs/splice.c:1349)\n   __do_splice (fs/splice.c:1431)\n   __x64_sys_splice (fs/splice.c:1634 fs/splice.c:1616)\n   do_syscall_64 (arch/x86/entry/syscall_64.c:63 arch/x86/entry/syscall_64.c:94)\n   entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)\n   </TASK>\n\nand, once the record is pushed:\n\n  UBSAN: array-index-out-of-bounds in net/tls/tls_device.c:300:24\n  index 18 is out of range for type 'skb_frag_t [17]'\n  UBSAN: array-index-out-of-bounds in net/tls/tls_device.c:301:41\n  index 18 is out of range for type 'scatterlist [17]'\n  UBSAN: array-index-out-of-bounds in net/tls/tls_device.c:302:39\n  index 18 is out of range for type 'scatterlist [17]'\n  UBSAN: array-index-out-of-bounds in net/tls/tls_device.c:307:38\n  index 26 is out of range for type 'scatterlist [17]'\n\n  kernel tried to execute NX-protected page - exploit attempt? (uid: 0)\n  BUG: unable to handle page fault for address: ffffea000411a680\n  #PF: supervisor instruction fetch in kernel mode\n  #PF: error_code(0x0011) - permissions violation\n  Oops: Oops: 0011 [#1] SMP KASAN PTI\n  Workqueue: ktls_device_destruct 0xffffea000411a680\n  RIP: 0010:0xffffea000411a680\n  Call Trace:\n   <TASK>\n   worker_thread (kernel/workqueue.c:3405 kernel/workqueue.c:3486)\n   kthread (kernel/kthread.c:436)\n   ret_from_fork (arch/x86/kernel/process.c:158)\n   ret_from_fork_asm (arch/x86/entry/entry_64.S:245)\n   </TASK>"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/tls/tls_device.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"e8f69799810c32dd40c6724d829eccc70baad07f","lessThan":"03ced5da6120965d80ed56dbb7d78fa5c9128906","versionType":"git","status":"affected"},{"version":"e8f69799810c32dd40c6724d829eccc70baad07f","lessThan":"a832d7cb09da2a8e4e9734b4be14d3e76169d805","versionType":"git","status":"affected"},{"version":"e8f69799810c32dd40c6724d829eccc70baad07f","lessThan":"b7f10d4ff987bda038df90052cd4a1434a7412d4","versionType":"git","status":"affected"},{"version":"e8f69799810c32dd40c6724d829eccc70baad07f","lessThan":"fadbc1ed2a872a8649a44cf9e1cf9621fc58cd6e","versionType":"git","status":"affected"},{"version":"e8f69799810c32dd40c6724d829eccc70baad07f","lessThan":"cd7e875b89597f3498917af764758391338d1802","versionType":"git","status":"affected"},{"version":"e8f69799810c32dd40c6724d829eccc70baad07f","lessThan":"7e1208c135618358da5d7d6664874dc6e53c62fc","versionType":"git","status":"affected"},{"version":"e8f69799810c32dd40c6724d829eccc70baad07f","lessThan":"b17cf742eaad70ae29ac558cefb3aa9bbeea03d4","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/tls/tls_device.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.18","status":"affected"},{"version":"0","lessThan":"4.18","versionType":"semver","status":"unaffected"},{"version":"6.1.187","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.156","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.108","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.49","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.13","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.3","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/03ced5da6120965d80ed56dbb7d78fa5c9128906","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7e1208c135618358da5d7d6664874dc6e53c62fc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a832d7cb09da2a8e4e9734b4be14d3e76169d805","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b17cf742eaad70ae29ac558cefb3aa9bbeea03d4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b7f10d4ff987bda038df90052cd4a1434a7412d4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cd7e875b89597f3498917af764758391338d1802","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fadbc1ed2a872a8649a44cf9e1cf9621fc58cd6e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80853","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:14.233","lastModified":"2026-09-04T16:18:14.233","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: SEV: Allocate full pages for {DE,EN}CRYPT ops on SNP-enabled hosts\n\nWhen {de,en}crypting memory of an SEV or SEV-ES guest on an SNP-enabled\nhost via a temporary buffer, allocate a full 4KiB page for the buffer to\nensure the page containing the buffer is wholly owned by KVM, i.e. won't\nbe concurrently allocated and accessed by other kernel code while KVM is\nusing the buffer to {de,en}crypt memory.  On SNP-enabled platforms, when\nsending SEV/SEV-ES commands that trigger firmware writes to memory, the\nto-be-written page(s) must be (temporarily) assigned to Firmware (as\nrequired by the SNP architecture, to guard against using such commands as\ngadgets to attack SNP guests).  See snp_map_cmd_buf_desc() and friends.\n\nUnfortunately, transferring ownership of a page to Firmware makes the page\ninaccessible to software, and thus writes generate RMP #PF violations.  If\nKVM uses a sub-page allocation for its temporary buffer, some other actor\nin the kernel can allocate and use the other portions of the page, and thus\ntrigger unexpected (and seemingly spurious) RMP #PF violations due to\nsoftware attempting to access a Firmware-owned page.\n\n  BUG: unable to handle page fault for address: ffff906ae30f0300\n  #PF: supervisor write access in kernel mode\n  #PF: error_code(0x80000003) - RMP violation\n  PGD 6b1b80d067 P4D 6b1b80d067 PUD 100231e2063 PMD 10055a88063 PTE 80000100630f0163\n  SEV-SNP: PFN 0x100630f0 unassigned, dumping non-zero entries in 2M PFN region: [0x10063000 - 0x10063200]\n  Oops: Oops: 0003 [#1] SMP\n  CPU: 70 UID: 0 PID: 10658 Comm: svw_WaiterThrea Tainted: G     U  W  O        7.1.0-smp--c22293789940-seanjc-next #1 PREEMPTLAZY\n  Tainted: [U]=USER, [W]=WARN, [O]=OOT_MODULE\n  Hardware name: Google, Inc.                                                       Arcadia_IT_80/Arcadia_IT_80, BIOS 34.86.0-102 01/25/2026\n  RIP: 0010:memset+0xf/0x20\n  Call Trace:\n   <TASK>\n   __kvmalloc_node_noprof+0x2a4/0x710\n   do_getxattr+0x4e/0x130\n   path_getxattrat+0x125/0x1b0\n   do_syscall_64+0x10a/0x480\n   entry_SYSCALL_64_after_hwframe+0x4b/0x53\n  RIP: 0033:0x7f3a22cb6daa\n   </TASK>\n  Modules linked in: kvm_amd kvm irqbypass vfat fat ccp k10temp sha3 libsha3 i2c_piix4 gq(O) cdc_acm xhci_pci xhci_hcd\n  gsmi: Log Shutdown Reason 0x03\n  CR2: ffff906ae30f0300\n  ---[ end trace 0000000000000000 ]---\n  RIP: 0010:memset+0xf/0x20\n  Kernel panic - not syncing: Fatal exception\n  Kernel Offset: 0x39e00000 from 0xffffffff81000000 (relocation range: 0xffffffff80000000-0xffffffffbfffffff)\n  gsmi: Log Shutdown Reason 0x02"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["arch/x86/kvm/svm/sev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4c735bf1bc22fd6ee66ab4bffe1d7599c3964781","lessThan":"97f6402f5950ca3450541287c4b3664f3acda976","versionType":"git","status":"affected"},{"version":"4c735bf1bc22fd6ee66ab4bffe1d7599c3964781","lessThan":"a33c40b93ccf5177e042253807d40e0b92e7f206","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["arch/x86/kvm/svm/sev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.2","status":"affected"},{"version":"0","lessThan":"7.2","versionType":"semver","status":"unaffected"},{"version":"7.2.3","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/97f6402f5950ca3450541287c4b3664f3acda976","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a33c40b93ccf5177e042253807d40e0b92e7f206","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80854","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:14.353","lastModified":"2026-09-04T16:18:14.353","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: f_tcm: keep port count until LUN teardown completes\n\ntcm_usbg_drop_nexus() permits session removal once tpg_port_count\nreaches zero. However, usbg_port_unlink() currently decrements that\ncount from the fabric_pre_unlink() callback, before core_dev_del_lun()\nwaits for active se_lun references to drain.\n\nIf removal of the last LUN races a nexus removal, the latter can observe\na zero port count and call target_remove_session(). This frees\nsess_cmd_map while an in-flight struct usbg_cmd, including its work item,\ncan still be accessed.\n\nOverlapping the last-LUN unlink with nexus removal reproduces this\nlifetime violation as a DEBUG_OBJECTS \"free active\" warning for\nusbg_cmd_work, followed by a target-core BUG/Oops.\n\nThe generic target-core unlink path has no callback after\ncore_dev_del_lun() completes. Add an optional fabric_post_unlink()\ncallback and use it for the f_tcm port count. The count now remains\nnonzero until core_dev_del_lun() has finished draining active LUN\nreferences, preventing nexus removal from freeing the session during\ncommand completion."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/target/target_core_fabric_configfs.c","drivers/usb/gadget/function/f_tcm.c","include/target/target_core_fabric.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"c52661d60f636d17e26ad834457db333bd1df494","lessThan":"c494c5562ca69b61a82f566e3b87a445d2c28929","versionType":"git","status":"affected"},{"version":"c52661d60f636d17e26ad834457db333bd1df494","lessThan":"c1f359d9a5efed458946063de65ddbeaacc4f165","versionType":"git","status":"affected"},{"version":"c52661d60f636d17e26ad834457db333bd1df494","lessThan":"178f59a0bccd3f66cdfa5184310f31a58b7257c4","versionType":"git","status":"affected"},{"version":"c52661d60f636d17e26ad834457db333bd1df494","lessThan":"ad6f0375d2e93a1d8c015463e5e92dfcb26e311b","versionType":"git","status":"affected"},{"version":"c52661d60f636d17e26ad834457db333bd1df494","lessThan":"2efbfd42441d3ef8137aff2d59e9835e1d5ae780","versionType":"git","status":"affected"},{"version":"c52661d60f636d17e26ad834457db333bd1df494","lessThan":"85aa61fedcb4eb13f3dc5db73f6dc359f41f5d95","versionType":"git","status":"affected"},{"version":"c52661d60f636d17e26ad834457db333bd1df494","lessThan":"bbd6aa311a9f4dd17822c7557451458d3d2e980b","versionType":"git","status":"affected"},{"version":"c52661d60f636d17e26ad834457db333bd1df494","lessThan":"eaa96a8458f54d6cf0954242ab8b1df2a6fccafa","versionType":"git","status":"affected"},{"version":"c52661d60f636d17e26ad834457db333bd1df494","lessThan":"c39d0916da47d94909391876c9e5bd429ea7b1b9","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/target/target_core_fabric_configfs.c","drivers/usb/gadget/function/f_tcm.c","include/target/target_core_fabric.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.5","status":"affected"},{"version":"0","lessThan":"3.5","versionType":"semver","status":"unaffected"},{"version":"5.10.269","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.220","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.187","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.156","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.108","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.49","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.13","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.3","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/178f59a0bccd3f66cdfa5184310f31a58b7257c4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2efbfd42441d3ef8137aff2d59e9835e1d5ae780","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/85aa61fedcb4eb13f3dc5db73f6dc359f41f5d95","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ad6f0375d2e93a1d8c015463e5e92dfcb26e311b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bbd6aa311a9f4dd17822c7557451458d3d2e980b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c1f359d9a5efed458946063de65ddbeaacc4f165","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c39d0916da47d94909391876c9e5bd429ea7b1b9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c494c5562ca69b61a82f566e3b87a445d2c28929","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/eaa96a8458f54d6cf0954242ab8b1df2a6fccafa","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80855","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:14.507","lastModified":"2026-09-04T16:18:14.507","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfuse: fix invalidate lock leak on open O_TRUNC DAX failure\n\nfuse_open() takes filemap_invalidate_lock() for a DAX truncate\n(dax_truncate = true) and releases it before the out_inode_unlock\nlabel.  But when fuse_dax_break_layouts() fails, the goto\nout_inode_unlock skips the unlock and leaks the rwsem, so any later\nfault or truncate on the file stalls on the stale lock.\n\nfuse_dax_break_layouts() can fail with -ERESTARTSYS when a signal\ninterrupts the wait for busy DAX pages to drain:\n\n  open(\"file\", O_RDWR | O_TRUNC)\n  └─ fuse_open()\n     ├─ filemap_invalidate_lock()        # dax_truncate\n     └─ fuse_dax_break_layouts()\n        └─ dax_break_layout()\n           └─ wait_page_idle()           # TASK_INTERRUPTIBLE\n              └─ fuse_wait_dax_page()    # unlock, schedule, re-lock\n                 └─ signal → -ERESTARTSYS\n     goto out_inode_unlock               # <- lock leaked\n\nFix this by moving filemap_invalidate_unlock() below the label so\nthat all error paths release the lock, and rename the label to\nout_unlock as it now covers more than just the inode lock."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/fuse/file.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"d58366aab86854217b81679d1a9dcd54a2edfc2a","lessThan":"1b04d80a27d317064cce2307472f5bef9975bc50","versionType":"git","status":"affected"},{"version":"2fdbb8dd01556e1501132b5ad3826e8f71e24a8b","lessThan":"a61524da59a2f5ac9c8de23ff98b30da769ab144","versionType":"git","status":"affected"},{"version":"2fdbb8dd01556e1501132b5ad3826e8f71e24a8b","lessThan":"dcf30a56624c2a0cfab1bada5b1ca8cc0c02f010","versionType":"git","status":"affected"},{"version":"2fdbb8dd01556e1501132b5ad3826e8f71e24a8b","lessThan":"7288c279ddbd654a06c82118c1a3f5570c1807f0","versionType":"git","status":"affected"},{"version":"2fdbb8dd01556e1501132b5ad3826e8f71e24a8b","lessThan":"776e85fda752f9a15e0f82dec42ecacd12a9bd94","versionType":"git","status":"affected"},{"version":"2fdbb8dd01556e1501132b5ad3826e8f71e24a8b","lessThan":"1d3e701cda2f41d48aa721b3ebefbe0fbf8d74da","versionType":"git","status":"affected"},{"version":"2fdbb8dd01556e1501132b5ad3826e8f71e24a8b","lessThan":"e981474d7bf1457da12404e169ea147d2c8ecea7","versionType":"git","status":"affected"},{"version":"2fdbb8dd01556e1501132b5ad3826e8f71e24a8b","lessThan":"a927f1867e61b78f39f9da0bbba3c98c2ca151fe","versionType":"git","status":"affected"},{"version":"81775ab858b4236c52c5da7e25cec6e49dd91b46","versionType":"git","status":"affected"},{"version":"b57e150ac2eac791d5d187923b73dc2dafaf67fa","versionType":"git","status":"affected"},{"version":"1fdbbe246daf348adaa0739463384b16ceba1fc0","versionType":"git","status":"affected"},{"version":"5.15.109","lessThan":"5.15.220","versionType":"semver","status":"affected"},{"version":"5.10.179","lessThan":"5.11","versionType":"semver","status":"affected"},{"version":"5.18.18","lessThan":"5.19","versionType":"semver","status":"affected"},{"version":"5.19.2","lessThan":"5.20","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/fuse/file.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.0","status":"affected"},{"version":"0","lessThan":"6.0","versionType":"semver","status":"unaffected"},{"version":"5.15.220","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.187","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.156","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.108","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.49","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.13","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.3","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1b04d80a27d317064cce2307472f5bef9975bc50","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1d3e701cda2f41d48aa721b3ebefbe0fbf8d74da","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7288c279ddbd654a06c82118c1a3f5570c1807f0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/776e85fda752f9a15e0f82dec42ecacd12a9bd94","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a61524da59a2f5ac9c8de23ff98b30da769ab144","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a927f1867e61b78f39f9da0bbba3c98c2ca151fe","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dcf30a56624c2a0cfab1bada5b1ca8cc0c02f010","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e981474d7bf1457da12404e169ea147d2c8ecea7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80856","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:14.660","lastModified":"2026-09-04T16:18:14.660","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfuse: fix invalidate lock leak on setattr writeback failure\n\nfuse_do_setattr() takes filemap_invalidate_lock() for a DAX truncate\n(fault_blocked = true) and releases it at the out:/error: labels.  But\nwhen a writeback flush is also needed, a write_inode_now() failure\nreturns directly and leaks the lock, so any later fault or truncate on\nthe file stalls on the stale rwsem.\n\nFor example, truncate(2) on a setuid file reaches fuse_do_setattr()\nwith both ATTR_SIZE and ATTR_MODE set:\n\n  truncate(2)\n  └─ do_truncate()\n     ├─ dentry_needs_remove_privs()         # S_ISUID\n     └─ notify_change()                     # KILL_SUID -> ATTR_MODE\n        └─ fuse_setattr()                   # no killpriv:\n           │                                #   ia_valid |= ATTR_MODE\n           └─ fuse_do_setattr()\n              ├─ filemap_invalidate_lock()  # IS_DAX && is_truncate\n              └─ write_inode_now()          # is_wb && ATTR_MODE\n                 └─ if (err)                # e.g. daemon -> -EIO\n                    return err              # <- lock leaked\n\nFix this by adding an unlock label that releases the lock before\nreturning the error, and use it for the fuse_dax_break_layouts()\nfailure path as well."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/fuse/dir.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6ae330cad6ef22ab8347ea9e0707dc56a7c7363f","lessThan":"8f14906ce9103ab8f2f1ebda45935a0d61b9d763","versionType":"git","status":"affected"},{"version":"6ae330cad6ef22ab8347ea9e0707dc56a7c7363f","lessThan":"03cfeeb135428fa83f0791d3f8f94d9298cae695","versionType":"git","status":"affected"},{"version":"6ae330cad6ef22ab8347ea9e0707dc56a7c7363f","lessThan":"92588d187ba4697a322e7aefe5d9e538a87d1cd2","versionType":"git","status":"affected"},{"version":"6ae330cad6ef22ab8347ea9e0707dc56a7c7363f","lessThan":"ea9fea370b8de4ffd72e0ef89550415c15637787","versionType":"git","status":"affected"},{"version":"6ae330cad6ef22ab8347ea9e0707dc56a7c7363f","lessThan":"1758730d9eaa3c06cf415c3446d9f6eed9ed3eed","versionType":"git","status":"affected"},{"version":"6ae330cad6ef22ab8347ea9e0707dc56a7c7363f","lessThan":"dd278d954c0e96a9cbd3cc491e07b8267d25f8d5","versionType":"git","status":"affected"},{"version":"6ae330cad6ef22ab8347ea9e0707dc56a7c7363f","lessThan":"e8457ebfd77a46e8d1210e8888ea914ad064558e","versionType":"git","status":"affected"},{"version":"6ae330cad6ef22ab8347ea9e0707dc56a7c7363f","lessThan":"9afeca0d569c9fc89d758fe7a9339d1e8afb1546","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/fuse/dir.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.10","status":"affected"},{"version":"0","lessThan":"5.10","versionType":"semver","status":"unaffected"},{"version":"5.15.220","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.187","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.156","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.108","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.49","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.13","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.3","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/03cfeeb135428fa83f0791d3f8f94d9298cae695","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1758730d9eaa3c06cf415c3446d9f6eed9ed3eed","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8f14906ce9103ab8f2f1ebda45935a0d61b9d763","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/92588d187ba4697a322e7aefe5d9e538a87d1cd2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9afeca0d569c9fc89d758fe7a9339d1e8afb1546","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dd278d954c0e96a9cbd3cc491e07b8267d25f8d5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e8457ebfd77a46e8d1210e8888ea914ad064558e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ea9fea370b8de4ffd72e0ef89550415c15637787","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80857","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:14.810","lastModified":"2026-09-04T16:18:14.810","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfuse: wait for FR_FINISHED on abort_on_kill to prevent use-after-free\n\nThe abort_on_kill path in request_wait_answer() calls fuse_abort_conn()\nand returns without waiting for FR_FINISHED.  If fuse_dev_do_write() is\nconcurrently processing the same request (FR_LOCKED set), the caller\nfrees req->args while it is still being accessed, causing a\nuse-after-free.\n\nFix this by jumping to the existing wait_event(FR_FINISHED) instead of\nreturning early.  The wait will not hang because fuse_abort_conn()\nensures all requests are ended."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/fuse/dev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"204aa22a686bfee48daca7db620c1e017615f2ff","lessThan":"715cb86e33cda43f5224cdc3fd5610c0b6a46f7a","versionType":"git","status":"affected"},{"version":"204aa22a686bfee48daca7db620c1e017615f2ff","lessThan":"64b0b5cacbd2fea88001464cb712c9dfc795b26e","versionType":"git","status":"affected"},{"version":"0c7fca880a40a209a9c92be14143996d14b93ff6","versionType":"git","status":"affected"},{"version":"300e812b882a174dca675d8028684001ad5826bc","versionType":"git","status":"affected"},{"version":"6.18.25","lessThan":"6.19","versionType":"semver","status":"affected"},{"version":"7.0.2","lessThan":"7.1","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/fuse/dev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1","status":"affected"},{"version":"0","lessThan":"7.1","versionType":"semver","status":"unaffected"},{"version":"7.2.3","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/64b0b5cacbd2fea88001464cb712c9dfc795b26e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/715cb86e33cda43f5224cdc3fd5610c0b6a46f7a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80858","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:14.940","lastModified":"2026-09-04T16:18:14.940","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfuse: publish io-uring queues with release semantics\n\nfuse_uring_create_queue() initializes a fuse_ring_queue and then\npublishes the pointer into ring->queues[qid] with WRITE_ONCE() under the\nfch->lock. There are several readers that may concurrently be fetching\nthat pointer locklessly and then deferencing it.\n\nWRITE_ONCE() doesn't ensure ordering of the queue's field\ninitialization before the ring->queues[qid] pointer assignment. The\nqueue must be published with smp_store_release() so the field\ninitialization is guaranteed to happen before.\n\nReaders in paths where the read may happen concurrently with the store\nneed to use READ_ONCE() because any race involving a plain access is\nundefined."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/fuse/dev_uring.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"24fe962c86f55347385933a1b06ca71b60854690","lessThan":"a1bb359c443d048fe5dfd6ca9caf4e3897f3e9aa","versionType":"git","status":"affected"},{"version":"24fe962c86f55347385933a1b06ca71b60854690","lessThan":"42df916e5a5f8fb4b60c8cefb54318d1ec02c580","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/fuse/dev_uring.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.14","status":"affected"},{"version":"0","lessThan":"6.14","versionType":"semver","status":"unaffected"},{"version":"7.2.3","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/42df916e5a5f8fb4b60c8cefb54318d1ec02c580","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a1bb359c443d048fe5dfd6ca9caf4e3897f3e9aa","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80859","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:15.070","lastModified":"2026-09-04T16:18:15.070","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfuse: fix missing barrier when checking io-uring readiness\n\nfuse_block_alloc() reads fch->initialized and then fch->io_uring.\nfch->io_uring is set before fch->initialized, ordered by the smp_wmb()\nin fuse_chan_set_intialized(), but fuse_block_alloc() has no matching\nread barrier between the two loads.\n\nThis may lead a CPU to observe fch->initialized=1 but fch->io_uring=0,\nand skip the check that blocks request allocation until the io-uring\nqueues are ready. This can reintroduce the lock-order inversion deadlock\nthat commit 3393ff964e0f prevents.\n\nAdd an smp_rmb() barrier to pair with the smp_wmb() in\nfuse_chan_set_initialized() to prevent this."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/fuse/dev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3393ff964e0fa5def66570c54a4612bf9df06b76","lessThan":"dd9c835709f4bb3e4256eea7573e4e6e18f956de","versionType":"git","status":"affected"},{"version":"3393ff964e0fa5def66570c54a4612bf9df06b76","lessThan":"edb310bc27f0ad83e7fd558a3caf1a94ca511654","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/fuse/dev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.14","status":"affected"},{"version":"0","lessThan":"6.14","versionType":"semver","status":"unaffected"},{"version":"7.2.3","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/dd9c835709f4bb3e4256eea7573e4e6e18f956de","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/edb310bc27f0ad83e7fd558a3caf1a94ca511654","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80860","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:15.173","lastModified":"2026-09-04T16:18:15.173","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nfuse: fix race between interrupt and resend\n\nAfter commit f8fce75fedf7 (\"fuse: clear intr_entry in fuse_resend and\nfuse_remove_pending_req\") the WARN_ON(!list_empty(&req->intr_entry)) in\nfuse_request_free() still triggers due to the following race:\n\nIn request_wait_answer()\n  if (test_bit(FR_SENT, &req->flags)) -> returns true\n\nIn fuse_chan_resend()\n  clear_bit(FR_SENT, &req->flags)\n\nIn request_wait_answer()\n  queue_interrupt(req)\n\nFix by:\n\n - move clearing FR_SENT inside fpq->lock\n\n - move setting FR_PENDING inside fiq->lock\n\n - recheck FR_SENT after acquiring fiq->lock in fuse_dev_queue_interrupt()"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/fuse/dev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"f8fce75fedf73ac72aa09163deb8f4291fdcaad2","lessThan":"26fbe4bc3ef3ab0200407681cbef182af5d151de","versionType":"git","status":"affected"},{"version":"f8fce75fedf73ac72aa09163deb8f4291fdcaad2","lessThan":"ed9c881f3b498383f73c42712b359419da42a7b0","versionType":"git","status":"affected"},{"version":"1d8ecd0cd696a5df0b2f72046a4ccee5d2a8ec2c","versionType":"git","status":"affected"},{"version":"7366e6f4d2b4c7002b13fb01219e83679dad4127","versionType":"git","status":"affected"},{"version":"893479015cb6442fd389d3b553ab3036c9541715","versionType":"git","status":"affected"},{"version":"6.12.96","lessThan":"6.13","versionType":"semver","status":"affected"},{"version":"6.18.39","lessThan":"6.19","versionType":"semver","status":"affected"},{"version":"7.1.4","lessThan":"7.2","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/fuse/dev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.2","status":"affected"},{"version":"0","lessThan":"7.2","versionType":"semver","status":"unaffected"},{"version":"7.2.3","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/26fbe4bc3ef3ab0200407681cbef182af5d151de","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ed9c881f3b498383f73c42712b359419da42a7b0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80861","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:15.290","lastModified":"2026-09-04T16:18:15.290","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: xhci: bail out of setup if the controller is inaccessible\n\nxhci_gen_setup() locates the operational registers using the capability\nlength read from the very first register:\n\n\txhci->op_regs = hcd->regs +\n\t\tHC_LENGTH(readl(&xhci->cap_regs->hc_capbase));\n\nIf the controller is dead or has dropped off the bus, that read returns\n~0, HC_LENGTH() truncates it to 0xff, and op_regs ends up 0xff bytes\npast the page-aligned MMIO base, i.e. unaligned. The first access\nthrough it, xhci_halt() -> xhci_handshake() reading op_regs->status, is\nthen an unaligned readl() on device memory. arm64 faults on unaligned\ndevice accesses, so instead of xhci_handshake() catching the all-ones\nvalue and returning -ENODEV, setup oopses:\n\n  xhci-pci-renesas 0005:08:00.0: Unable to change power state from D3cold to D0, device inaccessible\n  xhci-pci-renesas 0005:08:00.0: xHCI Host Controller\n  xhci-pci-renesas 0005:08:00.0: new USB bus registered, assigned bus number 1\n  Unable to handle kernel paging request at virtual address ffff80030a770103\n    ESR = 0x0000000096000021\n    FSC = 0x21: alignment fault\n  Internal error: Oops: 0000000096000021 [#1]  SMP\n  pc : xhci_halt [xhci_hcd]\n  Call trace:\n   xhci_halt\n   xhci_gen_setup\n   xhci_pci_setup\n   usb_add_hcd\n   usb_hcd_pci_probe\n   xhci_pci_common_probe\n   xhci_pci_renesas_probe\n\nThis was hit with a Renesas uPD720201 that failed to power up (\"Unable\nto change power state from D3cold to D0, device inaccessible\") yet still\nreached the HCD probe path.\n\nRead the capability register once, and if it reads back the all-ones\nvalue (as xhci_handshake() and xhci_reset() already test for), abort\nsetup with -ENODEV before op_regs is derived from it. Reading it once\nalso avoids re-reading a register that may change under a concurrent\nhot-removal."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/usb/host/xhci.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"66d4eadd8d067269ea8fead1a50fe87c2979a80d","lessThan":"bf84c6b0264947794fa783c324a6d874ca6657d8","versionType":"git","status":"affected"},{"version":"66d4eadd8d067269ea8fead1a50fe87c2979a80d","lessThan":"0b31744f70c5e06cce5fb660e02d057a3b9e0e37","versionType":"git","status":"affected"},{"version":"66d4eadd8d067269ea8fead1a50fe87c2979a80d","lessThan":"78203d5b54a40f0e36196ebf31c9c7a380fc8811","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/usb/host/xhci.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.31","status":"affected"},{"version":"0","lessThan":"2.6.31","versionType":"semver","status":"unaffected"},{"version":"7.1.13","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.3","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0b31744f70c5e06cce5fb660e02d057a3b9e0e37","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/78203d5b54a40f0e36196ebf31c9c7a380fc8811","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bf84c6b0264947794fa783c324a6d874ca6657d8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80862","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:15.420","lastModified":"2026-09-04T16:18:15.420","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnvme-tcp: fix usage of page_frag_cache\n\nnvme uses page_frag_cache to preallocate PDU for each preallocated request\nof block device. Block devices are created in parallel threads,\nconsequently page_frag_cache is used in not thread-safe manner.\nThat leads to incorrect refcounting of backstore pages and premature free.\n\nThat can be catched by !sendpage_ok inside network stack:\n\nWARNING: CPU: 7 PID: 467 at ../net/core/skbuff.c:6931 skb_splice_from_iter+0xfa/0x310.\n\ttcp_sendmsg_locked+0x782/0xce0\n\ttcp_sendmsg+0x27/0x40\n\tsock_sendmsg+0x8b/0xa0\n\tnvme_tcp_try_send_cmd_pdu+0x149/0x2a0\nThen random panic may occur.\n\nFix that by serializing the usage of page_frag_cache."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/nvme/host/tcp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4e893ca8117022de68ce1b61c0309e3d17bb8a25","lessThan":"d19f98c79f1b7e09e4cdf5c20d626e571e487467","versionType":"git","status":"affected"},{"version":"4e893ca8117022de68ce1b61c0309e3d17bb8a25","lessThan":"64561afb42d8390695bf810d9bbd087cbca00291","versionType":"git","status":"affected"},{"version":"4e893ca8117022de68ce1b61c0309e3d17bb8a25","lessThan":"0a9750263ffacbbd2048a391fd4bd22e2146c57d","versionType":"git","status":"affected"},{"version":"4e893ca8117022de68ce1b61c0309e3d17bb8a25","lessThan":"6e4cf281558709b92ec2ca3054fe2ffc69266ef9","versionType":"git","status":"affected"},{"version":"4e893ca8117022de68ce1b61c0309e3d17bb8a25","lessThan":"36ac05f7cfd59d90c597071304b14e98090d5dd1","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/nvme/host/tcp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.12","status":"affected"},{"version":"0","lessThan":"6.12","versionType":"semver","status":"unaffected"},{"version":"6.12.108","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.49","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.13","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.3","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0a9750263ffacbbd2048a391fd4bd22e2146c57d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/36ac05f7cfd59d90c597071304b14e98090d5dd1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/64561afb42d8390695bf810d9bbd087cbca00291","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6e4cf281558709b92ec2ca3054fe2ffc69266ef9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d19f98c79f1b7e09e4cdf5c20d626e571e487467","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80863","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:15.560","lastModified":"2026-09-04T16:18:15.560","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/rxe: Fix OOB in free_rd_atomic_resources()\n\nfree_rd_atomic_resources() iterates using qp->attr.max_dest_rd_atomic.\nUpdating max_dest_rd_atomic before freeing the old array can make the\nfree path walk past the old allocation and trigger a slab out-of-bounds\nwrite catched by KASAN:\n==================================================================\nBUG: KASAN: slab-out-of-bounds in free_rd_atomic_resource drivers/infiniband/sw/rxe/rxe_qp.c:180 [inline]\nBUG: KASAN: slab-out-of-bounds in free_rd_atomic_resources drivers/infiniband/sw/rxe/rxe_qp.c:171 [inline]\nBUG: KASAN: slab-out-of-bounds in free_rd_atomic_resources drivers/infiniband/sw/rxe/rxe_qp.c:163 [inline]\nBUG: KASAN: slab-out-of-bounds in rxe_qp_from_attr+0x1e88/0x2150 drivers/infiniband/sw/rxe/rxe_qp.c:712\nWrite of size 4 at addr ffff88802b8dddb8 by task syz.3.451/11063\n\nCPU: 0 UID: 0 PID: 11063 Comm: syz.3.451 Not tainted 7.1.0 #2 PREEMPT(full)\nHardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_caps fix, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014\nCall Trace:\n <TASK>\n __dump_stack lib/dump_stack.c:94 [inline]\n dump_stack_lvl+0x10e/0x1f0 lib/dump_stack.c:120\n print_address_description mm/kasan/report.c:378 [inline]\n print_report+0xf7/0x600 mm/kasan/report.c:482\n kasan_report+0xe4/0x120 mm/kasan/report.c:595\n free_rd_atomic_resource drivers/infiniband/sw/rxe/rxe_qp.c:180 [inline]\n free_rd_atomic_resources drivers/infiniband/sw/rxe/rxe_qp.c:171 [inline]\n free_rd_atomic_resources drivers/infiniband/sw/rxe/rxe_qp.c:163 [inline]\n rxe_qp_from_attr+0x1e88/0x2150 drivers/infiniband/sw/rxe/rxe_qp.c:712\n rxe_modify_qp+0x1e2/0x530 drivers/infiniband/sw/rxe/rxe_verbs.c:623\n ib_security_modify_qp+0x223/0xfa0 drivers/infiniband/core/security.c:625\n _ib_modify_qp+0x333/0xec0 drivers/infiniband/core/verbs.c:1915\n modify_qp+0x13ca/0x1940 drivers/infiniband/core/uverbs_cmd.c:1932\n ib_uverbs_modify_qp+0xcb/0x120 drivers/infiniband/core/uverbs_cmd.c:1958\n ib_uverbs_write+0xb86/0x1030 drivers/infiniband/core/uverbs_main.c:680\n vfs_write+0x2aa/0x1070 fs/read_write.c:686\n ksys_write+0x1f8/0x250 fs/read_write.c:740\n do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]\n do_syscall_64+0x116/0x800 arch/x86/entry/syscall_64.c:94\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\nRIP: 0033:0x7fefc75a70cd\nCode: ff c3 66 2e 0f 1f 84 00 00 00 00 00 90 f3 0f 1e fa 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b0 ff ff ff f7 d8 64 89 01 48\nRSP: 002b:00007fefc8495018 EFLAGS: 00000246 ORIG_RAX: 0000000000000001\nRAX: ffffffffffffffda RBX: 00007fefc7835fa0 RCX: 00007fefc75a70cd\nRDX: 0000000000000078 RSI: 0000200000000240 RDI: 0000000000000007\nRBP: 00007fefc764f10f R08: 0000000000000000 R09: 0000000000000000\nR10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000\nR13: 00007fefc7836038 R14: 00007fefc7835fa0 R15: 00007ffcf0586aa0\n </TASK>\n\nAllocated by task 11063:\n kasan_save_stack+0x33/0x60 mm/kasan/common.c:57\n kasan_save_track+0x14/0x30 mm/kasan/common.c:78\n poison_kmalloc_redzone mm/kasan/common.c:398 [inline]\n __kasan_kmalloc+0xaa/0xb0 mm/kasan/common.c:415\n kasan_kmalloc include/linux/kasan.h:263 [inline]\n __do_kmalloc_node mm/slub.c:5296 [inline]\n __kmalloc_noprof+0x32a/0x850 mm/slub.c:5308\n kmalloc_noprof include/linux/slab.h:954 [inline]\n kzalloc_noprof include/linux/slab.h:1188 [inline]\n alloc_rd_atomic_resources drivers/infiniband/sw/rxe/rxe_qp.c:155 [inline]\n rxe_qp_from_attr+0x3f8/0x2150 drivers/infiniband/sw/rxe/rxe_qp.c:714\n rxe_modify_qp+0x1e2/0x530 drivers/infiniband/sw/rxe/rxe_verbs.c:623\n ib_security_modify_qp+0x223/0xfa0 drivers/infiniband/core/security.c:625\n _ib_modify_qp+0x333/0xec0 drivers/infiniband/core/verbs.c:1915\n modify_qp+0x13ca/0x1940 drivers/infiniband/core/uverbs_cmd.c:1932\n ib_uverbs_modify_qp+0xcb/0x120 drivers/infiniband/core/uverbs_cmd.c:1958\n ib_uverbs_write+0xb86/0x1030 drivers/infiniband/core/uverbs_ma\n---truncated---"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/infiniband/sw/rxe/rxe_qp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"b6bbee0d2438a2c9c7525f5bd7047a8b2ce4f38f","lessThan":"142c8165b7974b40fa62c393653edb5c00b8b5fe","versionType":"git","status":"affected"},{"version":"b6bbee0d2438a2c9c7525f5bd7047a8b2ce4f38f","lessThan":"30b90b55201902b2b8edcdbe2315ccd4c7547002","versionType":"git","status":"affected"},{"version":"b6bbee0d2438a2c9c7525f5bd7047a8b2ce4f38f","lessThan":"9b7d66ea88ae9395e42766b94a5c717b158b940a","versionType":"git","status":"affected"},{"version":"b6bbee0d2438a2c9c7525f5bd7047a8b2ce4f38f","lessThan":"f5e6580a3a16a83c743ad5a7c16922854a0d8b71","versionType":"git","status":"affected"},{"version":"b6bbee0d2438a2c9c7525f5bd7047a8b2ce4f38f","lessThan":"bc6e943794515d2a8417b02597a27bd377468d04","versionType":"git","status":"affected"},{"version":"b6bbee0d2438a2c9c7525f5bd7047a8b2ce4f38f","lessThan":"bdf5deccfbf9f556a08d1d2ef52e9e48f969e53e","versionType":"git","status":"affected"},{"version":"b6bbee0d2438a2c9c7525f5bd7047a8b2ce4f38f","lessThan":"4e5f753e8c280278c09f68fe728abf846e2bdfc1","versionType":"git","status":"affected"},{"version":"b6bbee0d2438a2c9c7525f5bd7047a8b2ce4f38f","lessThan":"d219e7a8eed3802970c3e4d243d79c70ef0a31bf","versionType":"git","status":"affected"},{"version":"b6bbee0d2438a2c9c7525f5bd7047a8b2ce4f38f","lessThan":"de329533792a373186d79dca1ca120f8fa0afd05","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/infiniband/sw/rxe/rxe_qp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.9","status":"affected"},{"version":"0","lessThan":"4.9","versionType":"semver","status":"unaffected"},{"version":"5.10.269","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.220","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.187","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.156","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.108","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.49","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.13","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.3","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/142c8165b7974b40fa62c393653edb5c00b8b5fe","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/30b90b55201902b2b8edcdbe2315ccd4c7547002","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4e5f753e8c280278c09f68fe728abf846e2bdfc1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9b7d66ea88ae9395e42766b94a5c717b158b940a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bc6e943794515d2a8417b02597a27bd377468d04","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bdf5deccfbf9f556a08d1d2ef52e9e48f969e53e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d219e7a8eed3802970c3e4d243d79c70ef0a31bf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/de329533792a373186d79dca1ca120f8fa0afd05","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f5e6580a3a16a83c743ad5a7c16922854a0d8b71","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80864","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T16:18:15.737","lastModified":"2026-09-04T16:18:15.737","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/rxe: Fix responder UAF on IB_QP_MAX_DEST_RD_ATOMIC modify_qp\n\nrxe_qp_from_attr() handles IB_QP_MAX_DEST_RD_ATOMIC outside the\nIB_QP_STATE path, so it holds no state_lock and runs while the responder\ntask rxe_receiver() (recv_task on rxe_wq) is live. A modify_qp() setting\nonly that attribute calls free_rd_atomic_resources() then\nalloc_rd_atomic_resources(), swapping qp->resp.resources[] while\nrxe_prepare_res()/find_resource() walk it; free_rd_atomic_resources()\nalso leaves the cached pointer qp->resp.res dangling. A local\nunprivileged user can race the free/realloc into a use-after-free in\nrxe_receiver() (local DoS).\n\nDrain recv_task around the swap with rxe_disable_task()/rxe_enable_task(),\nas rxe_qp_reset() already does when tearing this array down, re-enabling\nonly after alloc_rd_atomic_resources() succeeds so the responder never\nresumes against a NULL qp->resp.resources on the ENOMEM path. Also clear\nqp->resp.res in free_rd_atomic_resources(), like the rxe_resp.c\ncompletion paths.\n\nReproduced under KASAN; the slab-use-after-free in rxe_receiver() is gone."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/infiniband/sw/rxe/rxe_qp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"8700e3e7c4857d28ebaa824509934556da0b3e76","lessThan":"0136b528b753c5a56e4d997ef20b86bb6750b8fb","versionType":"git","status":"affected"},{"version":"8700e3e7c4857d28ebaa824509934556da0b3e76","lessThan":"ffa4f0be69656be1755090f02db38d49816585c6","versionType":"git","status":"affected"},{"version":"8700e3e7c4857d28ebaa824509934556da0b3e76","lessThan":"d4cd32eb8bd2b0ffbdc7b1f3d82ce6a371f8f844","versionType":"git","status":"affected"},{"version":"8700e3e7c4857d28ebaa824509934556da0b3e76","lessThan":"60dfd47929cd1e7070daa810d40ce538d888410d","versionType":"git","status":"affected"},{"version":"8700e3e7c4857d28ebaa824509934556da0b3e76","lessThan":"6f7014237405e7f032b5c53a82d9eccf6161c291","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/infiniband/sw/rxe/rxe_qp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.8","status":"affected"},{"version":"0","lessThan":"4.8","versionType":"semver","status":"unaffected"},{"version":"6.12.108","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.49","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.13","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2.3","lessThanOrEqual":"7.2.*","versionType":"semver","status":"unaffected"},{"version":"7.3-rc1","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0136b528b753c5a56e4d997ef20b86bb6750b8fb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/60dfd47929cd1e7070daa810d40ce538d888410d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6f7014237405e7f032b5c53a82d9eccf6161c291","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d4cd32eb8bd2b0ffbdc7b1f3d82ce6a371f8f844","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ffa4f0be69656be1755090f02db38d49816585c6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-82911","sourceIdentifier":"4daa8cea-433a-44bd-9456-53b127fc289a","published":"2026-09-04T16:18:16.313","lastModified":"2026-09-04T20:17:30.113","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Cross-Site Request Forgery (CSRF) in the OrderConfirmController at GET /order/confirm/{order_number} in Roskus Prospero Flow CRM before 5.15.11 allows an unauthenticated attacker to confirm any order on behalf of an authenticated user by directing them to a crafted page. Laravel's VerifyCsrfToken middleware enforces CSRF tokens only on POST, PUT, PATCH, and DELETE requests; the Route::get declaration leaves this state-changing action unprotected. Session cookies configured with SameSite=Lax are automatically included in top-level cross-site navigation, so a single link click triggers OrderConfirmController::confirm() and transitions the target order from pending to confirmed without user authorization. Because order numbers are sequential integers, an attacker can enumerate and confirm all existing orders in a single automated sweep."}],"affected":[{"source":"4daa8cea-433a-44bd-9456-53b127fc289a","affectedData":[{"vendor":"Roskus","product":"Prospero Flow CRM","defaultStatus":"unaffected","cpes":["cpe:2.3:a:roskus:prospero_flow_crm:*:*:*:*:*:*:*:*"],"modules":["Order"],"programFiles":["routes/module/order.php","resources/views/order/index.blade.php","app/Http/Controllers/Order/OrderConfirmController.php"],"repo":"https://github.com/Roskus/prospero-flow-crm","versions":[{"version":"0","lessThan":"5.15.11","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"4daa8cea-433a-44bd-9456-53b127fc289a","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":5.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"ACTIVE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T19:31:22.351871Z","id":"CVE-2026-82911","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"4daa8cea-433a-44bd-9456-53b127fc289a","type":"Secondary","description":[{"lang":"en","value":"CWE-352"}]}],"references":[{"url":"https://github.com/Roskus/prospero-flow-crm/commit/a90c0c8c","source":"4daa8cea-433a-44bd-9456-53b127fc289a"},{"url":"https://secur0.com/en/cna/cve-list/cve-2026-82911-csrf-order-confirmation-prospero-flow-crm","source":"4daa8cea-433a-44bd-9456-53b127fc289a"}]}},{"cve":{"id":"CVE-2026-85730","sourceIdentifier":"security-advisories@github.com","published":"2026-09-04T16:18:23.417","lastModified":"2026-09-04T18:18:07.040","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"smol-toml is a small, fast, and correct TOML parser and serializer. Prior to 1.7.1, parse() can enter an infinite loop when a value inside an array or inline table is followed by a comment with no trailing newline. In src/util.ts, skipUntil() calls indexOfNewline(), receives -1 at the end of input, and resets the cursor to the beginning of the string instead of leaving the structure scan. The parser then hangs indefinitely and can consume a service's processing capacity when an application parses attacker-controlled TOML. This issue is fixed in version 1.7.1."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"squirrelchat","product":"smol-toml","versions":[{"version":"< 1.7.1","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T17:40:28.815540Z","id":"CVE-2026-85730","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-606"},{"lang":"en","value":"CWE-835"}]}],"references":[{"url":"https://github.com/squirrelchat/smol-toml/commit/30f5c367d946b695f379b5d4f0946b2f0a0a8c2f","source":"security-advisories@github.com"},{"url":"https://github.com/squirrelchat/smol-toml/releases/tag/v1.7.1","source":"security-advisories@github.com"},{"url":"https://github.com/squirrelchat/smol-toml/security/advisories/GHSA-7w5x-hrqm-74c2","source":"security-advisories@github.com"},{"url":"https://github.com/squirrelchat/smol-toml/security/advisories/GHSA-7w5x-hrqm-74c2","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}]}},{"cve":{"id":"CVE-2026-13297","sourceIdentifier":"psirt@us.ibm.com","published":"2026-09-04T17:16:51.573","lastModified":"2026-09-04T17:16:51.573","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"IBM Verify Identity Access Advanced Access Control may be vulnerable to an information disclosure attack."}],"affected":[{"source":"psirt@us.ibm.com","affectedData":[{"vendor":"IBM","product":"Verify Identity Access","cpes":["cpe:2.3:a:ibm:verify_identity_access:11.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:verify_identity_access:11.0.3:interim_fix_001:*:*:*:*:*:*"],"versions":[{"version":"11.0.0","lessThanOrEqual":"11.0.3 Interim Fix 001","versionType":"semver","status":"affected"}]},{"vendor":"IBM","product":"Security Verify Access","cpes":["cpe:2.3:a:ibm:security_verify_access:10.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:security_verify_access:10.0.9.2:interim_fix_001:*:*:*:*:*:*"],"versions":[{"version":"10.0.0","lessThanOrEqual":"10.0.9.2 Interim Fix 001","versionType":"semver","status":"affected"}]},{"vendor":"IBM","product":"Verify Identity Access Container","cpes":["cpe:2.3:a:ibm:verify_identity_access_container:11.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:verify_identity_access_container:11.0.3:interim_fix_001:*:*:*:*:*:*"],"versions":[{"version":"11.0.0","lessThanOrEqual":"11.0.3 Interim Fix 001","versionType":"semver","status":"affected"}]},{"vendor":"IBM","product":"Security Verify Access Container","cpes":["cpe:2.3:a:ibm:security_verify_access_container:10.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:security_verify_access_container:10.0.9.2:interim_fix_001:*:*:*:*:*:*"],"versions":[{"version":"10.0.0","lessThanOrEqual":"10.0.9.2 Interim Fix 001","versionType":"semver","status":"affected"}]}]}],"metrics":{},"weaknesses":[{"source":"psirt@us.ibm.com","type":"Primary","description":[{"lang":"en","value":"CWE-1336"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7286188","source":"psirt@us.ibm.com"}]}},{"cve":{"id":"CVE-2026-14350","sourceIdentifier":"psirt@us.ibm.com","published":"2026-09-04T17:16:51.710","lastModified":"2026-09-04T18:17:48.043","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"IBM Cloud Pak for Data System 11.3.0.2 through Interim Fix 001 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files."}],"affected":[{"source":"psirt@us.ibm.com","affectedData":[{"vendor":"IBM","product":"Cloud Pak for Data System","cpes":["cpe:2.3:a:ibm:cloud_pak_for_data_system:11.3.0.2:*:*:*:*:*:*:*","cpe:2.3:a:ibm:cloud_pak_for_data_system:interim:interim_fix_001:*:*:*:*:*:*"],"versions":[{"version":"11.3.0.2","lessThanOrEqual":"Interim Fix 001","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T17:26:41.510422Z","id":"CVE-2026-14350","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"psirt@us.ibm.com","type":"Secondary","description":[{"lang":"en","value":"CWE-117"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7286036","source":"psirt@us.ibm.com"}]}},{"cve":{"id":"CVE-2026-14470","sourceIdentifier":"psirt@us.ibm.com","published":"2026-09-04T17:16:51.847","lastModified":"2026-09-04T17:16:51.847","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"IBM Langflow OSS 1.0.0 through 1.10.2 could allow an authenticated attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing \"dot dot\" sequences (/../) to view arbitrary files on the system."}],"affected":[{"source":"psirt@us.ibm.com","affectedData":[{"vendor":"IBM","product":"Langflow OSS","cpes":["cpe:2.3:a:ibm:langflow_oss:1.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:langflow_oss:1.10.2:*:*:*:*:*:*:*"],"versions":[{"version":"1.0.0","lessThanOrEqual":"1.10.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}]},"weaknesses":[{"source":"psirt@us.ibm.com","type":"Primary","description":[{"lang":"en","value":"CWE-22"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7286293","source":"psirt@us.ibm.com"}]}},{"cve":{"id":"CVE-2026-16180","sourceIdentifier":"psirt@us.ibm.com","published":"2026-09-04T17:16:51.977","lastModified":"2026-09-04T18:17:48.167","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 Toolkit could allow an authenticated user to cause a denial-of-service condition due to improper validation of XML entities."}],"affected":[{"source":"psirt@us.ibm.com","affectedData":[{"vendor":"IBM","product":"App Connect Enterprise","cpes":["cpe:2.3:a:ibm:app_connect_enterprise:13.0.1.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:app_connect_enterprise:13.0.8.1:*:*:*:*:*:*:*","cpe:2.3:a:ibm:app_connect_enterprise:12.0.1.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:app_connect_enterprise:12.0.12.28:*:*:*:*:*:*:*"],"versions":[{"version":"13.0.1.0","lessThanOrEqual":"13.0.8.1","versionType":"semver","status":"affected"},{"version":"12.0.1.0","lessThanOrEqual":"12.0.12.28","versionType":"semver","status":"affected"}]},{"vendor":"IBM","product":"Integration Bus for z/OS","cpes":["cpe:2.3:a:ibm:integration_bus_for_zos:10.1.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:integration_bus_for_zos:10.1.0.7:*:*:*:*:*:*:*"],"versions":[{"version":"10.1.0.0","lessThanOrEqual":"10.1.0.7","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H","baseScore":5.7,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.1,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T17:32:10.822397Z","id":"CVE-2026-16180","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"psirt@us.ibm.com","type":"Secondary","description":[{"lang":"en","value":"CWE-776"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7286372","source":"psirt@us.ibm.com"}]}},{"cve":{"id":"CVE-2026-16660","sourceIdentifier":"psirt@us.ibm.com","published":"2026-09-04T17:16:52.117","lastModified":"2026-09-04T17:16:52.117","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to cause a denial of service due to an out-of-bounds read."}],"affected":[{"source":"psirt@us.ibm.com","affectedData":[{"vendor":"IBM","product":"Db2 Mirror for i","cpes":["cpe:2.3:a:ibm:db2_mirror_for_i:7.4:*:*:*:*:*:*:*","cpe:2.3:a:ibm:db2_mirror_for_i:7.4.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:db2_mirror_for_i:7.5:*:*:*:*:*:*:*","cpe:2.3:a:ibm:db2_mirror_for_i:7.5.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:db2_mirror_for_i:7.6:*:*:*:*:*:*:*","cpe:2.3:a:ibm:db2_mirror_for_i:7.6.0:*:*:*:*:*:*:*"],"versions":[{"version":"7.4","status":"affected"},{"version":"7.5","status":"affected"},{"version":"7.6","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":1.4}]},"weaknesses":[{"source":"psirt@us.ibm.com","type":"Primary","description":[{"lang":"en","value":"CWE-125"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7285904","source":"psirt@us.ibm.com"}]}},{"cve":{"id":"CVE-2026-16689","sourceIdentifier":"psirt@us.ibm.com","published":"2026-09-04T17:16:52.250","lastModified":"2026-09-04T17:16:52.250","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to obtain sensitive information due to improper logging of credentials."}],"affected":[{"source":"psirt@us.ibm.com","affectedData":[{"vendor":"IBM","product":"App Connect Enterprise","cpes":["cpe:2.3:a:ibm:app_connect_enterprise:13.0.1.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:app_connect_enterprise:13.0.8.1:*:*:*:*:*:*:*","cpe:2.3:a:ibm:app_connect_enterprise:12.0.1.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:app_connect_enterprise:12.0.12.28:*:*:*:*:*:*:*"],"versions":[{"version":"13.0.1.0","lessThanOrEqual":"13.0.8.1","versionType":"semver","status":"affected"},{"version":"12.0.1.0","lessThanOrEqual":"12.0.12.28","versionType":"semver","status":"affected"}]},{"vendor":"IBM","product":"Integration Bus for z/OS","cpes":["cpe:2.3:a:ibm:integration_bus_for_zos:10.1.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:integration_bus_for_zos:10.1.0.7:*:*:*:*:*:*:*"],"versions":[{"version":"10.1.0.0","lessThanOrEqual":"10.1.0.7","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":6.2,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.5,"impactScore":3.6}]},"weaknesses":[{"source":"psirt@us.ibm.com","type":"Primary","description":[{"lang":"en","value":"CWE-532"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7286372","source":"psirt@us.ibm.com"}]}},{"cve":{"id":"CVE-2026-16693","sourceIdentifier":"psirt@us.ibm.com","published":"2026-09-04T17:16:52.390","lastModified":"2026-09-04T18:17:48.443","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to the use of hardcoded cryptographic constants to obfuscate encryption keys."}],"affected":[{"source":"psirt@us.ibm.com","affectedData":[{"vendor":"IBM","product":"i","cpes":["cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*"],"versions":[{"version":"7.6","status":"affected"},{"version":"7.5","status":"affected"},{"version":"7.4","status":"affected"},{"version":"7.3","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N","baseScore":4.4,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":0.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T17:27:02.751732Z","id":"CVE-2026-16693","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"psirt@us.ibm.com","type":"Secondary","description":[{"lang":"en","value":"CWE-327"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7285846","source":"psirt@us.ibm.com"}]}},{"cve":{"id":"CVE-2026-16826","sourceIdentifier":"psirt@us.ibm.com","published":"2026-09-04T17:16:52.517","lastModified":"2026-09-04T17:16:52.517","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command."}],"affected":[{"source":"psirt@us.ibm.com","affectedData":[{"vendor":"IBM","product":"i","cpes":["cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*"],"versions":[{"version":"7.6","status":"affected"},{"version":"7.5","status":"affected"},{"version":"7.4","status":"affected"},{"version":"7.3","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":1.8,"impactScore":3.4}]},"weaknesses":[{"source":"psirt@us.ibm.com","type":"Primary","description":[{"lang":"en","value":"CWE-78"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7285844","source":"psirt@us.ibm.com"}]}},{"cve":{"id":"CVE-2026-16892","sourceIdentifier":"psirt@us.ibm.com","published":"2026-09-04T17:16:52.643","lastModified":"2026-09-04T18:17:48.733","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper authentication during service-name matching."}],"affected":[{"source":"psirt@us.ibm.com","affectedData":[{"vendor":"IBM","product":"i","cpes":["cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*"],"versions":[{"version":"7.6","status":"affected"},{"version":"7.5","status":"affected"},{"version":"7.4","status":"affected"},{"version":"7.3","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T17:31:49.062435Z","id":"CVE-2026-16892","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"psirt@us.ibm.com","type":"Secondary","description":[{"lang":"en","value":"CWE-287"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7285843","source":"psirt@us.ibm.com"}]}},{"cve":{"id":"CVE-2026-16941","sourceIdentifier":"psirt@us.ibm.com","published":"2026-09-04T17:16:52.770","lastModified":"2026-09-04T17:16:52.770","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"IBM i 7.6, 7.5, and 7.4 could allow a remote authenticated attacker to modify certain system messages due to improper authorization."}],"affected":[{"source":"psirt@us.ibm.com","affectedData":[{"vendor":"IBM","product":"i","cpes":["cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*"],"versions":[{"version":"7.6","status":"affected"},{"version":"7.5","status":"affected"},{"version":"7.4","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}]},"weaknesses":[{"source":"psirt@us.ibm.com","type":"Primary","description":[{"lang":"en","value":"CWE-863"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7285848","source":"psirt@us.ibm.com"}]}},{"cve":{"id":"CVE-2026-17057","sourceIdentifier":"psirt@us.ibm.com","published":"2026-09-04T17:16:52.893","lastModified":"2026-09-04T17:16:52.893","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and affect data integrity due to missing authentication for critical functions."}],"affected":[{"source":"psirt@us.ibm.com","affectedData":[{"vendor":"IBM","product":"i","cpes":["cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*"],"versions":[{"version":"7.6","status":"affected"},{"version":"7.5","status":"affected"},{"version":"7.4","status":"affected"},{"version":"7.3","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":2.5}]},"weaknesses":[{"source":"psirt@us.ibm.com","type":"Primary","description":[{"lang":"en","value":"CWE-306"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7285847","source":"psirt@us.ibm.com"}]}},{"cve":{"id":"CVE-2026-17207","sourceIdentifier":"psirt@us.ibm.com","published":"2026-09-04T17:16:53.020","lastModified":"2026-09-04T18:17:48.863","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and compromise integrity due to a buffer overflow."}],"affected":[{"source":"psirt@us.ibm.com","affectedData":[{"vendor":"IBM","product":"i","cpes":["cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*"],"versions":[{"version":"7.6","status":"affected"},{"version":"7.5","status":"affected"},{"version":"7.4","status":"affected"},{"version":"7.3","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":2.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T17:27:40.270608Z","id":"CVE-2026-17207","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"psirt@us.ibm.com","type":"Secondary","description":[{"lang":"en","value":"CWE-787"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7285847","source":"psirt@us.ibm.com"}]}},{"cve":{"id":"CVE-2026-17255","sourceIdentifier":"psirt@us.ibm.com","published":"2026-09-04T17:16:53.140","lastModified":"2026-09-04T17:16:53.140","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper validation of the prefix length in ICMPv6 Router Advertisements."}],"affected":[{"source":"psirt@us.ibm.com","affectedData":[{"vendor":"IBM","product":"i","cpes":["cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*"],"versions":[{"version":"7.6","status":"affected"},{"version":"7.5","status":"affected"},{"version":"7.4","status":"affected"},{"version":"7.3","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4}]},"weaknesses":[{"source":"psirt@us.ibm.com","type":"Primary","description":[{"lang":"en","value":"CWE-787"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7286093","source":"psirt@us.ibm.com"}]}},{"cve":{"id":"CVE-2026-17259","sourceIdentifier":"psirt@us.ibm.com","published":"2026-09-04T17:16:53.267","lastModified":"2026-09-04T18:17:48.973","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a stack-based buffer overflow."}],"affected":[{"source":"psirt@us.ibm.com","affectedData":[{"vendor":"IBM","product":"i","cpes":["cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*"],"versions":[{"version":"7.6","status":"affected"},{"version":"7.5","status":"affected"},{"version":"7.4","status":"affected"},{"version":"7.3","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T17:31:24.664667Z","id":"CVE-2026-17259","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"psirt@us.ibm.com","type":"Secondary","description":[{"lang":"en","value":"CWE-121"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7285844","source":"psirt@us.ibm.com"}]}},{"cve":{"id":"CVE-2026-17270","sourceIdentifier":"psirt@us.ibm.com","published":"2026-09-04T17:16:53.400","lastModified":"2026-09-04T17:16:53.400","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to cause a denial of service due to a stack-based buffer overflow."}],"affected":[{"source":"psirt@us.ibm.com","affectedData":[{"vendor":"IBM","product":"i","cpes":["cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*"],"versions":[{"version":"7.6","status":"affected"},{"version":"7.5","status":"affected"},{"version":"7.4","status":"affected"},{"version":"7.3","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4}]},"weaknesses":[{"source":"psirt@us.ibm.com","type":"Primary","description":[{"lang":"en","value":"CWE-121"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7285844","source":"psirt@us.ibm.com"}]}},{"cve":{"id":"CVE-2026-17273","sourceIdentifier":"psirt@us.ibm.com","published":"2026-09-04T17:16:53.570","lastModified":"2026-09-04T17:16:53.570","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a NULL pointer dereference."}],"affected":[{"source":"psirt@us.ibm.com","affectedData":[{"vendor":"IBM","product":"i","cpes":["cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*"],"versions":[{"version":"7.6","status":"affected"},{"version":"7.5","status":"affected"},{"version":"7.4","status":"affected"},{"version":"7.3","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}]},"weaknesses":[{"source":"psirt@us.ibm.com","type":"Primary","description":[{"lang":"en","value":"CWE-476"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7285844","source":"psirt@us.ibm.com"}]}},{"cve":{"id":"CVE-2026-17274","sourceIdentifier":"psirt@us.ibm.com","published":"2026-09-04T17:16:53.710","lastModified":"2026-09-04T17:16:53.710","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to predictable server seeds."}],"affected":[{"source":"psirt@us.ibm.com","affectedData":[{"vendor":"IBM","product":"i","cpes":["cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*"],"versions":[{"version":"7.6","status":"affected"},{"version":"7.5","status":"affected"},{"version":"7.4","status":"affected"},{"version":"7.3","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.5}]},"weaknesses":[{"source":"psirt@us.ibm.com","type":"Primary","description":[{"lang":"en","value":"CWE-330"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7285844","source":"psirt@us.ibm.com"}]}},{"cve":{"id":"CVE-2026-17440","sourceIdentifier":"psirt@us.ibm.com","published":"2026-09-04T17:16:53.870","lastModified":"2026-09-04T18:17:49.087","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to cause a denial of service due to uncontrolled recursion."}],"affected":[{"source":"psirt@us.ibm.com","affectedData":[{"vendor":"IBM","product":"App Connect Enterprise","cpes":["cpe:2.3:a:ibm:app_connect_enterprise:13.0.1.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:app_connect_enterprise:13.0.8.1:*:*:*:*:*:*:*","cpe:2.3:a:ibm:app_connect_enterprise:12.0.1.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:app_connect_enterprise:12.0.12.28:*:*:*:*:*:*:*"],"versions":[{"version":"13.0.1.0","lessThanOrEqual":"13.0.8.1","versionType":"semver","status":"affected"},{"version":"12.0.1.0","lessThanOrEqual":"12.0.12.28","versionType":"semver","status":"affected"}]},{"vendor":"IBM","product":"Integration Bus for z/OS","cpes":["cpe:2.3:a:ibm:integration_bus_for_zos:10.1.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:integration_bus_for_zos:10.1.0.7:*:*:*:*:*:*:*"],"versions":[{"version":"10.1.0.0","lessThanOrEqual":"10.1.0.7","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T17:33:10.386317Z","id":"CVE-2026-17440","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"psirt@us.ibm.com","type":"Secondary","description":[{"lang":"en","value":"CWE-674"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7286372","source":"psirt@us.ibm.com"}]}},{"cve":{"id":"CVE-2026-17442","sourceIdentifier":"psirt@us.ibm.com","published":"2026-09-04T17:16:54.020","lastModified":"2026-09-04T17:16:54.020","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to obtain sensitive information due to credentials being written to trace logs in cleartext."}],"affected":[{"source":"psirt@us.ibm.com","affectedData":[{"vendor":"IBM","product":"App Connect Enterprise","cpes":["cpe:2.3:a:ibm:app_connect_enterprise:13.0.1.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:app_connect_enterprise:13.0.8.1:*:*:*:*:*:*:*","cpe:2.3:a:ibm:app_connect_enterprise:12.0.1.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:app_connect_enterprise:12.0.12.28:*:*:*:*:*:*:*"],"versions":[{"version":"13.0.1.0","lessThanOrEqual":"13.0.8.1","versionType":"semver","status":"affected"},{"version":"12.0.1.0","lessThanOrEqual":"12.0.12.28","versionType":"semver","status":"affected"}]},{"vendor":"IBM","product":"Integration Bus for z/OS","cpes":["cpe:2.3:a:ibm:integration_bus_for_zos:10.1.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:integration_bus_for_zos:10.1.0.7:*:*:*:*:*:*:*"],"versions":[{"version":"10.1.0.0","lessThanOrEqual":"10.1.0.7","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":5.1,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.4,"impactScore":3.6}]},"weaknesses":[{"source":"psirt@us.ibm.com","type":"Primary","description":[{"lang":"en","value":"CWE-532"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7286372","source":"psirt@us.ibm.com"}]}},{"cve":{"id":"CVE-2026-17443","sourceIdentifier":"psirt@us.ibm.com","published":"2026-09-04T17:16:54.170","lastModified":"2026-09-04T18:17:49.200","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection flaw."}],"affected":[{"source":"psirt@us.ibm.com","affectedData":[{"vendor":"IBM","product":"App Connect Enterprise","cpes":["cpe:2.3:a:ibm:app_connect_enterprise:13.0.1.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:app_connect_enterprise:13.0.8.1:*:*:*:*:*:*:*","cpe:2.3:a:ibm:app_connect_enterprise:12.0.1.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:app_connect_enterprise:12.0.12.28:*:*:*:*:*:*:*"],"versions":[{"version":"13.0.1.0","lessThanOrEqual":"13.0.8.1","versionType":"semver","status":"affected"},{"version":"12.0.1.0","lessThanOrEqual":"12.0.12.28","versionType":"semver","status":"affected"}]},{"vendor":"IBM","product":"Integration Bus for z/OS","cpes":["cpe:2.3:a:ibm:integration_bus_for_zos:10.1.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:integration_bus_for_zos:10.1.0.7:*:*:*:*:*:*:*"],"versions":[{"version":"10.1.0.0","lessThanOrEqual":"10.1.0.7","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T17:31:01.441784Z","id":"CVE-2026-17443","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"psirt@us.ibm.com","type":"Secondary","description":[{"lang":"en","value":"CWE-611"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7286372","source":"psirt@us.ibm.com"}]}},{"cve":{"id":"CVE-2026-17444","sourceIdentifier":"psirt@us.ibm.com","published":"2026-09-04T17:16:54.337","lastModified":"2026-09-04T17:16:54.337","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection."}],"affected":[{"source":"psirt@us.ibm.com","affectedData":[{"vendor":"IBM","product":"App Connect Enterprise","cpes":["cpe:2.3:a:ibm:app_connect_enterprise:13.0.1.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:app_connect_enterprise:13.0.8.1:*:*:*:*:*:*:*","cpe:2.3:a:ibm:app_connect_enterprise:12.0.1.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:app_connect_enterprise:12.0.12.28:*:*:*:*:*:*:*"],"versions":[{"version":"13.0.1.0","lessThanOrEqual":"13.0.8.1","versionType":"semver","status":"affected"},{"version":"12.0.1.0","lessThanOrEqual":"12.0.12.28","versionType":"semver","status":"affected"}]},{"vendor":"IBM","product":"Integration Bus for z/OS","cpes":["cpe:2.3:a:ibm:integration_bus_for_zos:10.1.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:integration_bus_for_zos:10.1.0.7:*:*:*:*:*:*:*"],"versions":[{"version":"10.1.0.0","lessThanOrEqual":"10.1.0.7","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":3.6}]},"weaknesses":[{"source":"psirt@us.ibm.com","type":"Primary","description":[{"lang":"en","value":"CWE-611"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7286372","source":"psirt@us.ibm.com"}]}},{"cve":{"id":"CVE-2026-17469","sourceIdentifier":"psirt@us.ibm.com","published":"2026-09-04T17:16:54.487","lastModified":"2026-09-04T17:16:54.487","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to cause a denial of service due to an off-by-one write in the LPD queue name parser."}],"affected":[{"source":"psirt@us.ibm.com","affectedData":[{"vendor":"IBM","product":"i","cpes":["cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*"],"versions":[{"version":"7.6","status":"affected"},{"version":"7.5","status":"affected"},{"version":"7.4","status":"affected"},{"version":"7.3","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":1.4}]},"weaknesses":[{"source":"psirt@us.ibm.com","type":"Primary","description":[{"lang":"en","value":"CWE-787"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7285939","source":"psirt@us.ibm.com"}]}},{"cve":{"id":"CVE-2026-17470","sourceIdentifier":"psirt@us.ibm.com","published":"2026-09-04T17:16:54.630","lastModified":"2026-09-04T18:17:49.320","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to a buffer overflow."}],"affected":[{"source":"psirt@us.ibm.com","affectedData":[{"vendor":"IBM","product":"i","cpes":["cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*"],"versions":[{"version":"7.6","status":"affected"},{"version":"7.5","status":"affected"},{"version":"7.4","status":"affected"},{"version":"7.3","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T17:34:43.892701Z","id":"CVE-2026-17470","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"psirt@us.ibm.com","type":"Secondary","description":[{"lang":"en","value":"CWE-787"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7285939","source":"psirt@us.ibm.com"}]}},{"cve":{"id":"CVE-2026-17483","sourceIdentifier":"psirt@us.ibm.com","published":"2026-09-04T17:16:54.777","lastModified":"2026-09-04T17:16:54.777","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"IBM Db2 Mirror for i 7.4, 7.5, and 7.6 IBM i could allow a local attacker to delete historical flight-recorder archives due to improper access control in an SQL procedure."}],"affected":[{"source":"psirt@us.ibm.com","affectedData":[{"vendor":"IBM","product":"Db2 Mirror for i","cpes":["cpe:2.3:a:ibm:db2_mirror_for_i:7.4:*:*:*:*:*:*:*","cpe:2.3:a:ibm:db2_mirror_for_i:7.4.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:db2_mirror_for_i:7.5:*:*:*:*:*:*:*","cpe:2.3:a:ibm:db2_mirror_for_i:7.5.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:db2_mirror_for_i:7.6:*:*:*:*:*:*:*","cpe:2.3:a:ibm:db2_mirror_for_i:7.6.0:*:*:*:*:*:*:*"],"versions":[{"version":"7.4","status":"affected"},{"version":"7.5","status":"affected"},{"version":"7.6","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4}]},"weaknesses":[{"source":"psirt@us.ibm.com","type":"Primary","description":[{"lang":"en","value":"CWE-285"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7285904","source":"psirt@us.ibm.com"}]}},{"cve":{"id":"CVE-2026-17499","sourceIdentifier":"psirt@us.ibm.com","published":"2026-09-04T17:16:54.937","lastModified":"2026-09-04T18:17:49.427","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command."}],"affected":[{"source":"psirt@us.ibm.com","affectedData":[{"vendor":"IBM","product":"i","cpes":["cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*"],"versions":[{"version":"7.6","status":"affected"},{"version":"7.5","status":"affected"},{"version":"7.4","status":"affected"},{"version":"7.3","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L","baseScore":4.4,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":1.8,"impactScore":2.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T17:30:33.661124Z","id":"CVE-2026-17499","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"psirt@us.ibm.com","type":"Secondary","description":[{"lang":"en","value":"CWE-78"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7285844","source":"psirt@us.ibm.com"}]}},{"cve":{"id":"CVE-2026-17621","sourceIdentifier":"psirt@us.ibm.com","published":"2026-09-04T17:16:55.063","lastModified":"2026-09-04T17:16:55.063","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing \"dot dot \" sequences ( /.. /) to view arbitrary files on the system."}],"affected":[{"source":"psirt@us.ibm.com","affectedData":[{"vendor":"IBM","product":"Langflow OSS","cpes":["cpe:2.3:a:ibm:langflow_oss:1.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:langflow_oss:1.10.2:*:*:*:*:*:*:*"],"versions":[{"version":"1.0.0","lessThanOrEqual":"1.10.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.5}]},"weaknesses":[{"source":"psirt@us.ibm.com","type":"Primary","description":[{"lang":"en","value":"CWE-22"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7286293","source":"psirt@us.ibm.com"}]}},{"cve":{"id":"CVE-2026-17622","sourceIdentifier":"psirt@us.ibm.com","published":"2026-09-04T17:16:55.227","lastModified":"2026-09-04T17:16:55.227","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted directory."}],"affected":[{"source":"psirt@us.ibm.com","affectedData":[{"vendor":"IBM","product":"Langflow OSS","cpes":["cpe:2.3:a:ibm:langflow_oss:1.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:langflow_oss:1.10.2:*:*:*:*:*:*:*"],"versions":[{"version":"1.0.0","lessThanOrEqual":"1.10.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}]},"weaknesses":[{"source":"psirt@us.ibm.com","type":"Primary","description":[{"lang":"en","value":"CWE-22"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7286293","source":"psirt@us.ibm.com"}]}},{"cve":{"id":"CVE-2026-17627","sourceIdentifier":"psirt@us.ibm.com","published":"2026-09-04T17:16:55.380","lastModified":"2026-09-04T18:17:49.530","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information and inject messages into workflow history due to improper authorization."}],"affected":[{"source":"psirt@us.ibm.com","affectedData":[{"vendor":"IBM","product":"Langflow OSS","cpes":["cpe:2.3:a:ibm:langflow_oss:1.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:langflow_oss:1.10.2:*:*:*:*:*:*:*"],"versions":[{"version":"1.0.0","lessThanOrEqual":"1.10.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N","baseScore":4.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.8,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T17:36:16.244054Z","id":"CVE-2026-17627","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"psirt@us.ibm.com","type":"Secondary","description":[{"lang":"en","value":"CWE-639"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7286294","source":"psirt@us.ibm.com"}]}},{"cve":{"id":"CVE-2026-17631","sourceIdentifier":"psirt@us.ibm.com","published":"2026-09-04T17:16:55.507","lastModified":"2026-09-04T17:16:55.507","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information due to a server-side request forgery (SSRF) vulnerability."}],"affected":[{"source":"psirt@us.ibm.com","affectedData":[{"vendor":"IBM","product":"Langflow OSS","cpes":["cpe:2.3:a:ibm:langflow_oss:1.0.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:langflow_oss:1.10.2:*:*:*:*:*:*:*"],"versions":[{"version":"1.0.0","lessThanOrEqual":"1.10.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N","baseScore":5.0,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":1.4}]},"weaknesses":[{"source":"psirt@us.ibm.com","type":"Primary","description":[{"lang":"en","value":"CWE-918"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7285644","source":"psirt@us.ibm.com"}]}},{"cve":{"id":"CVE-2026-18073","sourceIdentifier":"psirt@us.ibm.com","published":"2026-09-04T17:16:55.627","lastModified":"2026-09-04T17:16:55.627","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to inject parameters into a CL command due to improper neutralization of special elements."}],"affected":[{"source":"psirt@us.ibm.com","affectedData":[{"vendor":"IBM","product":"i","cpes":["cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*"],"versions":[{"version":"7.6","status":"affected"},{"version":"7.5","status":"affected"},{"version":"7.4","status":"affected"},{"version":"7.3","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","baseScore":4.4,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.8,"impactScore":2.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T16:42:49.163299Z","id":"CVE-2026-18073","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"psirt@us.ibm.com","type":"Primary","description":[{"lang":"en","value":"CWE-78"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7285844","source":"psirt@us.ibm.com"}]}},{"cve":{"id":"CVE-2026-18076","sourceIdentifier":"psirt@us.ibm.com","published":"2026-09-04T17:16:55.760","lastModified":"2026-09-04T17:16:55.760","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a memory leak."}],"affected":[{"source":"psirt@us.ibm.com","affectedData":[{"vendor":"IBM","product":"i","cpes":["cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*"],"versions":[{"version":"7.6","status":"affected"},{"version":"7.5","status":"affected"},{"version":"7.4","status":"affected"},{"version":"7.3","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4}]},"weaknesses":[{"source":"psirt@us.ibm.com","type":"Primary","description":[{"lang":"en","value":"CWE-401"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7285844","source":"psirt@us.ibm.com"}]}},{"cve":{"id":"CVE-2026-18078","sourceIdentifier":"psirt@us.ibm.com","published":"2026-09-04T17:16:55.883","lastModified":"2026-09-04T18:17:49.627","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to an integer overflow."}],"affected":[{"source":"psirt@us.ibm.com","affectedData":[{"vendor":"IBM","product":"i","cpes":["cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*"],"versions":[{"version":"7.6","status":"affected"},{"version":"7.5","status":"affected"},{"version":"7.4","status":"affected"},{"version":"7.3","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T17:30:11.918412Z","id":"CVE-2026-18078","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"psirt@us.ibm.com","type":"Secondary","description":[{"lang":"en","value":"CWE-190"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7285937","source":"psirt@us.ibm.com"}]}},{"cve":{"id":"CVE-2026-18175","sourceIdentifier":"psirt@us.ibm.com","published":"2026-09-04T17:16:56.010","lastModified":"2026-09-04T17:16:56.010","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to manipulate database transactions due to improper authorization in the DDM target dispatcher."}],"affected":[{"source":"psirt@us.ibm.com","affectedData":[{"vendor":"IBM","product":"i","cpes":["cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*"],"versions":[{"version":"7.6","status":"affected"},{"version":"7.5","status":"affected"},{"version":"7.4","status":"affected"},{"version":"7.3","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:L","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":2.2,"impactScore":5.3}]},"weaknesses":[{"source":"psirt@us.ibm.com","type":"Primary","description":[{"lang":"en","value":"CWE-285"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7286186","source":"psirt@us.ibm.com"}]}},{"cve":{"id":"CVE-2026-18221","sourceIdentifier":"psirt@us.ibm.com","published":"2026-09-04T17:16:56.150","lastModified":"2026-09-04T17:16:56.150","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to gain unauthorized access due to improper validation of client-supplied authentication parameters."}],"affected":[{"source":"psirt@us.ibm.com","affectedData":[{"vendor":"IBM","product":"i","cpes":["cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*"],"versions":[{"version":"7.6","status":"affected"},{"version":"7.5","status":"affected"},{"version":"7.4","status":"affected"},{"version":"7.3","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.2,"impactScore":5.9}]},"weaknesses":[{"source":"psirt@us.ibm.com","type":"Primary","description":[{"lang":"en","value":"CWE-287"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7286186","source":"psirt@us.ibm.com"}]}},{"cve":{"id":"CVE-2026-18341","sourceIdentifier":"psirt@us.ibm.com","published":"2026-09-04T17:16:56.283","lastModified":"2026-09-04T17:16:56.283","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to corrupt memory due to an integer underflow."}],"affected":[{"source":"psirt@us.ibm.com","affectedData":[{"vendor":"IBM","product":"i","cpes":["cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*","cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*"],"versions":[{"version":"7.6","status":"affected"},{"version":"7.5","status":"affected"},{"version":"7.4","status":"affected"},{"version":"7.3","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","baseScore":6.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":3.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T16:43:46.679439Z","id":"CVE-2026-18341","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"psirt@us.ibm.com","type":"Primary","description":[{"lang":"en","value":"CWE-122"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7286094","source":"psirt@us.ibm.com"}]}},{"cve":{"id":"CVE-2026-18486","sourceIdentifier":"psirt@us.ibm.com","published":"2026-09-04T17:16:56.420","lastModified":"2026-09-04T17:16:56.420","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"IBM ContextForge MCP Gateway <= v1.0.7 MCP Context Forge could allow a remote authenticated attacker to obtain sensitive credentials and escalate privileges due to improper validation of jq filters."}],"affected":[{"source":"psirt@us.ibm.com","affectedData":[{"vendor":"IBM","product":"ContextForge MCP Gateway","cpes":["cpe:2.3:a:ibm:contextforge-mcp-gateway:*:*:*:*:*:*:*:*"],"versions":[{"version":"<= v1.0.7","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}]},"weaknesses":[{"source":"psirt@us.ibm.com","type":"Primary","description":[{"lang":"en","value":"CWE-200"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7286052","source":"psirt@us.ibm.com"}]}},{"cve":{"id":"CVE-2026-18489","sourceIdentifier":"psirt@us.ibm.com","published":"2026-09-04T17:16:56.550","lastModified":"2026-09-04T18:17:49.870","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"IBM ContextForge MCP Gateway - Translate utility <= 1.0.8 MCP Context Forge could allow a remote attacker to obtain sensitive information from other sessions due to exposure of data elements to the wrong session."}],"affected":[{"source":"psirt@us.ibm.com","affectedData":[{"vendor":"IBM","product":"ContextForge MCP Gateway - Translate utility","cpes":["cpe:2.3:a:ibm:contextforge_mcp_gateway_translate_utility:*:*:*:*:*:*:*:*"],"versions":[{"version":"<= 1.0.8","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@us.ibm.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","baseScore":7.4,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T17:29:48.993058Z","id":"CVE-2026-18489","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"psirt@us.ibm.com","type":"Secondary","description":[{"lang":"en","value":"CWE-488"}]}],"references":[{"url":"https://www.ibm.com/support/pages/node/7286056","source":"psirt@us.ibm.com"}]}},{"cve":{"id":"CVE-2026-31020","sourceIdentifier":"cve@mitre.org","published":"2026-09-04T17:16:56.910","lastModified":"2026-09-04T18:17:51.893","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In DocsGPT 0.15.0 and below, the application provides a custom prompt feature that allows users to define prompt content used during chatbot interactions. This functionality renders user-supplied prompt data using Jinja templates without input sanitization or sandboxing. An unauthenticated attacker can inject malicious template expressions, leading to a server-side template injection (SSTI) vulnerability that can be exploited to achieve full remote code execution (RCE)."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T17:39:05.794681Z","id":"CVE-2026-31020","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-94"}]}],"references":[{"url":"http://arc53.com","source":"cve@mitre.org"},{"url":"https://github.com/PhDg1410/CVE/tree/main/CVE-2026-31020","source":"cve@mitre.org"}]}},{"cve":{"id":"CVE-2026-38961","sourceIdentifier":"cve@mitre.org","published":"2026-09-04T17:16:57.030","lastModified":"2026-09-04T17:16:57.030","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Cross-Site Scripting (XSS) vulnerability in the RSS Widget of Netgate pfSense Plus (versions 26.03, 25.11.1) and pfSense CE (version 2.8.1) allows remote authenticated attackers to inject arbitrary JavaScript via malicious content in an RSS feed title. The injected script executes in the browser of any authenticated user who views the dashboard, due to insufficient sanitization of feed title data before rendering in the widget."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://docs.netgate.com/downloads/pfSense-SA-26_04.webgui.asc","source":"cve@mitre.org"},{"url":"https://github.com/pfsense/pfsense/commit/9363ac5b8651a1c7a333180425ce7719070f95f9","source":"cve@mitre.org"}]}},{"cve":{"id":"CVE-2026-75430","sourceIdentifier":"cve@mitre.org","published":"2026-09-04T17:16:57.767","lastModified":"2026-09-04T19:17:26.990","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"PowerJob Worker version 5.1.2 (and likely earlier versions) exposes the /worker/deployContainer HTTP endpoint without authentication on the default transport port. This allows a remote attacker to execute arbitrary code."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@mitre.org","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T18:22:29.890975Z","id":"CVE-2026-75430","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-306"}]}],"references":[{"url":"https://gist.github.com/unpredictable21/fcb62d394db30525412c4b5b1efd0233","source":"cve@mitre.org"},{"url":"https://github.com/PowerJob/PowerJob","source":"cve@mitre.org"},{"url":"https://github.com/PowerJob/PowerJob/blob/master/SECURITY.md","source":"cve@mitre.org"},{"url":"https://github.com/PowerJob/PowerJob/blob/master/powerjob-worker/src/main/java/tech/powerjob/worker/actors/WorkerActor.java","source":"cve@mitre.org"},{"url":"https://github.com/PowerJob/PowerJob/blob/master/powerjob-worker/src/main/java/tech/powerjob/worker/container/OmsContainerFactory.java","source":"cve@mitre.org"}]}},{"cve":{"id":"CVE-2026-78745","sourceIdentifier":"cve@mitre.org","published":"2026-09-04T17:16:58.013","lastModified":"2026-09-04T17:16:58.013","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"An issue in HiDPT/ Weyon HiDPTAndroid Hi3751V350 Hi3751V352E_DMO allows a remote attacker to execute arbitrary code via the Android Debug Bridge (ADB) daemon (adbd)"}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://github.com/n0c71v3x/CVE-2026-78745","source":"cve@mitre.org"},{"url":"https://www.weyontv.com/","source":"cve@mitre.org"}]}},{"cve":{"id":"CVE-2026-78849","sourceIdentifier":"cve@mitre.org","published":"2026-09-04T17:16:58.140","lastModified":"2026-09-04T17:16:58.140","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Cross Site Scripting vulnerability in Netgate pfSense Plus software versions <= 26.03 pfSense CE software versions <= 2.8.1 allows a remote attacker to execute arbitrary code via the captive_portal_status.widget.php file"}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://docs.netgate.com/downloads/pfSense-SA-26_05.webgui.asc","source":"cve@mitre.org"},{"url":"https://redmine.pfsense.org/issues/16773","source":"cve@mitre.org"}]}},{"cve":{"id":"CVE-2026-80865","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T17:16:58.267","lastModified":"2026-09-04T17:16:58.267","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Add missing access_ok call to copy_user_syms\n\nAs reported by sashiko we use __get_user without prior access_ok call on the\nuser space pointer. Adding the missing call for the whole pointer array.\n\nPlus removing the err check in the error path, because it's not needed and\nalso we can return -ENOMEM directly from the first kvmalloc_array fail path.\n\n[1] https://lore.kernel.org/bpf/20260611115503.AC16D1F00893@smtp.kernel.org/"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["kernel/trace/bpf_trace.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"0236fec57a15dc2a068dfe4488e0c2ab4559b1ec","lessThan":"a67f7f9647cb243b3be32163e88e5bc76e3d51e9","versionType":"git","status":"affected"},{"version":"0236fec57a15dc2a068dfe4488e0c2ab4559b1ec","lessThan":"8b719cef5ac30ab83ce5693c5faf10e4944874af","versionType":"git","status":"affected"},{"version":"0236fec57a15dc2a068dfe4488e0c2ab4559b1ec","lessThan":"128391b57e0977c35243672a6f970073651f3831","versionType":"git","status":"affected"},{"version":"0236fec57a15dc2a068dfe4488e0c2ab4559b1ec","lessThan":"0b6252afcd1965f77c6a6f8a802a2e1381822b98","versionType":"git","status":"affected"},{"version":"0236fec57a15dc2a068dfe4488e0c2ab4559b1ec","lessThan":"28ce7bcf8a29aa395b60764df4c97be745de89d0","versionType":"git","status":"affected"},{"version":"0236fec57a15dc2a068dfe4488e0c2ab4559b1ec","lessThan":"d5dc200c3a3f217de072af269dd90adddf90e48d","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["kernel/trace/bpf_trace.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.19","status":"affected"},{"version":"0","lessThan":"5.19","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0b6252afcd1965f77c6a6f8a802a2e1381822b98","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/128391b57e0977c35243672a6f970073651f3831","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/28ce7bcf8a29aa395b60764df4c97be745de89d0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8b719cef5ac30ab83ce5693c5faf10e4944874af","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a67f7f9647cb243b3be32163e88e5bc76e3d51e9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d5dc200c3a3f217de072af269dd90adddf90e48d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80866","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T17:16:58.390","lastModified":"2026-09-04T17:16:58.390","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: avoid busy looping in tipc_exit_net()\n\nBlamed commit introduced a busy-wait loop in tipc_exit_net()\nto wait for pending UDP bearer cleanup works to complete:\n\n       while (atomic_read(&tn->wq_count))\n               cond_resched();\n\nThis loop can busy-wait for a long time if cond_resched() is a NOP. This\ntypically happens if the netns exit is executed by a high priority task,\nor under kernels configured without preemption (CONFIG_PREEMPT_NONE). In\nsuch cases, it wastes CPU cycles and can lead to soft lockups.\n\nFix this by replacing the busy loop with wait_var_event(), allowing the\nthread to sleep properly until the work queue count reaches zero.\n\nAccordingly, update cleanup_bearer() to use atomic_dec_and_test() and\nwake_up_var() to wake up the waiter when the count drops to zero.\n\nThis uses the global wait queue hash table, avoiding the need to bloat\nstruct tipc_net with a wait_queue_head_t. The atomic_dec_and_test()\nprovides the necessary memory barrier to ensure the wakeup is not missed."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/tipc/core.c","net/tipc/udp_media.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"04c26faa51d1e2fe71cf13c45791f5174c37f986","lessThan":"522d1d950b9e3b68190a6de7534827c8dccedb73","versionType":"git","status":"affected"},{"version":"04c26faa51d1e2fe71cf13c45791f5174c37f986","lessThan":"c1481c94e74c955e0448ddf46b8615a44d840c1e","versionType":"git","status":"affected"},{"version":"d1f76dfadaf8f47ed1753f97dbcbd41c16215ffa","versionType":"git","status":"affected"},{"version":"5195ec5e365a2a9331bfeb585b613a6e94f98dba","versionType":"git","status":"affected"},{"version":"b9f5b7ad4ac3af006443f535b1ce7bff1d130d7d","versionType":"git","status":"affected"},{"version":"5.4.124","lessThan":"5.5","versionType":"semver","status":"affected"},{"version":"5.10.42","lessThan":"5.11","versionType":"semver","status":"affected"},{"version":"5.12.9","lessThan":"5.13","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/tipc/core.c","net/tipc/udp_media.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.13","status":"affected"},{"version":"0","lessThan":"5.13","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/522d1d950b9e3b68190a6de7534827c8dccedb73","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c1481c94e74c955e0448ddf46b8615a44d840c1e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80867","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T17:16:58.510","lastModified":"2026-09-04T17:16:58.510","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nalpha/PCI: Add security_locked_down() check to pci_mmap_resource()\n\nCurrently, Alpha's pci_mmap_resource() does not check\nsecurity_locked_down(LOCKDOWN_PCI_ACCESS) before allowing userspace to mmap\nPCI BARs.\n\nThe generic version has had this check since commit eb627e17727e (\"PCI:\nLock down BAR access when the kernel is locked down\") to prevent DMA\nattacks when the kernel is locked down.\n\nAdd the same check to Alpha's pci_mmap_resource()."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["arch/alpha/kernel/pci-sysfs.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"eb627e17727ebeede70697ae1798688b0d328b54","lessThan":"6e368485a1ac19fbde0a8b6a332d4545ae72a8ac","versionType":"git","status":"affected"},{"version":"eb627e17727ebeede70697ae1798688b0d328b54","lessThan":"ed2cd1fee0ed16a1c2dff49175e65c641eb8ae2b","versionType":"git","status":"affected"},{"version":"eb627e17727ebeede70697ae1798688b0d328b54","lessThan":"c3234efe21d4198945492cf7dba6859476f0f6ff","versionType":"git","status":"affected"},{"version":"eb627e17727ebeede70697ae1798688b0d328b54","lessThan":"4de5ff924c0a8ef8166c1a68af9087826e1e8d61","versionType":"git","status":"affected"},{"version":"eb627e17727ebeede70697ae1798688b0d328b54","lessThan":"85f966b1120874fe530edec50d28373ceb06ebcd","versionType":"git","status":"affected"},{"version":"eb627e17727ebeede70697ae1798688b0d328b54","lessThan":"94defb18ac792fd16407d5a52ad0d3f5055c4b43","versionType":"git","status":"affected"},{"version":"eb627e17727ebeede70697ae1798688b0d328b54","lessThan":"257b55dc3d18d7ef01f62a8ff7317871f7597e28","versionType":"git","status":"affected"},{"version":"eb627e17727ebeede70697ae1798688b0d328b54","lessThan":"78a228f0aa0e9eba31955950c8a40a9945e2c8bb","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["arch/alpha/kernel/pci-sysfs.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.4","status":"affected"},{"version":"0","lessThan":"5.4","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/257b55dc3d18d7ef01f62a8ff7317871f7597e28","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4de5ff924c0a8ef8166c1a68af9087826e1e8d61","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6e368485a1ac19fbde0a8b6a332d4545ae72a8ac","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/78a228f0aa0e9eba31955950c8a40a9945e2c8bb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/85f966b1120874fe530edec50d28373ceb06ebcd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/94defb18ac792fd16407d5a52ad0d3f5055c4b43","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c3234efe21d4198945492cf7dba6859476f0f6ff","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ed2cd1fee0ed16a1c2dff49175e65c641eb8ae2b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80868","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T17:16:58.643","lastModified":"2026-09-04T17:16:58.643","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nntfs3: Allocate iomap inline_data using alloc_page\n\nThis fixes a BUG reported in iomap_write_end_inline:\niomap_inline_data_valid checks that the inline_data fits within\na page. If the inline_data is allocated with kmemdup there's no\nguarantee that it's page-aligned, so the check sometimes fails.\nAllocate it with alloc_page to ensure it's page-aligned."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/ntfs3/attrib.c","fs/ntfs3/inode.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"099ef9ab9203dff327f2d61e44773f9acbc01f13","lessThan":"3cd2212012c06d2b1fd03a6bf84f6202ab70056c","versionType":"git","status":"affected"},{"version":"099ef9ab9203dff327f2d61e44773f9acbc01f13","lessThan":"70d3855594cf6e8791970714b65cac3202d6160e","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/ntfs3/attrib.c","fs/ntfs3/inode.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.0","status":"affected"},{"version":"0","lessThan":"7.0","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3cd2212012c06d2b1fd03a6bf84f6202ab70056c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/70d3855594cf6e8791970714b65cac3202d6160e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80869","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T17:16:58.750","lastModified":"2026-09-04T17:16:58.750","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nntfs: bound the attribute-list entry in ntfs_read_inode_mount()\n\nThe $MFT attribute-list walk in ntfs_read_inode_mount() validates each\nentry only with \"(u8 *)al_entry + 6 > al_end\" and\n\"(u8 *)al_entry + le16_to_cpu(al_entry->length) > al_end\", but then reads\nal_entry->lowest_vcn (an __le64 at offset 8) and al_entry->mft_reference\n(offset 16) -- fields beyond the 6 bytes proven in range. al_entry->length\nis attacker-controlled and only required non-zero, so a short entry (e.g.\nlength 8) placed at the tail passes both checks while the lowest_vcn /\nmft_reference reads fall past al_end.\n\nal_end is ni->attr_list + attr_list_size (the on-disk size); the buffer is\nkvzalloc(round_up(attr_list_size, SECTOR_SIZE)), so the sector rounding\nusually absorbs the over-read -- but when attr_list_size is a multiple of\nSECTOR_SIZE there is no slack and a crafted $MFT attribute list produces an\nout-of-bounds read at mount time.\n\nValidate the entry with ntfs_attr_list_entry_is_valid() (added in patch\n1/3) before dereferencing it, matching the bound the other attribute-list\nwalks now use. The validator already requires the length to cover the fixed\nheader, which makes the separate \"!al_entry->length\" check redundant, so\ndrop it too."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/ntfs/inode.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1e9ea7e04472d4e5e12e58c881eaacfb3e49b669","lessThan":"c7a7e48e71ce915ec4cbd6e9f355590c1ecbc29a","versionType":"git","status":"affected"},{"version":"1e9ea7e04472d4e5e12e58c881eaacfb3e49b669","lessThan":"98634df5b1cb56c26299b7409227025ddb0167d8","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/ntfs/inode.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1","status":"affected"},{"version":"0","lessThan":"7.1","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/98634df5b1cb56c26299b7409227025ddb0167d8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c7a7e48e71ce915ec4cbd6e9f355590c1ecbc29a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80870","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T17:16:58.860","lastModified":"2026-09-04T17:16:58.860","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdkfd: Validate CRIU-restored IDs before idr_alloc\n\nThe KFD CRIU restore flow restores previously saved object IDs from\nuserspace.\n\nFor event restore:\n\n  kfd_criu_restore_event()\n      -> create_signal_event() / create_other_event()\n          -> allocate_event_notification_slot()\n              -> idr_alloc(..., *restore_id, *restore_id + 1, ...)\n\nFor BO restore:\n\n  criu_restore_memory_of_gpu()\n      -> idr_alloc(..., bo_priv->idr_handle, ...)\n\nIn both cases, the restored ID comes from userspace-provided CRIU data.\n\nidr_alloc() expects the ID range values to fit within signed int\nlimits. If a restored ID is larger than INT_MAX, it can trigger a WARN\nin the IDR layer.\n\nA kernel WARN is undesirable because it prints a warning trace and may\ncause a panic or reboot on systems with panic_on_warn enabled.\n\nSmatch reported these paths as allowing unchecked userspace values to\nreach idr_alloc().\n\nAdd INT_MAX validation before using restored IDs in:\n\n- kfd_criu_restore_event()\n- criu_restore_memory_of_gpu()\n\nIf the restored ID is invalid, return -EINVAL.\n\nThis prevents invalid restore data from reaching the IDR layer and\navoids WARN-triggering paths, while keeping valid restore behavior\nunchanged."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/gpu/drm/amd/amdkfd/kfd_chardev.c","drivers/gpu/drm/amd/amdkfd/kfd_events.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"40e8a766a761f7fdc8530347527b344fddf6f1a8","lessThan":"f8687018f24037056692c1e93c7d96cc72889d5b","versionType":"git","status":"affected"},{"version":"40e8a766a761f7fdc8530347527b344fddf6f1a8","lessThan":"89a75e3349c4fae28cbedc711bc924cbc6293da2","versionType":"git","status":"affected"},{"version":"40e8a766a761f7fdc8530347527b344fddf6f1a8","lessThan":"085ea93bda71fee600cc12a17026598eb10dd1f9","versionType":"git","status":"affected"},{"version":"40e8a766a761f7fdc8530347527b344fddf6f1a8","lessThan":"543ed0f61d56501cc585162da600bbedd7c08c0f","versionType":"git","status":"affected"},{"version":"40e8a766a761f7fdc8530347527b344fddf6f1a8","lessThan":"cb6311f25a096621ac7ffd91b50d1bb1cfb63a96","versionType":"git","status":"affected"},{"version":"40e8a766a761f7fdc8530347527b344fddf6f1a8","lessThan":"85043dd49c2f51a37b22618168e3ae59ab92f0d6","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/gpu/drm/amd/amdkfd/kfd_chardev.c","drivers/gpu/drm/amd/amdkfd/kfd_events.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.18","status":"affected"},{"version":"0","lessThan":"5.18","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/085ea93bda71fee600cc12a17026598eb10dd1f9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/543ed0f61d56501cc585162da600bbedd7c08c0f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/85043dd49c2f51a37b22618168e3ae59ab92f0d6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/89a75e3349c4fae28cbedc711bc924cbc6293da2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cb6311f25a096621ac7ffd91b50d1bb1cfb63a96","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f8687018f24037056692c1e93c7d96cc72889d5b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80871","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T17:16:59.027","lastModified":"2026-09-04T17:16:59.027","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: xilinx-trng - Remove crypto_rng interface\n\nImplementing the crypto_rng interface has no purpose, as it isn't used\nin practice.  It's being removed from other drivers too.  Just remove\nit.  This leaves hwrng, which is actually used.\n\nTagging with 'Cc stable' due to the bugs that this removes:\n\n  - xtrng_trng_generate() sometimes returned success even when it didn't\n    fill in all the bytes.\n\n  - It was possible for xtrng_trng_generate() and\n    xtrng_hwrng_trng_read() to run concurrently and interfere with each\n    other, as the locking code in xtrng_hwrng_trng_read() was broken."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/crypto/Kconfig","drivers/crypto/xilinx/xilinx-trng.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"8979744aca8096ee5072798dfc1181606919b35d","lessThan":"83f29da85dc9d9a32fe62cd1055e8e6705e6bf80","versionType":"git","status":"affected"},{"version":"8979744aca8096ee5072798dfc1181606919b35d","lessThan":"9634db561e1594c151923f4950c012161c545c93","versionType":"git","status":"affected"},{"version":"8979744aca8096ee5072798dfc1181606919b35d","lessThan":"32b4d29280ed2a991dc196d5845b892acedc63b8","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/crypto/Kconfig","drivers/crypto/xilinx/xilinx-trng.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.18","status":"affected"},{"version":"0","lessThan":"6.18","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/32b4d29280ed2a991dc196d5845b892acedc63b8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/83f29da85dc9d9a32fe62cd1055e8e6705e6bf80","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9634db561e1594c151923f4950c012161c545c93","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80872","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T17:16:59.160","lastModified":"2026-09-04T17:16:59.160","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: hda/tas2781: Cancel async firmware request at unbind\n\nTAS2781 HDA I2C and SPI queue RCA firmware loading from component\nbind with request_firmware_nowait(). The firmware loader keeps the\ncallback module pinned and holds a device reference, but the callback\nstill uses driver-private HDA state.\n\nComponent unbind removes controls and DSP state immediately. Later\ndevice removal tears down the TAS2781 private data, including\ncodec_lock. If the async firmware callback runs after unbind has\nstarted, it can operate on state that is being torn down.\n\nCancel or synchronize the async firmware request before removing\ncontrols and DSP state. A queued callback is cancelled, and an\nalready-running callback is allowed to finish before unbind continues."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["sound/hda/codecs/side-codecs/tas2781_hda_i2c.c","sound/hda/codecs/side-codecs/tas2781_hda_spi.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5be27f1e3ec98975c18a91e220d4847d0dec9671","lessThan":"f8272331da877eec8fe8e89a1e98e6a710e12490","versionType":"git","status":"affected"},{"version":"5be27f1e3ec98975c18a91e220d4847d0dec9671","lessThan":"da9e3be9cf31d7138d23e9e2f7ba1c102ef09f07","versionType":"git","status":"affected"},{"version":"5be27f1e3ec98975c18a91e220d4847d0dec9671","lessThan":"5367e2ad14f0ae9350a7aaf2e77c87de39a43ae9","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["sound/hda/codecs/side-codecs/tas2781_hda_i2c.c","sound/hda/codecs/side-codecs/tas2781_hda_spi.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.6","status":"affected"},{"version":"0","lessThan":"6.6","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/5367e2ad14f0ae9350a7aaf2e77c87de39a43ae9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/da9e3be9cf31d7138d23e9e2f7ba1c102ef09f07","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f8272331da877eec8fe8e89a1e98e6a710e12490","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80873","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T17:16:59.273","lastModified":"2026-09-04T17:16:59.273","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: arm64: nv: Write ESR_EL2 for injected nested SError exceptions\n\nkvm_inject_el2_exception() writes ESR_EL2 for synchronous exceptions\nbut not for SError. enter_exception64() does not write ESR_ELx for any\nexception type, so the constructed syndrome is dropped. A guest L2\nhypervisor taking a nested SError observes stale ESR_EL2.\n\nThis affects both kvm_inject_nested_serror() and the EASE path in\nkvm_inject_nested_sea().\n\nWrite ESR_EL2 for except_type_serror, matching except_type_sync."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["arch/arm64/kvm/emulate-nested.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"77ee70a073575977b403e9add25f185d614217d8","lessThan":"09f35145f3a4aacea4d9b914ad895bf5af8fc4ae","versionType":"git","status":"affected"},{"version":"77ee70a073575977b403e9add25f185d614217d8","lessThan":"29227821e2320ff6a174c91742b4ce221fe8d563","versionType":"git","status":"affected"},{"version":"77ee70a073575977b403e9add25f185d614217d8","lessThan":"e2cb1f4578625e71f461d5c1ce70984193389cbb","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["arch/arm64/kvm/emulate-nested.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.17","status":"affected"},{"version":"0","lessThan":"6.17","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/09f35145f3a4aacea4d9b914ad895bf5af8fc4ae","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/29227821e2320ff6a174c91742b4ce221fe8d563","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e2cb1f4578625e71f461d5c1ce70984193389cbb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80874","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T17:16:59.390","lastModified":"2026-09-04T17:16:59.390","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\narm64: dts: renesas: ironhide: Describe inline ECC carveouts\n\nThe DBSC5 DRAM controller protects DRAM content using inline ECC.\nThe inline ECC utilizes areas of DRAM for its operation, which are\nin the DRAM address range, but must not be accessed or modified.\nDescribe the inline ECC carveout areas used by the DBSC5 controller\non this hardware as reserved-memory, which must not be accessed.\nInclude DRAM areas which are unprotected by ECC as well, those are\nparts of the DRAM which directly precede the ECC carveout.\n\nIn case of high DRAM utilization, unless the inline ECC carveouts\nare properly reserved, Linux may use and corrupt the memory used\nby the DBSC5 DRAM controller for inline ECC, which would lead to\nthe system becoming unstable."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["arch/arm64/boot/dts/renesas/r8a78000-ironhide.dts"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"ad142a4ef7106326bbf5c67eb39f21ef77fe8be3","lessThan":"7cc51bb053f6b4bb17db4e10afcef3147566cb47","versionType":"git","status":"affected"},{"version":"ad142a4ef7106326bbf5c67eb39f21ef77fe8be3","lessThan":"6fa6ee724d8dadf392139e242ac936b5da730c4b","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["arch/arm64/boot/dts/renesas/r8a78000-ironhide.dts"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.19","status":"affected"},{"version":"0","lessThan":"6.19","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/6fa6ee724d8dadf392139e242ac936b5da730c4b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7cc51bb053f6b4bb17db4e10afcef3147566cb47","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80875","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T17:16:59.507","lastModified":"2026-09-04T17:16:59.507","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nipvs: use parsed transport offset in TCP state lookup\n\nTCP state handling reparses the skb to find the TCP header. For IPv6 it\nuses sizeof(struct ipv6hdr), while the surrounding IPVS code already\nparsed the packet with ip_vs_fill_iph_skb() and has the real\ntransport-header offset in iph.len.\n\nThis makes TCP state handling look at the wrong bytes when an IPv6\npacket carries extension headers. Use the parsed transport offset passed\ndown from ip_vs_set_state() when reading the TCP header.\n\nFor IPv4 and for IPv6 packets without extension headers, the passed\noffset matches the previous value."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/netfilter/ipvs/ip_vs_proto_tcp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"0bbdd42b7efa66685b6d74701bcde3a596a3a59d","lessThan":"2d06e0897ce18228d199887f0823b431d841dd03","versionType":"git","status":"affected"},{"version":"0bbdd42b7efa66685b6d74701bcde3a596a3a59d","lessThan":"816efb7fc0aeae986e63ac73b428dd97a4ef69f5","versionType":"git","status":"affected"},{"version":"0bbdd42b7efa66685b6d74701bcde3a596a3a59d","lessThan":"5848e914b85e360a2dd9d19c00a72e2ea9617dd0","versionType":"git","status":"affected"},{"version":"0bbdd42b7efa66685b6d74701bcde3a596a3a59d","lessThan":"d45f73c274435703e8d7bc9d8b742a5d9111ab6e","versionType":"git","status":"affected"},{"version":"0bbdd42b7efa66685b6d74701bcde3a596a3a59d","lessThan":"f6f550f26562d191c30b2818e7925dcb1c7f166c","versionType":"git","status":"affected"},{"version":"0bbdd42b7efa66685b6d74701bcde3a596a3a59d","lessThan":"d73f4249776dd970ad65a69cfc51613dd8a034bb","versionType":"git","status":"affected"},{"version":"0bbdd42b7efa66685b6d74701bcde3a596a3a59d","lessThan":"c2ee845e292c278fac75bf28d96bc892607fd5c4","versionType":"git","status":"affected"},{"version":"0bbdd42b7efa66685b6d74701bcde3a596a3a59d","lessThan":"2500fa3958b1ba51c2b065e39db1b04dfa7e23a2","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/netfilter/ipvs/ip_vs_proto_tcp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.28","status":"affected"},{"version":"0","lessThan":"2.6.28","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2500fa3958b1ba51c2b065e39db1b04dfa7e23a2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2d06e0897ce18228d199887f0823b431d841dd03","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5848e914b85e360a2dd9d19c00a72e2ea9617dd0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/816efb7fc0aeae986e63ac73b428dd97a4ef69f5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c2ee845e292c278fac75bf28d96bc892607fd5c4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d45f73c274435703e8d7bc9d8b742a5d9111ab6e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d73f4249776dd970ad65a69cfc51613dd8a034bb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f6f550f26562d191c30b2818e7925dcb1c7f166c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80876","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T17:16:59.640","lastModified":"2026-09-04T17:16:59.640","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nring-buffer: Fix event length with forced 8-byte alignment\n\nWhen RB_FORCE_8BYTE_ALIGNMENT is true, rb_calculate_event_length()\nreserves the space of event->array[0] for placing the data length and\nrb_update_event() stores the data length in event->array[0]\naccordingly. As a result the whole event length will add extra 4 bytes\nfor sizeof(event.array[0]) unconditionally.\n\nBut ring_buffer_event_length() only subtracts the\nsizeof(event->array[0]) for events larger than RB_MAX_SMALL_DATA +\nsizeof(event->array[0]). As a result, small events on architectures\nwith RB_FORCE_8BYTE_ALIGNMENT=true report a data length that is 4\nbytes larger than expected.\n\nTo fix it, add the RB_FORCE_8BYTE_ALIGNMENT as a condition to subtract\nthe size of that length field whenever RB_FORCE_8BYTE_ALIGNMENT is\ntrue.\n\nThis issue is observed in a riscv64 kernel with\nCONFIG_HAVE_64BIT_ALIGNED_ACCESS set to y, when we run ftrace selftest\ntrace_marker_raw.tc, we get the weird log: for cases where the id is\n1..100, the number of data field is 8*N, but once id exceeds 100, the\nnumber of data field becomes 8*N+4:\n # 1 buf: 58 00 00 00 80 5e d1 63 (number of data field is 8*1)\n ...\n # a buf: 58 ...                  (number of data field is 8*2)\n ...\n # 64 buf: 58 ...                 (number of data field is 8*13)\n # 65 buf: 58 ...                 (number of data field is 8*13+4)\n\nAfter applying this change, the number of data field keeps being 8*N+4\nconsistently."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["kernel/trace/ring_buffer.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2271048d1b3b0aabf83d25b29c20646dcabedc05","lessThan":"7c9f0ccf9f04142458d2ac3d39414f4acae242f0","versionType":"git","status":"affected"},{"version":"2271048d1b3b0aabf83d25b29c20646dcabedc05","lessThan":"24c3fa71f9947b0e1f3b954db1b769b44140192e","versionType":"git","status":"affected"},{"version":"2271048d1b3b0aabf83d25b29c20646dcabedc05","lessThan":"14057268e79654c3e8ea2c9b5204cb9644b2964d","versionType":"git","status":"affected"},{"version":"2271048d1b3b0aabf83d25b29c20646dcabedc05","lessThan":"dbcb8635b1eb7603818591cf745c7b1d714f7ac6","versionType":"git","status":"affected"},{"version":"2271048d1b3b0aabf83d25b29c20646dcabedc05","lessThan":"cfada73fabe2ccc06ec77fe2ceaa088689213326","versionType":"git","status":"affected"},{"version":"2271048d1b3b0aabf83d25b29c20646dcabedc05","lessThan":"ec5e96aee75d27779b9a860307679f13f33adb0c","versionType":"git","status":"affected"},{"version":"2271048d1b3b0aabf83d25b29c20646dcabedc05","lessThan":"3a63a11897c7ba32d1be7a3fdbc48a8b01cf4992","versionType":"git","status":"affected"},{"version":"2271048d1b3b0aabf83d25b29c20646dcabedc05","lessThan":"c37e0a4b79a6bbb96ce5ffe279d7c001e20529e0","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["kernel/trace/ring_buffer.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.34","status":"affected"},{"version":"0","lessThan":"2.6.34","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/14057268e79654c3e8ea2c9b5204cb9644b2964d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/24c3fa71f9947b0e1f3b954db1b769b44140192e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3a63a11897c7ba32d1be7a3fdbc48a8b01cf4992","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7c9f0ccf9f04142458d2ac3d39414f4acae242f0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c37e0a4b79a6bbb96ce5ffe279d7c001e20529e0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cfada73fabe2ccc06ec77fe2ceaa088689213326","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dbcb8635b1eb7603818591cf745c7b1d714f7ac6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ec5e96aee75d27779b9a860307679f13f33adb0c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80877","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T17:16:59.790","lastModified":"2026-09-04T17:16:59.790","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nafs: Fix vllist leak\n\nFix a leak of the new vllist in afs_update_cell() in the event that it is an\nempty list (nr_servers == 0), in which case the old list isn't displaced\nunless the old list is also empty."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/afs/cell.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"d5c32c89b208e39a39cd8639aa21c012ce0daf4d","lessThan":"13403945c2385653e282dacda304dce2a25fdb53","versionType":"git","status":"affected"},{"version":"d5c32c89b208e39a39cd8639aa21c012ce0daf4d","lessThan":"2b169eedbb96f37f3f33d7b496d8283194988980","versionType":"git","status":"affected"},{"version":"d5c32c89b208e39a39cd8639aa21c012ce0daf4d","lessThan":"bf55969d9188380eb539bd216850bac27bc2e272","versionType":"git","status":"affected"},{"version":"d5c32c89b208e39a39cd8639aa21c012ce0daf4d","lessThan":"bef5514f6b6cb4bed9061f4b628d6be1cf26a39e","versionType":"git","status":"affected"},{"version":"d5c32c89b208e39a39cd8639aa21c012ce0daf4d","lessThan":"fbfe75c81bff2359a03e85cf84293484cf60fcb9","versionType":"git","status":"affected"},{"version":"d5c32c89b208e39a39cd8639aa21c012ce0daf4d","lessThan":"8afb1a787a2802caf1895dd96745cfd6790a6f95","versionType":"git","status":"affected"},{"version":"d5c32c89b208e39a39cd8639aa21c012ce0daf4d","lessThan":"91d8f8e5fd34d3aed26f0fe6cf52b3f71de66cc6","versionType":"git","status":"affected"},{"version":"d5c32c89b208e39a39cd8639aa21c012ce0daf4d","lessThan":"fc10c0ecf06f2981af5d04357612b00051e03e9e","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/afs/cell.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.2","status":"affected"},{"version":"0","lessThan":"5.2","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/13403945c2385653e282dacda304dce2a25fdb53","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2b169eedbb96f37f3f33d7b496d8283194988980","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8afb1a787a2802caf1895dd96745cfd6790a6f95","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/91d8f8e5fd34d3aed26f0fe6cf52b3f71de66cc6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bef5514f6b6cb4bed9061f4b628d6be1cf26a39e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bf55969d9188380eb539bd216850bac27bc2e272","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fbfe75c81bff2359a03e85cf84293484cf60fcb9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fc10c0ecf06f2981af5d04357612b00051e03e9e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80878","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T17:16:59.923","lastModified":"2026-09-04T17:16:59.923","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nafs: Fix leak of ungot volume\n\nFix afs_lookup_volume_rcu() so that it doesn't leak a dying volume if\nafs_try_get_volume() fails."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/afs/callback.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"32222f09782f1894fcfc37f6505ca676a6f4d1d6","lessThan":"9cabf1c86948793fbad09023bd2ec58c71b9c1d4","versionType":"git","status":"affected"},{"version":"32222f09782f1894fcfc37f6505ca676a6f4d1d6","lessThan":"d672c276f685a540ed2b2a8bafaed4650a89022c","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/afs/callback.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.8","status":"affected"},{"version":"0","lessThan":"6.8","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/9cabf1c86948793fbad09023bd2ec58c71b9c1d4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d672c276f685a540ed2b2a8bafaed4650a89022c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80879","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T17:17:00.080","lastModified":"2026-09-04T17:17:00.080","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: fix circular locking dependency in ocfs2_dio_end_io_write\n\nA circular locking dependency involves INODE_ALLOC_SYSTEM_INODE,\nEXTENT_ALLOC_SYSTEM_INODE, and ORPHAN_DIR_SYSTEM_INODE.\n\n1. ocfs2_mknod() acquires INODE_ALLOC then EXTENT_ALLOC.\n\n2. ocfs2_dio_end_io_write() acquires EXTENT_ALLOC for unwritten\n   extents, then ORPHAN_DIR via ocfs2_del_inode_from_orphan() while still\n   holding EXTENT_ALLOC.\n\n3. ocfs2_wipe_inode() acquires ORPHAN_DIR then INODE_ALLOC via\n   ocfs2_remove_inode.\n\nBreak the cycle in ocfs2_dio_end_io_write() by freeing the allocation\ncontexts (releasing EXTENT_ALLOC) before acquiring ORPHAN_DIR.\n\nWARNING: possible circular locking dependency detected\n------------------------------------------------------\nis trying to acquire lock:\nffff8881e78b33a0\n(&ocfs2_sysfile_lock_key[INODE_ALLOC_SYSTEM_INODE]){+.+.}-{4:4}, at:\nocfs2_evict_inode+0x1539/0x43b0 fs/ocfs2/inode.c:1299\n\nbut task is already holding lock:\nffff8881e78b4fa0\n(&ocfs2_sysfile_lock_key[ORPHAN_DIR_SYSTEM_INODE]){+.+.}-{4:4}, at:\nocfs2_evict_inode+0xe97/0x43b0 fs/ocfs2/inode.c:1299\n\nthe existing dependency chain (in reverse order) is:\n\n-> #2 (&ocfs2_sysfile_lock_key[ORPHAN_DIR_SYSTEM_INODE]){+.+.}-{4:4}:\n       inode_lock include/linux/fs.h:1029 [inline]\n       ocfs2_del_inode_from_orphan+0x12e/0x7a0 fs/ocfs2/namei.c:2728\n       ocfs2_dio_end_io+0xf9c/0x1370 fs/ocfs2/aops.c:2418\n       dio_complete+0x25b/0x790 fs/direct-io.c:281\n\n-> #1 (&ocfs2_sysfile_lock_key[EXTENT_ALLOC_SYSTEM_INODE]){+.+.}-{4:4}:\n       inode_lock include/linux/fs.h:1029 [inline]\n       ocfs2_reserve_suballoc_bits+0x16d/0x4840 fs/ocfs2/suballoc.c:882\n       ocfs2_reserve_new_metadata_blocks+0x415/0x9a0\n       fs/ocfs2/suballoc.c:1078\n       ocfs2_mknod+0x10f3/0x2260 fs/ocfs2/namei.c:351\n\n-> #0 (&ocfs2_sysfile_lock_key[INODE_ALLOC_SYSTEM_INODE]){+.+.}-{4:4}:\n       __lock_acquire+0x15a5/0x2cf0 kernel/locking/lockdep.c:5237\n       lock_acquire+0x106/0x350 kernel/locking/lockdep.c:5868\n       down_write+0x96/0x200 kernel/locking/rwsem.c:1625\n       inode_lock include/linux/fs.h:1029 [inline]\n       ocfs2_remove_inode fs/ocfs2/inode.c:733 [inline]\n       ocfs2_wipe_inode fs/ocfs2/inode.c:896 [inline]\n       ocfs2_delete_inode fs/ocfs2/inode.c:1157 [inline]\n       ocfs2_evict_inode+0x1539/0x43b0 fs/ocfs2/inode.c:1299\n\nChain exists of:\n  &ocfs2_sysfile_lock_key[INODE_ALLOC_SYSTEM_INODE] -->\n  &ocfs2_sysfile_lock_key[EXTENT_ALLOC_SYSTEM_INODE] -->\n  &ocfs2_sysfile_lock_key[ORPHAN_DIR_SYSTEM_INODE]\n\n Possible unsafe locking scenario:\n\n       CPU0                    CPU1\n       ----                    ----\n  lock(&ocfs2_sysfile_lock_key[ORPHAN_DIR_SYSTEM_INODE]);\n                               lock(&ocfs2_sysfile_lock_key[EXTENT_ALLOC_SYSTEM_INODE]);\n                               lock(&ocfs2_sysfile_lock_key[ORPHAN_DIR_SYSTEM_INODE]);\n  lock(&ocfs2_sysfile_lock_key[INODE_ALLOC_SYSTEM_INODE]);\n\n *** DEADLOCK ***"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/ocfs2/aops.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"97c03c0e9f73a5049794b3c69ee60fb5e8b0ebd8","lessThan":"f0ae0a6ca87dc2d4a789f71cdedb808ba6c16990","versionType":"git","status":"affected"},{"version":"1e99bb19994246514d63e656492904176f9d5edd","lessThan":"137e8b4823a9a11928428d4ec0a0cacb2f50a769","versionType":"git","status":"affected"},{"version":"91e05ac2336d00d5b99fc774be4bd50039084796","lessThan":"4273548e418bd935430d35e9d052870f323441f3","versionType":"git","status":"affected"},{"version":"886f97fa59d0bbfa9859fb1a66dd9e014b522d89","lessThan":"49b34bd3ad69611af03590a23abf2cda9ac1073d","versionType":"git","status":"affected"},{"version":"ea5bb1d20da756e4f41a48dad42b2e7d6e73f71e","lessThan":"ff187c502b39389b0d732cb7050a3db8e5ebfcd6","versionType":"git","status":"affected"},{"version":"3c636a3edca9c3f180b3079f94fe7e115730d9c6","lessThan":"ae1f3460833d3e427420ab260278ec0e45d68c86","versionType":"git","status":"affected"},{"version":"d647c5b2fbf81560818dacade360abc8c00a9665","lessThan":"f3dd1e534e9de64669415f8239e0094afecfed78","versionType":"git","status":"affected"},{"version":"d647c5b2fbf81560818dacade360abc8c00a9665","lessThan":"ff6f26c58421614b02694ac9d219ac61d924bc68","versionType":"git","status":"affected"},{"version":"069c3fb310e9336cf48cfdf8748a32c29fd0193d","versionType":"git","status":"affected"},{"version":"5.10.258","lessThan":"5.10.261","versionType":"semver","status":"affected"},{"version":"5.15.209","lessThan":"5.15.212","versionType":"semver","status":"affected"},{"version":"6.1.175","lessThan":"6.1.178","versionType":"semver","status":"affected"},{"version":"6.6.140","lessThan":"6.6.145","versionType":"semver","status":"affected"},{"version":"6.12.86","lessThan":"6.12.97","versionType":"semver","status":"affected"},{"version":"6.18.27","lessThan":"6.18.40","versionType":"semver","status":"affected"},{"version":"7.0.4","lessThan":"7.1","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/ocfs2/aops.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1","status":"affected"},{"version":"0","lessThan":"7.1","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/137e8b4823a9a11928428d4ec0a0cacb2f50a769","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4273548e418bd935430d35e9d052870f323441f3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/49b34bd3ad69611af03590a23abf2cda9ac1073d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ae1f3460833d3e427420ab260278ec0e45d68c86","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f0ae0a6ca87dc2d4a789f71cdedb808ba6c16990","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f3dd1e534e9de64669415f8239e0094afecfed78","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ff187c502b39389b0d732cb7050a3db8e5ebfcd6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ff6f26c58421614b02694ac9d219ac61d924bc68","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80880","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T17:17:00.250","lastModified":"2026-09-04T17:17:00.250","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nIB/mlx5: Properly support implicit ODP rereg_mr\n\nDue to all the child mkeys in the implicit ODP configuration we cannot\nchange anything in place for the parent mkey. Instead the whole thing\nneeds to be rebuilt if any change is requested. If the user does not\nspecify a translation then force the implicit values which will then fall\nthrough the logic into mlx5_ib_reg_user_mr() to allocate a completely new\nMR.\n\nSince implicit children were also touching the mr->pd, this removes\nanother case where the access was racy."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/infiniband/hw/mlx5/mr.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"ef3642c4f54d3493c92c71faf46139b2473bc532","lessThan":"cbc9982c8573fb9e35040063aa78c8ebe768a1ff","versionType":"git","status":"affected"},{"version":"ef3642c4f54d3493c92c71faf46139b2473bc532","lessThan":"ee914ef54a7e707453ecb43eb30fb0a5c6dd0d69","versionType":"git","status":"affected"},{"version":"ef3642c4f54d3493c92c71faf46139b2473bc532","lessThan":"94f7e50eb6b2ce7fbd9aeac1db22460d2013a3fb","versionType":"git","status":"affected"},{"version":"ef3642c4f54d3493c92c71faf46139b2473bc532","lessThan":"eb7cb798e563b3f3b3baeb9cc6f7455764267e50","versionType":"git","status":"affected"},{"version":"ef3642c4f54d3493c92c71faf46139b2473bc532","lessThan":"d4f84bfa089fe71f775d25beb29303e844494c25","versionType":"git","status":"affected"},{"version":"ef3642c4f54d3493c92c71faf46139b2473bc532","lessThan":"5d02b9a2efd11d28d2a8feac7769686b1b871d9c","versionType":"git","status":"affected"},{"version":"ef3642c4f54d3493c92c71faf46139b2473bc532","lessThan":"ee7a8335069150c3f1893a697ab30bbeca00d796","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/infiniband/hw/mlx5/mr.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.11","status":"affected"},{"version":"0","lessThan":"5.11","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/5d02b9a2efd11d28d2a8feac7769686b1b871d9c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/94f7e50eb6b2ce7fbd9aeac1db22460d2013a3fb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cbc9982c8573fb9e35040063aa78c8ebe768a1ff","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d4f84bfa089fe71f775d25beb29303e844494c25","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/eb7cb798e563b3f3b3baeb9cc6f7455764267e50","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ee7a8335069150c3f1893a697ab30bbeca00d796","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ee914ef54a7e707453ecb43eb30fb0a5c6dd0d69","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80881","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T17:17:00.390","lastModified":"2026-09-04T17:17:00.390","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: fix buffer head management in ocfs2_read_blocks()\n\nIn ocfs2_read_blocks(), caller should't assume that buffer head returned\nby 'sb_getblk()' is exclusively owned and so 'put_bh()' always drops\nb_count from 1 to 0.  If it is not so, buffer head remains on hold and\nlikely to be returned by the next call to 'sb_getblk()' unchanged - that\nis, with BH_Uptodate bit set even if it has failed validation previously,\nthus allowing to insert that buffer head into OCFS2 metadata cache and\nsubmit it to upper layers.  To avoid such a scenario, BH_Uptodate should\nbe cleared immediately after 'validate()' callback has detected some data\ninconsistency."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/ocfs2/buffer_head_io.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"cf76c78595ca87548ca5e45c862ac9e0949c4687","lessThan":"a4eae1499c760949a93459d11390bd1fd823d31d","versionType":"git","status":"affected"},{"version":"cf76c78595ca87548ca5e45c862ac9e0949c4687","lessThan":"4ab17e328522a4df5fe0f0dcf39098118b1feeaa","versionType":"git","status":"affected"},{"version":"cf76c78595ca87548ca5e45c862ac9e0949c4687","lessThan":"5927acb3e2c99985a14adecd9d1b67ba191c622d","versionType":"git","status":"affected"},{"version":"cf76c78595ca87548ca5e45c862ac9e0949c4687","lessThan":"ecb3f9386f4353034caef77239473c627232db17","versionType":"git","status":"affected"},{"version":"cf76c78595ca87548ca5e45c862ac9e0949c4687","lessThan":"61f7a5acb3bf8fc97dad78f54b1e8d0e1c819766","versionType":"git","status":"affected"},{"version":"cf76c78595ca87548ca5e45c862ac9e0949c4687","lessThan":"0e389fc290c350c67591abf4c367119f4689f310","versionType":"git","status":"affected"},{"version":"cf76c78595ca87548ca5e45c862ac9e0949c4687","lessThan":"9e7a057934cdd58e4cc94350bcfe5367bbee0f8e","versionType":"git","status":"affected"},{"version":"cf76c78595ca87548ca5e45c862ac9e0949c4687","lessThan":"6371a07148ee979af22a9d6f4c277462953a9a4a","versionType":"git","status":"affected"},{"version":"01f93d5e36753fc4d06ec67f05ce78c9c6f2dd56","versionType":"git","status":"affected"},{"version":"65cbd1279f4b999d56a838344a30642db24cd215","versionType":"git","status":"affected"},{"version":"97e1db17bc1ef4c2e1789bc9323c7be44fba53f8","versionType":"git","status":"affected"},{"version":"6c150df9c2e80b5cf86f5a0d98beb7390ad63bfc","versionType":"git","status":"affected"},{"version":"4.4.204","lessThan":"4.5","versionType":"semver","status":"affected"},{"version":"4.9.204","lessThan":"4.10","versionType":"semver","status":"affected"},{"version":"4.14.157","lessThan":"4.15","versionType":"semver","status":"affected"},{"version":"4.19.87","lessThan":"4.20","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/ocfs2/buffer_head_io.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.20","status":"affected"},{"version":"0","lessThan":"4.20","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0e389fc290c350c67591abf4c367119f4689f310","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4ab17e328522a4df5fe0f0dcf39098118b1feeaa","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5927acb3e2c99985a14adecd9d1b67ba191c622d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/61f7a5acb3bf8fc97dad78f54b1e8d0e1c819766","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6371a07148ee979af22a9d6f4c277462953a9a4a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9e7a057934cdd58e4cc94350bcfe5367bbee0f8e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a4eae1499c760949a93459d11390bd1fd823d31d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ecb3f9386f4353034caef77239473c627232db17","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80882","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T17:17:00.657","lastModified":"2026-09-04T17:17:00.657","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: tegra - Return ENOMEM when input buffer allocation fails for ccm\n\nEnsure the ENOMEM error value is set when the input buffer allocation\nfails in tegra_ccm_do_one_req."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/crypto/tegra/tegra-se-aes.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"23f03ebd52f07418a8e3143d944b4a40552645d4","lessThan":"5cf0f624191cd12bd0a376bd7850d63b2b2236d4","versionType":"git","status":"affected"},{"version":"1e245948ca0c252f561792fabb45de5518301d97","lessThan":"4f3c17f14cf9085a9c9ae2145f748ea55cf6d4e9","versionType":"git","status":"affected"},{"version":"1e245948ca0c252f561792fabb45de5518301d97","lessThan":"20360e125a8dd411b0cc2660cb70f58590740818","versionType":"git","status":"affected"},{"version":"1e245948ca0c252f561792fabb45de5518301d97","lessThan":"690a5f9e5c972a580565ce544ed1627ccf1e84de","versionType":"git","status":"affected"},{"version":"bd12207bd1fc95009029d7943cb973c787c874a4","versionType":"git","status":"affected"},{"version":"3ba914ad4991be67a4ff88ecaa388bafb55de298","versionType":"git","status":"affected"},{"version":"6.12.91","lessThan":"6.12.97","versionType":"semver","status":"affected"},{"version":"6.13.11","lessThan":"6.14","versionType":"semver","status":"affected"},{"version":"6.14.2","lessThan":"6.15","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/crypto/tegra/tegra-se-aes.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.15","status":"affected"},{"version":"0","lessThan":"6.15","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/20360e125a8dd411b0cc2660cb70f58590740818","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4f3c17f14cf9085a9c9ae2145f748ea55cf6d4e9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5cf0f624191cd12bd0a376bd7850d63b2b2236d4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/690a5f9e5c972a580565ce544ed1627ccf1e84de","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80883","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T17:17:00.983","lastModified":"2026-09-04T17:17:00.983","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/tegra: gr2d/gr3d: Initialize address register map before HOST1X client is registered\n\nThe host1x_client_register() function is called just prior to register map\ninitialization loop, making the device available to userspace. This may\nresult in userspace attempting to submits a job before the register map is\ninitialized. Address this by moving register initialization before host1x\nclient registration."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/gpu/drm/tegra/gr2d.c","drivers/gpu/drm/tegra/gr3d.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"6e22d5ad61cfa38aa53fab86a530113aff6a3619","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"5db37fd7710e74bc4df48bddab8f571d0bfc6769","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"40a2a91da02c434938f0ba53877984820800b5f0","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"3055292b8eed69553b389a609197a241df47e68e","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"c4ef5ba1131346159e31f4ef858525cf377380a6","versionType":"git","status":"affected"},{"version":"0","lessThan":"6.6.145","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.12.97","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.18.40","versionType":"semver","status":"affected"},{"version":"0","lessThan":"7.1.5","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/gpu/drm/tegra/gr2d.c","drivers/gpu/drm/tegra/gr3d.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3055292b8eed69553b389a609197a241df47e68e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/40a2a91da02c434938f0ba53877984820800b5f0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5db37fd7710e74bc4df48bddab8f571d0bfc6769","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6e22d5ad61cfa38aa53fab86a530113aff6a3619","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c4ef5ba1131346159e31f4ef858525cf377380a6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80884","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T17:17:01.103","lastModified":"2026-09-04T17:17:01.103","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nntb: Store original DMA address for future release\n\nThe DMA API requires that dma_free_attrs receive the exact dma_handle\noriginally returned by the allocation function. Do not modify it."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/ntb/ntb_transport.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"fc5d1829f9bf3d8275322727c0e9a8baf268b7c6","lessThan":"10662aafce4acd52278c942d0a5b3993594017b9","versionType":"git","status":"affected"},{"version":"fc5d1829f9bf3d8275322727c0e9a8baf268b7c6","lessThan":"da6d997ac556479c112554ab5d95cbd04683eb11","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/ntb/ntb_transport.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.20","status":"affected"},{"version":"0","lessThan":"4.20","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/10662aafce4acd52278c942d0a5b3993594017b9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/da6d997ac556479c112554ab5d95cbd04683eb11","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80885","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T17:17:01.207","lastModified":"2026-09-04T17:17:01.207","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nafs: Fix uncancelled rxrpc OOB message handler\n\nFix AFS to cancel its OOB message processing (typically to respond to\nsecurity challenges).  Also move OOB message processing to afs_wq so that\nit's also waited for and make the OOB handler just return if the net\nnamespace is no longer live."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/afs/cm_security.c","fs/afs/rxrpc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5800b1cf3fd8ccab752a101865be1e76dac33142","lessThan":"231414253b648b3518b56f09710b831945d6a2fc","versionType":"git","status":"affected"},{"version":"5800b1cf3fd8ccab752a101865be1e76dac33142","lessThan":"d14e96ddd616c8a9fff3b5bab3bf4af0cfc30ec4","versionType":"git","status":"affected"},{"version":"5800b1cf3fd8ccab752a101865be1e76dac33142","lessThan":"a4057e58b07005d0fe0491bdbf1868c1491909ee","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/afs/cm_security.c","fs/afs/rxrpc.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.16","status":"affected"},{"version":"0","lessThan":"6.16","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/231414253b648b3518b56f09710b831945d6a2fc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a4057e58b07005d0fe0491bdbf1868c1491909ee","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d14e96ddd616c8a9fff3b5bab3bf4af0cfc30ec4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80886","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T17:17:01.310","lastModified":"2026-09-04T17:17:01.310","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nserial: msm: Disable DMA for kernel console UART\n\nAt the moment, concurrent writes from userspace and the kernel to the\nconsole can trigger a race condition that results in an infinite loop of\nthe same messages printed over and over again. This is most likely to\nhappen during system startup or shutdown when the init system starts/stops\na large number of system services that interact with various kernel code.\n\nWhen userspace writes to the TTY device, the driver initiates an\nasynchronous DMA transfer and releases the port lock. At the same moment,\nthe kernel printk path might grab the port lock and re-configure the UART\ncontroller for PIO, without waiting for the DMA operation to complete. It\nseems like this collision results in zero progress being reported for the\nDMA engine, so the same text is printed to the console over and over again.\n\nFor the kernel console, we want a reliable output path that will be\nfunctional even during crashes etc. So rather than implementing complex\ncode to synchronize the kernel console write routines with the userspace\nDMA write routines, simply disable DMA for the console UART instance.\n\nSimilar checks exist in many other serial drivers, e.g. 8250_port.c,\nimx.c, sh-sci.c etc."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/tty/serial/msm_serial.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3a878c430fd6eb4f8587f9ebd187f773bf85d1d6","lessThan":"f58e568dc308c8e13f7730c8de2da5ed514e540d","versionType":"git","status":"affected"},{"version":"3a878c430fd6eb4f8587f9ebd187f773bf85d1d6","lessThan":"bb4296de5b538b575978c588cb3738ab8524d01a","versionType":"git","status":"affected"},{"version":"3a878c430fd6eb4f8587f9ebd187f773bf85d1d6","lessThan":"6acea62738ed4cae6746483026706a773b44dad7","versionType":"git","status":"affected"},{"version":"3a878c430fd6eb4f8587f9ebd187f773bf85d1d6","lessThan":"abc1926c88c189e5d698b91ed6890e09ab5c321d","versionType":"git","status":"affected"},{"version":"3a878c430fd6eb4f8587f9ebd187f773bf85d1d6","lessThan":"2727744ccb5ca59090451451ee94f530b1be04a5","versionType":"git","status":"affected"},{"version":"3a878c430fd6eb4f8587f9ebd187f773bf85d1d6","lessThan":"d354716245192de2d203f2b35f22ab8dc13595e2","versionType":"git","status":"affected"},{"version":"3a878c430fd6eb4f8587f9ebd187f773bf85d1d6","lessThan":"e3b42e326f4f30efcdc90bad5f5ba37e1cd91a47","versionType":"git","status":"affected"},{"version":"3a878c430fd6eb4f8587f9ebd187f773bf85d1d6","lessThan":"22dd2777e6c180e1c945b00f6d18550979436324","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/tty/serial/msm_serial.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"4.4","status":"affected"},{"version":"0","lessThan":"4.4","versionType":"semver","status":"unaffected"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/22dd2777e6c180e1c945b00f6d18550979436324","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2727744ccb5ca59090451451ee94f530b1be04a5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6acea62738ed4cae6746483026706a773b44dad7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/abc1926c88c189e5d698b91ed6890e09ab5c321d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bb4296de5b538b575978c588cb3738ab8524d01a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d354716245192de2d203f2b35f22ab8dc13595e2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e3b42e326f4f30efcdc90bad5f5ba37e1cd91a47","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f58e568dc308c8e13f7730c8de2da5ed514e540d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-84933","sourceIdentifier":"ce714d77-add3-4f53-aff5-83d477b104bb","published":"2026-09-04T17:17:01.973","lastModified":"2026-09-04T19:17:30.163","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"undici's cache interceptor does not handle the Set-Cookie response header anywhere in its cache path, so it neither refuses to store nor strips that header. In shared cache mode, which is the default, an otherwise cacheable response that carries a Set-Cookie header, for example one marked with a public and max-age directive, is stored and then re-served to a later caller that matches the same cache key. As a result one caller's cookie is disclosed to a different caller, and an untrusted server can inject cookies into cached responses served to all subsequent callers. This violates the requirement that a shared cache must not store cookies. This affects undici versions from 7.0.0 up to 7.29.1 and from 8.0.0 up to 8.10.2. Users should upgrade to undici 7.29.1 or 8.10.2."}],"affected":[{"source":"ce714d77-add3-4f53-aff5-83d477b104bb","affectedData":[{"vendor":"undici","product":"undici","defaultStatus":"unaffected","packageURL":"pkg:npm/undici","versions":[{"version":"7.0.0","lessThan":"7.29.1","versionType":"semver","status":"affected"},{"version":"7.29.1","versionType":"semver","status":"unaffected"},{"version":"8.0.0","lessThan":"8.10.2","versionType":"semver","status":"affected"},{"version":"8.10.2","versionType":"semver","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"ce714d77-add3-4f53-aff5-83d477b104bb","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":4.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T18:34:06.167949Z","id":"CVE-2026-84933","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"ce714d77-add3-4f53-aff5-83d477b104bb","type":"Secondary","description":[{"lang":"en","value":"CWE-200"},{"lang":"en","value":"CWE-524"}]}],"references":[{"url":"https://cna.openjsf.org/security-advisories.html","source":"ce714d77-add3-4f53-aff5-83d477b104bb"},{"url":"https://github.com/nodejs/undici/security/advisories/GHSA-2jfj-6hjv-fm6j","source":"ce714d77-add3-4f53-aff5-83d477b104bb"}]}},{"cve":{"id":"CVE-2026-84947","sourceIdentifier":"ce714d77-add3-4f53-aff5-83d477b104bb","published":"2026-09-04T17:17:02.103","lastModified":"2026-09-04T19:17:30.277","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"undici's dump interceptor reads and discards a response body up to a configurable maximum size. When a response declares a Content-Length that exceeds the maximum, the interceptor aborts cleanly, but when a response has no Content-Length and is chunked, the interceptor instead signals completion early once the accumulated size reaches the maximum, without pausing or aborting the request. Because the underlying parser keeps delivering body bytes, a second completion signal fires and trips an internal assertion, which aborts the request and tears down the connection. The application is left observing a misleading successful status with an empty or truncated body while the connection has actually been disconnected. This affects undici versions from 7.1.0 up to 7.29.1 and from 8.0.0 up to 8.10.2. Users should upgrade to undici 7.29.1 or 8.10.2."}],"affected":[{"source":"ce714d77-add3-4f53-aff5-83d477b104bb","affectedData":[{"vendor":"undici","product":"undici","defaultStatus":"unaffected","packageURL":"pkg:npm/undici","versions":[{"version":"7.1.0","lessThan":"7.29.1","versionType":"semver","status":"affected"},{"version":"7.29.1","versionType":"semver","status":"unaffected"},{"version":"8.0.0","lessThan":"8.10.2","versionType":"semver","status":"affected"},{"version":"8.10.2","versionType":"semver","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"ce714d77-add3-4f53-aff5-83d477b104bb","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","baseScore":3.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T18:34:39.083543Z","id":"CVE-2026-84947","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"ce714d77-add3-4f53-aff5-83d477b104bb","type":"Secondary","description":[{"lang":"en","value":"CWE-20"},{"lang":"en","value":"CWE-248"}]}],"references":[{"url":"https://cna.openjsf.org/security-advisories.html","source":"ce714d77-add3-4f53-aff5-83d477b104bb"},{"url":"https://github.com/nodejs/undici/security/advisories/GHSA-2gqq-gqf2-x968","source":"ce714d77-add3-4f53-aff5-83d477b104bb"}]}},{"cve":{"id":"CVE-2026-84961","sourceIdentifier":"ce714d77-add3-4f53-aff5-83d477b104bb","published":"2026-09-04T17:17:02.227","lastModified":"2026-09-04T19:17:30.387","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"undici's BalancedPool constructor passes its entire options object through an internal deep-clone that serializes and reparses the value as JSON. Because JSON cannot represent functions, any function-valued TLS option, such as a caller-supplied checkServerIdentity callback or a custom connector inside the connect option, is silently discarded before it reaches the TLS layer. As a result a peer whose certificate the application's custom checkServerIdentity was written to reject, but which still passes Node's default hostname and chain checks, is accepted when reached through BalancedPool. The Client, Pool, and Agent dispatchers are not affected because they extract the connect and tls options before cloning. This affects undici versions from 7.24.1 up to 7.29.1 and from 8.0.0 up to 8.10.2, and only when the application supplies a function-valued connect or tls option to BalancedPool. Users should upgrade to undici 7.29.1 or 8.10.2."}],"affected":[{"source":"ce714d77-add3-4f53-aff5-83d477b104bb","affectedData":[{"vendor":"undici","product":"undici","defaultStatus":"unaffected","packageURL":"pkg:npm/undici","versions":[{"version":"7.24.1","lessThan":"7.29.1","versionType":"semver","status":"affected"},{"version":"7.29.1","versionType":"semver","status":"unaffected"},{"version":"8.0.0","lessThan":"8.10.2","versionType":"semver","status":"affected"},{"version":"8.10.2","versionType":"semver","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"ce714d77-add3-4f53-aff5-83d477b104bb","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","baseScore":7.4,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T18:35:57.858790Z","id":"CVE-2026-84961","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"ce714d77-add3-4f53-aff5-83d477b104bb","type":"Secondary","description":[{"lang":"en","value":"CWE-295"}]}],"references":[{"url":"https://cna.openjsf.org/security-advisories.html","source":"ce714d77-add3-4f53-aff5-83d477b104bb"},{"url":"https://github.com/nodejs/undici/security/advisories/GHSA-w293-vg96-wgc3","source":"ce714d77-add3-4f53-aff5-83d477b104bb"}]}},{"cve":{"id":"CVE-2026-85008","sourceIdentifier":"ce714d77-add3-4f53-aff5-83d477b104bb","published":"2026-09-04T17:17:02.347","lastModified":"2026-09-04T20:17:30.920","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"undici's cache interceptor documents that only safe HTTP methods are cached, but its logic to skip caching is built by subtracting the configured methods from the set of safe methods, so an unsafe method such as POST, PUT, or DELETE is never placed in the skip list and instead falls through to the full cache-read path. The response-storage gate also lacked a method check, so a response to an unsafe request that is heuristically cacheable or carries an explicit Cache-Control directive is stored and later replayed from cache. Because response headers from a remote origin are untrusted, an origin can answer once with a cacheable status and then have the client's own subsequent state-changing requests to that path served from the stale cache entry without ever reaching the origin, an integrity failure that occurs under the interceptor's default configuration. This affects undici versions from 7.0.0 up to 7.29.1 and from 8.0.0 up to 8.10.2. Users should upgrade to undici 7.29.1 or 8.10.2."}],"affected":[{"source":"ce714d77-add3-4f53-aff5-83d477b104bb","affectedData":[{"vendor":"undici","product":"undici","defaultStatus":"unaffected","packageURL":"pkg:npm/undici","versions":[{"version":"7.0.0","lessThan":"7.29.1","versionType":"semver","status":"affected"},{"version":"7.29.1","versionType":"semver","status":"unaffected"},{"version":"8.0.0","lessThan":"8.10.2","versionType":"semver","status":"affected"},{"version":"8.10.2","versionType":"semver","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"ce714d77-add3-4f53-aff5-83d477b104bb","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","baseScore":3.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T19:28:49.240361Z","id":"CVE-2026-85008","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"ce714d77-add3-4f53-aff5-83d477b104bb","type":"Secondary","description":[{"lang":"en","value":"CWE-345"}]}],"references":[{"url":"https://cna.openjsf.org/security-advisories.html","source":"ce714d77-add3-4f53-aff5-83d477b104bb"},{"url":"https://github.com/nodejs/undici/security/advisories/GHSA-8436-99hf-9mmv","source":"ce714d77-add3-4f53-aff5-83d477b104bb"}]}},{"cve":{"id":"CVE-2026-85014","sourceIdentifier":"ce714d77-add3-4f53-aff5-83d477b104bb","published":"2026-09-04T17:17:02.470","lastModified":"2026-09-04T20:17:31.027","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"undici's experimental WebSocketStream client crashes the whole Node.js process when a remote peer closes the TCP connection without a WebSocket close handshake. On an unclean close the internal socket-close handler calls abort on the writable stream unconditionally and discards the returned promise, but per the WHATWG Streams standard aborting a locked writable returns a promise that rejects with a TypeError. Because the application holds a writer on that writable, which is the only way to write, the rejection is never observed and Node's default unhandled-rejection behavior terminates the process. An untrusted server can therefore crash a client with a single abrupt disconnect, with no authentication and no application mistake. This affects undici versions from 7.0.0 up to 7.29.1 and from 8.0.0 up to 8.10.2. Users should upgrade to undici 7.29.1 or 8.10.2."}],"affected":[{"source":"ce714d77-add3-4f53-aff5-83d477b104bb","affectedData":[{"vendor":"undici","product":"undici","defaultStatus":"unaffected","packageURL":"pkg:npm/undici","versions":[{"version":"7.0.0","lessThan":"7.29.1","versionType":"semver","status":"affected"},{"version":"7.29.1","versionType":"semver","status":"unaffected"},{"version":"8.0.0","lessThan":"8.10.2","versionType":"semver","status":"affected"},{"version":"8.10.2","versionType":"semver","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"ce714d77-add3-4f53-aff5-83d477b104bb","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":5.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.2,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T19:30:00.595466Z","id":"CVE-2026-85014","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"ce714d77-add3-4f53-aff5-83d477b104bb","type":"Secondary","description":[{"lang":"en","value":"CWE-248"},{"lang":"en","value":"CWE-754"}]}],"references":[{"url":"https://cna.openjsf.org/security-advisories.html","source":"ce714d77-add3-4f53-aff5-83d477b104bb"},{"url":"https://github.com/nodejs/undici/security/advisories/GHSA-rx4f-c7p8-82vq","source":"ce714d77-add3-4f53-aff5-83d477b104bb"}]}},{"cve":{"id":"CVE-2026-85024","sourceIdentifier":"ce714d77-add3-4f53-aff5-83d477b104bb","published":"2026-09-04T17:17:02.590","lastModified":"2026-09-04T20:17:31.137","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"undici bundles a WebSocket client whose permessage-deflate size-limit cleanup removes all listeners from the internal zlib inflate stream, including its error listener, while that stream can still emit. When a remote peer sends a compressed payload that crosses the built-in 128 MiB decompressed-payload limit and then contains a malformed DEFLATE byte, the inflate stream emits a data error with no listener attached, which Node.js treats as a fatal unhandled error and terminates the entire process. Exploitation is remote and unauthenticated, requires no application mistake, and is asymmetric, since roughly 130 KB on the wire expands past the limit and crashes the process, and reconnecting can repeat the crash. This affects undici versions from 6.25.0 up to 6.28.1, from 7.28.0 up to 7.29.1, and from 8.1.0 up to 8.10.2. Users should upgrade to undici 6.28.1, 7.29.1, or 8.10.2."}],"affected":[{"source":"ce714d77-add3-4f53-aff5-83d477b104bb","affectedData":[{"vendor":"undici","product":"undici","defaultStatus":"unaffected","packageURL":"pkg:npm/undici","versions":[{"version":"6.25.0","lessThan":"6.28.1","versionType":"semver","status":"affected"},{"version":"6.28.1","versionType":"semver","status":"unaffected"},{"version":"7.28.0","lessThan":"7.29.1","versionType":"semver","status":"affected"},{"version":"7.29.1","versionType":"semver","status":"unaffected"},{"version":"8.1.0","lessThan":"8.10.2","versionType":"semver","status":"affected"},{"version":"8.10.2","versionType":"semver","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"ce714d77-add3-4f53-aff5-83d477b104bb","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":5.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.2,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T19:30:33.342541Z","id":"CVE-2026-85024","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"ce714d77-add3-4f53-aff5-83d477b104bb","type":"Secondary","description":[{"lang":"en","value":"CWE-248"}]}],"references":[{"url":"https://cna.openjsf.org/security-advisories.html","source":"ce714d77-add3-4f53-aff5-83d477b104bb"},{"url":"https://github.com/nodejs/undici/security/advisories/GHSA-3wwx-pv8p-q78v","source":"ce714d77-add3-4f53-aff5-83d477b104bb"}]}},{"cve":{"id":"CVE-2026-85152","sourceIdentifier":"ce714d77-add3-4f53-aff5-83d477b104bb","published":"2026-09-04T17:17:02.717","lastModified":"2026-09-04T20:17:31.447","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"undici 8.10.0 omits the destination origin from the cache and request-deduplication keys when the cache or deduplicate interceptor is composed directly onto a Client or Pool. Because the internal cache key falls back to an empty origin string, a cacheable or in-flight response from one upstream origin is returned for a request to a different, trusted origin whenever the method, path, and relevant headers match, which permits cross-origin information disclosure and persistent cache poisoning. The reporter demonstrated a full authentication bypass in which a JWT signed with an attacker-controlled key was accepted as belonging to a trusted issuer, and the trusted origin was never contacted. This is a regression introduced in 8.10.0 and affects undici versions from 8.10.0 up to 8.10.2. Applications using an Agent, which carries the origin in its dispatch options, are not affected. Users should upgrade to undici 8.10.2."}],"affected":[{"source":"ce714d77-add3-4f53-aff5-83d477b104bb","affectedData":[{"vendor":"undici","product":"undici","defaultStatus":"unaffected","packageURL":"pkg:npm/undici","versions":[{"version":"8.10.0","lessThan":"8.10.2","versionType":"semver","status":"affected"},{"version":"8.10.2","versionType":"semver","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"ce714d77-add3-4f53-aff5-83d477b104bb","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","baseScore":7.4,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T19:29:18.959401Z","id":"CVE-2026-85152","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"ce714d77-add3-4f53-aff5-83d477b104bb","type":"Secondary","description":[{"lang":"en","value":"CWE-346"}]}],"references":[{"url":"https://cna.openjsf.org/security-advisories.html","source":"ce714d77-add3-4f53-aff5-83d477b104bb"},{"url":"https://github.com/nodejs/undici/security/advisories/GHSA-vp8m-p9jh-q5pm","source":"ce714d77-add3-4f53-aff5-83d477b104bb"}]}},{"cve":{"id":"CVE-2021-44319","sourceIdentifier":"cve@mitre.org","published":"2026-09-04T18:17:43.917","lastModified":"2026-09-04T18:17:43.917","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Parrot AR.Drone 1 and AR.Drone 2 are vulnerable to Denial of Service. The Parrot AR.Drone platform is vulnerable to Wi-Fi deauthentication attack, allowing remote and unauthenticated attackers to disconnect drone from controller during mid-flight."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{},"references":[{"url":"http://bertoli.tech/geral/parrot-ar-drone-denial-of-service-dos-attack/","source":"cve@mitre.org"},{"url":"https://github.com/gubertoli/cve/tree/main/CVE-2021-44319","source":"cve@mitre.org"},{"url":"https://web.archive.org/web/20180822165812/","source":"cve@mitre.org"}]}},{"cve":{"id":"CVE-2021-44320","sourceIdentifier":"cve@mitre.org","published":"2026-09-04T18:17:44.397","lastModified":"2026-09-04T20:17:19.860","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Parrot AR.Drone version 1 and 2 does not employ a suitable mechanism to prevent denial-of-service (DoS) attacks. An attacker can harm the device availability (i.e., video streaming and control) by using tool to perform an IPv4 flood attack. Verified attacks includes SYN flooding and UDP flooding."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T19:23:27.940459Z","id":"CVE-2021-44320","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-400"}]}],"references":[{"url":"https://github.com/gubertoli/cve/tree/main/CVE-2021-44320","source":"cve@mitre.org"},{"url":"https://www.researchgate.net/publication/257681090_ARDrone_corruption","source":"cve@mitre.org"},{"url":"https://www.researchgate.net/publication/313177418_The_Impact_of_DoS_Attacks_on_the_ARDrone_20","source":"cve@mitre.org"}]}},{"cve":{"id":"CVE-2026-18149","sourceIdentifier":"ce714d77-add3-4f53-aff5-83d477b104bb","published":"2026-09-04T18:17:49.733","lastModified":"2026-09-04T18:17:49.733","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"undici's retry handler can leave an already-exposed response body pending forever. When a server returns a successful response that declares a Content-Length, sends only part of the body, and closes the connection, the retry handler retries the request. If the retry returns a non-retryable status such as 400, the handler forwards that new response downstream and replaces its internal response stream, but the original response body that the application still holds is never ended or destroyed. As a result calls that read that body never settle, and the configured body timeout does not fire because its timer is tied to the connection parser rather than the orphaned body. An attacker-controlled server can trigger this with two short responses without keeping a connection open, and repeated requests accumulate pending promises and streams that can exhaust application concurrency or memory. This affects undici versions from 7.11.0 up to 7.29.1 and from 8.0.0 up to 8.10.2. Users should upgrade to undici 7.29.1 or 8.10.2."}],"affected":[{"source":"ce714d77-add3-4f53-aff5-83d477b104bb","affectedData":[{"vendor":"undici","product":"undici","defaultStatus":"unaffected","packageURL":"pkg:npm/undici","versions":[{"version":"7.11.0","lessThan":"7.29.1","versionType":"semver","status":"affected"},{"version":"7.29.1","versionType":"semver","status":"unaffected"},{"version":"8.0.0","lessThan":"8.10.2","versionType":"semver","status":"affected"},{"version":"8.10.2","versionType":"semver","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"ce714d77-add3-4f53-aff5-83d477b104bb","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":5.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.2,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T17:49:39.921559Z","id":"CVE-2026-18149","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"ce714d77-add3-4f53-aff5-83d477b104bb","type":"Secondary","description":[{"lang":"en","value":"CWE-772"}]}],"references":[{"url":"https://cna.openjsf.org/security-advisories.html","source":"ce714d77-add3-4f53-aff5-83d477b104bb"},{"url":"https://github.com/nodejs/undici/security/advisories/GHSA-pmjh-fq2x-6v4x","source":"ce714d77-add3-4f53-aff5-83d477b104bb"}]}},{"cve":{"id":"CVE-2026-18540","sourceIdentifier":"ce714d77-add3-4f53-aff5-83d477b104bb","published":"2026-09-04T18:17:50.020","lastModified":"2026-09-04T18:17:50.020","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"undici's retry interceptor can append the body of a ranged retry response to bytes already delivered from an earlier partial response while still presenting the original response's status and headers. This happens when an upstream server delivers part of a body without a trustworthy resume checkpoint, for example a non-success response whose headers were already sent or a partial-content response with an unusable content range, then closes the connection and answers the resumed range request with more bytes. As a result the response body can be longer than the Content-Length that the application observes. An application that relays such a response to a downstream HTTP/1.1 peer without normalizing the framing can emit a body that exceeds the forwarded Content-Length, and the excess bytes can be interpreted as the start of a following response, which enables downstream response splitting or desynchronization. Exploitation requires an attacker-controlled upstream server and an application that forwards the response through a framing-sensitive path. This affects undici versions before 6.28.1, from 7.0.0 up to 7.29.1, and from 8.0.0 up to 8.10.2. Users should upgrade to undici 6.28.1, 7.29.1, or 8.10.2."}],"affected":[{"source":"ce714d77-add3-4f53-aff5-83d477b104bb","affectedData":[{"vendor":"undici","product":"undici","defaultStatus":"unaffected","packageURL":"pkg:npm/undici","versions":[{"version":"0","lessThan":"6.28.1","versionType":"semver","status":"affected"},{"version":"6.28.1","versionType":"semver","status":"unaffected"},{"version":"7.0.0","lessThan":"7.29.1","versionType":"semver","status":"affected"},{"version":"7.29.1","versionType":"semver","status":"unaffected"},{"version":"8.0.0","lessThan":"8.10.2","versionType":"semver","status":"affected"},{"version":"8.10.2","versionType":"semver","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"ce714d77-add3-4f53-aff5-83d477b104bb","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","baseScore":3.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T17:50:05.851866Z","id":"CVE-2026-18540","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"ce714d77-add3-4f53-aff5-83d477b104bb","type":"Secondary","description":[{"lang":"en","value":"CWE-444"}]}],"references":[{"url":"https://cna.openjsf.org/security-advisories.html","source":"ce714d77-add3-4f53-aff5-83d477b104bb"},{"url":"https://github.com/nodejs/undici/security/advisories/GHSA-r53p-7pc4-xj5r","source":"ce714d77-add3-4f53-aff5-83d477b104bb"}]}},{"cve":{"id":"CVE-2026-18745","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-04T18:17:50.667","lastModified":"2026-09-04T18:17:50.667","vulnStatus":"Rejected","cveTags":[],"descriptions":[{"lang":"en","value":"Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority."}],"metrics":{},"references":[]}},{"cve":{"id":"CVE-2026-19534","sourceIdentifier":"ce714d77-add3-4f53-aff5-83d477b104bb","published":"2026-09-04T18:17:51.647","lastModified":"2026-09-04T19:17:24.857","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"undici's WebSocket client crashes the whole Node.js process during the opening handshake when a server responds with a subprotocol that the client never requested. A default WebSocket connection sends no subprotocol, but if the server's 101 response includes a Sec-WebSocket-Protocol header, undici dereferences a null value while checking it against the requested list and throws an uncaught TypeError. Because that code runs inside a microtask with no surrounding error handling, the exception propagates and terminates the process under Node's default behavior, instead of gracefully failing the connection as required by the WebSocket protocol. Any application that opens a WebSocket to an attacker-controlled or compromised server, or over a plaintext connection subject to a machine-in-the-middle, can be crashed remotely without authentication in the default configuration. This affects undici versions from 6.7.0 up to 6.28.1, from 7.0.0 up to 7.29.1, and from 8.0.0 up to 8.10.2. Users should upgrade to undici 6.28.1, 7.29.1, or 8.10.2."}],"affected":[{"source":"ce714d77-add3-4f53-aff5-83d477b104bb","affectedData":[{"vendor":"undici","product":"undici","defaultStatus":"unaffected","packageURL":"pkg:npm/undici","versions":[{"version":"6.7.0","lessThan":"6.28.1","versionType":"semver","status":"affected"},{"version":"6.28.1","versionType":"semver","status":"unaffected"},{"version":"7.0.0","lessThan":"7.29.1","versionType":"semver","status":"affected"},{"version":"7.29.1","versionType":"semver","status":"unaffected"},{"version":"8.0.0","lessThan":"8.10.2","versionType":"semver","status":"affected"},{"version":"8.10.2","versionType":"semver","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"ce714d77-add3-4f53-aff5-83d477b104bb","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T18:18:18.694757Z","id":"CVE-2026-19534","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"ce714d77-add3-4f53-aff5-83d477b104bb","type":"Secondary","description":[{"lang":"en","value":"CWE-248"},{"lang":"en","value":"CWE-252"}]}],"references":[{"url":"https://cna.openjsf.org/security-advisories.html","source":"ce714d77-add3-4f53-aff5-83d477b104bb"},{"url":"https://github.com/nodejs/undici/security/advisories/GHSA-rfgv-xxqx-mfg5","source":"ce714d77-add3-4f53-aff5-83d477b104bb"}]}},{"cve":{"id":"CVE-2026-50553","sourceIdentifier":"security-advisories@github.com","published":"2026-09-04T18:17:52.203","lastModified":"2026-09-04T18:17:52.203","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Note Mark is an open-source note-taking application. Prior to version 0.19.5, Note Mark validates book and note slug values with the OpenAPI/huma tag pattern:\"[a-z0-9-]+\". huma compiles this with regexp.MustCompile(s.Pattern) and tests it with patternRe.MatchString(str), an UNANCHORED match. Because the pattern is not anchored (^...$), any string that merely CONTAINS one [a-z0-9-] substring passes validation. A slug such as ../../../../../../tmp/escape is accepted and stored verbatim. The data-export CLI commands (note-mark migrate export and note-mark migrate export-v1) join these unsanitized slugs straight into the output path with path.Join / filepath.Join, then os.MkdirAll the directory and os.Create the note file. path.Join resolves the ../ segments, so the note content file is written OUTSIDE the configured export directory. The export process commonly runs as root (default in Docker / bare-metal admin usage), so this is a root-privilege arbitrary directory create + file write. This issue has been patched in version 0.19.5."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"enchant97","product":"note-mark","versions":[{"version":"< 0.19.5","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.6,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"PASSIVE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T17:46:26.605003Z","id":"CVE-2026-50553","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Primary","description":[{"lang":"en","value":"CWE-20"},{"lang":"en","value":"CWE-22"}]}],"references":[{"url":"https://github.com/enchant97/note-mark/commit/67b7de04308a858ef27ceff87b514067b6d667e5","source":"security-advisories@github.com"},{"url":"https://github.com/enchant97/note-mark/releases/tag/v0.19.5","source":"security-advisories@github.com"},{"url":"https://github.com/enchant97/note-mark/security/advisories/GHSA-rqrh-8wpv-x7hh","source":"security-advisories@github.com"},{"url":"https://github.com/enchant97/note-mark/security/advisories/GHSA-rqrh-8wpv-x7hh","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}]}},{"cve":{"id":"CVE-2026-53756","sourceIdentifier":"security-advisories@github.com","published":"2026-09-04T18:17:52.350","lastModified":"2026-09-04T18:17:52.350","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Emlog is an open source website building system. Prior to version 2.6.16, Emlog CMS Pro contains a blind SQL injection in User_Model::getUserDataByLogin(). The $account parameter is directly interpolated into SQL queries without any filtering. The vulnerability is reachable through the auth cookie validation path, where $username is extracted from the cookie and passed unfiltered into SQL — guarded only by an HMAC signature that requires AUTH_KEY to forge. This issue has been patched in version 2.6.16."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"emlog","product":"emlog","versions":[{"version":"< 2.6.16","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N","baseScore":4.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":3.6}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Primary","description":[{"lang":"en","value":"CWE-89"}]}],"references":[{"url":"https://github.com/emlog/emlog/commit/92b6eea618891b28ed0c520564dff26e170645b4","source":"security-advisories@github.com"},{"url":"https://github.com/emlog/emlog/releases/tag/pro-2.6.16","source":"security-advisories@github.com"},{"url":"https://github.com/emlog/emlog/security/advisories/GHSA-xq97-53c2-vvfg","source":"security-advisories@github.com"}]}},{"cve":{"id":"CVE-2026-53757","sourceIdentifier":"security-advisories@github.com","published":"2026-09-04T18:17:52.500","lastModified":"2026-09-04T18:17:52.500","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Emlog is an open source website building system. In versions 2.6.29 and prior, the emUnZip() function extracts all ZIP entries via ZipArchive::extractTo() without validating entry paths for ../ traversal sequences. Only the first entry's subdirectory structure is checked. An attacker can overwrite arbitrary files on the server filesystem, including config.php for immediate RCE. At time of publication, there are no publicly known patches."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"emlog","product":"emlog","versions":[{"version":"<= 2.6.29","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":6.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"HIGH","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Primary","description":[{"lang":"en","value":"CWE-22"}]}],"references":[{"url":"https://github.com/emlog/emlog/security/advisories/GHSA-gjj4-37r4-mf5g","source":"security-advisories@github.com"}]}},{"cve":{"id":"CVE-2026-53758","sourceIdentifier":"security-advisories@github.com","published":"2026-09-04T18:17:52.640","lastModified":"2026-09-04T18:17:52.640","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Emlog is an open source website building system. In versions 2.6.29 and prior, article content is processed by Parsedown without enabling safe mode, which means raw HTML including <script> tags embedded in Markdown is passed through unescaped. The output is rendered with no additional sanitization, resulting in stored XSS visible to all site visitors. At time of publication, there are no publicly known patches."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"emlog","product":"emlog","versions":[{"version":"<= 2.6.29","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://github.com/emlog/emlog/security/advisories/GHSA-35vc-2gv4-mw77","source":"security-advisories@github.com"}]}},{"cve":{"id":"CVE-2026-53760","sourceIdentifier":"security-advisories@github.com","published":"2026-09-04T18:17:52.770","lastModified":"2026-09-04T18:17:52.770","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Admidio is an open-source user management solution. In versions 5.0.11 and prior, the modules/plugins.php endpoint handles plugin installation, uninstallation, and update operations via GET requests without CSRF token validation. Because these are top-level navigations, browsers include SameSite=Lax session cookies. An attacker crafts a malicious page that, when an authenticated administrator visits it, triggers arbitrary plugin operations. The uninstall operation executes DROP TABLE SQL scripts and destroys plugin data. This issue has been patched via commit 056b1bd."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"Admidio","product":"admidio","versions":[{"version":"< 056b1bd9f995437395e337d2c73a32e5c96ee616","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:L","baseScore":5.2,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":0.9,"impactScore":4.2}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Primary","description":[{"lang":"en","value":"CWE-352"}]}],"references":[{"url":"https://github.com/Admidio/admidio/commit/056b1bd9f995437395e337d2c73a32e5c96ee616","source":"security-advisories@github.com"},{"url":"https://github.com/Admidio/admidio/security/advisories/GHSA-hm42-q32m-vj4f","source":"security-advisories@github.com"}]}},{"cve":{"id":"CVE-2026-53761","sourceIdentifier":"security-advisories@github.com","published":"2026-09-04T18:17:52.920","lastModified":"2026-09-04T19:17:25.300","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Frappe CRM is an open-source customer relationship management tool. Prior to version 1.73.0, there is an authentication bypass vulnerability via logged invitation keys in crm/api. This issue has been patched in version 1.73.0."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"frappe","product":"crm","versions":[{"version":"< 1.73.0","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T18:51:30.162511Z","id":"CVE-2026-53761","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-287"}]}],"references":[{"url":"https://github.com/frappe/crm/releases/tag/v1.73.0","source":"security-advisories@github.com"},{"url":"https://github.com/frappe/crm/security/advisories/GHSA-wqrv-q8m5-qr77","source":"security-advisories@github.com"}]}},{"cve":{"id":"CVE-2026-57159","sourceIdentifier":"security-advisories@github.com","published":"2026-09-04T18:17:53.313","lastModified":"2026-09-04T18:17:53.313","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"PJSIP is a free and open source multimedia communication library written in C. Prior to commit 673b978, a remote out-of-bounds read and write can occur in the SDP negotiator when the remote payload-type map maintenance feature is enabled. assign_pt_and_update_map() in pjmedia/src/pjmedia/sdp_neg.c uses payload-type numbers taken from a remote SDP offer or answer to index fixed-size internal tables without sufficient bounds validation, so a crafted remote SDP can cause memory access outside those tables. The practical impact is memory corruption and denial of service; code execution is not demonstrated. This path is only reached when PJMEDIA_SDP_NEG_MAINTAIN_REMOTE_PT_MAP is enabled. The default is disabled, so default builds are not affected; the feature is an interoperability option that integrating products may enable. This issue has been patched via commit 673b978."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"pjsip","product":"pjproject","versions":[{"version":"< 673b978aab1fe3ab874247be32c871acc880cbeb","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.4,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Primary","description":[{"lang":"en","value":"CWE-129"},{"lang":"en","value":"CWE-787"}]}],"references":[{"url":"https://github.com/pjsip/pjproject/commit/673b978aab1fe3ab874247be32c871acc880cbeb","source":"security-advisories@github.com"},{"url":"https://github.com/pjsip/pjproject/security/advisories/GHSA-rfwg-w9gq-9mw2","source":"security-advisories@github.com"}]}},{"cve":{"id":"CVE-2026-57160","sourceIdentifier":"security-advisories@github.com","published":"2026-09-04T18:17:53.740","lastModified":"2026-09-04T18:17:53.740","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"PJSIP is a free and open source multimedia communication library written in C. Prior to commit d6a0e7f, a buffer overflow can occur in pjsip_generic_array_hdr_print() in pjsip/src/pjsip/sip_msg.c, the function that serializes generic array headers (such as Allow, Require, Supported, and Unsupported). Under certain output-buffer boundary conditions the function can write one byte past the end of the buffer. This is reachable mainly in applications that parse and re-serialize incoming SIP requests — for example a proxy, SBC, or B2BUA — where a remote peer can influence the serialized message. The out-of-bounds write is a single fixed byte; code execution and information disclosure are not demonstrated, and in typical pool-based allocations the byte falls within allocation slack. This issue has been patched via commit d6a0e7f."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"pjsip","product":"pjproject","versions":[{"version":"< d6a0e7f76611c3a6f530ee051e3e7a622bb1748c","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":6.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"LOW","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Primary","description":[{"lang":"en","value":"CWE-193"}]}],"references":[{"url":"https://github.com/pjsip/pjproject/commit/d6a0e7f76611c3a6f530ee051e3e7a622bb1748c","source":"security-advisories@github.com"},{"url":"https://github.com/pjsip/pjproject/security/advisories/GHSA-277r-3q2j-mxcw","source":"security-advisories@github.com"}]}},{"cve":{"id":"CVE-2026-57161","sourceIdentifier":"security-advisories@github.com","published":"2026-09-04T18:17:54.193","lastModified":"2026-09-04T18:17:54.193","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"PJSIP is a free and open source multimedia communication library written in C. Prior to commit acc03b5, a stack buffer overflow exists in PJSUA when processing Service-Route headers in a registration response (update_service_route() in pjsua_acc.c). This affects applications that register using the PJSUA/PJSUA2 account API (the default registration path). The Service-Route URIs from a 2xx response to REGISTER are stored into a fixed-size array without bounding the number of headers; a registrar that returns an excessive number of Service-Route headers can write past the end of the array on the stack. The values written are internal pointers rather than arbitrary data, so the most likely impact is unexpected application termination (denial of service), though memory corruption cannot be excluded. The malicious response may come from a compromised or malicious registrar, or — over unprotected transports — a spoofed response. This issue has been patched via commit acc03b5."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"pjsip","product":"pjproject","versions":[{"version":"< acc03b57cef7a7d31b8e1f5b9117437d7e87c591","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Primary","description":[{"lang":"en","value":"CWE-121"}]}],"references":[{"url":"https://github.com/pjsip/pjproject/commit/acc03b57cef7a7d31b8e1f5b9117437d7e87c591","source":"security-advisories@github.com"},{"url":"https://github.com/pjsip/pjproject/security/advisories/GHSA-xc62-j9h2-mp84","source":"security-advisories@github.com"}]}},{"cve":{"id":"CVE-2026-57162","sourceIdentifier":"security-advisories@github.com","published":"2026-09-04T18:17:54.360","lastModified":"2026-09-04T18:17:54.360","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"PJSIP is a free and open source multimedia communication library written in C. Prior to commit a1b707c, a stack buffer overflow exists in the SRTP/SDES media transport when processing a=crypto attributes during SDP offer/answer (sdes_encode_sdp() in transport_srtp_sdes.c). This affects applications with SRTP enabled (use_srtp optional or mandatory, using SDES keying). During media negotiation, the crypto attributes from the remote SDP are collected into a fixed-size array without bounding their number; a remote peer that includes an excessive number of a=crypto attributes in a single media description can write past the end of that array on the stack. This is reachable from an incoming SIP INVITE during offer/answer, before application-level authentication. Impact may range from unexpected application termination to control flow hijack/memory corruption. Applications that do not enable SRTP are not affected. This issue has been patched via commit a1b707c."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"pjsip","product":"pjproject","versions":[{"version":"< a1b707c0c9b0506faf2a8a438b60f11ffd6a6fd9","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T17:25:22.007068Z","id":"CVE-2026-57162","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Primary","description":[{"lang":"en","value":"CWE-121"}]}],"references":[{"url":"https://github.com/pjsip/pjproject/commit/a1b707c0c9b0506faf2a8a438b60f11ffd6a6fd9","source":"security-advisories@github.com"},{"url":"https://github.com/pjsip/pjproject/security/advisories/GHSA-m9g3-jcj8-qjfm","source":"security-advisories@github.com"}]}},{"cve":{"id":"CVE-2026-57163","sourceIdentifier":"security-advisories@github.com","published":"2026-09-04T18:17:54.547","lastModified":"2026-09-04T18:17:54.547","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"PJSIP is a free and open source multimedia communication library written in C. Prior to commit c4a151a, a stack buffer overflow exists in the GnuTLS TLS backend when parsing the Subject Alternative Name extension of a peer certificate (tls_cert_get_info() in ssl_sock_gtls.c). Only GnuTLS builds are affected (--with-gnutls); OpenSSL and Apple SecureTransport/Network.framework builds are not affected. While extracting certificate information after a TLS handshake, an incorrect buffer-size value can cause an oversized SubjectAltName entry to be written past the end of a fixed-size stack buffer. A network-positioned attacker presenting a crafted certificate — a malicious server to a connecting client, or a malicious client to a server that requests certificates — can trigger this during the TLS handshake, before any SIP-level authentication. Impact may range from unexpected application termination to control flow hijack/memory corruption. This issue has been patched via commit c4a151a."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"pjsip","product":"pjproject","versions":[{"version":"< c4a151af86fadd16d9480b2603eeb2abf4fb4f78","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T17:25:40.460080Z","id":"CVE-2026-57163","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Primary","description":[{"lang":"en","value":"CWE-121"}]}],"references":[{"url":"https://github.com/pjsip/pjproject/commit/c4a151af86fadd16d9480b2603eeb2abf4fb4f78","source":"security-advisories@github.com"},{"url":"https://github.com/pjsip/pjproject/security/advisories/GHSA-jm2j-6rg6-qvwx","source":"security-advisories@github.com"}]}},{"cve":{"id":"CVE-2026-57164","sourceIdentifier":"security-advisories@github.com","published":"2026-09-04T18:17:54.703","lastModified":"2026-09-04T18:17:54.703","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"PJSIP is a free and open source multimedia communication library written in C. Prior to commit 8d5956a, a heap buffer overflow exists in the PJLIB-UTIL HTTP client (http_client.c) when buffering an HTTP response body. This affects applications that use the PJLIB-UTIL HTTP client to receive a whole response body at once (a completion callback with no incremental on_data_read callback). When growing the response buffer, an incorrect size calculation based on the server-supplied Content-Length can leave the buffer too small, causing response data to be written past the end of the allocation. A malicious or man-in-the-middle HTTP server can trigger this with a crafted response; impact may range from unexpected application termination to memory corruption. Applications that consume the response incrementally (via on_data_read), or that only connect to trusted servers, are not affected. This issue has been patched via commit 8d5956a."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"pjsip","product":"pjproject","versions":[{"version":"< 8d5956afab2ede95ddb199078dc19a8ac0114f3d","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.3,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Primary","description":[{"lang":"en","value":"CWE-122"}]}],"references":[{"url":"https://github.com/pjsip/pjproject/commit/8d5956afab2ede95ddb199078dc19a8ac0114f3d","source":"security-advisories@github.com"},{"url":"https://github.com/pjsip/pjproject/security/advisories/GHSA-59fr-724j-6fjv","source":"security-advisories@github.com"}]}},{"cve":{"id":"CVE-2026-57165","sourceIdentifier":"security-advisories@github.com","published":"2026-09-04T18:17:54.863","lastModified":"2026-09-04T18:17:54.863","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"PJSIP is a free and open source multimedia communication library written in C. Prior to commit 628b716, a stack buffer overflow exists in the PJLIB-UTIL telnet CLI front-end when redrawing the command line during history recall (handle_up_down() in cli_telnet.c). This affects only applications that enable the telnet CLI front-end (same gating as the related CLI issue). The line-redraw sequence for a recalled history entry can accumulate more data than a fixed-size stack buffer holds, which may lead to application termination. Exploitation requires access to the unauthenticated telnet CLI, which already permits arbitrary CLI commands, so the additional impact is limited. Applications that do not enable the telnet CLI front-end are not affected. This issue has been patched via commit 628b716."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"pjsip","product":"pjproject","versions":[{"version":"< 628b71638465bacf66e767959e6acbab822eccd6","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":6.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"LOW","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Primary","description":[{"lang":"en","value":"CWE-121"}]}],"references":[{"url":"https://github.com/pjsip/pjproject/commit/628b71638465bacf66e767959e6acbab822eccd6","source":"security-advisories@github.com"},{"url":"https://github.com/pjsip/pjproject/security/advisories/GHSA-rpq9-9fx7-95xw","source":"security-advisories@github.com"}]}},{"cve":{"id":"CVE-2026-57166","sourceIdentifier":"security-advisories@github.com","published":"2026-09-04T18:17:55.007","lastModified":"2026-09-04T18:17:55.007","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"PJSIP is a free and open source multimedia communication library written in C. Prior to commit 4472a31, a stack buffer overflow exists in the PJLIB-UTIL telnet CLI front-end when rendering feedback for an entered command line. Several command-line handling paths write an attacker-influenced amount of data into fixed-size buffers without sufficient bounds checking, so a long command line can overflow them. This affects only applications that enable the telnet CLI front-end (e.g. pj_cli_telnet_create() / --cli-telnet-port). The telnet CLI is an interactive administration interface with no authentication, so any client able to reach it can already issue arbitrary CLI commands. A malformed or overly long command line can overflow a fixed-size stack buffer while rendering command-line feedback, which may lead to application termination. Because reaching this code already requires access to the unauthenticated CLI, the impact beyond that existing access is limited. Applications that do not enable the telnet CLI front-end are not affected. This issue has been patched via commit 4472a31."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"pjsip","product":"pjproject","versions":[{"version":"< 4472a31d77a7506ff175dad5abef490f4e31bed1","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":6.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"LOW","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Primary","description":[{"lang":"en","value":"CWE-121"}]}],"references":[{"url":"https://github.com/pjsip/pjproject/commit/4472a31d77a7506ff175dad5abef490f4e31bed1","source":"security-advisories@github.com"},{"url":"https://github.com/pjsip/pjproject/security/advisories/GHSA-9c8q-h38q-p85j","source":"security-advisories@github.com"}]}},{"cve":{"id":"CVE-2026-61608","sourceIdentifier":"security-advisories@github.com","published":"2026-09-04T18:17:55.147","lastModified":"2026-09-04T19:17:25.413","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, `UserInvitation` entities have no expiry timestamp. Invitation links mailed to users remain valid indefinitely, meaning a leaked, forwarded, or archived invitation email can be used at any time in the future to join a company or silently add a compromised email account to a company. Version 3.0.1 fixes the issue."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"SolidInvoice","product":"SolidInvoice","versions":[{"version":"< 3.0.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N","baseScore":6.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T18:15:54.920872Z","id":"CVE-2026-61608","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-613"}]}],"references":[{"url":"https://github.com/SolidInvoice/SolidInvoice/releases/tag/3.0.1","source":"security-advisories@github.com"},{"url":"https://github.com/SolidInvoice/SolidInvoice/security/advisories/GHSA-5gcp-fm29-jgrp","source":"security-advisories@github.com"}]}},{"cve":{"id":"CVE-2026-61614","sourceIdentifier":"security-advisories@github.com","published":"2026-09-04T18:17:55.290","lastModified":"2026-09-04T19:17:25.510","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, the REST API authenticator accepts bearer tokens via a `?token=` URL query parameter as a fallback to the `X-API-TOKEN` header. This causes long-lived API credentials to be recorded in server access logs, proxy logs, browser history, and HTTP Referer headers sent to third-party origins. Version 3.0.1 fixes the issue."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"SolidInvoice","product":"SolidInvoice","versions":[{"version":"< 3.0.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":5.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T18:40:06.231247Z","id":"CVE-2026-61614","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-598"}]}],"references":[{"url":"https://github.com/SolidInvoice/SolidInvoice/releases/tag/3.0.1","source":"security-advisories@github.com"},{"url":"https://github.com/SolidInvoice/SolidInvoice/security/advisories/GHSA-mp4c-675j-mv67","source":"security-advisories@github.com"}]}},{"cve":{"id":"CVE-2026-61686","sourceIdentifier":"security-advisories@github.com","published":"2026-09-04T18:17:55.437","lastModified":"2026-09-04T19:17:25.617","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, the `DataGrid` LiveComponent deserializes a `context` prop value using PHP's `unserialize()` after receiving it from the client. Because the prop is marked `writable: true`, an authenticated attacker can supply an arbitrary PHP serialized payload. Version 3.0.1 fixes the issue."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"SolidInvoice","product":"SolidInvoice","versions":[{"version":"< 3.0.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.6,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T18:40:38.338430Z","id":"CVE-2026-61686","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-502"}]}],"references":[{"url":"https://github.com/SolidInvoice/SolidInvoice/releases/tag/3.0.1","source":"security-advisories@github.com"},{"url":"https://github.com/SolidInvoice/SolidInvoice/security/advisories/GHSA-4gj8-frx2-gmp6","source":"security-advisories@github.com"},{"url":"https://github.com/SolidInvoice/SolidInvoice/security/advisories/GHSA-4gj8-frx2-gmp6","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}]}},{"cve":{"id":"CVE-2026-61688","sourceIdentifier":"security-advisories@github.com","published":"2026-09-04T18:17:55.580","lastModified":"2026-09-04T18:17:55.580","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, an authenticated user can view the API request history of any other user's API tokens within the same company by manipulating two writable Symfony UX LiveComponent props on the `DataGrid` component. Version 3.0.1 fixes the issue."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"SolidInvoice","product":"SolidInvoice","versions":[{"version":"< 3.0.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Primary","description":[{"lang":"en","value":"CWE-639"}]}],"references":[{"url":"https://github.com/SolidInvoice/SolidInvoice/releases/tag/3.0.1","source":"security-advisories@github.com"},{"url":"https://github.com/SolidInvoice/SolidInvoice/security/advisories/GHSA-jhv9-9fv9-67cr","source":"security-advisories@github.com"}]}},{"cve":{"id":"CVE-2026-73848","sourceIdentifier":"security-advisories@github.com","published":"2026-09-04T18:17:55.953","lastModified":"2026-09-04T18:17:55.953","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Emlog is an open source website building system. In versions 2.6.29 and prior, tag names in emlog are not HTML-encoded when rendered in the article editor. An attacker can create a tag containing ');alert(document.domain);//. The addslashes() function does not escape HTML entities, so ' is stored as-is. When the browser renders the page, it decodes ' back to a literal single quote before evaluating the JavaScript, breaking out of the string and executing arbitrary code. At time of publication, there are no publicly known patches."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"emlog","product":"emlog","versions":[{"version":"<= 2.6.29","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":6.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://github.com/emlog/emlog/security/advisories/GHSA-fv6h-wr92-v4pj","source":"security-advisories@github.com"}]}},{"cve":{"id":"CVE-2026-80887","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T18:17:56.667","lastModified":"2026-09-04T18:17:56.667","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/vmwgfx: use check_add_overflow for shader size+offset bound\n\nvmw_shader_define() validates the user-supplied shader window against\nits backing buffer with\n\n\t(u64)buffer->tbo.base.size < (u64)size + (u64)offset\n\ndrm_vmw_shader_create_arg::offset is __u64 in the uapi; when it is\nnear U64_MAX the unsigned addition wraps and the resulting tiny value\npasses the check.  The unbounded offset is then stored in\nres->guest_memory_offset and forwarded to host SVGA shader-create\ncommands.\n\nUse check_add_overflow() to detect the wrap and compare the resulting\nendpoint against the buffer size."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/gpu/drm/vmwgfx/vmwgfx_shader.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"668b206601c5f5063e03b76784a0d3024fa2b249","lessThan":"1bbe7751f5ebac383405ef29a66622d65bd505d3","versionType":"git","status":"affected"},{"version":"668b206601c5f5063e03b76784a0d3024fa2b249","lessThan":"d3f44438aa805270aaead3b6840ccaea0f4c11f9","versionType":"git","status":"affected"},{"version":"668b206601c5f5063e03b76784a0d3024fa2b249","lessThan":"cfd163169af3be56eaef113c680ea251f0d09189","versionType":"git","status":"affected"},{"version":"668b206601c5f5063e03b76784a0d3024fa2b249","lessThan":"5c725901908eb1e52a16fc0e2373cb761df42d21","versionType":"git","status":"affected"},{"version":"668b206601c5f5063e03b76784a0d3024fa2b249","lessThan":"54d56d5b42d2e4c72ba6e365e9774da90698aa22","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/gpu/drm/vmwgfx/vmwgfx_shader.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.4","status":"affected"},{"version":"0","lessThan":"6.4","versionType":"semver","status":"unaffected"},{"version":"6.6.151","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.103","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.44","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.8","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/1bbe7751f5ebac383405ef29a66622d65bd505d3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/54d56d5b42d2e4c72ba6e365e9774da90698aa22","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5c725901908eb1e52a16fc0e2373cb761df42d21","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cfd163169af3be56eaef113c680ea251f0d09189","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d3f44438aa805270aaead3b6840ccaea0f4c11f9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80888","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T18:17:56.787","lastModified":"2026-09-04T18:17:56.787","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/vmwgfx: drop dma_buf reference on foreign-fd prime import\n\nttm_prime_fd_to_handle() returns -ENOSYS when the imported fd's\ndma_buf->ops do not match the ttm_object_device's ops, but does so\nwithout releasing the reference acquired by dma_buf_get().  Any\nunprivileged renderD client passing a non-vmwgfx prime fd through the\nDRM_VMW_GB_SURFACE_REF{,_EXT} path leaks one dma_buf reference per\ncall and indefinitely pins the foreign exporter's GEM resources.\n\nFunnel the error path through the existing dma_buf_put() so the\nreference is always dropped."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/gpu/drm/vmwgfx/ttm_object.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"65981f7681abdf92b25942222b629b9c512d0705","lessThan":"619c3cfa88e09603a13d918f754808db2dda7057","versionType":"git","status":"affected"},{"version":"65981f7681abdf92b25942222b629b9c512d0705","lessThan":"c1c22fca0a0896a452a7cb92422d67babd65b4be","versionType":"git","status":"affected"},{"version":"65981f7681abdf92b25942222b629b9c512d0705","lessThan":"a1e972fa94c3a8069e022c67b9d97c7aa7b05293","versionType":"git","status":"affected"},{"version":"65981f7681abdf92b25942222b629b9c512d0705","lessThan":"a8434b145b1e467940334c58c00af241e9494c5f","versionType":"git","status":"affected"},{"version":"65981f7681abdf92b25942222b629b9c512d0705","lessThan":"4df39eb99bb47d1f24d1952c23b21b10988356bf","versionType":"git","status":"affected"},{"version":"65981f7681abdf92b25942222b629b9c512d0705","lessThan":"f739416dc555fa205a785e5135d73fa39b26f35d","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/gpu/drm/vmwgfx/ttm_object.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.13","status":"affected"},{"version":"0","lessThan":"3.13","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.151","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.103","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.44","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.8","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/4df39eb99bb47d1f24d1952c23b21b10988356bf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/619c3cfa88e09603a13d918f754808db2dda7057","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a1e972fa94c3a8069e022c67b9d97c7aa7b05293","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a8434b145b1e467940334c58c00af241e9494c5f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c1c22fca0a0896a452a7cb92422d67babd65b4be","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f739416dc555fa205a785e5135d73fa39b26f35d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80889","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T18:17:56.910","lastModified":"2026-09-04T18:17:56.910","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncan: isotp: fix timer drain order, wakeup handling and tx_gen ordering\n\nThis patch is a follow-up to commit cf070fe33bfb (\"can: isotp: serialize\nTX state transitions under so->rx_lock\") which addresses following\nsashiko-bot findings:\n\n- isotp_sendmsg(): drain so->txfrtimer first so a stale callback can't\n  re-arm echotimer after the claim\n\n- isotp_release(): wake so->wait after forcing ISOTP_SHUTDOWN so a\n  sleeping sendmsg() claim isn't stranded\n\n- isotp_sendmsg(): have both wait_event_interruptible() calls in\n  isotp_sendmsg() also wake on ISOTP_SHUTDOWN and do not return claim to\n  IDLE to avoid corrupting a concurrent isotp_release() process.\n\n- isotp_sendmsg(): handle potential claim of a new transfer when\n  the wait_event_interruptible() call returns in CAN_ISOTP_WAIT_TX_DONE\n  mode. Don't touch timers and states of the new transfer if a new thread\n  incremented so->tx_gen before getting the lock at err_event_drop.\n\n- isotp_sendmsg(): handle a stuck can_send() and omit timer and state\n  changes if a new transfer was claimed. wait_tx_done() returns the error\n  recorded in so->tx_result[], tagged with the caller's own generation.\n\n- isotp_tx_timeout(): on a claimed timeout, record the ECOMM error for\n  the timed-out transfer's own generation in so->tx_result[]; sk->sk_err\n  is raised unconditionally, same as every other error path here.\n\n- isotp_tx_gen_done()/isotp_tx_timeout(): always read tx.state (acquire)\n  before tx_gen - the reverse order let a weakly ordered CPU pair a fresh\n  tx.state with a stale tx_gen/tx_result slot.\n\n- isotp_sendmsg(): wait_tx_done: drain sk_err via sock_error() once we\n  have read the result from so->tx_result[], so an already-reported error\n  doesn't stay latched for a later poll()/SO_ERROR.\n\nAlso align the remaining lock-free so->tx.state/rx.state/cfecho accesses\nand use skb->hash as unique loopback echo frame indicator."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/can/isotp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"bbedeb67a9a684f2fb78c55bd3662c400526715e","lessThan":"8acab9fc66d6f426c36968c91a979f70784945a7","versionType":"git","status":"affected"},{"version":"377a8f500704da42ed86a4541ed930e9dcfdb2ea","lessThan":"af7e25c649ed68cbad07f8185af0f31b892cbf29","versionType":"git","status":"affected"},{"version":"6da8119e8dd542194103139812d1a4b7dcd1aedd","lessThan":"2753722612d8824d3910096f93059f669009b0f0","versionType":"git","status":"affected"},{"version":"0b05eca9589f609e2491b528dccf683168a4cda8","lessThan":"bf5c4a8b24acb12739ebb9aea5510b007e4f5239","versionType":"git","status":"affected"},{"version":"a7d90e7b5e75d7406c889fe36e9a61ee364a00cb","lessThan":"deca7746b57d982cd4f0301f4443f56780c4a048","versionType":"git","status":"affected"},{"version":"37beb16e08cae94cc05840c7274225e3b0b38ae7","lessThan":"10be509fa8fd95d1e47d40d1f68b0b26dfe9d572","versionType":"git","status":"affected"},{"version":"4f1fdf1a1c317bcac0c6b6c8e12642c9983de1ca","lessThan":"35c62ac98d06669aa3f0f38b7829eaca929a611e","versionType":"git","status":"affected"},{"version":"cf070fe33bfbd1a4c21236078fadb35dd223a157","lessThan":"050f010f920da17c1044a4f174766ad553e770b6","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/can/isotp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.10.265","lessThan":"5.10.267","versionType":"semver","status":"affected"},{"version":"5.15.216","lessThan":"5.15.218","versionType":"semver","status":"affected"},{"version":"6.1.183","lessThan":"6.1.185","versionType":"semver","status":"affected"},{"version":"6.6.148","lessThan":"6.6.151","versionType":"semver","status":"affected"},{"version":"6.12.101","lessThan":"6.12.103","versionType":"semver","status":"affected"},{"version":"6.18.40","lessThan":"6.18.44","versionType":"semver","status":"affected"},{"version":"7.1.5","lessThan":"7.1.8","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/050f010f920da17c1044a4f174766ad553e770b6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/10be509fa8fd95d1e47d40d1f68b0b26dfe9d572","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2753722612d8824d3910096f93059f669009b0f0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/35c62ac98d06669aa3f0f38b7829eaca929a611e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8acab9fc66d6f426c36968c91a979f70784945a7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/af7e25c649ed68cbad07f8185af0f31b892cbf29","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bf5c4a8b24acb12739ebb9aea5510b007e4f5239","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/deca7746b57d982cd4f0301f4443f56780c4a048","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80890","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T18:17:57.077","lastModified":"2026-09-04T18:17:57.077","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: reject stale cookies with mismatched verification tags\n\nsctp_unpack_cookie() skips cookie expiration checks whenever an\nassociation already exists.  This is broader than the exception in\nRFC 9260 Section 5.2.4.\n\nFor an existing association, Section 5.2.4 permits an expired State\nCookie only when both Verification Tags in the cookie match the current\nassociation.  Otherwise, the packet SHOULD be discarded and a Stale\nCookie ERROR MUST be sent.\n\nThe broad check lets an expired Action A restart cookie reach\nsctp_sf_do_dupcook_a().  In a runtime test with the default 60 second\ncookie lifetime, replaying such a cookie after 65 seconds returned a\nCOOKIE-ACK and restarted the association.\n\nCheck cookie expiration unless both Verification Tags match.  This\npreserves the Action D exception for a lost COOKIE ACK while rejecting\nexpired cookies in all other cases."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/sctp/sm_make_chunk.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"f6e3cc296372accad4ee57405195021231ef4bcb","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"c151daba0ceb1fb068a215b07de89fb1eb5f87bc","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"817cffdbdbdf50e1f2b016599d1897de3ca54964","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"61baa5020b0afb41bfd97f8f6ce5e336c4a4546e","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"c68557a49e960dbcdede22c7a9b488603078b8b4","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"a0d1693923f41d6f49083aa2446686aed09d1d79","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"35c279113498d19a8734e2aae67b951b9b20f634","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"9d8da8e0a9bce4a340af60dd0446bc7eb8d07587","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/sctp/sm_make_chunk.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.12","status":"affected"},{"version":"0","lessThan":"2.6.12","versionType":"semver","status":"unaffected"},{"version":"5.10.265","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.151","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.103","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.44","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.8","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/35c279113498d19a8734e2aae67b951b9b20f634","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/61baa5020b0afb41bfd97f8f6ce5e336c4a4546e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/817cffdbdbdf50e1f2b016599d1897de3ca54964","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9d8da8e0a9bce4a340af60dd0446bc7eb8d07587","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a0d1693923f41d6f49083aa2446686aed09d1d79","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c151daba0ceb1fb068a215b07de89fb1eb5f87bc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c68557a49e960dbcdede22c7a9b488603078b8b4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f6e3cc296372accad4ee57405195021231ef4bcb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80891","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T18:17:57.217","lastModified":"2026-09-04T18:17:57.217","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: s390: pci: Validate AIBV and AISB before pinning guest pages\n\nThe AIBV holds one bit per MSI-X vector for a given function. The size of\nthe bit vector is derived from the NOI and the AIBVO. If the size of the\nAIBV exceeds a single page boundary, then reject the request as we cannot\nsafely pin the guest AIBV.\n\nSimilarly reject the request if the AISB address is not 8-byte aligned as\nthe architecture requires doubleword alignment for the summary bit address.\nSince the AISBO can address up to 64 bits, the size of the AISB can only be\n8 bytes for the function. This also ensures the AISB doesn't exceed a\nsingle page boundary."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["arch/s390/kvm/pci.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc","lessThan":"3a1c64220ede4ac9ef9a3e76f008ff60a34f4c48","versionType":"git","status":"affected"},{"version":"3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc","lessThan":"f00ef8efd41440129ccd88f4a1ebebf8d61d297f","versionType":"git","status":"affected"},{"version":"3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc","lessThan":"15df7700dd99f8a37f5c6ed2dcf1e33009cdba47","versionType":"git","status":"affected"},{"version":"3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc","lessThan":"b878ba7e28144c9a857bc847d31f3c45413450ac","versionType":"git","status":"affected"},{"version":"3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc","lessThan":"fbfe683f8b1ae7e40b56bdd6daf5bd671bc3a528","versionType":"git","status":"affected"},{"version":"3c5a1b6f0a18520a0edd0600fef6f1a8553b8fdc","lessThan":"868d32ac72cba21c5c6d8a66a814b7c25a3a5c01","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["arch/s390/kvm/pci.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.0","status":"affected"},{"version":"0","lessThan":"6.0","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.151","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.103","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.44","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.8","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/15df7700dd99f8a37f5c6ed2dcf1e33009cdba47","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3a1c64220ede4ac9ef9a3e76f008ff60a34f4c48","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/868d32ac72cba21c5c6d8a66a814b7c25a3a5c01","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b878ba7e28144c9a857bc847d31f3c45413450ac","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f00ef8efd41440129ccd88f4a1ebebf8d61d297f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fbfe683f8b1ae7e40b56bdd6daf5bd671bc3a528","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80892","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T18:17:57.337","lastModified":"2026-09-04T18:17:57.337","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nerofs: cap LZMA stream pool size\n\nfs/erofs/decompressor_lzma.c sizes the module-global MicroLZMA stream\npool from num_possible_cpus() when the lzma_streams module parameter is\nunset, then z_erofs_load_lzma_config() preallocates one image-supplied\ndictionary per stream, accepting dictionaries up to 8 MiB.  On high-CPU\nsystems, a small EROFS image can pin hundreds of MiB of vmalloc-backed\ndecoder state until the erofs module is unloaded.\n\nImpact: An EROFS image mounted by the system can pin up to 8 MiB of\nvmalloc memory per LZMA stream, either as intended or unexpectedly.\n\nBound the default stream count by a new\nCONFIG_EROFS_FS_ZIP_LZMA_DEFAULT_MAX_STREAMS option, default 16, so the\nworst-case default preallocation is 128 MiB if the number of CPUs is no\nless than 16 while preserving the existing per-image dictionary limit.\nAn explicit lzma_streams module parameter is still honoured as-is, so\nadministrators who deliberately size the pool are not affected."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/erofs/Kconfig","fs/erofs/decompressor_lzma.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"622ceaddb7649ca328832f50ba1400af778d75fa","lessThan":"682cb3ece37fc5141e73bc726ccf4adb833e5189","versionType":"git","status":"affected"},{"version":"622ceaddb7649ca328832f50ba1400af778d75fa","lessThan":"e8b3d09aa8889dda9be9cbb3d2f0218c4b9acde4","versionType":"git","status":"affected"},{"version":"622ceaddb7649ca328832f50ba1400af778d75fa","lessThan":"0c676903cb2a61992ded8e7907609cc6b0f11744","versionType":"git","status":"affected"},{"version":"622ceaddb7649ca328832f50ba1400af778d75fa","lessThan":"5aaa06dfc10f8398c8807453dbec738ea9af10e4","versionType":"git","status":"affected"},{"version":"622ceaddb7649ca328832f50ba1400af778d75fa","lessThan":"e52da169b8c0d19bb2d803f2a07fe0e5a00462d6","versionType":"git","status":"affected"},{"version":"622ceaddb7649ca328832f50ba1400af778d75fa","lessThan":"c9b47e6b23114e939b17f818471c7a46e59006e7","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/erofs/Kconfig","fs/erofs/decompressor_lzma.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.16","status":"affected"},{"version":"0","lessThan":"5.16","versionType":"semver","status":"unaffected"},{"version":"6.1.184","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.151","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.103","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.44","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.8","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0c676903cb2a61992ded8e7907609cc6b0f11744","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5aaa06dfc10f8398c8807453dbec738ea9af10e4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/682cb3ece37fc5141e73bc726ccf4adb833e5189","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c9b47e6b23114e939b17f818471c7a46e59006e7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e52da169b8c0d19bb2d803f2a07fe0e5a00462d6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e8b3d09aa8889dda9be9cbb3d2f0218c4b9acde4","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80893","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T18:17:57.467","lastModified":"2026-09-04T18:17:57.467","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmm/hugetlb: fix swap entry corruption when clearing uffd-wp at fork()\n\ncopy_hugetlb_page_range() clears the uffd-wp bit of migration and hwpoison\nentries with huge_pte_clear_uffd_wp(), which operates on the present-PTE\nbit position.  Swap entries keep the uffd-wp state elsewhere -- the\nmigration branch reads and sets it with pte_swp_uffd_wp() and\npte_swp_mkuffd_wp() -- and the present-PTE position falls into the swap\npayload.  On x86-64 it lands in the inverted swap offset, where a\nnaturally-aligned hugetlb PFN always has the affected bit set, so the\nclear advances the encoded PFN by two pages.\n\nNo userfaultfd needs to be involved: the clear is guarded only by the\nchild VMA not being uffd-wp registered, so a plain fork() with an\nin-flight hugetlb migration entry (or a poisoned hugetlb page) corrupts\nthe entry copied into the child.  Instrumenting the clear and forking\nafter MADV_HWPOISON on a 2MB anon hugetlb page shows:\n\n  offset before=120e00\n  offset after =120e02\n\nThe fallout is mostly latent: rmap walks match migration entries by folio\nrange and remove_migration_pte() rebuilds the PTE from the folio, so a\nwithin-folio PFN skew heals once migration completes.  But any path that\nre-encodes the corrupted offset -- e.g.  hugetlb_change_protection()\nrewriting a writable migration entry via\nmake_readable_migration_entry(swp_offset(entry)) -- propagates it.\n\nMigration entries legitimately carry uffd-wp, so clear it with\npte_swp_clear_uffd_wp(), matching copy_nonpresent_pte() and\nmove_huge_pte().\n\nA hwpoison entry, on the other hand, never carries the uffd-wp bit: it is\ninstalled fresh by make_hwpoison_entry() (try_to_unmap_one() does not\npreserve uffd-wp on the hwpoison path) and hugetlb_change_protection()\nleaves hwpoison entries untouched.  There was nothing to clear there, only\nthe corruption, so drop the clear entirely."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["mm/hugetlb.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"bc70fbf269fdff410b0b6d75c3770b9f59117b90","lessThan":"f1b1311c0352873137768bac5a126e491271a747","versionType":"git","status":"affected"},{"version":"bc70fbf269fdff410b0b6d75c3770b9f59117b90","lessThan":"69cb5825d9988c7944bc9f1dc08cb233655405a7","versionType":"git","status":"affected"},{"version":"bc70fbf269fdff410b0b6d75c3770b9f59117b90","lessThan":"8b0de7005b148738d79d6c45594d566489948a68","versionType":"git","status":"affected"},{"version":"bc70fbf269fdff410b0b6d75c3770b9f59117b90","lessThan":"2b9a07002c2f296aa6a9c591213933d3492e3089","versionType":"git","status":"affected"},{"version":"bc70fbf269fdff410b0b6d75c3770b9f59117b90","lessThan":"2fa11c60c9c06bafc19cf4d9efdaa36a38079e87","versionType":"git","status":"affected"},{"version":"bc70fbf269fdff410b0b6d75c3770b9f59117b90","lessThan":"83abe2fd5b3aeb3123b5408a5a91709c5538fb23","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["mm/hugetlb.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.19","status":"affected"},{"version":"0","lessThan":"5.19","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.151","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.103","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.44","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.8","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2b9a07002c2f296aa6a9c591213933d3492e3089","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2fa11c60c9c06bafc19cf4d9efdaa36a38079e87","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/69cb5825d9988c7944bc9f1dc08cb233655405a7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/83abe2fd5b3aeb3123b5408a5a91709c5538fb23","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8b0de7005b148738d79d6c45594d566489948a68","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f1b1311c0352873137768bac5a126e491271a747","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80894","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T18:17:57.603","lastModified":"2026-09-04T18:17:57.603","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\niommufd: Fix wrong hwpt passed to iommufd_auto_response_faults on replace\n\niommufd_hwpt_replace_device() calls:\n\n\tiommufd_auto_response_faults(hwpt, old_handle);\n\npassing the *new* hwpt together with the handle of\nthe device's *old* domain. This should be a parameter mismatch:\n\n1. Semantically, iommufd_auto_response_faults(x, handle) scans\n   x->fault's deliver list and response xarray for groups matching\n   \"handle\". A group is queued under the hwpt that was attached at\n   fault-delivery time. old_handle is fetched *before* the domain switch,\n   so its group lives on old->fault, not on the new hwpt->fault.\n\n2. Historically, the first argument was \"old\". The routine was\n   introduced by commit b7d8833677ba (\"iommufd: Fault-capable hwpt\n   attach/detach/replace\") as __fault_domain_replace_dev() in\n   fault.c, correctly calling iommufd_auto_response_faults(old, curr).\n   Commit fb21b1568ada (\"iommufd: Make attach_handle generic than\n   fault specific\") moved this into iommufd_hwpt_replace_device() in\n   device.c and swapped it to \"hwpt\". This should be a refactor regression,\n   not an intentional change.\n\nFix this by passing \"old\" instead."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/iommu/iommufd/device.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6d11543bf37abdf60b8e6022a62fccfb82a5fe2e","lessThan":"adb87155b67f9759ff010c0a99559f5bffa45dcf","versionType":"git","status":"affected"},{"version":"fb21b1568adaa76af7a8c853f37c60fba8b28661","lessThan":"564ac339c0f8bada4e77a57a92bab9d3df635e07","versionType":"git","status":"affected"},{"version":"fb21b1568adaa76af7a8c853f37c60fba8b28661","lessThan":"8eb077025279304268bd58657f0af3d388822b21","versionType":"git","status":"affected"},{"version":"fb21b1568adaa76af7a8c853f37c60fba8b28661","lessThan":"ba5c0f28a26e7d9be1e0997f8920dd638e2782fd","versionType":"git","status":"affected"},{"version":"1e0216b6a58c79b5ee91c78706d5f560e4d1f56f","versionType":"git","status":"affected"},{"version":"4b23c4b991eb90cc7bca42e9f81142feedd4bb56","versionType":"git","status":"affected"},{"version":"6.12.24","lessThan":"6.12.105","versionType":"semver","status":"affected"},{"version":"6.13.12","lessThan":"6.14","versionType":"semver","status":"affected"},{"version":"6.14.3","lessThan":"6.15","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/iommu/iommufd/device.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.15","status":"affected"},{"version":"0","lessThan":"6.15","versionType":"semver","status":"unaffected"},{"version":"6.12.105","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.44","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.8","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/564ac339c0f8bada4e77a57a92bab9d3df635e07","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8eb077025279304268bd58657f0af3d388822b21","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/adb87155b67f9759ff010c0a99559f5bffa45dcf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ba5c0f28a26e7d9be1e0997f8920dd638e2782fd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80895","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T18:17:57.727","lastModified":"2026-09-04T18:17:57.727","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmshv: Order pt_vp_array publish against irqfd assertion path\n\nmshv_partition_ioctl_create_vp() initialises a VP struct (allocations,\nmutex_init, init_waitqueue_head, page mappings) and then publishes the\npointer into partition->pt_vp_array.  Several ISR paths read this array\nlocklessly: the intercept ISR, the two scheduler ISRs, and\nmshv_try_assert_irq_fast() on the irqfd fast path.\n\nOf these, only mshv_try_assert_irq_fast() can structurally race the\npublish.  It runs from an eventfd waker without holding pt_mutex, and\nMSHV_IRQFD does not require the target lapic_apic_id (== vp_index) to\nrefer to an existing VP at registration time.  A user can therefore\nregister an irqfd targeting a yet-to-be-created VP, then trigger\nmshv_try_assert_irq_fast() concurrently with MSHV_CREATE_VP for the\nsame index.  On weakly-ordered architectures the reader can observe a\nnon-NULL pointer in pt_vp_array before the initialising stores to the\nVP struct become visible, leading to use of partially-initialised\nfields (e.g. vp_register_page).\n\nThe other ISR readers cannot reach this race: the hypervisor will not\ngenerate intercept or scheduler messages for a VP that has never been\ntold to run, and the user can only call MSHV_RUN_VP on the VP fd\nreturned by MSHV_CREATE_VP, which by construction is returned after\nthe publish.  Leave those readers as plain loads.\n\nUse smp_store_release() in mshv_partition_ioctl_create_vp() to publish\nthe pointer, and pair it with smp_load_acquire() in\nmshv_try_assert_irq_fast().  On x86 these compile to plain accesses\nunder TSO; on ARM64 they emit one-instruction acquire/release barriers,\nacceptable on this fast path.\n\nThe destroy-side path (destroy_partition() clearing pt_vp_array[i] to\nNULL after kfree(vp)) has a separate ordering and lifetime concern\nthat is out of scope here."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/hv/mshv_eventfd.c","drivers/hv/mshv_root_main.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"621191d709b14882270dfd8ea5d7d6cdfebe2c35","lessThan":"062aa5dcc49a9ad96726a80c2a0ab0a1233bc2b9","versionType":"git","status":"affected"},{"version":"621191d709b14882270dfd8ea5d7d6cdfebe2c35","lessThan":"eba2bf5daa7933f94c53ebbbf0f567d4274716df","versionType":"git","status":"affected"},{"version":"621191d709b14882270dfd8ea5d7d6cdfebe2c35","lessThan":"b098dc869219c15dc49bf9cf63fb5fc1481d3373","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/hv/mshv_eventfd.c","drivers/hv/mshv_root_main.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.15","status":"affected"},{"version":"0","lessThan":"6.15","versionType":"semver","status":"unaffected"},{"version":"6.18.44","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.8","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/062aa5dcc49a9ad96726a80c2a0ab0a1233bc2b9","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b098dc869219c15dc49bf9cf63fb5fc1481d3373","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/eba2bf5daa7933f94c53ebbbf0f567d4274716df","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80896","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T18:17:57.847","lastModified":"2026-09-04T18:17:57.847","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmshv: Fix race in mshv_irqfd_deassign\n\nmshv_irqfd_deactivate() and the hlist traversal of pt_irqfds_list\nrequire pt->pt_irqfds_lock to be held, but mshv_irqfd_deassign()\nomits it. This races with the EPOLLHUP path in mshv_irqfd_wakeup(),\nwhich does take the lock before calling mshv_irqfd_deactivate().\n\nAdditionally, mshv_irqfd_deactivate() uses hlist_del() which poisons\nthe node pointers rather than resetting them. Since\nmshv_irqfd_is_active() relies on hlist_unhashed() (checks pprev ==\nNULL), a poisoned node still appears active. If a concurrent path calls\nmshv_irqfd_deactivate() again on the same irqfd, the guard fails to\nprevent a double hlist_del() on poisoned pointers.\n\nFix both issues:\n- Add the missing spin_lock_irq/spin_unlock_irq around the list\n  traversal in mshv_irqfd_deassign(), matching mshv_irqfd_release().\n- Use hlist_del_init() instead of hlist_del() so the node is properly\n  marked as unhashed after removal, making the is_active guard reliable."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/hv/mshv_eventfd.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"621191d709b14882270dfd8ea5d7d6cdfebe2c35","lessThan":"72a90ce4918b5a2d4820fe20677ba9af780d8826","versionType":"git","status":"affected"},{"version":"621191d709b14882270dfd8ea5d7d6cdfebe2c35","lessThan":"4529a41a675b96e0f876eef1cc93a31a57cb4d18","versionType":"git","status":"affected"},{"version":"621191d709b14882270dfd8ea5d7d6cdfebe2c35","lessThan":"0762262ac3e70f65b3bb843fe892f8bac1562d08","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/hv/mshv_eventfd.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.15","status":"affected"},{"version":"0","lessThan":"6.15","versionType":"semver","status":"unaffected"},{"version":"6.18.44","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.8","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0762262ac3e70f65b3bb843fe892f8bac1562d08","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4529a41a675b96e0f876eef1cc93a31a57cb4d18","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/72a90ce4918b5a2d4820fe20677ba9af780d8826","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80897","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T18:17:57.957","lastModified":"2026-09-04T18:17:57.957","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfs: release readahead folios on iterator preparation failure\n\nnetfs_prepare_read_iterator() batches readahead folios in put_batch so that\nthe folio references can be dropped after the I/O iterator has been\nprepared.\n\nIf rolling_buffer_load_from_ra() fails after earlier folios have been\nbatched, the function returns immediately and leaves those references held.\nRelease the batch before returning the error."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/netfs/buffered_read.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"06fa229ceb36898e68022b5654c017d2c6582d7d","lessThan":"2c148a31ca01fc160aceec777bbc0041b0d0b8bd","versionType":"git","status":"affected"},{"version":"06fa229ceb36898e68022b5654c017d2c6582d7d","lessThan":"935e7b74bb2368f215cf8c2ad4bff60ee4e7589e","versionType":"git","status":"affected"},{"version":"06fa229ceb36898e68022b5654c017d2c6582d7d","lessThan":"87eb3d272dcbcbbfe5c1576c10e5dc72810cf1f6","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/netfs/buffered_read.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.14","status":"affected"},{"version":"0","lessThan":"6.14","versionType":"semver","status":"unaffected"},{"version":"6.18.44","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.8","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2c148a31ca01fc160aceec777bbc0041b0d0b8bd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/87eb3d272dcbcbbfe5c1576c10e5dc72810cf1f6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/935e7b74bb2368f215cf8c2ad4bff60ee4e7589e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80898","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T18:17:58.067","lastModified":"2026-09-04T18:17:58.067","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfs: clear PG_private_2 on copy-to-cache append failure\n\nnetfs_pgpriv2_copy_to_cache() marks the folio with PG_private_2 before\nnetfs_pgpriv2_copy_folio() appends it to the copy-to-cache rolling\nbuffer.\n\nIf the append fails, the folio is not queued for cache writeback, so\nthe PG_private_2 state and its reference must be released immediately."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/netfs/read_pgpriv2.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"e2d46f2ec332533816417b60933954173f602121","lessThan":"627826ef4208042b0470d1a3fdb729ce35471a0d","versionType":"git","status":"affected"},{"version":"e2d46f2ec332533816417b60933954173f602121","lessThan":"614b7f4bfcf665a751ae89ff9ae336a1b2d5af4e","versionType":"git","status":"affected"},{"version":"e2d46f2ec332533816417b60933954173f602121","lessThan":"a81fc9266e1c5fef9ccf675a9b44b2f4ab464923","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/netfs/read_pgpriv2.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.14","status":"affected"},{"version":"0","lessThan":"6.14","versionType":"semver","status":"unaffected"},{"version":"6.18.44","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.8","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/614b7f4bfcf665a751ae89ff9ae336a1b2d5af4e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/627826ef4208042b0470d1a3fdb729ce35471a0d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a81fc9266e1c5fef9ccf675a9b44b2f4ab464923","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80899","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T18:17:58.170","lastModified":"2026-09-04T18:17:58.170","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nerofs: remove fscache backend entirely\n\nEROFS over fscache was introduced to provide image lazy pulling\nfunctionality. After the feature landed, the fscache subsystem made\nnetfs a new hard dependency, which is unexpected for a local filesystem\nand has an kernel-defined caching hierarchy which could be inflexible\ncompared to the fanotify pre-content hooks. Therefore, this feature has\nbeen deprecated for almost two years.\n\nAs EROFS file-backed mounts and fanotify pre-content hooks both upstream\nfor a while and already providing equivalent functionality (erofs-utils\nhas supported fanotify pre-content hooks), let's remove the fscache\nbackend now.\n\nThe main application of this feature is Nydus [1], and they plan to move\nto use fanotify pre-content hooks in the near future too.\n\nI hope this patch can be merged into Linux 7.2, which is also motivated\nby newly found implementation issues [2][3] that are not worth\ninvestigating given the deprecation and limited development resources.\nThe associated fscache/cachefiles cleanup patch will follow separately\nthrough the vfs tree (netfs) later: it seems fine since the codebase is\nisolated by CONFIG_CACHEFILES_ONDEMAND.\n\n[1] https://github.com/dragonflyoss/nydus/blob/v2.1.0/docs/nydus-fscache.md\n[2] https://github.com/dragonflyoss/nydus/pull/1824\n[3] https://lore.kernel.org/r/20260619135800.1594811-1-michael.bommarito@gmail.com"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["Documentation/filesystems/erofs.rst","fs/erofs/Kconfig","fs/erofs/Makefile","fs/erofs/data.c","fs/erofs/fscache.c","fs/erofs/inode.c","fs/erofs/internal.h","fs/erofs/ishare.c","fs/erofs/super.c","fs/erofs/zdata.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"f6145794f17a27d25f8a84edb80731fb0e07c196","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"c37460cd9b2fcb61ec66b7eb4fde737e65ec2a56","versionType":"git","status":"affected"},{"version":"0","lessThan":"7.1.8","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["Documentation/filesystems/erofs.rst","fs/erofs/Kconfig","fs/erofs/Makefile","fs/erofs/data.c","fs/erofs/fscache.c","fs/erofs/inode.c","fs/erofs/internal.h","fs/erofs/ishare.c","fs/erofs/super.c","fs/erofs/zdata.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"7.1.8","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/c37460cd9b2fcb61ec66b7eb4fde737e65ec2a56","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f6145794f17a27d25f8a84edb80731fb0e07c196","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80900","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T18:17:58.300","lastModified":"2026-09-04T18:17:58.300","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: SDCA: Make UMP message size check more robust\n\nIf message offset was larger than the buffer length the size\ncheck will pass incorrectly. Refactor the check such that it is\nmore robust to invalid sizes."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["sound/soc/sdca/sdca_ump.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"daab108504be73182c16a72b9cfe47ac3b1928ca","lessThan":"fe5c53a952970ba15be8f512babd922e273579de","versionType":"git","status":"affected"},{"version":"daab108504be73182c16a72b9cfe47ac3b1928ca","lessThan":"556d872e7c2a0b570c5b0974813847ef0d0cd637","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["sound/soc/sdca/sdca_ump.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.19","status":"affected"},{"version":"0","lessThan":"6.19","versionType":"semver","status":"unaffected"},{"version":"7.1.8","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/556d872e7c2a0b570c5b0974813847ef0d0cd637","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fe5c53a952970ba15be8f512babd922e273579de","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80901","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T18:17:58.767","lastModified":"2026-09-04T18:17:58.767","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nipvs: fix the checksum validations\n\nip_vs_in_icmp_v6() is missing checksum validation for ICMPv6\npackets from clients. In fact, as for TCP/UDP we should\nvalidate the checksum for ICMP packets only when we\nmangle the packets on MASQ or on reply for tunnel.\n\nAlso, Sashiko points out that handle_response_icmp() being\ncommon for IPv4 and IPv6 is missing the pseudo-header\ncalculation while validating ICMPv6 messages from real\nservers which is a problem if checksum is not validated\nby the hardware.\n\nFix the problems by creating ip_vs_checksum_common_check()\nhelper and use it for TCP/UDP/ICMP both for IPv4 and IPv6.\nRely on the nf_checksum() for validating the ICMP messages\nbut use it also for TCP and UDP.\n\nUse correct IP offset for IP_VS_DBG_RL_PKT for TCP/UDP/SCTP.\n\nIPVS packets (TCP/UDP/SCTP/ICMP) do not need checksum\nvalidation on LOCAL_OUT (local clients or local real\nservers) and on FORWARD (traffic from servers on LAN).\nDo it only on LOCAL_IN, in case nf_checksum() is not\ncalled on PRE_ROUTING.\n\nAlso, ip_vs_checksum_complete() can be marked static."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["include/net/ip_vs.h","net/netfilter/ipvs/ip_vs_core.c","net/netfilter/ipvs/ip_vs_proto_sctp.c","net/netfilter/ipvs/ip_vs_proto_tcp.c","net/netfilter/ipvs/ip_vs_proto_udp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2a3b791e6e1169f374224d164738e9f7be703d77","lessThan":"d418d73acf8be62744dc47359dfdde8c2148845d","versionType":"git","status":"affected"},{"version":"2a3b791e6e1169f374224d164738e9f7be703d77","lessThan":"b3869d9b54e76dff64118dee4c8fd9302fcd5171","versionType":"git","status":"affected"},{"version":"2a3b791e6e1169f374224d164738e9f7be703d77","lessThan":"9cbe2c0fdb71904ee929b1851cdc1c73341a03c0","versionType":"git","status":"affected"},{"version":"2a3b791e6e1169f374224d164738e9f7be703d77","lessThan":"00eb23829fd08df1b5e057cb6b625996a70e7e65","versionType":"git","status":"affected"},{"version":"2a3b791e6e1169f374224d164738e9f7be703d77","lessThan":"5558a85add073215b298f3e044ff9a6d86d714ae","versionType":"git","status":"affected"},{"version":"2a3b791e6e1169f374224d164738e9f7be703d77","lessThan":"e876b75b9020a97bbdc79721e7fc749024891c65","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["include/net/ip_vs.h","net/netfilter/ipvs/ip_vs_core.c","net/netfilter/ipvs/ip_vs_proto_sctp.c","net/netfilter/ipvs/ip_vs_proto_tcp.c","net/netfilter/ipvs/ip_vs_proto_udp.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.28","status":"affected"},{"version":"0","lessThan":"2.6.28","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.151","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.103","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.44","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.8","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/00eb23829fd08df1b5e057cb6b625996a70e7e65","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5558a85add073215b298f3e044ff9a6d86d714ae","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9cbe2c0fdb71904ee929b1851cdc1c73341a03c0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b3869d9b54e76dff64118dee4c8fd9302fcd5171","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d418d73acf8be62744dc47359dfdde8c2148845d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e876b75b9020a97bbdc79721e7fc749024891c65","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80902","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T18:17:59.260","lastModified":"2026-09-04T18:17:59.260","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: sun6i-dma: Fix reclaim descriptors while terminating DMA\n\nWhen terminating DMA transfers, active descriptors are not properly\nreclaimed. Only cyclic descriptors were handled, leaving non-cyclic\ndescriptors and their LLI chains to be permanently leaked.\n\nFix by using vchan_terminate_vdesc() which handles both cyclic and\nnon-cyclic descriptors by adding them to desc_terminated queue for\nproper cleanup.\n\nAdd pchan->desc != pchan->done check to prevent double-adding completed\ndescriptors, which would corrupt the list."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/dma/sun6i-dma.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"555859308723d8d5b828304f5eb9281143fd86b5","lessThan":"bb87440561eb72b47a2b848b5373b86433b247e6","versionType":"git","status":"affected"},{"version":"555859308723d8d5b828304f5eb9281143fd86b5","lessThan":"004a7a02982bed0a727a4ac7be400f00f353e7a2","versionType":"git","status":"affected"},{"version":"555859308723d8d5b828304f5eb9281143fd86b5","lessThan":"b150f603083cc8b72b0cbf13ec3e91f85b4390a0","versionType":"git","status":"affected"},{"version":"555859308723d8d5b828304f5eb9281143fd86b5","lessThan":"27806fe7b9701af0963dcd510e30e7d0cc314c43","versionType":"git","status":"affected"},{"version":"555859308723d8d5b828304f5eb9281143fd86b5","lessThan":"1ccc5c059d067c5358682ad5352e7d7e9239ed9b","versionType":"git","status":"affected"},{"version":"555859308723d8d5b828304f5eb9281143fd86b5","lessThan":"9086b488f2737d5dcee86852b83f2059f1cdfabf","versionType":"git","status":"affected"},{"version":"555859308723d8d5b828304f5eb9281143fd86b5","lessThan":"d4ba6aa65fcd797152d3aebd428a7b2da49cd5eb","versionType":"git","status":"affected"},{"version":"555859308723d8d5b828304f5eb9281143fd86b5","lessThan":"ab1150115e68a46b687eb38c1ab92782018c9f2c","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/dma/sun6i-dma.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3.17","status":"affected"},{"version":"0","lessThan":"3.17","versionType":"semver","status":"unaffected"},{"version":"5.10.265","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.151","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.103","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.44","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.8","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/004a7a02982bed0a727a4ac7be400f00f353e7a2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1ccc5c059d067c5358682ad5352e7d7e9239ed9b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/27806fe7b9701af0963dcd510e30e7d0cc314c43","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9086b488f2737d5dcee86852b83f2059f1cdfabf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ab1150115e68a46b687eb38c1ab92782018c9f2c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b150f603083cc8b72b0cbf13ec3e91f85b4390a0","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bb87440561eb72b47a2b848b5373b86433b247e6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d4ba6aa65fcd797152d3aebd428a7b2da49cd5eb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80903","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T18:17:59.707","lastModified":"2026-09-04T18:17:59.707","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe/oa: Fix sync entry leak on OA config emit failure\n\nxe_oa_emit_oa_config() releases the sync entries and the syncs array\nonly on its success path. When it fails before the point of no return\n(fence allocation, config buffer allocation or batch submission), it\nreturns without touching stream->syncs.\n\nThe stream open path handles such failures in the caller, but\nxe_oa_config_locked() propagates the error without any cleanup, so the\nsyncs array and the fence references held by the parsed entries are\nleaked. The next config ioctl overwrites stream->syncs, making the\nmemory unreachable for good.\n\nClean up the parsed syncs when xe_oa_emit_oa_config() fails, matching\nthe cleanup done by the stream open error path.\n\n(cherry picked from commit 8af97b3da2cfce04e6b457c6eb17ed3c1daf912b)"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/gpu/drm/xe/xe_oa.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"f0ab9cd205d852a9024b73c71c8d8b217a04e8f0","lessThan":"fcf7943b0a38568c547d7b5702de1d8190480616","versionType":"git","status":"affected"},{"version":"9920c8b88c5cf2e44f4ff508dd3c0c96e4364db0","lessThan":"948f346fe36e1d02353c3d61b1f6b66c6af91996","versionType":"git","status":"affected"},{"version":"9920c8b88c5cf2e44f4ff508dd3c0c96e4364db0","lessThan":"027150e24e173a5dffe7f5ab3a6600618f634da2","versionType":"git","status":"affected"},{"version":"9920c8b88c5cf2e44f4ff508dd3c0c96e4364db0","lessThan":"8d33c4987cd162527375a3905017ae129ba7c3fe","versionType":"git","status":"affected"},{"version":"6.12.18","lessThan":"6.12.105","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/gpu/drm/xe/xe_oa.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.13","status":"affected"},{"version":"0","lessThan":"6.13","versionType":"semver","status":"unaffected"},{"version":"6.12.105","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.46","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.10","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/027150e24e173a5dffe7f5ab3a6600618f634da2","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8d33c4987cd162527375a3905017ae129ba7c3fe","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/948f346fe36e1d02353c3d61b1f6b66c6af91996","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fcf7943b0a38568c547d7b5702de1d8190480616","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80904","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T18:17:59.983","lastModified":"2026-09-04T18:17:59.983","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/tls: Fail tls_sw_splice_read() after a failed async decrypt\n\nWhen an async decrypt fails, tls_decrypt_done() records the error in\nctx->async_wait.err and calls tls_err_abort(), which stores it in\nsk_err. tls_sw_recvmsg() and tls_sw_read_sock() each read\nasync_wait.err once they hold the reader lock and fail the call: a\nrecord that did not authenticate breaks the connection.\n\ntls_sw_splice_read() has no such check, and sk_err does not stand in\nfor one. tls_rx_rec_wait() tests sk_err only inside the loop it\nskips whenever a record is already parsed, and the first reader to\nreach sock_error() clears it, while async_wait.err persists. A\nsplice therefore keeps delivering records on a connection that\nrecvmsg() and read_sock() refuse to read.\n\nRead async_wait.err in tls_sw_splice_read() as the other two readers\ndo."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/tls/tls_sw.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"f314bfee81b1bf8e01168177b2f65f24eb8da63a","lessThan":"a808aadff634c7a408b2ab84d5919e9a741fdb5b","versionType":"git","status":"affected"},{"version":"f314bfee81b1bf8e01168177b2f65f24eb8da63a","lessThan":"06c2a53604fa1dc4820063828d7dadb3675b7af8","versionType":"git","status":"affected"},{"version":"f314bfee81b1bf8e01168177b2f65f24eb8da63a","lessThan":"18ae1e95f20867106a28820c208a9cec99dda861","versionType":"git","status":"affected"},{"version":"f314bfee81b1bf8e01168177b2f65f24eb8da63a","lessThan":"82d9269f01ebfd835b6256aa17016a974cbbc647","versionType":"git","status":"affected"},{"version":"f314bfee81b1bf8e01168177b2f65f24eb8da63a","lessThan":"4b177911eb9f799e9841c2f87c75b08cb112757a","versionType":"git","status":"affected"},{"version":"f314bfee81b1bf8e01168177b2f65f24eb8da63a","lessThan":"976df67f463db1fddaf2a32fb04f57ad2891a23d","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/tls/tls_sw.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.19","status":"affected"},{"version":"0","lessThan":"5.19","versionType":"semver","status":"unaffected"},{"version":"6.1.184","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.153","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.105","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.46","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.10","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/06c2a53604fa1dc4820063828d7dadb3675b7af8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/18ae1e95f20867106a28820c208a9cec99dda861","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4b177911eb9f799e9841c2f87c75b08cb112757a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/82d9269f01ebfd835b6256aa17016a974cbbc647","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/976df67f463db1fddaf2a32fb04f57ad2891a23d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a808aadff634c7a408b2ab84d5919e9a741fdb5b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80905","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T18:18:00.120","lastModified":"2026-09-04T18:18:00.120","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: tap: fix wrong transport_header when sending VLAN-tagged frame\n\nIn tap_get_user_xdp(), when processing a VLAN-tagged frame (e.g.\nETH_P_8021Q), skb_set_network_header() is called first to advance\nnetwork_header past the VLAN tag to the inner protocol header.\nskb_probe_transport_header() is then called with skb->protocol still\nset to ETH_P_8021Q, while nhoff (derived from skb_network_offset())\nalready points past the VLAN tag to the inner protocol header.\n\nIn __skb_flow_dissect(), proto is initialized to ETH_P_8021Q and nhoff\npoints past the VLAN tag. When the dissector hits case ETH_P_8021Q, it\nreads a struct vlan_hdr at the current nhoff via __skb_header_pointer(),\nbut that offset contains the inner protocol header (e.g. an IP header).\nThe bytes are misinterpreted as a VLAN header, yielding a garbage\nencapsulated EtherType that matches no known protocol. The dissector\nreturns false, so skb_probe_transport_header() never calls\nskb_set_transport_header(), leaving transport_header at its uninitialized\nsentinel value (~0U).\n\nMove skb_set_network_header() to after skb_probe_transport_header(). At\nthe time skb_probe_transport_header() is called, network_header still\npoints to the VLAN header (offset ETH_HLEN), so nhoff is correct and the\nflow dissector can parse the VLAN header, extract the inner EtherType,\nand advance nhoff to the inner protocol header, allowing transport_header\nto be set correctly."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/net/tap.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"8c76e77f9069f10505c08e02646c3ee11ad79038","lessThan":"5ffaa5d7f56ab24a8e23cf131eadfef31a3bbc4b","versionType":"git","status":"affected"},{"version":"8c76e77f9069f10505c08e02646c3ee11ad79038","lessThan":"88b79ac89ecc04d7f2613f7e1c0b46f0c4ddb2f3","versionType":"git","status":"affected"},{"version":"8c76e77f9069f10505c08e02646c3ee11ad79038","lessThan":"cbb35cbe8db268fefe34c23df15348cf99025298","versionType":"git","status":"affected"},{"version":"3cae5ef1f37a475faf7c40bc6a3c170779f3e0b1","versionType":"git","status":"affected"},{"version":"4.20.1","lessThan":"4.21","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/net/tap.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.0","status":"affected"},{"version":"0","lessThan":"5.0","versionType":"semver","status":"unaffected"},{"version":"6.18.46","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.10","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/5ffaa5d7f56ab24a8e23cf131eadfef31a3bbc4b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/88b79ac89ecc04d7f2613f7e1c0b46f0c4ddb2f3","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cbb35cbe8db268fefe34c23df15348cf99025298","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80906","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T18:18:00.240","lastModified":"2026-09-04T18:18:00.240","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: packet: fix wrong transport_header when sending VLAN-tagged frame\n\nIn packet_parse_headers(), when processing a VLAN-tagged frame,\nskb_set_network_header() is called to advance network_header past the\nVLAN tag to the inner protocol header. skb_probe_transport_header() is\nthen called with skb->protocol still set to the outer VLAN EtherType\n(e.g. ETH_P_8021Q), while nhoff (derived from skb_network_offset())\nalready points past the VLAN tag to the inner protocol header.\n\nIn __skb_flow_dissect(), proto is initialized to ETH_P_8021Q and nhoff\npoints past the VLAN tag. When the dissector hits case ETH_P_8021Q, it\nreads a struct vlan_hdr at nhoff via __skb_header_pointer(), but that\noffset contains the inner protocol header (e.g. an IP header). The bytes\nare misinterpreted as a VLAN header, yielding a garbage encapsulated\nEtherType that matches no known protocol. The dissector returns false,\nso skb_probe_transport_header() never calls skb_set_transport_header(),\nleaving transport_header at its uninitialized sentinel value (~0U).\n\nMove skb_probe_transport_header() to before skb_set_network_header(). At\nthe time skb_probe_transport_header() is called, network_header still\npoints to the VLAN header, so nhoff correctly points to the VLAN header.\nThe flow dissector can then parse the VLAN header, extract the inner\nEtherType, and advance nhoff to the inner protocol header, allowing\ntransport_header to be set correctly."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["net/packet/af_packet.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"c2137d565ceb505de69593c181a0543bc4083838","lessThan":"a4b82de96d465ddb44bc931145c0fa80c4fe9c9c","versionType":"git","status":"affected"},{"version":"9ff46c36df2e0a1ac352f2f4038eaf3f0f7361b8","lessThan":"fa86bc52ea8ba981f74f851fd61e2a3d3bc0feac","versionType":"git","status":"affected"},{"version":"dfed913e8b55a0c2c4906f1242fd38fd9a116e49","lessThan":"5479eb9b355f44745d7ccfe112386bd4f96eceea","versionType":"git","status":"affected"},{"version":"dfed913e8b55a0c2c4906f1242fd38fd9a116e49","lessThan":"e451e20adb869a983a21dda158625f024142e61f","versionType":"git","status":"affected"},{"version":"dfed913e8b55a0c2c4906f1242fd38fd9a116e49","lessThan":"6971cf319263d6a1b4096f9248aca9e57d77a1eb","versionType":"git","status":"affected"},{"version":"dfed913e8b55a0c2c4906f1242fd38fd9a116e49","lessThan":"f9297abbcaba760b7a7b9d63b839f607f738013e","versionType":"git","status":"affected"},{"version":"dfed913e8b55a0c2c4906f1242fd38fd9a116e49","lessThan":"6386a6ffa2efba2965ed8e4fa303582c0b76a215","versionType":"git","status":"affected"},{"version":"dfed913e8b55a0c2c4906f1242fd38fd9a116e49","lessThan":"01fdecc0480d916c799dbee584833a4a37e94d06","versionType":"git","status":"affected"},{"version":"ad3f90a9c4a2c74bb3711f2031bffda4ec44c849","versionType":"git","status":"affected"},{"version":"5.10.163","lessThan":"5.10.266","versionType":"semver","status":"affected"},{"version":"5.15.87","lessThan":"5.15.217","versionType":"semver","status":"affected"},{"version":"5.4.229","lessThan":"5.5","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["net/packet/af_packet.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.19","status":"affected"},{"version":"0","lessThan":"5.19","versionType":"semver","status":"unaffected"},{"version":"5.10.266","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.217","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.184","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.153","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.105","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.46","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.10","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/01fdecc0480d916c799dbee584833a4a37e94d06","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5479eb9b355f44745d7ccfe112386bd4f96eceea","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6386a6ffa2efba2965ed8e4fa303582c0b76a215","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6971cf319263d6a1b4096f9248aca9e57d77a1eb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a4b82de96d465ddb44bc931145c0fa80c4fe9c9c","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e451e20adb869a983a21dda158625f024142e61f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f9297abbcaba760b7a7b9d63b839f607f738013e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fa86bc52ea8ba981f74f851fd61e2a3d3bc0feac","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80907","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T18:18:00.393","lastModified":"2026-09-04T18:18:00.393","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: Fix UVD dpb min size calculation for H264\n\nThis should use actual number of references from the decode\nmessage, instead of maximum derived from level.\n\n(cherry picked from commit 64b525edb7e7bdfcdc77883c5e413804e2396856)"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/gpu/drm/amd/amdgpu/amdgpu_uvd.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"fa96c24485942e277483cc70d9551d9e0111d7c5","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"33f4ef585368fe93523dca1e5440e006f6e5146e","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"38914cb2c6afb5fe00241ea3438e655822196378","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"ff4361816b6ba4bd29b548b17d993056a1ae2502","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"21a8084cd76223a13493237e04d45f5226d7cee6","versionType":"git","status":"affected"},{"version":"0","lessThan":"6.6.153","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.12.105","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.18.46","versionType":"semver","status":"affected"},{"version":"0","lessThan":"7.1.10","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/gpu/drm/amd/amdgpu/amdgpu_uvd.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.6.153","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.105","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.46","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.10","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/21a8084cd76223a13493237e04d45f5226d7cee6","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/33f4ef585368fe93523dca1e5440e006f6e5146e","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/38914cb2c6afb5fe00241ea3438e655822196378","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fa96c24485942e277483cc70d9551d9e0111d7c5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ff4361816b6ba4bd29b548b17d993056a1ae2502","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80908","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T18:18:00.507","lastModified":"2026-09-04T18:18:00.507","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: Reject UVD message with dimensions above 4096\n\nFixes potential overflow in DPB size calculations.\n\n(cherry picked from commit 05e1387d151f71569fbe122d2c89f9db0c21dc10)"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/gpu/drm/amd/amdgpu/amdgpu_uvd.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"8bae80eaed00e7ae28412a3cdf590f4beca72294","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"9adc5e25f31d7ee7dfc18814499b6e3a6d402904","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"382bef781ff441ce8055bdada57b8c291dc0fd30","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"8435d41afcf2bc31ecee213ef651c12bd1a16d38","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"f7af372d3b892b95dd3cd1c6acf29daa39ba076d","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"339deb76ee4859ea973e435c9a9a4a4fefc29338","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"17fbb996c05f2190e0fa20927ca0b9804d481b02","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"8c9aebcdd9f46f7a14b98d6ab18574b7a48fbb08","versionType":"git","status":"affected"},{"version":"0","lessThan":"5.10.266","versionType":"semver","status":"affected"},{"version":"0","lessThan":"5.15.217","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.1.184","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.6.153","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.12.105","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.18.46","versionType":"semver","status":"affected"},{"version":"0","lessThan":"7.1.10","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/gpu/drm/amd/amdgpu/amdgpu_uvd.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.10.266","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.217","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.184","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.153","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.105","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.46","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.10","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/17fbb996c05f2190e0fa20927ca0b9804d481b02","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/339deb76ee4859ea973e435c9a9a4a4fefc29338","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/382bef781ff441ce8055bdada57b8c291dc0fd30","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8435d41afcf2bc31ecee213ef651c12bd1a16d38","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8bae80eaed00e7ae28412a3cdf590f4beca72294","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8c9aebcdd9f46f7a14b98d6ab18574b7a48fbb08","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9adc5e25f31d7ee7dfc18814499b6e3a6d402904","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f7af372d3b892b95dd3cd1c6acf29daa39ba076d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80909","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T18:18:00.640","lastModified":"2026-09-04T18:18:00.640","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: Reject UVD message with invalid number of h265 refs\n\nSame change as for h264, avoids overflow later when calculating\nmin dpb size.\n\n(cherry picked from commit a4b0720e4f1601f97f59a2be9c1b4b94fa6527d5)"}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["drivers/gpu/drm/amd/amdgpu/amdgpu_uvd.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"1facad2a78c1a8aeecc36eb4d560c7f1e10ce198","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"499907e5d46e575e96967c0230a0a6af980a17ab","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"cbf1c84bf5cac2b3742ea3d2085fa713424465cc","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"a930c54cb67200de8bc0de87480d09ece7dcd85d","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"2abcdc5f738574e7fcdd9417575dffb877fdc26f","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"e304c3e0d9ce251887be1f274aa0ed52219d5fd7","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"0acdf1a575f59bd46717d5c487d84575af5bee8f","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"9fca434208f1f9ab977feac62df8ebb1cc7ce893","versionType":"git","status":"affected"},{"version":"0","lessThan":"5.10.266","versionType":"semver","status":"affected"},{"version":"0","lessThan":"5.15.217","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.1.184","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.6.153","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.12.105","versionType":"semver","status":"affected"},{"version":"0","lessThan":"6.18.46","versionType":"semver","status":"affected"},{"version":"0","lessThan":"7.1.10","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["drivers/gpu/drm/amd/amdgpu/amdgpu_uvd.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.10.266","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.217","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.184","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.153","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.105","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.46","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.10","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/0acdf1a575f59bd46717d5c487d84575af5bee8f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1facad2a78c1a8aeecc36eb4d560c7f1e10ce198","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2abcdc5f738574e7fcdd9417575dffb877fdc26f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/499907e5d46e575e96967c0230a0a6af980a17ab","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9fca434208f1f9ab977feac62df8ebb1cc7ce893","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a930c54cb67200de8bc0de87480d09ece7dcd85d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cbf1c84bf5cac2b3742ea3d2085fa713424465cc","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e304c3e0d9ce251887be1f274aa0ed52219d5fd7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80910","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T18:18:00.783","lastModified":"2026-09-04T18:18:00.783","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: codecs: lpass-wsa-macro: Fix enum kcontrol accesses\n\nEAR SPKR PA Gain\" and the four \"WSA RX* Mux\" controls are enumerated,\nbut their get and put callbacks access the value through\nucontrol->value.integer.value[0] (a long) instead of\nucontrol->value.enumerated.item[0] (an unsigned int).\n\nThis same pattern was fixed in the sibling drivers by\ncommit bcfe5f76cc40 (\"ASoC: codecs: rx-macro: fix accessing array\nout of bounds for enum type\") and\ncommit 0ea5eff7c606 (\"ASoC: codecs: va-macro: fix accessing array\nout of bounds for enum type\"), but wsa-macro was missed.\n\nOn 64-bit kernels with CONFIG_SND_CTL_DEBUG this trips the elem value\nsanity check and every read of these controls fails with -EINVAL."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["sound/soc/codecs/lpass-wsa-macro.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"809bcbcecebff86003e13f07444d21b9d6652a64","lessThan":"bd4e5f9c3b764dc0e2a5662f92d63d2f3767a78d","versionType":"git","status":"affected"},{"version":"809bcbcecebff86003e13f07444d21b9d6652a64","lessThan":"4bcac4bf304a3ec746192e49a669c236aaf27dbf","versionType":"git","status":"affected"},{"version":"809bcbcecebff86003e13f07444d21b9d6652a64","lessThan":"891129df5de79cd533ae335c6eab24df2ff2b0fd","versionType":"git","status":"affected"},{"version":"809bcbcecebff86003e13f07444d21b9d6652a64","lessThan":"524aa7b9954b0a43dd13f71ecbbac52a151c326d","versionType":"git","status":"affected"},{"version":"809bcbcecebff86003e13f07444d21b9d6652a64","lessThan":"2fe7a89b2b5b73be35c1e493d0246314ba54e427","versionType":"git","status":"affected"},{"version":"809bcbcecebff86003e13f07444d21b9d6652a64","lessThan":"7bcdde412e6c744f6135e02b12a735e2e37b639f","versionType":"git","status":"affected"},{"version":"809bcbcecebff86003e13f07444d21b9d6652a64","lessThan":"56f24311fd5607588a47e44675195a9efb200f29","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["sound/soc/codecs/lpass-wsa-macro.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.11","status":"affected"},{"version":"0","lessThan":"5.11","versionType":"semver","status":"unaffected"},{"version":"5.15.217","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.184","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.153","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.105","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.46","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.10","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/2fe7a89b2b5b73be35c1e493d0246314ba54e427","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4bcac4bf304a3ec746192e49a669c236aaf27dbf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/524aa7b9954b0a43dd13f71ecbbac52a151c326d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/56f24311fd5607588a47e44675195a9efb200f29","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/7bcdde412e6c744f6135e02b12a735e2e37b639f","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/891129df5de79cd533ae335c6eab24df2ff2b0fd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bd4e5f9c3b764dc0e2a5662f92d63d2f3767a78d","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80911","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T18:18:00.920","lastModified":"2026-09-04T18:18:00.920","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: SOF: sof-audio: Fix error path in sof_widget_setup_unlocked()\n\nIf either tplg_ops->dai_config or widget_kcontrol_setup fail during widget\nsetup we would double decrement the use_count of the widget because the\nsof_widget_free_unlocked() would be called twice, similarly the core_put\nwould be invoked twice as well.\n\nSince the use_count and core_put() is handled within the widget_free\nfunction we need to return without falling through the pipe_widget_free\nlabel.\n\nThe fixes tag is picked to the last change around this part of the code\nwhich is adequately old enough for backporting purposes."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["sound/soc/sof/sof-audio.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"3c124f09b7ff0434b076a8dec1ed446a6170b549","lessThan":"b270ed327380428581bbcbd85707f62e942428d7","versionType":"git","status":"affected"},{"version":"31ed8da1c8e5e504710bb36863700e3389f8fc81","lessThan":"c06995637f6a4667f2b540ac65315bfc8196a099","versionType":"git","status":"affected"},{"version":"31ed8da1c8e5e504710bb36863700e3389f8fc81","lessThan":"8cba53b862e1437257ec206d303ff942684284f1","versionType":"git","status":"affected"},{"version":"31ed8da1c8e5e504710bb36863700e3389f8fc81","lessThan":"d48691e70d4a9434b71039d4ed12bb0df4601acf","versionType":"git","status":"affected"},{"version":"31ed8da1c8e5e504710bb36863700e3389f8fc81","lessThan":"e780e4917d43683224812400fe3dc4816fceba75","versionType":"git","status":"affected"},{"version":"6.6.13","lessThan":"6.6.153","versionType":"semver","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["sound/soc/sof/sof-audio.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"6.7","status":"affected"},{"version":"0","lessThan":"6.7","versionType":"semver","status":"unaffected"},{"version":"6.6.153","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.105","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.46","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.10","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/8cba53b862e1437257ec206d303ff942684284f1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b270ed327380428581bbcbd85707f62e942428d7","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c06995637f6a4667f2b540ac65315bfc8196a099","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d48691e70d4a9434b71039d4ed12bb0df4601acf","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e780e4917d43683224812400fe3dc4816fceba75","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80912","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T18:18:01.047","lastModified":"2026-09-04T18:18:01.047","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nselinux: reject an unclaimed class value in security_get_classes()\n\nsecurity_get_classes() sizes an array by p_classes.nprim and fills it at\nvalue - 1, so a class value the policy never defines leaves a NULL.\nsel_make_classes() passes every entry to sel_make_dir(), reaching the same\nd_alloc_name() dereference as the permission array. The class symbol table\nis allowed to be sparse (policydb_class_isvalid() exists to absorb that),\nbut this getter builds its own array straight from the hash table and has\nno such predicate.\n\nFail the lookup when a value went unclaimed instead of handing out the\nNULL. Conforming policies define every class they declare and are\nunaffected."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["security/selinux/ss/services.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"55fcf09b3fe4325c9395ebbb0322a547a157ebc7","lessThan":"e0285bb152211c00900136b66d4b420c14a59094","versionType":"git","status":"affected"},{"version":"55fcf09b3fe4325c9395ebbb0322a547a157ebc7","lessThan":"099869e9343a5f8c22b58497f074b34f63cbf856","versionType":"git","status":"affected"},{"version":"55fcf09b3fe4325c9395ebbb0322a547a157ebc7","lessThan":"841aea4d5a25e16273d04cd07a74142b4687e03b","versionType":"git","status":"affected"},{"version":"55fcf09b3fe4325c9395ebbb0322a547a157ebc7","lessThan":"d8a10899ea3c84b80de72ca8ee9039e9a5156c9a","versionType":"git","status":"affected"},{"version":"55fcf09b3fe4325c9395ebbb0322a547a157ebc7","lessThan":"22b05fec62c0fe9864cfceb52f7d0f3a34d9b1dd","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["security/selinux/ss/services.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.23","status":"affected"},{"version":"0","lessThan":"2.6.23","versionType":"semver","status":"unaffected"},{"version":"6.6.153","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.105","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.46","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.10","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/099869e9343a5f8c22b58497f074b34f63cbf856","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/22b05fec62c0fe9864cfceb52f7d0f3a34d9b1dd","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/841aea4d5a25e16273d04cd07a74142b4687e03b","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d8a10899ea3c84b80de72ca8ee9039e9a5156c9a","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e0285bb152211c00900136b66d4b420c14a59094","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-80913","sourceIdentifier":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","published":"2026-09-04T18:18:01.200","lastModified":"2026-09-04T18:18:01.200","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nselinux: require every boolean value to be defined\n\np_bools.nprim comes from the policy image independently of how many\nbooleans follow it, and cond_index_bool() fills bool_val_to_struct[] at\nvalue - 1, so a count larger than the values present leaves NULL entries.\nEvery user of that array then walks it by index and dereferences each\nentry: cond_evaluate_expr() on the access-vector path,\nsecurity_get_bools() and security_get_bool_value() behind selinuxfs, and\nsecurity_set_bools(). A sparse class value is absorbed by\npolicydb_class_isvalid() and its siblings; booleans have no such\npredicate, and no consumer that could use one.\n\nReject a boolean value that no boolean defines, once, where the array is\nbuilt. Conforming policies define every boolean they declare and are\nunaffected."}],"affected":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","affectedData":[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["security/selinux/ss/policydb.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"4d0ece18e648bd4362704fd087249ac697f2b7fb","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"3938c8494d3c5d84a53fd7d1966ae9dde46cb5f8","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"4dfb997c60f7951011d3dcbee926e3a7f80d8a76","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"3161daa3f1e3ca68f8b2b8fa01720b5a8dcc6b40","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"740012aebdb8311332bf66e2aabf453ba73c2c45","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"42a7107f99d86a7524c37f108047dfa3db096ab5","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"ed901e88aa3fb3d5d7b0b52c2ee3073209df9bec","versionType":"git","status":"affected"},{"version":"1da177e4c3f41524e886b7f1b8a0c1fc7321cac2","lessThan":"a93d37a09b863810653f93d371fb197457d59deb","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["security/selinux/ss/policydb.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"2.6.12","status":"affected"},{"version":"0","lessThan":"2.6.12","versionType":"semver","status":"unaffected"},{"version":"5.10.266","lessThanOrEqual":"5.10.*","versionType":"semver","status":"unaffected"},{"version":"5.15.217","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.184","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.153","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.105","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.46","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.10","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]}],"metrics":{},"references":[{"url":"https://git.kernel.org/stable/c/3161daa3f1e3ca68f8b2b8fa01720b5a8dcc6b40","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3938c8494d3c5d84a53fd7d1966ae9dde46cb5f8","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/42a7107f99d86a7524c37f108047dfa3db096ab5","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4d0ece18e648bd4362704fd087249ac697f2b7fb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4dfb997c60f7951011d3dcbee926e3a7f80d8a76","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/740012aebdb8311332bf66e2aabf453ba73c2c45","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a93d37a09b863810653f93d371fb197457d59deb","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ed901e88aa3fb3d5d7b0b52c2ee3073209df9bec","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}]}},{"cve":{"id":"CVE-2026-82538","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-04T18:18:01.357","lastModified":"2026-09-04T18:18:01.357","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"ILIAS before versions 9.22, 10.10, and 11.3 contains a SQL injection vulnerability in the repository trash table where the table navigation sort field from HTTP requests is passed directly into the ORDER BY clause of a SQL query without validation against declared sortable columns. Authenticated users with write permission on any container can inject arbitrary SQL through the sort parameter, and because multi-statement execution is enabled in the database layer, stacked queries enable full database read and write access as well as administrator account takeover."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"ILIAS-eLearning e.V.","product":"ILIAS","defaultStatus":"unaffected","collectionURL":"https://github.com/ILIAS-eLearning/ILIAS","repo":"https://github.com/ILIAS-eLearning/ILIAS","packageURL":"pkg:github/ILIAS-eLearning/ILIAS","versions":[{"version":"9.0","lessThan":"9.22","versionType":"custom","status":"affected"},{"version":"10.0","lessThan":"10.10","versionType":"custom","status":"affected"},{"version":"11.0","lessThan":"11.3","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Primary","description":[{"lang":"en","value":"CWE-89"}]}],"references":[{"url":"https://docu.ilias.de/ilias.php?baseClass=illmpresentationgui&obj_id=225630&ref_id=35","source":"disclosure@vulncheck.com"},{"url":"https://docu.ilias.de/ilias.php?baseClass=illmpresentationgui&obj_id=225631&ref_id=35","source":"disclosure@vulncheck.com"},{"url":"https://docu.ilias.de/ilias.php?baseClass=illmpresentationgui&obj_id=225632&ref_id=35","source":"disclosure@vulncheck.com"},{"url":"https://docu.ilias.de/ilias.php?baseClass=ilrepositorygui&cmdNode=wy:ll:6t&cmdClass=ilBlogPostingGUI&cmd=previewFullscreen&ref_id=15821&blpg=934","source":"disclosure@vulncheck.com"},{"url":"https://docu.ilias.de/ilias.php?baseClass=ilrepositorygui&cmdNode=wy:ll:6t&cmdClass=ilBlogPostingGUI&cmd=previewFullscreen&ref_id=15821&blpg=935","source":"disclosure@vulncheck.com"},{"url":"https://docu.ilias.de/ilias.php?baseClass=ilrepositorygui&cmdNode=wy:ll:6t&cmdClass=ilBlogPostingGUI&cmd=previewFullscreen&ref_id=15821&blpg=936","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/ilias-arbitrary-file-read-via-soap-addfile","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/ilias-arbitrary-sql-injection-via-repository-trash-table-sort-parameter","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-84890","sourceIdentifier":"ce714d77-add3-4f53-aff5-83d477b104bb","published":"2026-09-04T18:18:01.633","lastModified":"2026-09-04T19:17:30.043","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"undici's decompress interceptor decompresses response bodies according to the untrusted Content-Encoding header. While the number of content-encoding layers is capped, the total decompressed output size is unbounded and there is no configuration option to limit it. A malicious or faulty upstream can therefore return a small compressed payload, a compression bomb, that expands to hundreds of megabytes or more in client memory, an asymmetric resource consumption that can exhaust memory and crash the process. This affects undici versions from 7.15.0 up to 7.29.1 and from 8.0.0 up to 8.10.2. Users should upgrade to undici 7.29.1 or 8.10.2."}],"affected":[{"source":"ce714d77-add3-4f53-aff5-83d477b104bb","affectedData":[{"vendor":"undici","product":"undici","defaultStatus":"unaffected","packageURL":"pkg:npm/undici","versions":[{"version":"7.15.0","lessThan":"7.29.1","versionType":"semver","status":"affected"},{"version":"7.29.1","versionType":"semver","status":"unaffected"},{"version":"8.0.0","lessThan":"8.10.2","versionType":"semver","status":"affected"},{"version":"8.10.2","versionType":"semver","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"ce714d77-add3-4f53-aff5-83d477b104bb","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":5.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.2,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T18:32:49.819558Z","id":"CVE-2026-84890","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"ce714d77-add3-4f53-aff5-83d477b104bb","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]}],"references":[{"url":"https://cna.openjsf.org/security-advisories.html","source":"ce714d77-add3-4f53-aff5-83d477b104bb"},{"url":"https://github.com/nodejs/undici/security/advisories/GHSA-3xpg-4rpp-hhhm","source":"ce714d77-add3-4f53-aff5-83d477b104bb"}]}},{"cve":{"id":"CVE-2026-85636","sourceIdentifier":"cna@vuldb.com","published":"2026-09-04T18:18:05.300","lastModified":"2026-09-04T18:18:05.300","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability was identified in jofpin trape 1.0.0. Affected by this vulnerability is an unknown functionality of the file core/stats.py of the component Login Endpoint. The manipulation leads to missing authentication. The attack may be initiated remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet."}],"affected":[{"source":"cna@vuldb.com","affectedData":[{"vendor":"jofpin","product":"trape","cpes":["cpe:2.3:a:jofpin:trape:*:*:*:*:*:*:*:*"],"modules":["Login Endpoint"],"versions":[{"version":"1.0.0","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"PROOF_OF_CONCEPT","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"cna@vuldb.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"cna@vuldb.com","type":"Primary","description":[{"lang":"en","value":"CWE-287"},{"lang":"en","value":"CWE-306"}]}],"references":[{"url":"https://github.com/jofpin/trape/","source":"cna@vuldb.com"},{"url":"https://github.com/jofpin/trape/issues/405","source":"cna@vuldb.com"},{"url":"https://vuldb.com/cve/CVE-2026-85636","source":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/895135","source":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/895141","source":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/398784","source":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/398784/cti","source":"cna@vuldb.com"}]}},{"cve":{"id":"CVE-2026-85654","sourceIdentifier":"ff89ba41-3aa1-4d27-914a-91399e9639e5","published":"2026-09-04T18:18:05.977","lastModified":"2026-09-04T19:17:33.773","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Improper neutralization of special elements used in a template engine in the CDK generator in Amazon awslabs.dynamodb-mcp-server before 2.1.6 might allow a context-dependent actor to execute arbitrary code on the host that deploys the generated application via crafted table, index, or attribute names in a data model file."}],"affected":[{"source":"ff89ba41-3aa1-4d27-914a-91399e9639e5","affectedData":[{"vendor":"Amazon","product":"awslabs.dynamodb-mcp-server","defaultStatus":"unaffected","versions":[{"version":"2.0.10","lessThanOrEqual":"2.1.5","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"ff89ba41-3aa1-4d27-914a-91399e9639e5","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"ACTIVE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"ff89ba41-3aa1-4d27-914a-91399e9639e5","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T18:32:12.620174Z","id":"CVE-2026-85654","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"ff89ba41-3aa1-4d27-914a-91399e9639e5","type":"Secondary","description":[{"lang":"en","value":"CWE-1336"}]}],"references":[{"url":"https://aws.amazon.com/security/security-bulletins/2026-097-aws/","source":"ff89ba41-3aa1-4d27-914a-91399e9639e5"},{"url":"https://pypi.org/project/awslabs.dynamodb-mcp-server/2.1.6/","source":"ff89ba41-3aa1-4d27-914a-91399e9639e5"}]}},{"cve":{"id":"CVE-2026-85656","sourceIdentifier":"ff89ba41-3aa1-4d27-914a-91399e9639e5","published":"2026-09-04T18:18:06.133","lastModified":"2026-09-04T18:18:06.133","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"An OS command injection issue in the log4j-cve-2021-44228-hotpatch package in Amazon Linux before 1.3-9 might allow a local user to execute arbitrary commands with root privileges via a Java process whose executable path contains embedded newline characters."}],"affected":[{"source":"ff89ba41-3aa1-4d27-914a-91399e9639e5","affectedData":[{"vendor":"Amazon","product":"log4j-cve-2021-44228-hotpatch","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"1.3-9.amzn2","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"ff89ba41-3aa1-4d27-914a-91399e9639e5","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.5,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"ff89ba41-3aa1-4d27-914a-91399e9639e5","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T17:49:18.878769Z","id":"CVE-2026-85656","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"ff89ba41-3aa1-4d27-914a-91399e9639e5","type":"Secondary","description":[{"lang":"en","value":"CWE-78"}]}],"references":[{"url":"https://alas.aws.amazon.com/AL2/ALAS2-2026-3784.html","source":"ff89ba41-3aa1-4d27-914a-91399e9639e5"},{"url":"https://aws.amazon.com/security/security-bulletins/2026-098-aws/","source":"ff89ba41-3aa1-4d27-914a-91399e9639e5"}]}},{"cve":{"id":"CVE-2026-85769","sourceIdentifier":"secalert@redhat.com","published":"2026-09-04T18:18:07.153","lastModified":"2026-09-04T19:17:34.020","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"A flaw was found in libtpms, a library that provides software TPM 2.0 emulation. When restoring TPM 2.0 state (for example during a virtual machine's power-on or state/migration restore), a malformed state blob can supply an oversized skip-block length that is not validated against the remaining size of the input buffer. This can drive an internal size counter negative, which bypasses a subsequent bounds check due to an unsafe signed-to-unsigned conversion, causing the parser to read memory outside the bounds of the heap buffer holding the state data. Successful exploitation can crash the process hosting libtpms (such as swtpm), resulting in a denial of service of the emulated TPM device and the virtual machine that depends on it. No data corruption or information disclosure was confirmed."}],"affected":[{"source":"secalert@redhat.com","affectedData":[{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"libtpms","cpes":["cpe:/o:redhat:enterprise_linux:10"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"virt:rhel/libtpms","cpes":["cpe:/o:redhat:enterprise_linux:8"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"libtpms","cpes":["cpe:/o:redhat:enterprise_linux:9"]}]}],"metrics":{"cvssMetricV31":[{"source":"secalert@redhat.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T18:51:03.667125Z","id":"CVE-2026-85769","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"secalert@redhat.com","type":"Secondary","description":[{"lang":"en","value":"CWE-125"}]}],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-85769","source":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2528538","source":"secalert@redhat.com"},{"url":"https://github.com/stefanberger/libtpms/commit/b1462888180d896af03cae0487e8d45009cc445e","source":"secalert@redhat.com"},{"url":"https://github.com/stefanberger/libtpms/issues/614","source":"secalert@redhat.com"}]}},{"cve":{"id":"CVE-2026-9317","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-04T18:18:07.297","lastModified":"2026-09-04T18:18:07.297","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Nango before 0.71.6 contains a missing authentication vulnerability in the runner tRPC server that allows unauthenticated attackers to execute arbitrary JavaScript code by invoking the exposed start procedure without credentials. Attackers with network access to the runner port can send requests to the unauthenticated start procedure, bypassing the unenforced RUNNER_SECRET_KEY environment variable, to achieve remote code execution within the runner process."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"NangoHQ","product":"nango","defaultStatus":"unaffected","repo":"https://github.com/NangoHQ/nango","packageURL":"pkg:github/NangoHQ/nango","versions":[{"version":"0","lessThan":"0.71.6","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":9.2,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.2,"impactScore":5.9}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Primary","description":[{"lang":"en","value":"CWE-306"}]}],"references":[{"url":"https://github.com/NangoHQ/nango/commit/ed3030a9a0f8e4f3810fd10cb3a1905a2f5f87d2","source":"disclosure@vulncheck.com"},{"url":"https://github.com/NangoHQ/nango/pull/7288","source":"disclosure@vulncheck.com"},{"url":"https://github.com/NangoHQ/nango/releases/tag/v0.71.6","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/nango-missing-authentication-rce-via-runner-trpc-server","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-71620","sourceIdentifier":"cve@mitre.org","published":"2026-09-04T19:17:26.607","lastModified":"2026-09-04T19:17:26.607","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"File Upload vulnerability in Zhao-github ApiAdmin v.5.0.1 allows a remote attacker to execute arbitrary code via a crafted .php file"}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://colorful-quill-4fe.notion.site/ApiAdmin-v5-0-1-rce-37fe5670300c80e3bc07da4694b5b953?pvs=73","source":"cve@mitre.org"}]}},{"cve":{"id":"CVE-2026-78327","sourceIdentifier":"PSIRT@sonicwall.com","published":"2026-09-04T19:17:27.347","lastModified":"2026-09-04T20:17:27.827","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows an authenticated attacker with SuperAdmin privileges to inject arbitrary commands that are executed on the underlying host, resulting in remote code execution."}],"affected":[{"source":"PSIRT@sonicwall.com","affectedData":[{"vendor":"SonicWall","product":"Network Security Manager (NSM)","defaultStatus":"unknown","platforms":["Linux","On-Prem"],"versions":[{"version":"4.3.0 and earlier versions","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H","baseScore":9.1,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.3,"impactScore":6.0}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T19:49:49.013441Z","id":"CVE-2026-78327","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"PSIRT@sonicwall.com","type":"Secondary","description":[{"lang":"en","value":"CWE-78"}]}],"references":[{"url":"https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0015","source":"PSIRT@sonicwall.com"}]}},{"cve":{"id":"CVE-2026-78328","sourceIdentifier":"PSIRT@sonicwall.com","published":"2026-09-04T19:17:27.463","lastModified":"2026-09-04T20:17:27.993","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"A missing authorization vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows a lower-privileged Admin user to escalate privileges to SuperAdmin."}],"affected":[{"source":"PSIRT@sonicwall.com","affectedData":[{"vendor":"SonicWall","product":"Network Security Manager (NSM)","defaultStatus":"unknown","platforms":["Linux","On-Prem"],"versions":[{"version":"4.3.0 and earlier versions","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H","baseScore":9.1,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.3,"impactScore":6.0}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T19:49:15.329704Z","id":"CVE-2026-78328","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"PSIRT@sonicwall.com","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]}],"references":[{"url":"https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0015","source":"PSIRT@sonicwall.com"}]}},{"cve":{"id":"CVE-2026-78839","sourceIdentifier":"cve@mitre.org","published":"2026-09-04T19:17:27.703","lastModified":"2026-09-04T19:17:27.703","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"An arbitrary file upload vulnerability in AppNitro MachForm v30 allows attackers to execute arbitrary code via uploading a crafted .phar file."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://github.com/nabeelmkhan/CVE-2026-78839","source":"cve@mitre.org"},{"url":"https://packetstormsecurity.com","source":"cve@mitre.org"}]}},{"cve":{"id":"CVE-2026-80112","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-04T19:17:27.823","lastModified":"2026-09-04T19:17:27.823","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an improper access control vulnerability in the DirectIo64.sys kernel driver that allows unprivileged local users to perform privileged hardware operations by opening a handle to the device object created without a security descriptor. Attackers can issue IOCTLs through the permissive default Windows ACL applied to the device to access restricted hardware operations regardless of privilege or integrity level."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"PassMark Software","product":"PerformanceTest","defaultStatus":"affected","versions":[{"version":"0","lessThan":"11.1 build 1012","versionType":"custom","status":"affected"}]},{"vendor":"PassMark Software","product":"BurnInTest","defaultStatus":"affected","versions":[{"version":"0","lessThan":"11.1 build 1000","versionType":"custom","status":"affected"}]},{"vendor":"PassMark Software","product":"OSForensics","defaultStatus":"affected","versions":[{"version":"0","lessThan":"11.1 build 1016","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.5,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T18:54:15.097013Z","id":"CVE-2026-80112","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Primary","description":[{"lang":"en","value":"CWE-732"}]}],"references":[{"url":"https://dkom.dev/posts/directio64-disclosure/","source":"disclosure@vulncheck.com"},{"url":"https://github.com/floppywiggler/directio64-disclosure","source":"disclosure@vulncheck.com"},{"url":"https://www.osforensics.com/whats-new.html","source":"disclosure@vulncheck.com"},{"url":"https://www.passmark.com/products/burnintest/history.php","source":"disclosure@vulncheck.com"},{"url":"https://www.passmark.com/products/performancetest/history.php","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/passmark-performancetest-burnintest-and-osforensics-improper-access-control-via-directio64-sys","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-80113","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-04T19:17:27.997","lastModified":"2026-09-04T19:17:27.997","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation vulnerability in DirectIo64.sys that allows local users to clear arbitrary bits at any physical memory address due to missing validation of the physical address parameter in an exposed IOCTL handler. Attackers can obtain a device handle and supply an arbitrary 64-bit physical address with a bit index to invoke MmMapIoSpace and clear bits in kernel code pages or page table entries, enabling local privilege escalation or system compromise."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"PassMark Software","product":"PerformanceTest","defaultStatus":"affected","versions":[{"version":"0","lessThan":"11.1 build 1012","versionType":"custom","status":"affected"}]},{"vendor":"PassMark Software","product":"BurnInTest","defaultStatus":"affected","versions":[{"version":"0","lessThan":"11.1 build 1000","versionType":"custom","status":"affected"}]},{"vendor":"PassMark Software","product":"OSForensics","defaultStatus":"affected","versions":[{"version":"0","lessThan":"11.1 build 1016","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":6.9,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.2}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Primary","description":[{"lang":"en","value":"CWE-782"},{"lang":"en","value":"CWE-787"}]}],"references":[{"url":"https://dkom.dev/posts/directio64-disclosure/","source":"disclosure@vulncheck.com"},{"url":"https://github.com/floppywiggler/directio64-disclosure","source":"disclosure@vulncheck.com"},{"url":"https://www.osforensics.com/whats-new.html","source":"disclosure@vulncheck.com"},{"url":"https://www.passmark.com/products/burnintest/history.php","source":"disclosure@vulncheck.com"},{"url":"https://www.passmark.com/products/performancetest/history.php","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/passmark-performancetest-burnintest-and-osforensics-arbitrary-bit-clear-via-directio64-sys-ioctl","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-80114","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-04T19:17:28.140","lastModified":"2026-09-04T20:17:28.787","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a hard-coded credentials vulnerability in DirectIo64.sys that allows local attackers to perform arbitrary physical memory writes by extracting an 8-byte key embedded as a hardcoded literal in the distributed binary and computing valid MD5 authentication tags for arbitrary IOCTL write requests. Attackers can additionally bypass a secondary validation gate by using the driver's own bit-clear IOCTL to clear a single bit in the gating instruction's displacement byte, causing all subsequent write requests to skip MAC verification, size checks, and Vendor ID checks entirely."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"PassMark Software","product":"PerformanceTest","defaultStatus":"affected","versions":[{"version":"0","lessThan":"11.1 build 1012","versionType":"custom","status":"affected"}]},{"vendor":"PassMark Software","product":"BurnInTest","defaultStatus":"affected","versions":[{"version":"0","lessThan":"11.1 build 1000","versionType":"custom","status":"affected"}]},{"vendor":"PassMark Software","product":"OSForensics","defaultStatus":"affected","versions":[{"version":"0","lessThan":"11.1 build 1016","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.5,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T19:20:29.283225Z","id":"CVE-2026-80114","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-321"}]}],"references":[{"url":"https://dkom.dev/posts/directio64-disclosure/","source":"disclosure@vulncheck.com"},{"url":"https://github.com/floppywiggler/directio64-disclosure","source":"disclosure@vulncheck.com"},{"url":"https://www.osforensics.com/whats-new.html","source":"disclosure@vulncheck.com"},{"url":"https://www.passmark.com/products/burnintest/history.php","source":"disclosure@vulncheck.com"},{"url":"https://www.passmark.com/products/performancetest/history.php","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/passmark-performancetest-burnintest-and-osforensics-hard-coded-credentials-authentication-bypass-via-directio64-sys","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-80115","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-04T19:17:28.280","lastModified":"2026-09-04T19:17:28.280","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation and denial-of-service vulnerability in DirectIo64.sys that allows local attackers to read arbitrary Model-Specific Registers or write zero to any MSR through exposed IOCTLs with insufficient blocklist enforcement. Attackers can exploit the unrestricted write IOCTL to zero out the system call handler MSR, causing an immediate unrecoverable kernel crash on the next system call, or read security-sensitive MSRs used to locate kernel data structures."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"PassMark Software","product":"PerformanceTest","defaultStatus":"affected","versions":[{"version":"0","lessThan":"11.1 build 1012","versionType":"custom","status":"affected"}]},{"vendor":"PassMark Software","product":"BurnInTest","defaultStatus":"affected","versions":[{"version":"0","lessThan":"11.1 build 1000","versionType":"custom","status":"affected"}]},{"vendor":"PassMark Software","product":"OSForensics","defaultStatus":"affected","versions":[{"version":"0","lessThan":"11.1 build 1016","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":6.9,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":4.2}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Primary","description":[{"lang":"en","value":"CWE-782"}]}],"references":[{"url":"https://dkom.dev/posts/directio64-disclosure/","source":"disclosure@vulncheck.com"},{"url":"https://github.com/floppywiggler/directio64-disclosure","source":"disclosure@vulncheck.com"},{"url":"https://www.osforensics.com/whats-new.html","source":"disclosure@vulncheck.com"},{"url":"https://www.passmark.com/products/burnintest/history.php","source":"disclosure@vulncheck.com"},{"url":"https://www.passmark.com/products/performancetest/history.php","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/passmark-performancetest-burnintest-and-osforensics-kernel-crash-via-directio64-sys-msr-write-ioctl","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-80116","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-04T19:17:28.420","lastModified":"2026-09-04T19:17:28.420","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation vulnerability in DirectIo64.sys that allows local users to modify hardware configuration by exploiting exposed IOCTLs with no validation on device selection, register offset, or value. Attackers can obtain a device handle and issue arbitrary PCI configuration space read/write operations to enable Bus Master DMA on any PCI device, halt storage controller I/O by clearing command registers, or remap Base Address Registers to redirect DMA to an attacker-chosen physical address."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"PassMark Software","product":"PerformanceTest","defaultStatus":"affected","versions":[{"version":"0","lessThan":"11.1 build 1012","versionType":"custom","status":"affected"}]},{"vendor":"PassMark Software","product":"BurnInTest","defaultStatus":"affected","versions":[{"version":"0","lessThan":"11.1 build 1000","versionType":"custom","status":"affected"}]},{"vendor":"PassMark Software","product":"OSForensics","defaultStatus":"affected","versions":[{"version":"0","lessThan":"11.1 build 1016","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.5,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Primary","description":[{"lang":"en","value":"CWE-782"}]}],"references":[{"url":"https://dkom.dev/posts/directio64-disclosure/","source":"disclosure@vulncheck.com"},{"url":"https://github.com/floppywiggler/directio64-disclosure","source":"disclosure@vulncheck.com"},{"url":"https://www.osforensics.com/whats-new.html","source":"disclosure@vulncheck.com"},{"url":"https://www.passmark.com/products/burnintest/history.php","source":"disclosure@vulncheck.com"},{"url":"https://www.passmark.com/products/performancetest/history.php","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/passmark-performancetest-burnintest-and-osforensics-privilege-escalation-via-directio64-sys-ioctl","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-80117","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-04T19:17:28.560","lastModified":"2026-09-04T19:17:28.560","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation vulnerability in DirectIo64.sys that allows local users to issue arbitrary IN and OUT instructions to any x86 I/O port due to missing allowlist or port validation on exposed IOCTLs. Attackers can obtain a device handle and write to sensitive ports including the PS/2 controller port, CPU reset ports, CMOS configuration ports, and interrupt controller ports to cause an immediate system reset or other hardware-level manipulation from a standard user account."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"PassMark Software","product":"PerformanceTest","defaultStatus":"affected","versions":[{"version":"0","lessThan":"11.1 build 1012","versionType":"custom","status":"affected"}]},{"vendor":"PassMark Software","product":"BurnInTest","defaultStatus":"affected","versions":[{"version":"0","lessThan":"11.1 build 1000","versionType":"custom","status":"affected"}]},{"vendor":"PassMark Software","product":"OSForensics","defaultStatus":"affected","versions":[{"version":"0","lessThan":"11.1 build 1016","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":6.9,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T18:53:15.285367Z","id":"CVE-2026-80117","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Primary","description":[{"lang":"en","value":"CWE-782"}]}],"references":[{"url":"https://dkom.dev/posts/directio64-disclosure/","source":"disclosure@vulncheck.com"},{"url":"https://github.com/floppywiggler/directio64-disclosure","source":"disclosure@vulncheck.com"},{"url":"https://www.osforensics.com/whats-new.html","source":"disclosure@vulncheck.com"},{"url":"https://www.passmark.com/products/burnintest/history.php","source":"disclosure@vulncheck.com"},{"url":"https://www.passmark.com/products/performancetest/history.php","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/passmark-performancetest-burnintest-and-osforensics-arbitrary-i-o-port-access-via-directio64-sys","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-80118","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-04T19:17:28.710","lastModified":"2026-09-04T19:17:28.710","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an unauthenticated physical memory disclosure in DirectIo64.sys, reachable by unprivileged local users through a single IOCTL with no caller-identity check. The handler writes a crash-dump-format (PAGEDU64) image of all physical memory to a caller-supplied file path in the SYSTEM context, allowing a standard user to create files in locations they cannot otherwise write and to recover memory belonging to processes of other users. The image is preceded by a header that exposes the kernel loaded-module list, active-process list and PFN database pointers, defeating KASLR. The same handler also dereferences the return value of an internal kernel-structure locator without a NULL check; that locator returns NULL on three distinct failure paths, and a kernel crash results on builds where any of those paths is taken."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"PassMark Software","product":"PerformanceTest","defaultStatus":"affected","versions":[{"version":"0","lessThan":"11.1 build 1012","versionType":"custom","status":"affected"}]},{"vendor":"PassMark Software","product":"BurnInTest","defaultStatus":"affected","versions":[{"version":"0","lessThan":"11.1 build 1000","versionType":"custom","status":"affected"}]},{"vendor":"PassMark Software","product":"OSForensics","defaultStatus":"affected","versions":[{"version":"0","lessThan":"11.1 build 1016","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.4,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.8,"impactScore":5.2}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Primary","description":[{"lang":"en","value":"CWE-73"},{"lang":"en","value":"CWE-476"},{"lang":"en","value":"CWE-497"}]}],"references":[{"url":"https://dkom.dev/posts/directio64-disclosure/","source":"disclosure@vulncheck.com"},{"url":"https://github.com/floppywiggler/directio64-disclosure","source":"disclosure@vulncheck.com"},{"url":"https://www.osforensics.com/whats-new.html","source":"disclosure@vulncheck.com"},{"url":"https://www.passmark.com/products/burnintest/history.php","source":"disclosure@vulncheck.com"},{"url":"https://www.passmark.com/products/performancetest/history.php","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/passmark-performancetest-burnintest-and-osforensics-kernel-null-pointer-dereference-via-directio64-sys-ioctl","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-80119","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-04T19:17:28.857","lastModified":"2026-09-04T20:17:28.917","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an information disclosure vulnerability in DirectIo64.sys that allows unauthenticated local attackers to dump complete physical memory contents by supplying a caller-controlled file path to an exposed IOCTL. Attackers can issue a single IOCTL call to trigger the driver to iterate all physical memory ranges via MmGetPhysicalMemoryRanges and map each page through ZwMapViewOfSection on the PhysicalMemory section object, writing a full RAM image to an attacker-specified path in the SYSTEM context, bypassing user-mode ACLs and exposing LSASS working set, process memory, and cryptographic material from all running processes."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"PassMark Software","product":"PerformanceTest","defaultStatus":"affected","versions":[{"version":"0","lessThan":"11.1 build 1012","versionType":"custom","status":"affected"}]},{"vendor":"PassMark Software","product":"BurnInTest","defaultStatus":"affected","versions":[{"version":"0","lessThan":"11.1 build 1000","versionType":"custom","status":"affected"}]},{"vendor":"PassMark Software","product":"OSForensics","defaultStatus":"affected","versions":[{"version":"0","lessThan":"11.1 build 1016","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.5,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T19:19:47.375349Z","id":"CVE-2026-80119","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Secondary","description":[{"lang":"en","value":"CWE-73"},{"lang":"en","value":"CWE-497"}]}],"references":[{"url":"https://dkom.dev/posts/directio64-disclosure/","source":"disclosure@vulncheck.com"},{"url":"https://github.com/floppywiggler/directio64-disclosure","source":"disclosure@vulncheck.com"},{"url":"https://www.osforensics.com/whats-new.html","source":"disclosure@vulncheck.com"},{"url":"https://www.passmark.com/products/burnintest/history.php","source":"disclosure@vulncheck.com"},{"url":"https://www.passmark.com/products/performancetest/history.php","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/passmark-performancetest-burnintest-and-osforensics-physical-memory-disclosure-via-directio64-sys-ioctl","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-81939","sourceIdentifier":"PSIRT@sonicwall.com","published":"2026-09-04T19:17:29.237","lastModified":"2026-09-04T20:17:29.647","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-Prem file upload and archive processing functionality allows an attacker to extract files outside the intended destination directory using a specially crafted archive."}],"affected":[{"source":"PSIRT@sonicwall.com","affectedData":[{"vendor":"SonicWall","product":"Network Security Manager (NSM)","defaultStatus":"unknown","platforms":["Linux","On-Prem"],"versions":[{"version":"4.3.0 and earlier versions","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H","baseScore":9.1,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.3,"impactScore":6.0}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T19:47:14.778353Z","id":"CVE-2026-81939","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"PSIRT@sonicwall.com","type":"Secondary","description":[{"lang":"en","value":"CWE-22"}]}],"references":[{"url":"https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0015","source":"PSIRT@sonicwall.com"}]}},{"cve":{"id":"CVE-2026-85637","sourceIdentifier":"cna@vuldb.com","published":"2026-09-04T19:17:33.263","lastModified":"2026-09-04T20:17:32.720","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"A security flaw has been discovered in jofpin trape 1.0.0/2.0. Affected by this issue is the function join_room of the file core/sockets.py of the component Admin Endpoint. The manipulation results in missing authentication. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet."}],"affected":[{"source":"cna@vuldb.com","affectedData":[{"vendor":"jofpin","product":"trape","cpes":["cpe:2.3:a:jofpin:trape:*:*:*:*:*:*:*:*"],"modules":["Admin Endpoint"],"versions":[{"version":"1.0.0","status":"affected"},{"version":"2.0","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"PROOF_OF_CONCEPT","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T19:21:07.635492Z","id":"CVE-2026-85637","options":[{"exploitation":"poc"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cna@vuldb.com","type":"Secondary","description":[{"lang":"en","value":"CWE-287"},{"lang":"en","value":"CWE-306"}]}],"references":[{"url":"https://github.com/jofpin/trape/","source":"cna@vuldb.com"},{"url":"https://github.com/jofpin/trape/issues/406","source":"cna@vuldb.com"},{"url":"https://vuldb.com/cve/CVE-2026-85637","source":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/895138","source":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/398785","source":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/398785/cti","source":"cna@vuldb.com"}]}},{"cve":{"id":"CVE-2026-85638","sourceIdentifier":"cna@vuldb.com","published":"2026-09-04T19:17:33.430","lastModified":"2026-09-04T19:17:33.430","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"A weakness has been identified in jofpin trape 2.0. This affects an unknown part of the file core/user.py. This manipulation of the argument vId/id causes authorization bypass. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet."}],"affected":[{"source":"cna@vuldb.com","affectedData":[{"vendor":"jofpin","product":"trape","cpes":["cpe:2.3:a:jofpin:trape:*:*:*:*:*:*:*:*"],"versions":[{"version":"2.0","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"LOW","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"PROOF_OF_CONCEPT","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"cna@vuldb.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","baseScore":7.3,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":3.4}],"cvssMetricV2":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"cna@vuldb.com","type":"Primary","description":[{"lang":"en","value":"CWE-285"},{"lang":"en","value":"CWE-639"}]}],"references":[{"url":"https://github.com/jofpin/trape/","source":"cna@vuldb.com"},{"url":"https://github.com/jofpin/trape/issues/407","source":"cna@vuldb.com"},{"url":"https://vuldb.com/cve/CVE-2026-85638","source":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/895139","source":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/398786","source":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/398786/cti","source":"cna@vuldb.com"}]}},{"cve":{"id":"CVE-2026-85639","sourceIdentifier":"cna@vuldb.com","published":"2026-09-04T19:17:33.600","lastModified":"2026-09-04T19:17:33.600","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"A security vulnerability has been detected in jofpin trape 2.0. This vulnerability affects unknown code of the file core/user.py of the component Telemetry Endpoint. Such manipulation of the argument vId leads to race condition. The attack can be executed remotely. Attacks of this nature are highly complex. It is stated that the exploitability is difficult. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet."}],"affected":[{"source":"cna@vuldb.com","affectedData":[{"vendor":"jofpin","product":"trape","cpes":["cpe:2.3:a:jofpin:trape:*:*:*:*:*:*:*:*"],"modules":["Telemetry Endpoint"],"versions":[{"version":"2.0","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":2.9,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"LOW","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"PROOF_OF_CONCEPT","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"cna@vuldb.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","baseScore":5.6,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":2.2,"impactScore":3.4}],"cvssMetricV2":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:H/Au:N/C:P/I:P/A:P","baseScore":5.1,"accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":4.9,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"cna@vuldb.com","type":"Primary","description":[{"lang":"en","value":"CWE-362"}]}],"references":[{"url":"https://github.com/jofpin/trape/","source":"cna@vuldb.com"},{"url":"https://github.com/jofpin/trape/issues/408","source":"cna@vuldb.com"},{"url":"https://vuldb.com/cve/CVE-2026-85639","source":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/895140","source":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/398787","source":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/398787/cti","source":"cna@vuldb.com"}]}},{"cve":{"id":"CVE-2026-85781","sourceIdentifier":"ff89ba41-3aa1-4d27-914a-91399e9639e5","published":"2026-09-04T19:17:34.157","lastModified":"2026-09-04T20:17:33.030","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Unverified ownership of a storage access point in the volume deletion component of the Amazon EFS CSI Driver before v3.4.1 might allow an authenticated Kubernetes user with PersistentVolume creation privileges to cause recursive deletion of directories on an EFS filesystem they are not authorized to access, via a crafted PersistentVolume volumeHandle that pairs an access point from one filesystem with a different target filesystem.\n\n\n\nTo remediate this issue, users should upgrade to version v3.4.1."}],"affected":[{"source":"ff89ba41-3aa1-4d27-914a-91399e9639e5","affectedData":[{"vendor":"aws","product":"aws-efs-csi-driver","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"3.4.0","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"ff89ba41-3aa1-4d27-914a-91399e9639e5","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":5.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"HIGH","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"HIGH","subAvailabilityImpact":"HIGH","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"ff89ba41-3aa1-4d27-914a-91399e9639e5","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.3,"impactScore":5.8}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T19:27:47.756572Z","id":"CVE-2026-85781","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"ff89ba41-3aa1-4d27-914a-91399e9639e5","type":"Secondary","description":[{"lang":"en","value":"CWE-283"}]}],"references":[{"url":"https://aws.amazon.com/security/security-bulletins/2026-099-aws/","source":"ff89ba41-3aa1-4d27-914a-91399e9639e5"},{"url":"https://github.com/kubernetes-sigs/aws-efs-csi-driver/releases/tag/v3.4.1","source":"ff89ba41-3aa1-4d27-914a-91399e9639e5"}]}},{"cve":{"id":"CVE-2026-53602","sourceIdentifier":"security-advisories@github.com","published":"2026-09-04T20:17:23.130","lastModified":"2026-09-04T20:17:23.130","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.3.7, two related authorization gaps let a host that should no longer be trusted obtain a fresh, valid Nebula certificate, because nebula-mgmt does not re-evaluate revocation/authorization state at certificate issuance time — only at poll time. Firstly, the blocklist is not enforced at sign / re-enroll time. internal/api/enroll.go:128 calls caMgr.Sign(...) without consulting the blocklist. The blocklist is only checked in the poll path (internal/api/updates.go:57, fingerprintInBlocklist). The blocklist is keyed by certificate fingerprint (internal/store/sqlite.go), so a re-enrollment produces a new fingerprint that is not in the blocklist. Secondly, renewal does not re-validate operator / CA status. Auto-renewal at poll time (internal/api/updates.go:285-319, signHostCert) reads host.Name, host.Groups, host.NebulaIPs from the DB and re-signs without checking whether the owning operator is still active or the CA still valid. DisableOperator (internal/store/sqlite_operators.go) revokes sessions and API keys but does not retire the operator's CAs, and pki/signer.go checks only CA cert time-expiry, not operator/CA status. This issue has been patched in version 0.3.7."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"forgekeep","product":"nebula-mesh","versions":[{"version":"< 0.3.7","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":6.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T19:49:54.943637Z","id":"CVE-2026-53602","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Primary","description":[{"lang":"en","value":"CWE-285"},{"lang":"en","value":"CWE-862"}]}],"references":[{"url":"https://github.com/forgekeep/nebula-mesh/issues/178","source":"security-advisories@github.com"},{"url":"https://github.com/forgekeep/nebula-mesh/releases/tag/v0.3.7","source":"security-advisories@github.com"},{"url":"https://github.com/forgekeep/nebula-mesh/security/advisories/GHSA-339v-266x-79xr","source":"security-advisories@github.com"}]}},{"cve":{"id":"CVE-2026-53603","sourceIdentifier":"security-advisories@github.com","published":"2026-09-04T20:17:23.287","lastModified":"2026-09-04T20:17:23.287","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.3.8, Operator session tokens are stored in plaintext in the operator_sessions table (the token column is the PRIMARY KEY). The session token is a 32-byte random hex value sent directly in a cookie and valid for 24 hours. Anyone who can read the database (backup, snapshot, file copy, or SQL-level disclosure) obtains every active session token and can hijack operator sessions directly, with no further authentication. This issue has been patched in version 0.3.8."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"forgekeep","product":"nebula-mesh","versions":[{"version":"< 0.3.8","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Primary","description":[{"lang":"en","value":"CWE-312"},{"lang":"en","value":"CWE-522"}]}],"references":[{"url":"https://github.com/forgekeep/nebula-mesh/commit/7cb01bab281ded557f8b6c81dab5f48d4c10182e","source":"security-advisories@github.com"},{"url":"https://github.com/forgekeep/nebula-mesh/releases/tag/v0.3.8","source":"security-advisories@github.com"},{"url":"https://github.com/forgekeep/nebula-mesh/security/advisories/GHSA-q4vm-pq3q-8wgq","source":"security-advisories@github.com"}]}},{"cve":{"id":"CVE-2026-53604","sourceIdentifier":"security-advisories@github.com","published":"2026-09-04T20:17:23.437","lastModified":"2026-09-04T20:17:23.437","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.3.8, the web handler renderMobileBundle passes the real *pki.CAResolver directly into mobilebundle.Build. Inside Build, resolver.LoadByID decrypts the CA's ed25519 private key into a *pki.CAManager, but Build never calls CAManager.Wipe() on any return path. As a result, when a mobile-bundle request goes through the web UI and Build returns — especially on error (missing network, invalid prefix, DB error, signing failure) — the plaintext CA private key remains on the Go heap, unwiped, until garbage collection. An attacker able to read process memory (core dump, swap, memory-scraping) can recover the CA signing key, which would allow minting arbitrary host certificates for the mesh. The API handler already does this correctly: it loads the CAManager, defer caMgr.Wipe(), and wraps it in caManagerResolver. Only the web path is affected. This issue has been patched in version 0.3.8."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"forgekeep","product":"nebula-mesh","versions":[{"version":"< 0.3.8","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Primary","description":[{"lang":"en","value":"CWE-212"},{"lang":"en","value":"CWE-316"}]}],"references":[{"url":"https://github.com/forgekeep/nebula-mesh/commit/1f1ab9aa8472239763d967e3d50a3cd53a1a79b9","source":"security-advisories@github.com"},{"url":"https://github.com/forgekeep/nebula-mesh/releases/tag/v0.3.8","source":"security-advisories@github.com"},{"url":"https://github.com/forgekeep/nebula-mesh/security/advisories/GHSA-2p2f-px33-4vv5","source":"security-advisories@github.com"}]}},{"cve":{"id":"CVE-2026-53932","sourceIdentifier":"security-advisories@github.com","published":"2026-09-04T20:17:23.570","lastModified":"2026-09-04T20:17:23.570","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"laravel-backup-restore restores database backups made with spatie/laravel-backup. Prior to version 1.9.4, a crafted backup archive can trigger OS command injection during database restore. This issue has been patched in version 1.9.4."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"stefanzweifel","product":"laravel-backup-restore","versions":[{"version":"< 1.9.4","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","baseScore":8.0,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.1,"impactScore":5.9}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Primary","description":[{"lang":"en","value":"CWE-77"},{"lang":"en","value":"CWE-78"}]}],"references":[{"url":"https://github.com/stefanzweifel/laravel-backup-restore/commit/a73f6c3dfd57c5efbc46cce4e93ed033bedce8b0","source":"security-advisories@github.com"},{"url":"https://github.com/stefanzweifel/laravel-backup-restore/pull/116","source":"security-advisories@github.com"},{"url":"https://github.com/stefanzweifel/laravel-backup-restore/releases/tag/v1.9.4","source":"security-advisories@github.com"},{"url":"https://github.com/stefanzweifel/laravel-backup-restore/security/advisories/GHSA-w9mx-xmg4-gc4r","source":"security-advisories@github.com"}]}},{"cve":{"id":"CVE-2026-55512","sourceIdentifier":"security-advisories@github.com","published":"2026-09-04T20:17:23.717","lastModified":"2026-09-04T20:17:23.717","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. From version 0.2.0 to before version 0.5.0, when OIDC is enabled, GET /ui/oidc/login is reachable without authentication and is registered outside the Web UI rate-limited auth routes. Every request creates a fresh random OIDC state value and stores it in an in-memory map for 10m. Expired states are swept lazily, but there is no rate limit or maximum live-state cap on the allocation path. An unauthenticated remote client can therefore grow OIDC.states for the full state TTL, bounded by request throughput rather than by configured auth rate limits. This issue has been patched in version 0.5.0."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"forgekeep","product":"nebula-mesh","versions":[{"version":">= 0.2.0, < 0.5.0","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":1.4}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Primary","description":[{"lang":"en","value":"CWE-400"}]}],"references":[{"url":"https://github.com/forgekeep/nebula-mesh/commit/bc387086cc0e4b9c1654468b7391af19cacfe367","source":"security-advisories@github.com"},{"url":"https://github.com/forgekeep/nebula-mesh/releases/tag/v0.5.0","source":"security-advisories@github.com"},{"url":"https://github.com/forgekeep/nebula-mesh/security/advisories/GHSA-m3cx-mwpg-32jg","source":"security-advisories@github.com"}]}},{"cve":{"id":"CVE-2026-55513","sourceIdentifier":"security-advisories@github.com","published":"2026-09-04T20:17:23.857","lastModified":"2026-09-04T20:17:23.857","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. From version 0.3.0 to before version 0.5.0, the nebula-mgmt Web UI host-creation path ignores both the server-wide enrollment_token_ttl security setting and per-network network_config.enrollment_token_ttl overrides. API host creation and token-regeneration paths use the configured TTL resolver, but POST /ui/hosts hardcodes now.Add(24 * time.Hour) for newly minted agent enrollment tokens. In deployments that intentionally reduce enrollment-token lifetime, any authenticated operator who can create a host through the Web UI can still mint a bearer enrollment token valid for about 24 hours. This issue has been patched in version 0.5.0."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"forgekeep","product":"nebula-mesh","versions":[{"version":">= 0.3.0, < 0.5.0","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.5}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Primary","description":[{"lang":"en","value":"CWE-613"}]}],"references":[{"url":"https://github.com/forgekeep/nebula-mesh/commit/514006029e09f1991122b86a80e7b25970bcfa98","source":"security-advisories@github.com"},{"url":"https://github.com/forgekeep/nebula-mesh/releases/tag/v0.5.0","source":"security-advisories@github.com"},{"url":"https://github.com/forgekeep/nebula-mesh/security/advisories/GHSA-g4x6-jcvr-9m3g","source":"security-advisories@github.com"}]}},{"cve":{"id":"CVE-2026-61699","sourceIdentifier":"security-advisories@github.com","published":"2026-09-04T20:17:24.347","lastModified":"2026-09-04T20:17:24.347","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.7.1, revocation is the only in-band mechanism that isolates a compromised/offboarded host from a Nebula mesh. Because the blocklist never reaches any peer's config.yml, a Blocked host retains full overlay reachability to every peer under its CA (and internal services on the mesh) for up to 30d (agent) / 365d (mobile). An attacker who exfiltrates host.key+host.crt can run stock slackhq/nebula directly, ignore the agent's 403/410 poll responses, and stay connected after the operator revokes the host. Operator-visible state (UI shows blocked, audit log records it) is misleading. This issue has been patched in version 0.7.1."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"forgekeep","product":"nebula-mesh","versions":[{"version":"< 0.7.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":5.2}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Primary","description":[{"lang":"en","value":"CWE-299"},{"lang":"en","value":"CWE-672"}]}],"references":[{"url":"https://github.com/forgekeep/nebula-mesh/commit/0426e2f224a9b1e2029029bf923c93ed39d21cdb","source":"security-advisories@github.com"},{"url":"https://github.com/forgekeep/nebula-mesh/releases/tag/v0.7.1","source":"security-advisories@github.com"},{"url":"https://github.com/forgekeep/nebula-mesh/security/advisories/GHSA-cm26-5974-52h8","source":"security-advisories@github.com"}]}},{"cve":{"id":"CVE-2026-63464","sourceIdentifier":"security-advisories@github.com","published":"2026-09-04T20:17:24.730","lastModified":"2026-09-04T20:17:24.730","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. From version 0.6.0 to before version 0.7.2, non-admin operators (role user) can set allow_private: true on their own managed webhook subscription (POST/PATCH /api/v1/webhook-subscriptions). No admin check exists on this field. At delivery time, allow_private switches the dispatcher to an unguarded HTTP client, bypassing the private/loopback/link-local SSRF guard — letting a low-privilege operator make the server request internal addresses. This issue has been patched in version 0.7.2."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"forgekeep","product":"nebula-mesh","versions":[{"version":">= 0.6.0, < 0.7.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","baseScore":7.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":4.0}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Primary","description":[{"lang":"en","value":"CWE-862"},{"lang":"en","value":"CWE-918"}]}],"references":[{"url":"https://github.com/forgekeep/nebula-mesh/commit/f3c54530e388dd21763e548923426e60a8e93ff0","source":"security-advisories@github.com"},{"url":"https://github.com/forgekeep/nebula-mesh/releases/tag/v0.7.2","source":"security-advisories@github.com"},{"url":"https://github.com/forgekeep/nebula-mesh/security/advisories/GHSA-7rx3-5wx3-5v76","source":"security-advisories@github.com"}]}},{"cve":{"id":"CVE-2026-71622","sourceIdentifier":"cve@mitre.org","published":"2026-09-04T20:17:26.053","lastModified":"2026-09-04T20:17:26.053","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"SQL injection vulnerability in Zhao-github APiAdmin v.5.0.1 allows a remote attacker to obtain sensitive information via the User.php component"}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://colorful-quill-4fe.notion.site/CVE-2026-71622-ApiAdmin-v5-0-1-sql-injection-37fe5670300c809b86e1ec773b6fda4d","source":"cve@mitre.org"}]}},{"cve":{"id":"CVE-2026-71624","sourceIdentifier":"cve@mitre.org","published":"2026-09-04T20:17:26.183","lastModified":"2026-09-04T20:17:26.183","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"An issue in esoTalk v.1.0.0g4 allows a remote attacker to execute arbitrary code via the core/models/ETMemberModel.class.php, core/controllers/ETMemberController.class.php, and core/lib/ET.class.php components"}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://colorful-quill-4fe.notion.site/CVE-2026-71624-esoTalk-Configuration-Comment-Injection-Leading-to-PHP-Code-Execution-380e5670300c80b98d36f207d7aaac6e?source=copy_link","source":"cve@mitre.org"}]}},{"cve":{"id":"CVE-2026-71625","sourceIdentifier":"cve@mitre.org","published":"2026-09-04T20:17:26.293","lastModified":"2026-09-04T20:17:26.293","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"An issue in slimkit plus ThinkSNS+ v.2.4 allows a remote attacker to escalate privileges via the ResetPasswordController.php component"}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://colorful-quill-4fe.notion.site/CVE-2026-71625-ThinkSNS-Plus-Account-Takeover-via-Expired-Verification-Code-in-Password-Reset-380e5670300c808bbf82ee8cf8ed25e3?source=copy_link","source":"cve@mitre.org"},{"url":"https://github.com/slimkit/plus","source":"cve@mitre.org"}]}},{"cve":{"id":"CVE-2026-71626","sourceIdentifier":"cve@mitre.org","published":"2026-09-04T20:17:26.413","lastModified":"2026-09-04T20:17:26.413","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"An issue in Invoice Ninja v5.13.24 allows a remote attacker to obtain sensitive information via the StoreWebhookRequest.php, UpdateWebhookRequest.php, and WebhookSingle.php components"}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://colorful-quill-4fe.notion.site/CVE-2026-71626-API-Webhook-SSRF-via-Internal-and-Loopback-Targets-382e5670300c80b6b4dac4c8216b5ff8?source=copy_link","source":"cve@mitre.org"}]}},{"cve":{"id":"CVE-2026-79389","sourceIdentifier":"cve@mitre.org","published":"2026-09-04T20:17:28.133","lastModified":"2026-09-04T20:17:28.133","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Trueview T18161 S 6.0.23.4 contains an improper verification in MQTT command processing. An attacker with network access can replay or modify captured MQTT messages, including security-related nonce, timestamp, and signature fields, and the device accepts the modified messages and executes the associated commands."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://github.com/EmbdCDACHyd/CVE/tree/main/CVE-2026-79389","source":"cve@mitre.org"}]}},{"cve":{"id":"CVE-2026-79390","sourceIdentifier":"cve@mitre.org","published":"2026-09-04T20:17:28.257","lastModified":"2026-09-04T20:17:28.257","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Trueview TI8161 6.0.23.4 is vulnerable to information disclosure due to the transmission of MQTT communications in plaintext over TCP port 1883. An unauthenticated attacker with access to the same network segment can intercept MQTT traffic and obtain sensitive device information and operational data, including device identifiers, message metadata, and control-related information."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://github.com/EmbdCDACHyd/CVE/blob/main/CVE-2026-79390/README.md","source":"cve@mitre.org"}]}},{"cve":{"id":"CVE-2026-79391","sourceIdentifier":"cve@mitre.org","published":"2026-09-04T20:17:28.363","lastModified":"2026-09-04T20:17:28.363","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"No authentication exists in the MQTT service of Trueview 6.0.23.4. The MQTT broker accepts client connections on TCP port 1883 without requiring authentication, allowing a remote attacker with network access to establish an MQTT session and perform unauthorized publish or subscribe operations."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://github.com/EmbdCDACHyd/CVE/blob/main/CVE-2026-79391/README.md","source":"cve@mitre.org"}]}},{"cve":{"id":"CVE-2026-85643","sourceIdentifier":"cna@vuldb.com","published":"2026-09-04T20:17:32.853","lastModified":"2026-09-04T20:17:32.853","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"A flaw has been found in code-projects Online Shopping System 1.0. Impacted is the function mysqli_query of the file admin/adduser.php. Executing a manipulation of the argument mobile can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used."}],"affected":[{"source":"cna@vuldb.com","affectedData":[{"vendor":"code-projects","product":"Online Shopping System","cpes":["cpe:2.3:a:code-projects:online_shopping_system:*:*:*:*:*:*:*:*"],"versions":[{"version":"1.0","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":2.0,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"HIGH","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"LOW","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"PROOF_OF_CONCEPT","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"cna@vuldb.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L","baseScore":4.7,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":1.2,"impactScore":3.4}],"cvssMetricV2":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:M/C:P/I:P/A:P","baseScore":5.8,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"MULTIPLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":6.4,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"cna@vuldb.com","type":"Primary","description":[{"lang":"en","value":"CWE-74"},{"lang":"en","value":"CWE-89"}]}],"references":[{"url":"https://code-projects.org/","source":"cna@vuldb.com"},{"url":"https://github.com/zzzxc643/CVE1/blob/main/online-shopping-system/vul8.md","source":"cna@vuldb.com"},{"url":"https://vuldb.com/cve/CVE-2026-85643","source":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/895253","source":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/398789","source":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/398789/cti","source":"cna@vuldb.com"}]}},{"cve":{"id":"CVE-2026-85786","sourceIdentifier":"ff89ba41-3aa1-4d27-914a-91399e9639e5","published":"2026-09-04T20:17:33.153","lastModified":"2026-09-04T20:17:33.153","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Improper handling of highly compressed data in Amazon ion-java before 1.12.1 might allow remote attackers to cause a denial of service via a crafted compressed Ion document that expands to an arbitrarily large size upon decompression due to insufficient coverage of the GZIP auto-decompression opt-out introduced for CVE-2026-75936.\n\n\n\nTo remediate this issue, users should upgrade to version 1.12.1."}],"affected":[{"source":"ff89ba41-3aa1-4d27-914a-91399e9639e5","affectedData":[{"vendor":"Amazon","product":"ion-java","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"1.12.1","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"ff89ba41-3aa1-4d27-914a-91399e9639e5","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"ff89ba41-3aa1-4d27-914a-91399e9639e5","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-04T19:27:20.392003Z","id":"CVE-2026-85786","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"ff89ba41-3aa1-4d27-914a-91399e9639e5","type":"Secondary","description":[{"lang":"en","value":"CWE-409"}]}],"references":[{"url":"https://aws.amazon.com/security/security-bulletins/2026-100-aws/","source":"ff89ba41-3aa1-4d27-914a-91399e9639e5"},{"url":"https://github.com/amazon-ion/ion-java/releases/tag/v1.12.1","source":"ff89ba41-3aa1-4d27-914a-91399e9639e5"}]}},{"cve":{"id":"CVE-2022-26961","sourceIdentifier":"cve@mitre.org","published":"2026-09-04T21:17:19.887","lastModified":"2026-09-04T21:17:19.887","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Italtel NetMatch-S 5.0.0-20200703 allows Multiple Stored XSS under NP_IBCF-NATUP-01/NMSCI-WebGui/backup_restore.jsp and NP_IBCF-MIBER-03/NMSCI-WebGui/storage.jsp via the name parameter. A malicious user leveraging this vulnerability could inject arbitrary JavaScript. The malicious payload will then be triggered every time an authenticated user browses the page containing it."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://www.gruppotim.it/it/footer/red-team/2022/CVE-2022-26961-Italtel-NETMATCH-S-CLOUD-INSIDE-VNF.html","source":"cve@mitre.org"}]}},{"cve":{"id":"CVE-2025-67066","sourceIdentifier":"cve@mitre.org","published":"2026-09-04T21:17:24.143","lastModified":"2026-09-04T21:17:24.143","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"SQL Injection vulnerability in oasys sysoa version 1.0 allows a remote attacker to execute arbitrary code via the outtype parameter in the /outaddresspaging path"}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://github.com/lanpan001/OASYS-SQL-injection/blob/main/vulnerability/OASYS%20SQL%20Injection%20Vulnerability.md","source":"cve@mitre.org"}]}},{"cve":{"id":"CVE-2026-50894","sourceIdentifier":"cve@mitre.org","published":"2026-09-04T21:17:25.177","lastModified":"2026-09-04T21:17:25.177","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"easyadmin v2.0.2.2 is vulnerable to Unrestricted Upload of File with Dangerous Type in the background management interface which allows authenticated remote attackers to execute arbitrary code and gain server privileges via a crafted file upload."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://github.com/lilil3333/cve/issues/1","source":"cve@mitre.org"},{"url":"https://github.com/zhongshaofa/easyadmin/","source":"cve@mitre.org"}]}},{"cve":{"id":"CVE-2026-53769","sourceIdentifier":"security-advisories@github.com","published":"2026-09-04T21:17:25.300","lastModified":"2026-09-04T21:17:25.300","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Avo is a framework to create admin panels for Ruby on Rails apps. From version 2.28.0 to before version 3.32.0, Avo's direct attachment upload endpoint lacks server-side upload authorization and bypasses the documented field-level upload policy methods such as upload_{FIELD_ID}?. An authenticated Avo user who can reach the Avo attachment upload endpoint can replace or add attachment content, including binary content, filename, and content-type metadata, on a resolved record even when both update? and upload_<field>? policies deny the operation. This primarily affects multi-role Avo Pro/Advanced-style deployments where non-administrator or restricted operator users can reach Avo and per-record or per-field operations are expected to be enforced by policies. This issue has been patched in version 3.32.0."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"avo-hq","product":"avo","versions":[{"version":">= 2.28.0, < 3.32.0","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Primary","description":[{"lang":"en","value":"CWE-862"},{"lang":"en","value":"CWE-863"}]}],"references":[{"url":"https://github.com/avo-hq/avo/commit/de12070dbac0cb6a7e2bea357f9697f99e92554c","source":"security-advisories@github.com"},{"url":"https://github.com/avo-hq/avo/pull/4520","source":"security-advisories@github.com"},{"url":"https://github.com/avo-hq/avo/releases/tag/v3.32.0","source":"security-advisories@github.com"},{"url":"https://github.com/avo-hq/avo/security/advisories/GHSA-pqpw-cvm4-8mv9","source":"security-advisories@github.com"}]}},{"cve":{"id":"CVE-2026-75438","sourceIdentifier":"cve@mitre.org","published":"2026-09-04T21:17:25.453","lastModified":"2026-09-04T21:17:25.453","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Buffer Overflow vulnerability in Open5GS v2.7.7 allows a remote attacker to cause a denial of service via the ogs_sbi_time_parse() function"}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://gist.github.com/hackeryounow/c299d593b89fd6487cab4182c8aecabf","source":"cve@mitre.org"},{"url":"https://github.com/hackeryounow/5GCVulDB/blob/main/smf_crash_uelocationtimestamp.sh","source":"cve@mitre.org"},{"url":"https://github.com/hackeryounow/5GCVulDB/tree/main/CVE-2026-75438","source":"cve@mitre.org"},{"url":"https://github.com/open5gs/open5gs/commit/7227b2f5b254160286798e058c189224360d99fc","source":"cve@mitre.org"},{"url":"https://github.com/open5gs/open5gs/issues/4612","source":"cve@mitre.org"}]}},{"cve":{"id":"CVE-2026-75439","sourceIdentifier":"cve@mitre.org","published":"2026-09-04T21:17:25.583","lastModified":"2026-09-04T21:17:25.583","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"An issue in Free5GC v.4.2.2 allows a remote attacker to cause a denial of service via the UPF component"}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://gist.github.com/hackeryounow/0f434c03008462e6eec3b43ed3cd12d8","source":"cve@mitre.org"},{"url":"https://github.com/free5gc/free5gc/issues/1059","source":"cve@mitre.org"},{"url":"https://github.com/free5gc/free5gc/issues/1059.https://github.com/free5gc/go-upf/pull/97","source":"cve@mitre.org"},{"url":"https://github.com/free5gc/go-upf/pull/97","source":"cve@mitre.org"},{"url":"https://github.com/hackeryounow/5GCVulDB/tree/main/CVE-2026-75439","source":"cve@mitre.org"}]}},{"cve":{"id":"CVE-2026-77847","sourceIdentifier":"ics-cert@hq.dhs.gov","published":"2026-09-04T21:17:25.710","lastModified":"2026-09-04T21:17:25.710","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a use of hard-coded credential vulnerability. This could allow an attacker to intercept sensitive information or credentials."}],"affected":[{"source":"ics-cert@hq.dhs.gov","affectedData":[{"vendor":"Tycon Systems","product":"TPDIN-Monitor-WEB3","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"2.2.9","versionType":"custom","status":"affected"},{"version":"v2.4.2","status":"unaffected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"ics-cert@hq.dhs.gov","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"ADJACENT","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"ics-cert@hq.dhs.gov","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}]},"weaknesses":[{"source":"ics-cert@hq.dhs.gov","type":"Primary","description":[{"lang":"en","value":"CWE-798"}]}],"references":[{"url":"https://firm.tyconsystems.com/tpdin-monitor-web3-v2/TPDIN-MONITOR-WEB3-V2_v2.4.2.tfw","source":"ics-cert@hq.dhs.gov"},{"url":"https://firm.tyconsystems.com/tpdin-monitor-web3-v2/TPDIN-MONITOR-WEB3-V2_v2.4.2T.hex","source":"ics-cert@hq.dhs.gov"},{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-246-08.json","source":"ics-cert@hq.dhs.gov"},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-08","source":"ics-cert@hq.dhs.gov"}]}},{"cve":{"id":"CVE-2026-79423","sourceIdentifier":"cve@mitre.org","published":"2026-09-04T21:17:25.870","lastModified":"2026-09-04T21:17:25.870","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"An authenticated remote code execution (RCE) vulnerability in the admin_config.php component of seacms v13.6 allows attackers to execute arbitrary code via a crafted POST request."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://github.com/returnwrong/returnwrong-security-advisories/blob/main/CVE-2026-79423.md","source":"cve@mitre.org"},{"url":"https://github.com/seacmscom/seacms","source":"cve@mitre.org"}]}},{"cve":{"id":"CVE-2026-79426","sourceIdentifier":"cve@mitre.org","published":"2026-09-04T21:17:25.990","lastModified":"2026-09-04T21:17:25.990","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"An arbitrary file deletion vulnerability in the /adminapi/file/video_data_save component of CRMEB v6.0.0 allows authenticated attackers to delete arbitrary files via crafted POST request."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://github.com/crmeb/CRMEB","source":"cve@mitre.org"},{"url":"https://github.com/returnwrong/returnwrong-security-advisories/blob/main/CVE-2026-79426.md","source":"cve@mitre.org"}]}},{"cve":{"id":"CVE-2026-82712","sourceIdentifier":"ics-cert@hq.dhs.gov","published":"2026-09-04T21:17:26.100","lastModified":"2026-09-04T21:17:26.100","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a cross-site request forgery vulnerability. This could allow an attacker to perform state changing operations on the device."}],"affected":[{"source":"ics-cert@hq.dhs.gov","affectedData":[{"vendor":"Tycon Systems","product":"TPDIN-Monitor-WEB3","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"2.2.9","versionType":"custom","status":"affected"},{"version":"v2.4.2","status":"unaffected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"ics-cert@hq.dhs.gov","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.6,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"ACTIVE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"ics-cert@hq.dhs.gov","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}]},"weaknesses":[{"source":"ics-cert@hq.dhs.gov","type":"Primary","description":[{"lang":"en","value":"CWE-352"}]}],"references":[{"url":"https://firm.tyconsystems.com/tpdin-monitor-web3-v2/TPDIN-MONITOR-WEB3-V2_v2.4.2.tfw","source":"ics-cert@hq.dhs.gov"},{"url":"https://firm.tyconsystems.com/tpdin-monitor-web3-v2/TPDIN-MONITOR-WEB3-V2_v2.4.2T.hex","source":"ics-cert@hq.dhs.gov"},{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-246-08.json","source":"ics-cert@hq.dhs.gov"},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-08","source":"ics-cert@hq.dhs.gov"}]}},{"cve":{"id":"CVE-2026-85701","sourceIdentifier":"cna@vuldb.com","published":"2026-09-04T21:17:26.260","lastModified":"2026-09-04T21:17:26.260","vulnStatus":"Received","cveTags":[{"sourceIdentifier":"cna@vuldb.com","tags":["unsupported-when-assigned"]}],"descriptions":[{"lang":"en","value":"A vulnerability has been found in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. This issue affects the function ChatCompletion.create of the file g4f/__init__.py of the component Authentication Check. Such manipulation leads to missing authentication. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. This vulnerability only affects products that are no longer supported by the maintainer."}],"affected":[{"source":"cna@vuldb.com","affectedData":[{"vendor":"ramon-victor","product":"freegpt-webui","cpes":["cpe:2.3:a:ramon-victor:freegpt-webui:*:*:*:*:*:*:*:*"],"modules":["Authentication Check"],"versions":[{"version":"098db3dfeb41555c2ca9269df0f13e10ec1c35dc","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"PROOF_OF_CONCEPT","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"cna@vuldb.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"cna@vuldb.com","type":"Primary","description":[{"lang":"en","value":"CWE-287"},{"lang":"en","value":"CWE-306"}]}],"references":[{"url":"https://gist.github.com/Galaxync/4e91898128de8fffbaf893fb1f9d4272","source":"cna@vuldb.com"},{"url":"https://vuldb.com/cve/CVE-2026-85701","source":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/895266","source":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/398799","source":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/398799/cti","source":"cna@vuldb.com"}]}},{"cve":{"id":"CVE-2026-85702","sourceIdentifier":"cna@vuldb.com","published":"2026-09-04T21:17:26.480","lastModified":"2026-09-04T21:17:26.480","vulnStatus":"Received","cveTags":[{"sourceIdentifier":"cna@vuldb.com","tags":["unsupported-when-assigned"]}],"descriptions":[{"lang":"en","value":"A security vulnerability has been detected in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. Affected is the function _conversation of the file server/backend.py of the component Backend Conversation API. Such manipulation of the argument model leads to missing authentication. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. This vulnerability only affects products that are no longer supported by the maintainer."}],"affected":[{"source":"cna@vuldb.com","affectedData":[{"vendor":"ramon-victor","product":"freegpt-webui","cpes":["cpe:2.3:a:ramon-victor:freegpt-webui:*:*:*:*:*:*:*:*"],"modules":["Backend Conversation API"],"versions":[{"version":"098db3dfeb41555c2ca9269df0f13e10ec1c35dc","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"LOW","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"PROOF_OF_CONCEPT","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"cna@vuldb.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","baseScore":7.3,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":3.4}],"cvssMetricV2":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"cna@vuldb.com","type":"Primary","description":[{"lang":"en","value":"CWE-287"},{"lang":"en","value":"CWE-306"}]}],"references":[{"url":"https://gist.github.com/Galaxync/15cb5d1bf6ab110f0cba91664ed511dd","source":"cna@vuldb.com"},{"url":"https://vuldb.com/cve/CVE-2026-85702","source":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/895267","source":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/398805","source":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/398805/cti","source":"cna@vuldb.com"}]}},{"cve":{"id":"CVE-2026-85703","sourceIdentifier":"cna@vuldb.com","published":"2026-09-04T21:17:26.667","lastModified":"2026-09-04T21:17:26.667","vulnStatus":"Received","cveTags":[{"sourceIdentifier":"cna@vuldb.com","tags":["unsupported-when-assigned"]}],"descriptions":[{"lang":"en","value":"A flaw has been found in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. Affected by this issue is the function getJailbreak of the file server/backend.py of the component Jailbreak Mode. Executing a manipulation can lead to allocation of resources. The attack can be executed remotely. The exploit has been published and may be used. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. This vulnerability only affects products that are no longer supported by the maintainer."}],"affected":[{"source":"cna@vuldb.com","affectedData":[{"vendor":"ramon-victor","product":"freegpt-webui","cpes":["cpe:2.3:a:ramon-victor:freegpt-webui:*:*:*:*:*:*:*:*"],"modules":["Jailbreak Mode"],"versions":[{"version":"098db3dfeb41555c2ca9269df0f13e10ec1c35dc","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"LOW","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"PROOF_OF_CONCEPT","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"cna@vuldb.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":2.5}],"cvssMetricV2":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:P","baseScore":6.4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"cna@vuldb.com","type":"Primary","description":[{"lang":"en","value":"CWE-400"},{"lang":"en","value":"CWE-770"}]}],"references":[{"url":"https://gist.github.com/Galaxync/04d5b16498911c405580c735148a53be","source":"cna@vuldb.com"},{"url":"https://vuldb.com/cve/CVE-2026-85703","source":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/895268","source":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/398807","source":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/398807/cti","source":"cna@vuldb.com"}]}},{"cve":{"id":"CVE-2026-85704","sourceIdentifier":"cna@vuldb.com","published":"2026-09-04T21:17:26.863","lastModified":"2026-09-04T21:17:26.863","vulnStatus":"Received","cveTags":[{"sourceIdentifier":"cna@vuldb.com","tags":["unsupported-when-assigned"]}],"descriptions":[{"lang":"en","value":"A security flaw has been discovered in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. This issue affects the function getJailbreak of the file server/config.py of the component Jailbreak Mode. The manipulation results in race condition. It is possible to launch the attack remotely. The attack requires a high level of complexity. The exploitability is assessed as difficult. The exploit has been released to the public and may be used for attacks. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. This vulnerability only affects products that are no longer supported by the maintainer."}],"affected":[{"source":"cna@vuldb.com","affectedData":[{"vendor":"ramon-victor","product":"freegpt-webui","cpes":["cpe:2.3:a:ramon-victor:freegpt-webui:*:*:*:*:*:*:*:*"],"modules":["Jailbreak Mode"],"versions":[{"version":"098db3dfeb41555c2ca9269df0f13e10ec1c35dc","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":2.9,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"LOW","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"PROOF_OF_CONCEPT","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"cna@vuldb.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","baseScore":3.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.2,"impactScore":1.4}],"cvssMetricV2":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:H/Au:N/C:N/I:N/A:P","baseScore":2.6,"accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"LOW","exploitabilityScore":4.9,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"cna@vuldb.com","type":"Primary","description":[{"lang":"en","value":"CWE-362"}]}],"references":[{"url":"https://gist.github.com/Galaxync/04108fe7068324c998f33c5713105709","source":"cna@vuldb.com"},{"url":"https://vuldb.com/cve/CVE-2026-85704","source":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/895269","source":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/398821","source":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/398821/cti","source":"cna@vuldb.com"}]}},{"cve":{"id":"CVE-2026-85787","sourceIdentifier":"ff89ba41-3aa1-4d27-914a-91399e9639e5","published":"2026-09-04T21:17:27.057","lastModified":"2026-09-04T21:17:27.057","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"An incomplete list of disallowed inputs in the SQL validation component in Amazon awslabs postgres-mcp-server before  version 1.1.7 might allow an unauthenticated actor to modify data beyond the read-only scope by placing crafted SQL into the content that is submitted when an authenticated user interacts with the MCP server.\n\n\n\nTo remediate this issue, users should upgrade to version 1.1.7 or above."}],"affected":[{"source":"ff89ba41-3aa1-4d27-914a-91399e9639e5","affectedData":[{"vendor":"Amazon","product":"postgres-mcp-server","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"1.1.7","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"ff89ba41-3aa1-4d27-914a-91399e9639e5","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"PASSIVE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"ff89ba41-3aa1-4d27-914a-91399e9639e5","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}]},"weaknesses":[{"source":"ff89ba41-3aa1-4d27-914a-91399e9639e5","type":"Secondary","description":[{"lang":"en","value":"CWE-184"}]}],"references":[{"url":"https://aws.amazon.com/security/security-bulletins/2026-101-aws/","source":"ff89ba41-3aa1-4d27-914a-91399e9639e5"},{"url":"https://pypi.org/project/awslabs.postgres-mcp-server/1.1.7/","source":"ff89ba41-3aa1-4d27-914a-91399e9639e5"}]}},{"cve":{"id":"CVE-2026-46636","sourceIdentifier":"security-advisories@github.com","published":"2026-09-04T22:17:17.360","lastModified":"2026-09-04T22:17:17.360","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Twig is a template language for PHP. From version 1.0.0 to before version 3.27.0, SecurityPolicy::checkMethodAllowed() unconditionally whitelists all method calls on instances of Twig\\Markup. Twig\\Markup is not final, so subclasses inherit the bypass. An application that passes an object of a Markup-derived class into a sandboxed template (typically to mark a chunk of HTML as safe) inadvertently exposes every public method of that subclass to template authors, regardless of the configured allowedMethods list. This issue has been patched in version 3.27.0."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"twigphp","product":"Twig","versions":[{"version":">= 1.0.0, < 3.27.0","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Primary","description":[{"lang":"en","value":"CWE-1336"}]}],"references":[{"url":"http://github.com/twigphp/Twig/releases/tag/v3.27.0","source":"security-advisories@github.com"},{"url":"https://github.com/twigphp/Twig/security/advisories/GHSA-64jr-qjx4-w2fh","source":"security-advisories@github.com"},{"url":"https://security-tracker.debian.org/tracker/CVE-2026-46636","source":"security-advisories@github.com"},{"url":"https://security-tracker.debian.org/tracker/DSA-6311-1","source":"security-advisories@github.com"},{"url":"https://symfony.com/blog/cve-2026-46636-sandbox-filter-tag-and-function-allow-list-bypass-when-sandbox-state-changes-between-renders","source":"security-advisories@github.com"}]}},{"cve":{"id":"CVE-2026-75925","sourceIdentifier":"ics-cert@hq.dhs.gov","published":"2026-09-04T22:17:18.017","lastModified":"2026-09-04T22:17:18.017","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Improper neutralization of CRLF sequences in IXON VPN Client before version 1.4.7 allows an attacker to execute commands as root or SYSTEM. Configuration values accepted by the local service are written to a file later consumed by a privileged subprocess, without line-ending sequences being neutralized, which allows additional directives to be introduced into that file. The configuration interface accepts changes without authenticating or verifying the origin of the requester. The injected configuration persists on disk across restarts of the client and the operating system, and the VPN connection continues to function normally, so there is no behavioral change visible to the user."}],"affected":[{"source":"ics-cert@hq.dhs.gov","affectedData":[{"vendor":"IXON","product":"IXON VPN Client","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"1.4.7","versionType":"custom","status":"affected"},{"version":"1.4.7","status":"unaffected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"ics-cert@hq.dhs.gov","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":9.4,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"PASSIVE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"HIGH","subIntegrityImpact":"HIGH","subAvailabilityImpact":"HIGH","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"ics-cert@hq.dhs.gov","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","baseScore":9.6,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":6.0}]},"weaknesses":[{"source":"ics-cert@hq.dhs.gov","type":"Primary","description":[{"lang":"en","value":"CWE-93"}]}],"references":[{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-246-02.json","source":"ics-cert@hq.dhs.gov"},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-02","source":"ics-cert@hq.dhs.gov"},{"url":"https://www.ixon.cloud/Advisories/ADV-2026-08-05.pdf","source":"ics-cert@hq.dhs.gov"}]}},{"cve":{"id":"CVE-2026-76925","sourceIdentifier":"secalert@redhat.com","published":"2026-09-04T22:17:18.190","lastModified":"2026-09-04T22:17:18.190","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"A flaw was found in Flatpak. A Time-of-check to time-of-use (TOCTOU) race condition exists in the `org.freedesktop.Flatpak.SystemHelper` component. This vulnerability occurs because a privileged `chmod` operation executes before the OSTree repository validation within the `Deploy()` function. An attacker can exploit this timing window to redirect symlinks to arbitrary files, potentially leading to unauthorized file manipulation or information disclosure."}],"affected":[{"source":"secalert@redhat.com","affectedData":[{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"flatpak","cpes":["cpe:/o:redhat:enterprise_linux:10"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 7","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"flatpak","cpes":["cpe:/o:redhat:enterprise_linux:7"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 8","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"flatpak","cpes":["cpe:/o:redhat:enterprise_linux:8"]},{"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","defaultStatus":"affected","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"flatpak","cpes":["cpe:/o:redhat:enterprise_linux:9"]}]}],"metrics":{"cvssMetricV31":[{"source":"secalert@redhat.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:L","baseScore":5.8,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":1.0,"impactScore":4.7}]},"weaknesses":[{"source":"secalert@redhat.com","type":"Primary","description":[{"lang":"en","value":"CWE-367"}]}],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-76925","source":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2520099","source":"secalert@redhat.com"}]}},{"cve":{"id":"CVE-2026-77393","sourceIdentifier":"ics-cert@hq.dhs.gov","published":"2026-09-04T22:17:18.333","lastModified":"2026-09-04T22:17:18.333","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In Ignition 8.1.53 and earlier, the Gateway \"Create Project Role(s)\" setting shipped blank, which permitted any authenticated user to create projects (if they can execute gateway scripts). Ignition 8.1.54 restricts project creation to Designer sessions and no longer relies on this setting. The 8.3 series is not affected."}],"affected":[{"source":"ics-cert@hq.dhs.gov","affectedData":[{"vendor":"Inductive Automation","product":"Ignition","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"8.1.53","versionType":"custom","status":"affected"},{"version":"8.1.54","status":"unaffected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"ics-cert@hq.dhs.gov","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"ics-cert@hq.dhs.gov","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}]},"weaknesses":[{"source":"ics-cert@hq.dhs.gov","type":"Primary","description":[{"lang":"en","value":"CWE-276"}]}],"references":[{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-246-06.json","source":"ics-cert@hq.dhs.gov"},{"url":"https://security.inductiveautomation.com/?tcuUid=34477620-731d-4b70-b22b-9450f9a659a3","source":"ics-cert@hq.dhs.gov"},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-06","source":"ics-cert@hq.dhs.gov"}]}},{"cve":{"id":"CVE-2026-82684","sourceIdentifier":"ics-cert@hq.dhs.gov","published":"2026-09-04T22:17:18.683","lastModified":"2026-09-04T22:17:18.683","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a Missing Authorization vulnerability. This could allow an attacker to extract system credentials, configurations, or flash contents."}],"affected":[{"source":"ics-cert@hq.dhs.gov","affectedData":[{"vendor":"Tycon Systems","product":"TPDIN-Monitor-WEB3","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"2.2.9","versionType":"custom","status":"affected"},{"version":"v2.4.2","status":"unaffected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"ics-cert@hq.dhs.gov","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.6,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"ics-cert@hq.dhs.gov","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":5.2}]},"weaknesses":[{"source":"ics-cert@hq.dhs.gov","type":"Primary","description":[{"lang":"en","value":"CWE-862"}]}],"references":[{"url":"https://firm.tyconsystems.com/tpdin-monitor-web3-v2/TPDIN-MONITOR-WEB3-V2_v2.4.2.tfw","source":"ics-cert@hq.dhs.gov"},{"url":"https://firm.tyconsystems.com/tpdin-monitor-web3-v2/TPDIN-MONITOR-WEB3-V2_v2.4.2T.hex","source":"ics-cert@hq.dhs.gov"},{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-246-08.json","source":"ics-cert@hq.dhs.gov"},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-08","source":"ics-cert@hq.dhs.gov"}]}},{"cve":{"id":"CVE-2026-86090","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-04T22:17:18.840","lastModified":"2026-09-04T22:17:18.840","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"ntopng before 6.7.260717 fails to perform authorization checks in the delete endpoints and recipients REST v2 handlers. Authenticated non-administrator users can issue POST requests to irreversibly delete all configured notification endpoints and recipients, silencing all alerts."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"ntop","product":"ntopng","defaultStatus":"unaffected","packageURL":"pkg:github/ntop/ntopng","versions":[{"version":"0","lessThan":"6.7.260717","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":4.2}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Primary","description":[{"lang":"en","value":"CWE-862"}]}],"references":[{"url":"https://github.com/ntop/ntopng","source":"disclosure@vulncheck.com"},{"url":"https://github.com/ntop/ntopng/blob/f41cc1beff90e40e12bbc2cc135bdbf649ec559f/scripts/lua/rest/v2/delete/endpoints.lua","source":"disclosure@vulncheck.com"},{"url":"https://github.com/ntop/ntopng/blob/f41cc1beff90e40e12bbc2cc135bdbf649ec559f/scripts/lua/rest/v2/delete/recipients.lua","source":"disclosure@vulncheck.com"},{"url":"https://github.com/ntop/ntopng/commit/7d830f31af367745431c5d92e2e82fc432f6bdd8","source":"disclosure@vulncheck.com"},{"url":"https://github.com/ntop/ntopng/security/advisories/GHSA-m22w-f647-vx88","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/ntopng-before-6.7.260717-missing-authorization-on-the-notification-endpoint-and-recipient-delete-handlers","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-86091","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-04T22:17:18.990","lastModified":"2026-09-04T22:17:18.990","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"ntopng before 6.7.260717 fails to check user privileges in the pools bulk-delete endpoint, allowing authenticated non-administrators to delete all host pools and member bindings. Attackers can issue POST requests to the delete pools endpoint to irreversibly destroy every host pool, removing traffic policy bindings and visibility restrictions that may bypass security policies."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"ntop","product":"ntopng","defaultStatus":"unaffected","packageURL":"pkg:github/ntop/ntopng","versions":[{"version":"0","lessThan":"6.7.260717","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"LOW","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":4.2}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Primary","description":[{"lang":"en","value":"CWE-862"}]}],"references":[{"url":"https://github.com/ntop/ntopng","source":"disclosure@vulncheck.com"},{"url":"https://github.com/ntop/ntopng/blob/f41cc1beff90e40e12bbc2cc135bdbf649ec559f/scripts/lua/modules/pools/pools_rest_utils.lua","source":"disclosure@vulncheck.com"},{"url":"https://github.com/ntop/ntopng/blob/f41cc1beff90e40e12bbc2cc135bdbf649ec559f/scripts/lua/rest/v2/delete/pools.lua","source":"disclosure@vulncheck.com"},{"url":"https://github.com/ntop/ntopng/commit/7d830f31af367745431c5d92e2e82fc432f6bdd8","source":"disclosure@vulncheck.com"},{"url":"https://github.com/ntop/ntopng/security/advisories/GHSA-m22w-f647-vx88","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/ntopng-before-6.7.260717-missing-authorization-on-the-host-pool-bulk-delete-handler","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-48019","sourceIdentifier":"security-advisories@github.com","published":"2026-09-04T23:17:09.143","lastModified":"2026-09-04T23:17:09.143","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Laravel is a web application framework. Prior to versions 12.60.0 and 13.10.0, a CRLF injection vulnerability in Laravel's email validation, in combination with how Symfony Mailer and Symfony Mime handle certain character sequences, may allow an unauthenticated attacker to interfere with outbound email processing in applications that send mail to user-supplied addresses. This issue has been patched in versions 12.60.0 and 13.10.0."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"laravel","product":"framework","versions":[{"version":">= 13.0.0, < 13.10.0","status":"affected"},{"version":"< 12.60.0","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L","baseScore":8.9,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":2.2,"impactScore":6.0}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Primary","description":[{"lang":"en","value":"CWE-93"}]}],"references":[{"url":"https://github.com/laravel/framework/commit/96e9a663db657cf37ef26cd794fda8ff60eaa451","source":"security-advisories@github.com"},{"url":"https://github.com/laravel/framework/commit/f336ba79e744257f84ebf0d096b0ebc62e8e1a4d","source":"security-advisories@github.com"},{"url":"https://github.com/laravel/framework/pull/60151","source":"security-advisories@github.com"},{"url":"https://github.com/laravel/framework/releases/tag/v12.60.0","source":"security-advisories@github.com"},{"url":"https://github.com/laravel/framework/releases/tag/v13.10.0","source":"security-advisories@github.com"},{"url":"https://github.com/laravel/framework/security/advisories/GHSA-5vg9-5847-vvmq","source":"security-advisories@github.com"}]}},{"cve":{"id":"CVE-2026-86095","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-04T23:18:03.220","lastModified":"2026-09-04T23:18:03.220","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Unidata netcdf-c through 4.10.1 contains an out-of-bounds write vulnerability in NC4_HDF5_inq_attname() that copies HDF5 attribute names into a fixed 256-byte buffer without length validation. Attackers can craft HDF5 files with oversized attribute names to overflow the destination buffer, causing memory corruption and crashes when applications enumerate attribute names."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"Unidata","product":"netcdf-c","defaultStatus":"unaffected","collectionURL":"https://github.com/Unidata/netcdf-c","repo":"https://github.com/Unidata/netcdf-c","packageURL":"pkg:github/Unidata/netcdf-c","versions":[{"version":"0","lessThanOrEqual":"4.10.1","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.5,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"PASSIVE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Primary","description":[{"lang":"en","value":"CWE-787"}]}],"references":[{"url":"https://github.com/Unidata/netcdf-c","source":"disclosure@vulncheck.com"},{"url":"https://github.com/Unidata/netcdf-c/blob/v4.10.1/libhdf5/hdf5attr.c","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/unidata-netcdf-c-through-4.10.1-out-of-bounds-write-via-oversized-hdf5-attribute-name","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-86096","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-04T23:18:03.377","lastModified":"2026-09-04T23:18:03.377","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"PX4 Autopilot through 1.17.0 contains a use-after-free vulnerability in TemperatureCalibration::start() due to a race condition between task spawning and object deletion. Attackers can trigger the calibration process via shell commands to write to freed heap memory, corrupting unrelated objects or allocator metadata and destabilizing heap operations."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"PX4","product":"PX4-Autopilot","defaultStatus":"unaffected","collectionURL":"https://github.com/PX4/PX4-Autopilot","repo":"https://github.com/PX4/PX4-Autopilot","packageURL":"pkg:github/PX4/PX4-Autopilot","versions":[{"version":"0","lessThanOrEqual":"1.17.0","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":6.0,"baseSeverity":"MEDIUM","attackVector":"ADJACENT","attackComplexity":"HIGH","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","baseScore":5.9,"baseSeverity":"MEDIUM","attackVector":"ADJACENT_NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"HIGH"},"exploitabilityScore":1.6,"impactScore":4.2}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Primary","description":[{"lang":"en","value":"CWE-416"}]}],"references":[{"url":"https://github.com/PX4/PX4-Autopilot","source":"disclosure@vulncheck.com"},{"url":"https://github.com/PX4/PX4-Autopilot/blob/v1.17.0/src/modules/temperature_compensation/temperature_calibration/task.cpp","source":"disclosure@vulncheck.com"},{"url":"https://github.com/PX4/PX4-Autopilot/commit/b182e523d154fe029a49b48bb5f9d3d6693bc6bb","source":"disclosure@vulncheck.com"},{"url":"https://github.com/PX4/PX4-Autopilot/pull/28487","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/px4-autopilot-through-1.17.0-use-after-free-via-temperature-calibration-task-startup","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-86097","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-04T23:18:03.547","lastModified":"2026-09-04T23:18:03.547","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"PX4 Autopilot through 1.17.0 contains a null pointer dereference vulnerability in param_set_default_file() and param_set_backup_file() functions that allows attackers to crash the autopilot process. Attackers can invoke 'param select' or 'param select-backup' commands with no path argument from any PX4 shell to trigger the crash."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"PX4","product":"PX4-Autopilot","defaultStatus":"unaffected","collectionURL":"https://github.com/PX4/PX4-Autopilot","repo":"https://github.com/PX4/PX4-Autopilot","packageURL":"pkg:github/PX4/PX4-Autopilot","versions":[{"version":"0","lessThanOrEqual":"1.17.0","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"ADJACENT","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":3.6}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Primary","description":[{"lang":"en","value":"CWE-476"}]}],"references":[{"url":"https://github.com/PX4/PX4-Autopilot","source":"disclosure@vulncheck.com"},{"url":"https://github.com/PX4/PX4-Autopilot/blob/v1.17.0/src/lib/parameters/parameters.cpp","source":"disclosure@vulncheck.com"},{"url":"https://github.com/PX4/PX4-Autopilot/commit/02eabc08c9b8cb1de525070cacb7ea0c495136f6","source":"disclosure@vulncheck.com"},{"url":"https://github.com/PX4/PX4-Autopilot/pull/28475","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/px4-autopilot-through-1.17.0-null-pointer-dereference-via-param-select","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-86098","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-04T23:18:03.687","lastModified":"2026-09-04T23:18:03.687","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"ntop nDPI versions before 6.0 contain a heap buffer overflow vulnerability in the ndpi_json_string_escape function that writes beyond caller-supplied buffer boundaries. Attackers can trigger the overflow by supplying crafted network packet data including TLS SNI, HTTP headers, or DNS names that reach the vulnerable function, causing heap corruption."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"ntop","product":"nDPI","defaultStatus":"unaffected","collectionURL":"https://github.com/ntop/nDPI","repo":"https://github.com/ntop/nDPI","packageURL":"pkg:github/ntop/nDPI","versions":[{"version":"0","lessThan":"6.0","versionType":"custom","status":"affected"},{"version":"6.0","versionType":"custom","status":"unaffected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.3,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H","baseScore":7.4,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.2,"impactScore":5.2}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Primary","description":[{"lang":"en","value":"CWE-787"}]}],"references":[{"url":"https://github.com/ntop/nDPI","source":"disclosure@vulncheck.com"},{"url":"https://github.com/ntop/nDPI/blob/5.0/src/lib/ndpi_serializer.c","source":"disclosure@vulncheck.com"},{"url":"https://github.com/ntop/nDPI/commit/94e82c1de12323d992895830231865736a8abf2c","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/ntop-ndpi-before-6.0-heap-buffer-overflow-via-ndpi-json-string-escape","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-52762","sourceIdentifier":"security-advisories@github.com","published":"2026-09-05T00:17:18.607","lastModified":"2026-09-05T00:17:18.607","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki Bazar contains a stored Server-Side Template Injection (SSTI) vulnerability in the semantic template feature that can be escalated to confirmed Remote Code Execution (RCE). An authenticated administrator can place arbitrary Twig expressions into the Semantic template (Twig) field (bn_sem_template), and that content is later executed server-side when public semantic endpoints are requested. This issue has been patched in version 4.6.6."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"YesWiki","product":"yeswiki","versions":[{"version":"< 4.6.6","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Primary","description":[{"lang":"en","value":"CWE-1336"}]}],"references":[{"url":"https://github.com/YesWiki/yeswiki/commit/89462f1577a8a1fe7fcff75e77b5058a74d8047b","source":"security-advisories@github.com"},{"url":"https://github.com/YesWiki/yeswiki/releases/tag/v4.6.6","source":"security-advisories@github.com"},{"url":"https://github.com/YesWiki/yeswiki/security/advisories/GHSA-65p8-9433-jpcp","source":"security-advisories@github.com"}]}},{"cve":{"id":"CVE-2026-52763","sourceIdentifier":"security-advisories@github.com","published":"2026-09-05T00:17:19.257","lastModified":"2026-09-05T00:17:19.257","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"YesWiki is a wiki system written in PHP. Prior to version 4.6.6, the recentchanges action (actions/recentchanges.php) accepts a period argument from two disjoint parameter spaces. A whitelist validates only the URL form against ['day','week','month']. The action-argument form takes the else branch with no validation, and the value flows into PageManager::getRecentlyChanged(), where it is interpolated into a WHERE time >= '...' ORDER BY time DESC clause without escaping or parameterization. UNION-based injection succeeds, the leaked rows render into the response page, so any visitor of the trigger page sees the exfiltrated data. The vulnerability provides arbitrary read of the YesWiki database to anyone who can save the trigger page. On a default install (default_write_acl='*'), this includes anonymous users, subject to the hashcash JS check on the page-edit form. Once the trigger page is saved, every subsequent view fires the injection as the SQLi is stored. Stored SQL injection is reachable through the page-edit flow, with arbitrary database read. This issue has been patched in version 4.6.6."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"YesWiki","product":"yeswiki","versions":[{"version":"< 4.6.6","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Primary","description":[{"lang":"en","value":"CWE-89"},{"lang":"en","value":"CWE-1287"}]}],"references":[{"url":"https://github.com/YesWiki/yeswiki/releases/tag/v4.6.6","source":"security-advisories@github.com"},{"url":"https://github.com/YesWiki/yeswiki/security/advisories/GHSA-89v6-j5x6-cmj3","source":"security-advisories@github.com"}]}},{"cve":{"id":"CVE-2026-52766","sourceIdentifier":"security-advisories@github.com","published":"2026-09-05T00:17:19.393","lastModified":"2026-09-05T00:17:19.393","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"YesWiki is a wiki system written in PHP. Prior to version 4.6.6, the {{erasespamedcomments}} wiki action (actions/EraseSpamedCommentsAction.php) accepts a suppr[] array from POST and deletes every wiki page whose tag appears in that array, with no authorization check anywhere in the action body or in the page-deletion path it invokes. Combined with YesWiki's allow-by-default action ACL model, any user who has page write access, which is the default for everyone (default_write_acl='*') on a fresh install can permanently delete arbitrary wiki pages, including the front page, admin pages, and pages owned by other users. This issue has been patched in version 4.6.6."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"YesWiki","product":"yeswiki","versions":[{"version":"< 4.6.6","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","baseScore":9.1,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.2}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Primary","description":[{"lang":"en","value":"CWE-276"},{"lang":"en","value":"CWE-862"}]}],"references":[{"url":"https://github.com/YesWiki/yeswiki/commit/ed5b548a705c8091ba0282aaaba73ddda976abef","source":"security-advisories@github.com"},{"url":"https://github.com/YesWiki/yeswiki/releases/tag/v4.6.6","source":"security-advisories@github.com"},{"url":"https://github.com/YesWiki/yeswiki/security/advisories/GHSA-6x7x-gcmf-7r8x","source":"security-advisories@github.com"}]}},{"cve":{"id":"CVE-2026-52767","sourceIdentifier":"security-advisories@github.com","published":"2026-09-05T00:17:19.540","lastModified":"2026-09-05T00:17:19.540","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"YesWiki is a wiki system written in PHP. From version 4.6.2 to before version 4.6.6, HttpSignatureService::verifySignature() checks the result of PHP's openssl_verify() with a loose boolean negation - if (!openssl_verify(...)) { throw ... }. PHP's openssl_verify has four possible return values: 1, 0, -1, and \"false\". The -1 row is the bypass: PHP's truthiness rules make -1 a truthy value, so !(-1) === false, the throw is skipped, and the controller proceeds to processActivity(). Any condition that makes OpenSSL's EVP_VerifyFinal() return -1 triggers the bypass. The reachable consequence is the controller silently treats a failed verification as success and processes the attacker's payload. This issue has been patched in version 4.6.6."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"YesWiki","product":"yeswiki","versions":[{"version":">= 4.6.2, < 4.6.6","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L","baseScore":8.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":4.2}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Primary","description":[{"lang":"en","value":"CWE-347"}]}],"references":[{"url":"https://github.com/YesWiki/yeswiki/commit/d1795e0301e1a1078f17b4b98f56fff70de2029e","source":"security-advisories@github.com"},{"url":"https://github.com/YesWiki/yeswiki/releases/tag/v4.6.6","source":"security-advisories@github.com"},{"url":"https://github.com/YesWiki/yeswiki/security/advisories/GHSA-mv28-wj57-f57g","source":"security-advisories@github.com"}]}},{"cve":{"id":"CVE-2026-52769","sourceIdentifier":"security-advisories@github.com","published":"2026-09-05T00:17:19.683","lastModified":"2026-09-05T00:17:19.683","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"YesWiki is a wiki system written in PHP. From version 4.6.2 to before version 4.6.6, the POST /api/forms/{formId}/actor/inbox route - exposed publicly with acl:\"public\" - accepts an HTTP Signature header whose keyId parameter is a URL. HttpSignatureService::verifySignature() parses the header and immediately makes a server-side HTTP GET to that URL, before any cryptographic verification or URL validation. An unauthenticated remote attacker can therefore make YesWiki issue arbitrary outbound HTTP requests to any host the server can reach - internal services, cloud-metadata endpoints (169.254.169.254), intranet-only admin panels, etc. - and read enough back via timing and error-message oracles to scan ports, enumerate services, and (on a real cloud instance) reach IAM metadata. The only deployment-side precondition is that ActivityPub be enabled on at least one Bazar form. This issue has been patched in version 4.6.6."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"YesWiki","product":"yeswiki","versions":[{"version":">= 4.6.2, < 4.6.6","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L","baseScore":8.3,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":3.7}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Primary","description":[{"lang":"en","value":"CWE-918"}]}],"references":[{"url":"http://github.com/YesWiki/yeswiki/commit/87e627f33e79879827a3669fee2aa1244612c487","source":"security-advisories@github.com"},{"url":"https://github.com/YesWiki/yeswiki/releases/tag/v4.6.6","source":"security-advisories@github.com"},{"url":"https://github.com/YesWiki/yeswiki/security/advisories/GHSA-vw42-752g-5mrp","source":"security-advisories@github.com"}]}},{"cve":{"id":"CVE-2026-52770","sourceIdentifier":"security-advisories@github.com","published":"2026-09-05T00:17:19.827","lastModified":"2026-09-05T00:17:19.827","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki’s public Bazar entry-listing APIs are vulnerable to unauthenticated SQL injection in numeric query / queries filters. For Bazar fields whose value structure is numeric, YesWiki escapes the attacker-controlled filter value but inserts it into SQL without quotes or numeric validation. An unauthenticated attacker can inject boolean SQL expressions and infer database contents from whether entries are returned. This issue has been patched in version 4.6.6."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"YesWiki","product":"yeswiki","versions":[{"version":"< 4.6.6","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Primary","description":[{"lang":"en","value":"CWE-89"}]}],"references":[{"url":"https://github.com/YesWiki/yeswiki/commit/f3b0dd093a7ace47dc29a515faeb02635baceae2","source":"security-advisories@github.com"},{"url":"https://github.com/YesWiki/yeswiki/releases/tag/v4.6.6","source":"security-advisories@github.com"},{"url":"https://github.com/YesWiki/yeswiki/security/advisories/GHSA-qg78-vmvc-fhjw","source":"security-advisories@github.com"}]}},{"cve":{"id":"CVE-2026-52771","sourceIdentifier":"security-advisories@github.com","published":"2026-09-05T00:17:19.963","lastModified":"2026-09-05T00:17:19.963","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"YesWiki is a wiki system written in PHP. From version 4.2.0 to before version 4.6.6, ApiController::deletePage() interpolates a page tag retrieved from the database into a DELETE FROM …_links WHERE to_tag = '$tag' query without escaping. The page tag is attacker-controlled — the POST /api/pages/{tag} API accepts arbitrary URL-encoded values, including single quotes, and stores them. A low-privilege authenticated user can therefore create a page whose tag is a SQL fragment, make the page non-orphaned via the standard {{include page=\"…\"}} link mechanism, and then invoke the delete endpoint to execute arbitrary SQL inside the wiki database - including time-based blind data exfiltration from any table. This issue has been patched in version 4.6.6."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"YesWiki","product":"yeswiki","versions":[{"version":">= 4.2.0, < 4.6.6","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L","baseScore":8.3,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":5.5}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Primary","description":[{"lang":"en","value":"CWE-89"}]}],"references":[{"url":"https://github.com/YesWiki/yeswiki/commit/23d3cc124613b9428ab963b31807c08879a9c631","source":"security-advisories@github.com"},{"url":"https://github.com/YesWiki/yeswiki/releases/tag/v4.6.6","source":"security-advisories@github.com"},{"url":"https://github.com/YesWiki/yeswiki/security/advisories/GHSA-8f2v-2qhj-gfwg","source":"security-advisories@github.com"}]}},{"cve":{"id":"CVE-2026-52772","sourceIdentifier":"security-advisories@github.com","published":"2026-09-05T00:17:20.110","lastModified":"2026-09-05T00:17:20.110","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"YesWiki is a wiki system written in PHP. Prior to version 4.6.6, Bazar form-field templates still apply |raw('html') to field.label / field.hint in attribute and label-body contexts, resulting stored XSS in form renders. This issue has been patched in version 4.6.6."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"YesWiki","product":"yeswiki","versions":[{"version":"< 4.6.6","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Primary","description":[{"lang":"en","value":"CWE-79"},{"lang":"en","value":"CWE-116"}]}],"references":[{"url":"https://github.com/YesWiki/yeswiki/commit/5d1a4d07fecb0706f33e5dfbbe6ff5ef1892b2a7","source":"security-advisories@github.com"},{"url":"https://github.com/YesWiki/yeswiki/releases/tag/v4.6.6","source":"security-advisories@github.com"},{"url":"https://github.com/YesWiki/yeswiki/security/advisories/GHSA-xc7j-3g8q-9vh4","source":"security-advisories@github.com"}]}},{"cve":{"id":"CVE-2026-52773","sourceIdentifier":"security-advisories@github.com","published":"2026-09-05T00:17:20.243","lastModified":"2026-09-05T00:17:20.243","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"YesWiki is a wiki system written in PHP. From version 4.1.0 to before version 4.6.6, YesWiki's archived-revision view reflects the time GET parameter into a hidden HTML input in handlers/page/show.php without escaping. Because MySQL coerces malformed DATETIME strings, an attacker can append HTML or JavaScript to a valid archived revision timestamp, still load that archived revision, and execute arbitrary JavaScript in the victim's browser. The vulnerable form is only rendered when the victim can both read and edit the target page. In restricted deployments this requires a victim with read and write access to that page. On a default doryphore 4.6.5 install, public pages such as PagePrincipale were editable anonymously during validation, so the issue can also affect unauthenticated visitors in that configuration. This issue has been patched in version 4.6.6."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"YesWiki","product":"yeswiki","versions":[{"version":">= 4.1.0, < 4.6.6","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Primary","description":[{"lang":"en","value":"CWE-80"}]}],"references":[{"url":"https://github.com/YesWiki/yeswiki/commit/35ad9c2bb6cd338198b37c1f745e24bc302a3560","source":"security-advisories@github.com"},{"url":"https://github.com/YesWiki/yeswiki/releases/tag/v4.6.6","source":"security-advisories@github.com"},{"url":"https://github.com/YesWiki/yeswiki/security/advisories/GHSA-35f3-pg38-486f","source":"security-advisories@github.com"}]}},{"cve":{"id":"CVE-2026-52774","sourceIdentifier":"security-advisories@github.com","published":"2026-09-05T00:17:20.380","lastModified":"2026-09-05T00:17:20.380","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki's Bazar widget handler reflects the id GET parameter into HTML attributes using strip_tags() only. Because strip_tags() does not escape double quotes, an attacker can break out of the attribute value, inject an event handler such as onmouseover, and execute arbitrary JavaScript in the victim's browser. This issue is reachable without authentication. During validation, the vulnerable widget route returned the injected HTML for both /HomePage/widget?id=... and /NoSuchPage/widget?id=..., which shows that no login, no page ownership, no edit rights, and not even a valid page tag were required. The only routing prerequisite observed was that the Bazar extension is enabled and the request includes an id parameter. This issue has been patched in version 4.6.6."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"YesWiki","product":"yeswiki","versions":[{"version":"< 4.6.6","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Primary","description":[{"lang":"en","value":"CWE-80"}]}],"references":[{"url":"https://github.com/YesWiki/yeswiki/commit/1aa2710c7505630b858f2142a65f9441bfaba2b2","source":"security-advisories@github.com"},{"url":"https://github.com/YesWiki/yeswiki/releases/tag/v4.6.6","source":"security-advisories@github.com"},{"url":"https://github.com/YesWiki/yeswiki/security/advisories/GHSA-r5xw-gcgw-hwp5","source":"security-advisories@github.com"}]}},{"cve":{"id":"CVE-2026-52775","sourceIdentifier":"security-advisories@github.com","published":"2026-09-05T00:17:20.520","lastModified":"2026-09-05T00:17:20.520","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki through the latest development branch contains a SQL injection vulnerability in ReactionManager::deleteUserReaction() that allows any authenticated user to inject arbitrary SQL via the {idreaction} and {id} URL path parameters. The parameters are concatenated directly into a SQL LIKE clause without escaping or parameterization. This issue has been patched in version 4.6.6."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"YesWiki","product":"yeswiki","versions":[{"version":"< 4.6.6","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Primary","description":[{"lang":"en","value":"CWE-89"}]}],"references":[{"url":"https://github.com/YesWiki/yeswiki/commit/90ca54fb518e1c43a1ead6e4f5bf9f0389789841","source":"security-advisories@github.com"},{"url":"https://github.com/YesWiki/yeswiki/releases/tag/v4.6.6","source":"security-advisories@github.com"},{"url":"https://github.com/YesWiki/yeswiki/security/advisories/GHSA-4pf7-cc4r-g63h","source":"security-advisories@github.com"}]}},{"cve":{"id":"CVE-2026-52777","sourceIdentifier":"security-advisories@github.com","published":"2026-09-05T00:17:20.663","lastModified":"2026-09-05T00:17:20.663","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"YesWiki is a wiki system written in PHP. Prior to version 4.6.6, there is an authenticated PHP object injection vulnerability in BazarImportAction via unserialize. This issue has been patched in version 4.6.6."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"YesWiki","product":"yeswiki","versions":[{"version":"< 4.6.6","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":9.4,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"ACTIVE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"HIGH","subIntegrityImpact":"HIGH","subAvailabilityImpact":"HIGH","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Primary","description":[{"lang":"en","value":"CWE-352"},{"lang":"en","value":"CWE-502"}]}],"references":[{"url":"https://github.com/YesWiki/yeswiki/commit/8f70a8d6b8befa0e644d03c785701dbbc55b8fd0","source":"security-advisories@github.com"},{"url":"https://github.com/YesWiki/yeswiki/releases/tag/v4.6.6","source":"security-advisories@github.com"},{"url":"https://github.com/YesWiki/yeswiki/security/advisories/GHSA-9369-69wj-7m2f","source":"security-advisories@github.com"}]}},{"cve":{"id":"CVE-2026-86100","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-05T00:17:20.810","lastModified":"2026-09-05T00:17:20.810","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Camaleon CMS versions 2.7.5 through 2.9.1 fail to validate redirect targets when fetching remote files in the Upload from URL media feature. Authenticated attackers can supply URLs that pass initial validation but redirect to internal network addresses, allowing server-side request forgery to internal services."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"owen2345","product":"CamaleonCMS","defaultStatus":"unaffected","collectionURL":"https://rubygems.org/gems/camaleon_cms","packageName":"camaleon_cms","repo":"https://github.com/owen2345/camaleon-cms","packageURL":"pkg:gem/camaleon_cms","versions":[{"version":"2.7.5","lessThan":"2.9.2","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"LOW","subIntegrityImpact":"LOW","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":2.7}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Primary","description":[{"lang":"en","value":"CWE-918"}]}],"references":[{"url":"https://github.com/owen2345/camaleon-cms","source":"disclosure@vulncheck.com"},{"url":"https://github.com/owen2345/camaleon-cms/blob/2.9.1/app/helpers/camaleon_cms/uploader_helper.rb","source":"disclosure@vulncheck.com"},{"url":"https://github.com/owen2345/camaleon-cms/commit/3c46b6e512518ded476226162305c8eae00aac3f","source":"disclosure@vulncheck.com"},{"url":"https://github.com/owen2345/camaleon-cms/pull/1133","source":"disclosure@vulncheck.com"},{"url":"https://github.com/owen2345/camaleon-cms/releases/tag/2.9.2","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/camaleon-cms-2.7.5-through-2.9.1-ssrf-via-http-redirect-in-upload-from-url","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-86137","sourceIdentifier":"cve@mitre.org","published":"2026-09-05T05:17:11.490","lastModified":"2026-09-05T05:17:11.490","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds read, aka an out-of-bounds read in the NXT macro in xmlregexp."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"xmlsoft","product":"libxml2","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"2.15.4","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@mitre.org","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","baseScore":2.9,"baseSeverity":"LOW","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":1.4,"impactScore":1.4}]},"weaknesses":[{"source":"cve@mitre.org","type":"Primary","description":[{"lang":"en","value":"CWE-125"}]}],"references":[{"url":"https://github.com/GNOME/libxml2/commit/76fe08d97de88bfaef2f7d5cd27f11954cc5bee2","source":"cve@mitre.org"},{"url":"https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4","source":"cve@mitre.org"},{"url":"https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1099","source":"cve@mitre.org"}]}},{"cve":{"id":"CVE-2026-86138","sourceIdentifier":"cve@mitre.org","published":"2026-09-05T05:17:12.600","lastModified":"2026-09-05T05:17:12.600","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"xmlsoft","product":"libxml2","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"2.15.4","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@mitre.org","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","baseScore":6.9,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":1.4,"impactScore":5.5}]},"weaknesses":[{"source":"cve@mitre.org","type":"Primary","description":[{"lang":"en","value":"CWE-190"}]}],"references":[{"url":"https://github.com/GNOME/libxml2/commit/a4cba4b5b5a8c42e155ed42d2d2a44955465a2e4","source":"cve@mitre.org"},{"url":"https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4","source":"cve@mitre.org"}]}},{"cve":{"id":"CVE-2026-86139","sourceIdentifier":"cve@mitre.org","published":"2026-09-05T05:17:12.730","lastModified":"2026-09-05T05:17:12.730","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"xmlsoft","product":"libxml2","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"2.15.4","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@mitre.org","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","baseScore":6.9,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":1.4,"impactScore":5.5}]},"weaknesses":[{"source":"cve@mitre.org","type":"Primary","description":[{"lang":"en","value":"CWE-190"}]}],"references":[{"url":"https://github.com/GNOME/libxml2/commit/8edbbdb09f24d26a2f900141fddc2b9d014f53b0","source":"cve@mitre.org"},{"url":"https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4","source":"cve@mitre.org"}]}},{"cve":{"id":"CVE-2026-86140","sourceIdentifier":"cve@mitre.org","published":"2026-09-05T05:17:12.877","lastModified":"2026-09-05T05:17:12.877","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat stack-based buffer overflow."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"xmlsoft","product":"libxml2","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"2.15.4","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@mitre.org","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L","baseScore":8.0,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":2.5,"impactScore":5.5}]},"weaknesses":[{"source":"cve@mitre.org","type":"Primary","description":[{"lang":"en","value":"CWE-121"}]}],"references":[{"url":"https://github.com/GNOME/libxml2/commit/d1686f91dbda141a752200419d35639fd6b38340","source":"cve@mitre.org"},{"url":"https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4","source":"cve@mitre.org"}]}},{"cve":{"id":"CVE-2026-86141","sourceIdentifier":"cve@mitre.org","published":"2026-09-05T05:17:13.007","lastModified":"2026-09-05T05:17:13.007","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in xmlRegNewParserCtxt after a strdup failure, i.e., it does not calculate a string length after NULL checking."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"xmlsoft","product":"libxml2","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"2.15.4","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@mitre.org","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","baseScore":2.9,"baseSeverity":"LOW","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":1.4,"impactScore":1.4}]},"weaknesses":[{"source":"cve@mitre.org","type":"Primary","description":[{"lang":"en","value":"CWE-252"}]}],"references":[{"url":"https://github.com/GNOME/libxml2/commit/e89a8aae4c9b40cdafcf66b3f9e57c62db37bb55","source":"cve@mitre.org"},{"url":"https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4","source":"cve@mitre.org"},{"url":"https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1107","source":"cve@mitre.org"}]}},{"cve":{"id":"CVE-2026-86142","sourceIdentifier":"cve@mitre.org","published":"2026-09-05T05:17:13.133","lastModified":"2026-09-05T05:17:13.133","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"xmlsoft","product":"libxml2","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"2.15.4","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@mitre.org","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","baseScore":6.9,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":1.4,"impactScore":5.5}]},"weaknesses":[{"source":"cve@mitre.org","type":"Primary","description":[{"lang":"en","value":"CWE-122"}]}],"references":[{"url":"https://github.com/GNOME/libxml2/commit/6b3a736c0edc74ceec3d82f5252499d7911b3a58","source":"cve@mitre.org"},{"url":"https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4","source":"cve@mitre.org"},{"url":"https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1113","source":"cve@mitre.org"}]}},{"cve":{"id":"CVE-2026-86143","sourceIdentifier":"cve@mitre.org","published":"2026-09-05T05:17:13.270","lastModified":"2026-09-05T05:17:13.270","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for integer overflow before calling writecallback. This has security relevance for many types of uses of that length value within a callback."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"xmlsoft","product":"libxml2","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"2.15.4","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@mitre.org","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","baseScore":6.9,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":1.4,"impactScore":5.5}]},"weaknesses":[{"source":"cve@mitre.org","type":"Primary","description":[{"lang":"en","value":"CWE-192"}]}],"references":[{"url":"https://github.com/GNOME/libxml2/commit/90f293ba74d28b1d570920382e707586f68ebf35","source":"cve@mitre.org"},{"url":"https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4","source":"cve@mitre.org"},{"url":"https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1111","source":"cve@mitre.org"}]}},{"cve":{"id":"CVE-2026-86144","sourceIdentifier":"cve@mitre.org","published":"2026-09-05T05:17:13.407","lastModified":"2026-09-05T05:17:13.407","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevance for, for example, the XML_PARSE_NONET flag, if (without it) a custom resource loader accesses the internet and triggers XML external entity injection, SSRF, or a denial of service (e.g., for an attacker-controlled internet resource that is intentionally slow)."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"xmlsoft","product":"libxml2","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"2.15.4","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@mitre.org","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L","baseScore":5.6,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":1.4,"impactScore":3.7}]},"weaknesses":[{"source":"cve@mitre.org","type":"Primary","description":[{"lang":"en","value":"CWE-669"}]}],"references":[{"url":"https://github.com/GNOME/libxml2/commit/b63cd517afecb76582dd9488c55e54ceaf50de61","source":"cve@mitre.org"},{"url":"https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4","source":"cve@mitre.org"}]}},{"cve":{"id":"CVE-2025-14945","sourceIdentifier":"security@wordfence.com","published":"2026-09-05T06:17:09.017","lastModified":"2026-09-05T06:17:09.017","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Events Manager - Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via event attribute values in all versions up to, and including, 7.3.3. This is due to insufficient input sanitization when storing attribute values (using only `wp_unslash()` without sanitization) and lack of output escaping when rendering the '#_ATT{key}' placeholder. This makes it possible for authenticated attackers, with Author-level access and above, or unauthenticated attackers when anonymous event submissions are enabled, to inject arbitrary web scripts that execute when any user views the affected event page."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"netweblogic","product":"Events Manager – Calendar, Bookings, Tickets, and more!","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"7.3.3","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":2.7}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/events-manager/trunk/classes/em-event.php#L1206","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/events-manager/trunk/classes/em-event.php#L2608","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset/3567065/","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/a1985eb5-bfb5-4220-a4f8-fcfa84beae6a?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-13447","sourceIdentifier":"security@wordfence.com","published":"2026-09-05T06:17:09.403","lastModified":"2026-09-05T06:17:09.403","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Mstore Api plugin for WordPress is vulnerable to Authentication Bypass via JWT Forgery in versions up to, and including, 4.20.0 This is due to missing cryptographic signature verification in the FirebasePhoneAuthHelper::verify_id_token() function, which decodes and validates Firebase ID token claims (alg, kid, aud, iss) but never calls openssl_verify() or any equivalent to validate the JWT signature against Google's actual public key certificates. This makes it possible for unauthenticated attackers to forge a Firebase Phone Auth JWT signed with a self-generated RSA key pair and impersonate any phone number, resulting in unauthorized access to existing WordPress accounts or creation of new arbitrary accounts."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"inspireui","product":"MStore API – Create Native Android & iOS Apps On The Cloud","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"4.20.0","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-287"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/mstore-api/tags/4.18.4/controllers/flutter-user.php#L829","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/mstore-api/tags/4.18.4/controllers/flutter-user.php#L940","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/mstore-api/tags/4.18.4/controllers/helpers/firebase-phone-auth-helper.php#L5","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/mstore-api/trunk/controllers/flutter-user.php#L829","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/mstore-api/trunk/controllers/flutter-user.php#L940","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/mstore-api/trunk/controllers/helpers/firebase-phone-auth-helper.php#L5","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/4a1127af-74f6-4748-9aee-5a8c6c2766a4?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-18404","sourceIdentifier":"security@wordfence.com","published":"2026-09-05T06:17:09.577","lastModified":"2026-09-05T06:17:09.577","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Social Chat – Click To Chat App Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'consent_message' JSON Attribute in .qlwapp data-box in all versions up to, and including, 8.6.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The exploit requires no user interaction beyond page load, as setting auto_open and consent_enabled to 'yes' in the injected data-box JSON causes the consent box — and the embedded script — to execute immediately on page load."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"quadlayers","product":"Social Chat – Click To Chat App Button","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"8.6.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":2.7}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/wp-whatsapp-chat/tags/8.5.1/build/frontend/js/index.js#L2","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/wp-whatsapp-chat/tags/8.5.1/lib/controllers/class-frontend.php#L86","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/wp-whatsapp-chat/tags/8.6.1/build/frontend/js/index.js#L2","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/wp-whatsapp-chat/tags/8.6.1/lib/controllers/class-frontend.php#L86","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?old_path=%2Fwp-whatsapp-chat/tags/8.6.2&new_path=%2Fwp-whatsapp-chat/tags/8.6.3","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?reponame=&new=3667778%40wp-whatsapp-chat%2Ftags%2F8.6.3&old=3664149%40wp-whatsapp-chat%2Ftags%2F8.6.2","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f159392b-5bc6-4c12-a924-13ea170bb7fa?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-77233","sourceIdentifier":"security@wordfence.com","published":"2026-09-05T06:17:09.780","lastModified":"2026-09-05T06:17:09.780","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via AdSense Regex Rewrite in all versions up to, and including, 3.13.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This vulnerability only manifests when the 'Secondary' parser engine is active (parser_engine=default); it does not exist under the default 'new' DOM-based parser engine."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"iubenda","product":"iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"3.13.4","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N","baseScore":7.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":2.7}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/iubenda-cookie-law-solution/tags/3.13.2/iubenda-cookie-class/iubenda.class.php#L557","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/iubenda-cookie-law-solution/tags/3.13.2/iubenda-cookie-class/iubenda.class.php#L570","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/iubenda-cookie-law-solution/tags/3.13.2/iubenda_cookie_solution.php#L986","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/iubenda-cookie-law-solution/tags/3.13.3/iubenda-cookie-class/iubenda.class.php#L557","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/iubenda-cookie-law-solution/tags/3.13.3/iubenda-cookie-class/iubenda.class.php#L570","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/iubenda-cookie-law-solution/tags/3.13.3/iubenda_cookie_solution.php#L986","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset/3675630/iubenda-cookie-law-solution/trunk/iubenda-cookie-class/iubenda.class.php","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?old_path=%2Fiubenda-cookie-law-solution/tags/3.13.4&new_path=%2Fiubenda-cookie-law-solution/tags/3.13.5","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?reponame=&new=3675630%40iubenda-cookie-law-solution%2Ftags%2F3.13.5&old=3663183%40iubenda-cookie-law-solution%2Ftags%2F3.13.4","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/af459f28-a058-42d3-8818-43603c6a14eb?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-77263","sourceIdentifier":"security@wordfence.com","published":"2026-09-05T06:17:09.950","lastModified":"2026-09-05T06:17:09.950","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 3.13.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The exploit works by embedding KSES-allowed markup such as abbr title attributes and HTML comments in a submitted comment so that the global strtr() substitution strips substrings from an inert tag, mutating it into an executable element such as an img onerror handler that runs in the WordPress origin for any visitor, including logged-in administrators."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"iubenda","product":"iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"3.13.4","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N","baseScore":7.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":2.7}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/iubenda-cookie-law-solution/trunk/iubenda-cookie-class/iubenda.class.php#L381","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/iubenda-cookie-law-solution/trunk/iubenda-cookie-class/iubenda.class.php#L941","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/iubenda-cookie-law-solution/trunk/iubenda_cookie_solution.php#L834","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/iubenda-cookie-law-solution/trunk/iubenda_cookie_solution.php#L857","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset/3675630/iubenda-cookie-law-solution/trunk/iubenda-cookie-class/iubenda.class.php","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?old_path=%2Fiubenda-cookie-law-solution/tags/3.13.4&new_path=%2Fiubenda-cookie-law-solution/tags/3.13.5","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?reponame=&new=3675630%40iubenda-cookie-law-solution%2Ftags%2F3.13.5&old=3663183%40iubenda-cookie-law-solution%2Ftags%2F3.13.4","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f8d18aaa-c8f4-4688-841d-2a77b71b60b0?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-83627","sourceIdentifier":"security@wordfence.com","published":"2026-09-05T06:17:10.080","lastModified":"2026-09-05T06:17:10.080","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Hummingbird – Speed Optimization, Caching, Minify, Compress & CDN plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.21.0 via the log_msg() function in core/modules/class-page-cache.php. The page-cache debug log is written to wp-content/wphb-logs/page-caching-log.php, a directly web-accessible PHP file that is supposed to be protected by a leading '<?php die(); ?>' header. That header is guarded by class_exists( 'Filesystem' ), which can never match because class_exists() resolves string arguments in the global namespace while the class is Hummingbird\\Core\\Filesystem; when the log is created during a front-end request the header is therefore omitted entirely. get_cookies() then writes the raw name of any cookie matching the wphb_cache_ prefix into that file without sanitization. This makes it possible for unauthenticated attackers to write arbitrary PHP into the log file with a single anonymous request and execute it by requesting the file directly, resulting in full remote code execution. Exploitation requires the site administrator to have enabled Page Caching with the Debug Log option (non-default), and the log file to be created during a front-end request — a state reached by the plugin's own 'Clear logs' action, any cache flush, or unattended via the plugin's daily log-rotation cron, which can strip the protective header from an existing log file."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"wpmudev","product":"Hummingbird Performance – Cache & Page Speed Optimization for Core Web Vitals | Critical CSS | Minify CSS | Defer CSS Javascript | CDN","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"3.21.0","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-94"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/hummingbird-performance/trunk/core/modules/class-page-cache.php#L1973","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/hummingbird-performance/trunk/core/modules/class-page-cache.php#L1982","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/hummingbird-performance/trunk/core/modules/class-page-cache.php#L749","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/hummingbird-performance/trunk/core/modules/class-page-cache.php#L752","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset/3675836/hummingbird-performance/trunk/core/modules/class-page-cache.php","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?old_path=%2Fhummingbird-performance/tags/3.20.0&new_path=%2Fhummingbird-performance/tags/3.21.2","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?reponame=&new=3675836%40hummingbird-performance%2Ftags%2F3.21.2&old=3614991%40hummingbird-performance%2Ftags%2F3.20.0","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/65c3ca36-79e6-47f8-9524-27e7631f4caf?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-83628","sourceIdentifier":"security@wordfence.com","published":"2026-09-05T06:17:10.230","lastModified":"2026-09-05T06:17:10.230","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Theme My Login plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 7.1.15 on Multisite installations. This is due to the `tml_ms_signup_handler()` function's `gimmeanotherblog` branch failing to enforce the network's `active_signup` registration policy, checking only `is_user_logged_in()` while sibling branches such as `validate-blog-signup` apply the full policy gate. This makes it possible for authenticated attackers, with Subscriber-level access and above, to directly POST `stage=gimmeanotherblog` to Theme My Login's signup route, bypassing the configured registration policy entirely — even when it is set to `none` or `user` — which causes `wpmu_create_blog()` to execute with the attacker's user ID, after which WordPress core assigns the Administrator role on the newly created subsite via `add_user_to_blog()`. The privilege gain is scoped to the newly created subsite only; the attacker's account retains Subscriber-level access on the main site and does not obtain Super Admin or network-level capabilities such as `manage_network` or `manage_sites`."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"jfarthing84","product":"Theme My Login","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"7.1.15","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-862"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/theme-my-login/tags/7.1.15/includes/ms-functions.php#L580","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/theme-my-login/tags/7.1.15/includes/ms-functions.php#L661","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/theme-my-login/tags/7.1.15/includes/ms-functions.php#L708","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset/3669721/theme-my-login/trunk/includes/ms-functions.php","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?old_path=%2Ftheme-my-login/tags/7.1.15&new_path=%2Ftheme-my-login/tags/7.2.0","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?reponame=&new=3669722%40theme-my-login%2Ftags%2F7.2.0&old=3643898%40theme-my-login%2Ftags%2F7.1.15","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/72585c12-baa9-4c63-8584-906a1d3b332f?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-86145","sourceIdentifier":"cve@mitre.org","published":"2026-09-05T06:17:10.370","lastModified":"2026-09-05T14:17:23.897","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a size check). This outcome requires an attacker-controlled regular expression, or a recursive pattern in conjunction with a small heap limit (this can be set through the API)."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"PCRE","product":"PCRE2","defaultStatus":"unaffected","versions":[{"version":"10.32","lessThan":"10.48","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@mitre.org","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L","baseScore":8.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"LOW"},"exploitabilityScore":3.9,"impactScore":4.2}]},"weaknesses":[{"source":"cve@mitre.org","type":"Secondary","description":[{"lang":"en","value":"CWE-424"}]}],"references":[{"url":"https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48","source":"cve@mitre.org"},{"url":"https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-3r4p-g7gg-ppmf","source":"cve@mitre.org"},{"url":"http://www.openwall.com/lists/oss-security/2026/09/05/3","source":"af854a3a-2127-422b-91ae-364da2661108"}]}},{"cve":{"id":"CVE-2026-8623","sourceIdentifier":"security@wordfence.com","published":"2026-09-05T06:17:10.547","lastModified":"2026-09-05T06:17:10.547","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'post_content (class attribute of .dvcss element)' parameter in all versions up to, and including, 2.4.30 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The payload is embedded as a Base64-encoded JSON object in a CSS class name on a Custom HTML block; the frontend parseCSSElements() function decodes it client-side with atob() and JSON.parse() and renders the logo property as raw HTML, meaning no server-side or client-side sanitization intercepts the malicious script before DOM insertion."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"dearhive","product":"DearFlip – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"2.4.30","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":2.7}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/3d-flipbook-dflip-lite/tags/2.4.27/assets/js/dflip.js#L11255","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/3d-flipbook-dflip-lite/tags/2.4.27/assets/js/dflip.js#L2687","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset/3641463/3d-flipbook-dflip-lite/trunk/assets/js/dflip.js","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?old_path=%2F3d-flipbook-dflip-lite/tags/2.4.30&new_path=%2F3d-flipbook-dflip-lite/tags/2.4.37","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?reponame=&new=3641463%403d-flipbook-dflip-lite%2Ftags%2F2.4.37&old=3557511%403d-flipbook-dflip-lite%2Ftags%2F2.4.30","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/27e2848d-6271-4bb9-92e2-0f8c8860745d?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-8625","sourceIdentifier":"security@wordfence.com","published":"2026-09-05T06:17:10.690","lastModified":"2026-09-05T06:17:10.690","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'post_content (Custom HTML block inner HTML)' parameter in all versions up to, and including, 2.4.30 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. A Contributor-level attacker can insert a crafted .df-element div with data-df-lightbox='thumb' via a Custom HTML block, whose inner HTML is passed as the title argument to parseThumbs() at render time, enabling both innerHTML injection into a span element and attribute breakout via an onerror handler on a constructed img element."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"dearhive","product":"DearFlip – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"2.4.30","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":2.7}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/3d-flipbook-dflip-lite/tags/2.4.27/assets/js/dflip.js#L2712","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/3d-flipbook-dflip-lite/tags/2.4.27/assets/js/dflip.js#L2718","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/3d-flipbook-dflip-lite/tags/2.4.27/assets/js/dflip.js#L2791","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/3d-flipbook-dflip-lite/tags/2.4.27/assets/js/dflip.js#L2796","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset/3641463/3d-flipbook-dflip-lite/trunk/assets/js/dflip.js","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?old_path=%2F3d-flipbook-dflip-lite/tags/2.4.30&new_path=%2F3d-flipbook-dflip-lite/tags/2.4.37","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?reponame=&new=3641463%403d-flipbook-dflip-lite%2Ftags%2F2.4.37&old=3557511%403d-flipbook-dflip-lite%2Ftags%2F2.4.30","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/741150a3-1b2a-4b54-9dd5-992d3d7079dc?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2025-15693","sourceIdentifier":"contact@wpscan.com","published":"2026-09-05T07:17:10.343","lastModified":"2026-09-05T07:17:10.343","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The JCH Optimize WordPress plugin before 5.0.1 does not properly restrict a directory path provided to one of its administrative image-browsing features to within the site, allowing high-privilege users, administrators on single-site and sub-site administrators on multisite, to enumerate directories and file names outside the web root."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"JCH Optimize","defaultStatus":"unaffected","versions":[{"version":"4.2.1","lessThan":"5.0.1","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/73e664a8-9075-4fe6-9af4-b6f5d2ccfe3c/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2025-15694","sourceIdentifier":"contact@wpscan.com","published":"2026-09-05T07:17:10.447","lastModified":"2026-09-05T07:17:10.447","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Joli Table Of Contents WordPress plugin before 2.8.1 does not sanitise and escape some of its settings before outputting them in an admin page, which could allow high-privilege users such as administrators to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed, for example in a multisite setup."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Joli Table Of Contents","defaultStatus":"unaffected","versions":[{"version":"2.0.0","lessThan":"2.8.1","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/9ebaf1aa-eb8b-4c62-bbd0-07918503fbf1/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-14975","sourceIdentifier":"security@wordfence.com","published":"2026-09-05T07:17:10.560","lastModified":"2026-09-05T07:17:10.560","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The WP File Download plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.3.8 via the 'remoteurl' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information. An authenticated attacker with Subscriber-level access first poisons the _wpfd_file_metadata['file'] post-meta value via the unprotected file.save handler, after which the streaming endpoint — hooked on init with no authentication requirement — resolves and streams the traversed file path to any caller, including unauthenticated visitors."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"JoomUnited","product":"WP File Download","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"6.3.8","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-22"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/wp-file-download/trunk/app/site/init.php#L225","source":"security@wordfence.com"},{"url":"https://www.joomunited.com/changelog/wp-file-download-changelog","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2b99e525-c1d3-463d-8b87-b7d7fdd535d1?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-15247","sourceIdentifier":"contact@wpscan.com","published":"2026-09-05T07:17:10.693","lastModified":"2026-09-05T07:17:10.693","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Search Atlas SEO  WordPress plugin before 2.6.24 does not perform a nonce or capability check before processing a settings update in one of its early-priority handlers, allowing any authenticated user such as a Subscriber to overwrite or delete the site's stored Google service-account credentials."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Search Atlas SEO","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"2.6.24","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/1618ba19-c410-440b-a2d9-1e1526614549/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-15984","sourceIdentifier":"security@wordfence.com","published":"2026-09-05T07:17:10.793","lastModified":"2026-09-05T07:17:10.793","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The QuickCal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Custom Field Parameters in all versions up to, and including, 1.0.20 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The nonce guarding the unauthenticated booked_add_appt AJAX action is publicly embedded on any page rendering the booking calendar shortcode, making it trivially obtainable by unauthenticated attackers without any prior account or privilege."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"Themovation","product":"QuickCal","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"1.0.20","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N","baseScore":7.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":2.7}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://codecanyon.net/item/quickcal-appointment-booking-calendar-for-wordpress/47981746","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9bfcfc13-ccfb-4319-99a7-7d7510a11cfe?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-16649","sourceIdentifier":"security@wordfence.com","published":"2026-09-05T07:17:10.917","lastModified":"2026-09-05T07:17:10.917","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Post Body Field Value in all versions up to, and including, 2.10.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The exploit survives save-time sanitization because wp_kses_post allows the required HTML tags and attributes, and the client-side tooltip script re-parses the browser-decoded aria-label value as innerHTML while only stripping script elements, leaving onerror and other event-handler attributes fully intact and executable."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"Gravity Forms","product":"Gravity Forms","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"2.10.5","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N","baseScore":7.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":2.7}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://docs.gravityforms.com/gravityforms-change-log/","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/187a420d-a5a5-4b0e-945b-c5694243e68f?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-18406","sourceIdentifier":"security@wordfence.com","published":"2026-09-05T07:17:11.040","lastModified":"2026-09-05T07:17:11.040","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Text Field Entity-Encoded Payload in all versions up to, and including, 2.12.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"brainstormforce","product":"SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"2.12.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N","baseScore":7.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":2.7}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/sureforms/tags/2.12.2/assets/build/entries.js#L172","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/sureforms/tags/2.12.2/inc/form-submit.php#L1451","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/sureforms/tags/2.12.2/inc/form-submit.php#L229","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/sureforms/tags/2.12.2/inc/form-submit.php#L93","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/sureforms/tags/2.12.2/inc/helper.php#L241","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset/3635980/sureforms/trunk/inc/form-submit.php","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?old_path=%2Fsureforms/tags/2.12.2&new_path=%2Fsureforms/tags/2.12.3","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?reponame=&new=3636000%40sureforms%2Ftags%2F2.12.3&old=3618798%40sureforms%2Ftags%2F2.12.2","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8583c1f2-0820-492c-9fa1-d96e0ce2ddf2?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-18843","sourceIdentifier":"security@wordfence.com","published":"2026-09-05T07:17:11.207","lastModified":"2026-09-05T07:17:11.207","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Beaver Builder Plugin (Starter Version) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'no_results_message' node_preview Parameter in all versions up to, and including, 2.11.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"The Beaver Builder Team","product":"Beaver Builder Plugin (Starter Version)","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"2.11.0.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/074c95bb-c68e-452d-bd2e-c44866aeedba?source=cve","source":"security@wordfence.com"},{"url":"https://www.wpbeaverbuilder.com/","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-19769","sourceIdentifier":"security@wordfence.com","published":"2026-09-05T07:17:11.333","lastModified":"2026-09-05T07:17:11.333","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeater Child 'type' Confusion via Unmatched Array Key in all versions up to, and including, 3.15.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the Ninja Forms File Uploads add-on to be active, as the attack routes the unwhitelisted child entry through the File Uploads handler to write an attacker-supplied HTML file containing arbitrary JavaScript into any web-server-writable directory, including the site root, where it is served from the site's own origin."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"kstover","product":"Ninja Forms – The Contact Form Builder That Grows With You","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"3.15.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N","baseScore":7.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":2.7}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/ninja-forms/tags/3.14.11/includes/AJAX/Controllers/Submission.php#L303","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/ninja-forms/tags/3.14.11/includes/AJAX/Controllers/Submission.php#L55","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/ninja-forms/tags/3.14.11/includes/AJAX/Controllers/Submission.php#L609","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/ninja-forms/tags/3.14.11/includes/AJAX/Controllers/Submission.php#L61","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset/3674413/ninja-forms/trunk/includes/AJAX/Controllers/Submission.php","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?old_path=%2Fninja-forms/tags/3.15.1&new_path=%2Fninja-forms/tags/3.15.2","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?reponame=&new=3674413%40ninja-forms%2Ftags%2F3.15.2&old=3663678%40ninja-forms%2Ftags%2F3.15.1","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2330e381-7db3-4b79-8827-818d2ea954b5?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-19858","sourceIdentifier":"contact@wpscan.com","published":"2026-09-05T07:17:11.467","lastModified":"2026-09-05T07:17:11.467","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not perform authorisation checks when resolving request-derived data during page rendering, allowing unauthenticated users to read arbitrary user, post and term properties and metadata, including password hashes, private and draft content, and secrets other JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 store in metadata."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"JetFormBuilder — Dynamic Blocks Form Builder","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"3.6.5.2","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/a9d091f3-6887-4f26-a736-ba26a81d2b32/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-19861","sourceIdentifier":"contact@wpscan.com","published":"2026-09-05T07:17:11.563","lastModified":"2026-09-05T07:17:11.563","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not properly sanitise and escape a form field's value before including it in the HTML notification emails it sends, allowing unauthenticated users to inject arbitrary HTML into messages delivered to administrators and other recipients. Whether injected script executes depends on the recipient's mail client, but the injected markup is rendered regardless."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"JetFormBuilder — Dynamic Blocks Form Builder","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"3.6.5.2","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/c9c834a3-dc65-4972-9315-d4dcc7f26599/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-19887","sourceIdentifier":"security@wordfence.com","published":"2026-09-05T07:17:11.657","lastModified":"2026-09-05T07:17:11.657","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Welcart e-Commerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.12.1 via deserialization of untrusted input in the Telecom EDY payment callback (usces_action_acting_transaction). Unauthenticated attackers can store arbitrary 'reserve' key/value pairs as order metadata during a public checkout, then invoke the callback with an attacker-chosen 'option' parameter to select and unserialize that metadata without any provider signature, source-address, transaction-identity or ownership check. A POP chain is present in the TCPDF library bundled with the plugin itself, so no additional plugin or theme is required. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, including wp-config.php, which can lead to remote code execution when an attacker re-runs the WordPress installer against a database they control. Successful exploitation is contingent on an admin printing an invoice to trigger file deletion."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"uscnanbu","product":"Welcart e-Commerce","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"2.12.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-502"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/usc-e-shop/trunk/classes/cart.class.php#L546","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/usc-e-shop/trunk/classes/orderData.class.php#L41","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/usc-e-shop/trunk/functions/function.php#L218","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/usc-e-shop/trunk/functions/hoock_func.php#L517","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/usc-e-shop/trunk/includes/order_print.php#L16","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/usc-e-shop/trunk/pdf/tcpdf/tcpdf.php#L7794","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset/3673344/usc-e-shop/trunk/classes/orderData.class.php","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?old_path=%2Fusc-e-shop/tags/2.12.1&new_path=%2Fusc-e-shop/tags/2.12.2","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?reponame=&new=3673346%40usc-e-shop%2Ftags%2F2.12.2&old=3651925%40usc-e-shop%2Ftags%2F2.12.1","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/716a7c3c-2e26-4da9-a299-7dcbaa7e4895?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-3853","sourceIdentifier":"security@wordfence.com","published":"2026-09-05T07:17:11.803","lastModified":"2026-09-05T07:17:11.803","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Divi theme for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the `image_src` attribute of the `et_pb_video_slider_item` shortcode in all versions up to, and including, 4.27.6. This is due to the `image_src` field not being included in the `$url_options` whitelist (which only contains `url`, `button_link`, `button_url`), so it never receives `esc_url_raw()` at save time. On the server side, the value is rendered into a `data-image` HTML attribute using `esc_attr()`, which encodes double quotes as `&quot;`. However, the client-side JavaScript carousel code in `custom.unified.js` reads this attribute using jQuery's `.data('image')`, which returns the browser-decoded value (with `&quot;` decoded back to `\"`). The decoded value is then concatenated directly into an HTML string and injected into the DOM via `jQuery.after()` without re-escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user hovers over the carousel thumbnail."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"Elegant Themes","product":"Divi","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"4.27.6","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":2.7}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://www.divichangelog.com/divi-update/divi-4/version-4-27-7","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d5de8f35-266f-45ce-8678-e52a33036b30?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-4361","sourceIdentifier":"security@wordfence.com","published":"2026-09-05T07:17:11.930","lastModified":"2026-09-05T07:17:11.930","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Divi theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.27.6. This is due to the `et_pb_set_video_oembed_thumbnail_resolution()` function using `wp_remote_get()` instead of `wp_safe_remote_get()` to fetch a remote image URL, which does not restrict requests to private or reserved IP ranges. This makes it possible for authenticated attackers, with Contributor-level access and above, to make web requests to arbitrary locations originating from the web application server. The response body is not returned to the attacker (blind SSRF), but two oracles exist: a status oracle (the returned URL string differs depending on whether the target responded with HTTP 200) and a timing oracle (response time varies by target reachability)."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"Elegant Themes","product":"Divi","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"4.27.6","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N","baseScore":5.0,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":1.4}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-918"}]}],"references":[{"url":"https://www.divichangelog.com/divi-update/divi-4/version-4-27-7","source":"security@wordfence.com"},{"url":"https://www.elegantthemes.com/","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/f35c0de9-abed-4cbf-a28c-48f8133a1bad?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-77826","sourceIdentifier":"contact@wpscan.com","published":"2026-09-05T07:17:12.063","lastModified":"2026-09-05T07:17:12.063","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The RegistrationMagic  WordPress plugin before 6.0.9.9 does not verify which application a Facebook access token was issued to before accepting it as proof of identity, allowing unauthenticated attackers to log in as an existing user whose token they can obtain, or to create and log into a new account even when user registration is disabled."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"RegistrationMagic","defaultStatus":"unaffected","versions":[{"version":"5.0.1.8","lessThan":"6.0.9.9","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/b79a83e8-d7b0-4aa8-b2ba-37a7eecd437b/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-77830","sourceIdentifier":"security@wordfence.com","published":"2026-09-05T07:17:12.163","lastModified":"2026-09-05T07:17:12.163","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Spam protection, Honeypot, Anti-Spam by CleanTalk plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content aria-label Placeholder in all versions up to, and including, 6.86 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with custom-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The payload is deliverable via unauthenticated comment submission and executes exclusively for non-logged-in visitors; if comment moderation is enabled, an approving moderator must first publish the comment before the script reaches other users."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"cleantalk","product":"Spam protection, Honeypot, Anti-Spam by CleanTalk","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"6.86","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N","baseScore":7.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":2.7}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/cleantalk-spam-protect/tags/6.84/cleantalk.php#L234","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/cleantalk-spam-protect/tags/6.84/lib/Cleantalk/ApbctWP/ContactsEncoder/ContactsEncoder.php#L114","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/cleantalk-spam-protect/tags/6.84/lib/Cleantalk/Common/ContactsEncoder/ContactsEncoder.php#L914","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/cleantalk-spam-protect/tags/6.84/lib/Cleantalk/Common/ContactsEncoder/ContactsEncoder.php#L933","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/cleantalk-spam-protect/tags/6.85/cleantalk.php#L234","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/cleantalk-spam-protect/tags/6.85/lib/Cleantalk/ApbctWP/ContactsEncoder/ContactsEncoder.php#L114","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/cleantalk-spam-protect/tags/6.85/lib/Cleantalk/Common/ContactsEncoder/ContactsEncoder.php#L914","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/cleantalk-spam-protect/tags/6.85/lib/Cleantalk/Common/ContactsEncoder/ContactsEncoder.php#L933","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset/3677388/cleantalk-spam-protect/trunk/lib/Cleantalk/Common/ContactsEncoder/ContactsEncoder.php","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?old_path=%2Fcleantalk-spam-protect/tags/6.86&new_path=%2Fcleantalk-spam-protect/tags/6.87","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?reponame=&new=3677388%40cleantalk-spam-protect%2Ftags%2F6.87&old=3654120%40cleantalk-spam-protect%2Ftags%2F6.86","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/10e7000b-597a-4165-8604-cb6b29714abb?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-78149","sourceIdentifier":"contact@wpscan.com","published":"2026-09-05T07:17:12.300","lastModified":"2026-09-05T07:17:12.300","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Smart Post  WordPress plugin before 4.0.8 does not check whether a post is password protected before returning its content and its stored password through an unauthenticated AJAX action, allowing unauthenticated users to read protected post content and the password that guards it."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Smart Post","defaultStatus":"unaffected","versions":[{"version":"4.0.0","lessThan":"4.0.8","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/8140528f-27d4-485c-ad63-4dcaa3932af2/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-78150","sourceIdentifier":"contact@wpscan.com","published":"2026-09-05T07:17:12.393","lastModified":"2026-09-05T07:17:12.393","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Smart Post  WordPress plugin before 4.0.8 does not check the type, ownership or status of the post it is asked to duplicate, allowing users with contributor privileges and above to copy any private or password protected post into a draft of their own and read its content and metadata."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Smart Post","defaultStatus":"unaffected","versions":[{"version":"4.0.0","lessThan":"4.0.8","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/e6c8a115-88a2-4fdf-9b97-8ae8a8c7f0aa/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-78362","sourceIdentifier":"contact@wpscan.com","published":"2026-09-05T07:17:12.487","lastModified":"2026-09-05T07:17:12.487","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The SEO Flow by LupsOnline WordPress plugin before 3.0.3 does not correctly validate the credential supplied with its API requests, allowing unauthenticated users to be served as the administrator who configured the SEO Flow by LupsOnline WordPress plugin before 3.0.3 and take over the site. Exploitation requires the SEO Flow by LupsOnline WordPress plugin before 3.0.3 to have been configured, which is its normal operating state."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"SEO Flow by LupsOnline","defaultStatus":"unaffected","versions":[{"version":"3.0.0","lessThan":"3.0.3","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/0833424b-1231-4a48-be90-13fe4edc60c9/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-78438","sourceIdentifier":"security@wordfence.com","published":"2026-09-05T07:17:12.580","lastModified":"2026-09-05T07:17:12.580","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via LazyLoad Background Mutator in all versions up to, and including, 2.10.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the \"Lazy Load Images\" feature with \"Process background images\" to be enabled, and the malicious comment to be approved by a moderator before execution is triggered."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"boldgrid","product":"W3 Total Cache","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"2.10.5","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N","baseScore":7.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":2.7}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/w3-total-cache/tags/2.10.5/UserExperience_LazyLoad_Mutator.php#L255","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/w3-total-cache/tags/2.10.5/UserExperience_LazyLoad_Mutator.php#L293","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/w3-total-cache/tags/2.10.5/UserExperience_LazyLoad_Mutator.php#L91","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/w3-total-cache/tags/2.10.5/UserExperience_LazyLoad_Plugin.php#L87","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset/3680101/w3-total-cache/tags/2.10.6/UserExperience_LazyLoad_Mutator.php","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?old_path=%2Fw3-total-cache/tags/2.10.5&new_path=%2Fw3-total-cache/tags/2.10.6","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?reponame=&new=3680101%40w3-total-cache%2Ftags%2F2.10.6&old=3653442%40w3-total-cache%2Ftags%2F2.10.5","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5580ad05-af50-4899-9cbf-39ad8000eb6a?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-81348","sourceIdentifier":"contact@wpscan.com","published":"2026-09-05T07:17:12.710","lastModified":"2026-09-05T07:17:12.710","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The My Private Site  WordPress plugin before 4.2.3 does not apply its site-privacy access control to certain unauthenticated front-end read surfaces, allowing unauthenticated users to view post content, comments and post URLs from a site the administrator placed behind mandatory login."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"My Private Site","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"4.2.3","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/54228ea4-eec6-4752-a16e-85209d4445b0/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-81404","sourceIdentifier":"contact@wpscan.com","published":"2026-09-05T07:17:12.810","lastModified":"2026-09-05T07:17:12.810","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The IPGP Visitors Origin WordPress plugin before 1.6 does not sanitise or escape user input before reflecting it back in the HTTP response, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting attacks against users who are tricked into submitting a crafted request."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"IPGP Visitors Origin","defaultStatus":"unaffected","versions":[{"version":"1.3","lessThan":"1.6","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/8fbfb296-78d8-4f3b-ab21-7a5a4e0ea421/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-81423","sourceIdentifier":"contact@wpscan.com","published":"2026-09-05T07:17:12.900","lastModified":"2026-09-05T07:17:12.900","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Accept Stripe Payments WordPress plugin before 2.1.4 does not validate a user-supplied URL before using it in a redirect, allowing unauthenticated attackers to redirect visitors to an arbitrary external website, which can be leveraged for phishing."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Accept Stripe Payments","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"2.1.4","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/0e4bbbde-b93e-4b58-8baf-301073e9a0c5/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-81424","sourceIdentifier":"contact@wpscan.com","published":"2026-09-05T07:17:12.997","lastModified":"2026-09-05T07:17:12.997","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Accept Stripe Payments WordPress plugin before 2.1.4 does not verify that the product fulfilled when a checkout is completed matches the product the authoritative payment was actually made for, checking only that the amount paid is at least the referenced product's price, allowing unauthenticated attackers who complete a genuine payment to obtain fulfilment for a different, equal- or lower-priced product than the one they paid for."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Accept Stripe Payments","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"2.1.4","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/64c20ce4-d94d-4f09-8d95-9ba232066f62/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-82304","sourceIdentifier":"contact@wpscan.com","published":"2026-09-05T07:17:13.090","lastModified":"2026-09-05T07:17:13.090","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Music Store  WordPress plugin before 1.4.5 does not sanitise and escape user input before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Music Store","defaultStatus":"unaffected","versions":[{"version":"1.0.245","lessThan":"1.4.5","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/0a4d2ffc-a437-430e-a760-d8d7fb388f0c/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-82846","sourceIdentifier":"contact@wpscan.com","published":"2026-09-05T07:17:13.187","lastModified":"2026-09-05T07:17:13.187","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Masteriyo LMS  WordPress plugin before 3.4.0 does not sanitise and escape some course settings before outputting them in a page available to all visitors, allowing users with a course-author role to perform Stored Cross-Site Scripting attacks that run in the session of anyone viewing the course, including a logged-in administrator."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Masteriyo LMS","defaultStatus":"unaffected","versions":[{"version":"1.18.0","lessThan":"3.4.0","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/0ee2052c-90a8-4b98-947a-adc55feb1de7/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-83543","sourceIdentifier":"contact@wpscan.com","published":"2026-09-05T07:17:13.280","lastModified":"2026-09-05T07:17:13.280","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Greenshift  WordPress plugin before 13.2.0 does not validate a user-supplied URL before fetching it server-side, allowing users with contributor-level access and above to make the server issue requests to arbitrary hosts and read the response."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Greenshift","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"13.2.0","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/902e46ad-e577-4a3e-be19-a3bcc75ece77/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-83544","sourceIdentifier":"contact@wpscan.com","published":"2026-09-05T07:17:13.373","lastModified":"2026-09-05T07:17:13.373","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Greenshift  WordPress plugin before 13.2.0 does not properly escape a block animation attribute before outputting it within an HTML attribute, allowing users with contributor-level access and above to inject arbitrary web scripts that execute when the content is viewed."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Greenshift","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"13.2.0","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/f2bd202b-43fc-4ca7-9bab-649ed87e7cbd/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-84021","sourceIdentifier":"contact@wpscan.com","published":"2026-09-05T07:17:13.470","lastModified":"2026-09-05T07:17:13.470","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Bold Page Builder WordPress plugin before 5.9.8 does not properly validate a link URL before outputting it in an HTML attribute, relying on a filter that can be evaded, allowing users with the Contributor role and above to inject arbitrary web scripts that execute when a user clicks the affected link."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Bold Page Builder","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"5.9.8","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/ca226eab-59a2-42d5-96f6-84dacf7c6c5a/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-84022","sourceIdentifier":"contact@wpscan.com","published":"2026-09-05T07:17:13.573","lastModified":"2026-09-05T07:17:13.573","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Bold Page Builder WordPress plugin before 5.9.8 does not sanitise and escape several shortcode attributes before outputting them in HTML attributes, allowing users with the Contributor role and above to inject arbitrary web scripts that execute when a user views the affected page."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Bold Page Builder","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"5.9.8","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/53bbe80c-caea-4893-82a6-03e5173390de/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-84221","sourceIdentifier":"contact@wpscan.com","published":"2026-09-05T07:17:13.667","lastModified":"2026-09-05T07:17:13.667","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Kirki  WordPress plugin before 6.3.0 does not escape a user-supplied identifier before using it in a SQL query, allowing users with editor-level access and above to append arbitrary SQL and read the contents of the database, including user credentials."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Kirki","defaultStatus":"unaffected","versions":[{"version":"6.0.0","lessThan":"6.3.0","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/6c34da62-46fb-4dd4-a433-bd3df4d9fcfd/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-84225","sourceIdentifier":"contact@wpscan.com","published":"2026-09-05T07:17:13.760","lastModified":"2026-09-05T07:17:13.760","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Kirki  WordPress plugin before 6.3.0 does not check that a user is allowed to act on a collaboration comment before changing its state, allowing users whom an administrator has granted content-level access to the page builder to modify comments left by other users, including on pages they cannot themselves open."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Kirki","defaultStatus":"unaffected","versions":[{"version":"6.0.0","lessThan":"6.3.0","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/9f83f0a2-7d77-49a2-a23a-03f787e2e356/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-84745","sourceIdentifier":"contact@wpscan.com","published":"2026-09-05T07:17:13.850","lastModified":"2026-09-05T07:17:13.850","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Events Calendar WordPress plugin before 6.17.3.1 does not restrict non-public content to the users entitled to read it on its public REST archives, allowing users with a low-privilege role such as contributor to read the full contents of every unpublished record on the site, including other users'."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"The Events Calendar","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"6.17.3.1","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/cf23ee00-322c-4443-a50d-a91f90d179aa/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-84896","sourceIdentifier":"contact@wpscan.com","published":"2026-09-05T07:17:13.940","lastModified":"2026-09-05T07:17:13.940","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The King Addons for Elementor  WordPress plugin before 51.1.77 does not escape a widget display-style setting before outputting it in an HTML attribute, allowing users with Contributor-level access and above to store JavaScript that executes in the browser of any visitor to the affected page, including logged-in administrators."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"King Addons for Elementor","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"51.1.77","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/fe9ac024-53dc-48a3-99c8-1ec97c84c959/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-84898","sourceIdentifier":"contact@wpscan.com","published":"2026-09-05T07:17:14.033","lastModified":"2026-09-05T07:17:14.033","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Eventin  WordPress plugin before 4.1.21 does not properly validate a template path value before using it to include a local file, allowing users with contributor-level access and above to include and execute arbitrary local PHP files."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Eventin","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"4.1.21","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/d8dea263-5676-4e3c-9ea4-36904e1ac4d3/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-84899","sourceIdentifier":"contact@wpscan.com","published":"2026-09-05T07:17:14.127","lastModified":"2026-09-05T07:17:14.127","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The VikWidgetsLoader  WordPress plugin before 1.12.0 does not sanitise or escape a block attribute before outputting it inside an inline script, allowing users with the Contributor role to store arbitrary JavaScript that executes in the browser of any user viewing the affected post, including the administrator who reviews the pending submission."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"VikWidgetsLoader","defaultStatus":"unaffected","versions":[{"version":"1.11.0","lessThan":"1.12.0","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/4e0beb72-d73b-4802-894d-141aadbd8d4f/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-84901","sourceIdentifier":"contact@wpscan.com","published":"2026-09-05T07:17:14.227","lastModified":"2026-09-05T07:17:14.227","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Eventin  WordPress plugin before 4.1.22 does not properly check authorization on several of its event-management REST routes, allowing users with contributor-level access and above to change the site's front-page setting to an event they do not own and to create, edit and delete global event and speaker taxonomy terms they should not be able to manage."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Eventin","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"4.1.22","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/b1906fd4-82ab-435f-bb07-e8f2db402029/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-84926","sourceIdentifier":"contact@wpscan.com","published":"2026-09-05T07:17:14.317","lastModified":"2026-09-05T07:17:14.317","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The EmbedPress  WordPress plugin before 4.6.4 does not correctly restrict access to one of its Google Reviews REST routes to administrators, allowing any authenticated user with contributor-level access or above to read the site administrator's email address, a value WordPress core withholds from that role."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"EmbedPress","defaultStatus":"unaffected","versions":[{"version":"4.6.0","lessThan":"4.6.4","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/5f1bc0f2-1112-4f75-b2b6-27498e43cd4b/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-84927","sourceIdentifier":"contact@wpscan.com","published":"2026-09-05T07:17:14.410","lastModified":"2026-09-05T07:17:14.410","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The EmbedPress  WordPress plugin before 4.6.4 does not perform a sufficient authorization check on one of its Google Reviews REST API routes, allowing users with the Contributor role and above to modify a site-wide store, deleting entries an administrator configured and injecting their own, which are rendered publicly across the site."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"EmbedPress","defaultStatus":"unaffected","versions":[{"version":"4.6.0","lessThan":"4.6.4","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/12984501-5d93-4941-9e12-6bb8049bd23d/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-84930","sourceIdentifier":"contact@wpscan.com","published":"2026-09-05T07:17:14.503","lastModified":"2026-09-05T07:17:14.503","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The CatFolders Document Gallery & PDF Library WordPress plugin before 2.0.7 does not properly validate a block attribute before using it as an HTML tag name in its gallery output, allowing users with the Author role and above to inject arbitrary web scripts that execute in the browser of anyone who views the affected post."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"CatFolders Document Gallery & PDF Library","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"2.0.7","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/c38b69f2-60cb-46b3-aa81-451ac062f5c7/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-84931","sourceIdentifier":"contact@wpscan.com","published":"2026-09-05T07:17:14.600","lastModified":"2026-09-05T07:17:14.600","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Joli Table Of Contents WordPress plugin before 3.0.3 does not sanitise or escape a shortcode attribute value before outputting it inside an HTML element's attribute, allowing users with the Author role and above to inject arbitrary HTML attributes and JavaScript that execute in the browser of any user who views the post, including higher-privileged users such as administrators. This crosses a privilege boundary even on multisite, where such users are not permitted to post unfiltered HTML."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Joli Table Of Contents","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"3.0.3","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/0dc8747c-14c2-4bb2-9b99-7978ff5128f5/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-84934","sourceIdentifier":"contact@wpscan.com","published":"2026-09-05T07:17:14.690","lastModified":"2026-09-05T07:17:14.690","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The JCH Optimize WordPress plugin before 6.0.1 does not perform a capability check on one of its authenticated AJAX actions and lets the request choose which internal action runs, allowing any authenticated users such as Subscribers to import arbitrary JCH Optimize WordPress plugin before 6.0.1 settings and store a script that executes in the browser of any visitor or administrator viewing the site."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"JCH Optimize","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"6.0.1","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/d808ad17-d20e-4ee5-94f3-935c10cde772/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-84935","sourceIdentifier":"contact@wpscan.com","published":"2026-09-05T07:17:14.783","lastModified":"2026-09-05T07:17:14.783","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The HT Menu  WordPress plugin before 1.2.7 does not perform any capability or object-ownership check when saving navigation menu-item settings, and does not escape those stored settings when the menu is rendered, allowing users with minimal permissions such as Subscribers to store JavaScript that executes in the browser of any visitor, administrators included, who views the affected menu."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"HT Menu","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"1.2.7","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/10aeb456-764d-4f4d-a2c9-e357474d59c7/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-84936","sourceIdentifier":"contact@wpscan.com","published":"2026-09-05T07:17:14.873","lastModified":"2026-09-05T07:17:14.873","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The EmbedPress  WordPress plugin before 4.6.4 does not have proper authorization on a public review-loading action, allowing unauthenticated users to force the site to make repeated billable third-party API requests using the site's own configured API key, and to create an unbounded number of attacker-controlled rows in the database."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"EmbedPress","defaultStatus":"unaffected","versions":[{"version":"4.6.0","lessThan":"4.6.4","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/bd708c98-1657-423b-aa2b-14aa18307c03/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-84937","sourceIdentifier":"contact@wpscan.com","published":"2026-09-05T07:17:14.963","lastModified":"2026-09-05T07:17:14.963","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Video Player for YouTube  WordPress plugin before 2.1.0 does not properly sanitise and escape user-supplied input before using it in a SQL statement, allowing users with the Contributor role and above to perform SQL injection attacks and read arbitrary data from the database."}],"affected":[{"source":"contact@wpscan.com","affectedData":[{"vendor":"Unknown","product":"Video Player for YouTube","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"2.1.0","versionType":"semver","status":"affected"}]}]}],"metrics":{},"references":[{"url":"https://wpscan.com/vulnerability/5f81c233-8544-4a7b-a1c6-e447dc889a8d/","source":"contact@wpscan.com"}]}},{"cve":{"id":"CVE-2026-75018","sourceIdentifier":"security@wordfence.com","published":"2026-09-05T08:16:40.397","lastModified":"2026-09-05T08:16:40.397","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Custom Contact Forms plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.16. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-level access and above, to permanently force-delete arbitrary posts of any post type (including pages, administrator-authored posts, and WooCommerce products) and write arbitrary ccf_field_* post meta onto any post regardless of ownership or post type. The top-level form ID is checked via edit_post/publish_posts, but the nested fields[].ID and choices[].ID paths processed by _create_and_map_fields() and _create_and_map_choices() carry no equivalent capability or post-type guard, leaving those sinks fully exposed while delete_item() and delete_submission() contain explicit post-type restriction fixes demonstrating the developer's awareness of scoping requirements."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"outlawgt","product":"Custom Contact Forms","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"7.16","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-862"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/custom-contact-forms/tags/7.15.0/classes/class-ccf-api-form-controller.php#L1026","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/custom-contact-forms/tags/7.15.0/classes/class-ccf-api-form-controller.php#L291","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/custom-contact-forms/tags/7.15.0/classes/class-ccf-api-form-controller.php#L336","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/custom-contact-forms/tags/7.15.0/classes/class-ccf-api-form-controller.php#L360","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/custom-contact-forms/tags/7.15.0/classes/class-ccf-api-form-controller.php#L977","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/custom-contact-forms/tags/7.15.0/classes/class-ccf-api-form-controller.php#L993","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/custom-contact-forms/tags/7.15.2/classes/class-ccf-api-form-controller.php#L1026","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/custom-contact-forms/tags/7.15.2/classes/class-ccf-api-form-controller.php#L291","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/custom-contact-forms/tags/7.15.2/classes/class-ccf-api-form-controller.php#L336","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/custom-contact-forms/tags/7.15.2/classes/class-ccf-api-form-controller.php#L360","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/custom-contact-forms/tags/7.15.2/classes/class-ccf-api-form-controller.php#L977","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/custom-contact-forms/tags/7.15.2/classes/class-ccf-api-form-controller.php#L993","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?reponame=&old=3669565%40custom-contact-forms&new=3669565%40custom-contact-forms","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/9a34ec54-7629-4c14-b5e0-d47f5d3a72ce?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-75586","sourceIdentifier":"security@wordfence.com","published":"2026-09-05T08:16:40.600","lastModified":"2026-09-05T08:16:40.600","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'formData[id]' Parameter in all versions up to, and including, 2.0.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. The front-end AJAX handler is registered on the public 'wp' action with no nonce, capability, or referer check, and the raw attacker-controlled id value is interpolated verbatim into an exception message that is echoed back without escaping; when the response is served as text/html rather than application/json, the browser parses the injected markup."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"unitecms","product":"Unlimited Elements For Elementor","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"2.0.17","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/unlimited-elements-for-elementor/trunk/inc_php/framework/helper_base.class.php#L44","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/unlimited-elements-for-elementor/trunk/inc_php/unitecreator_filters_process.class.php#L4083","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/unlimited-elements-for-elementor/trunk/inc_php/unitecreator_form.class.php#L1159","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/unlimited-elements-for-elementor/trunk/inc_php/unitecreator_form.class.php#L179","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/unlimited-elements-for-elementor/trunk/provider/core/unlimited_elements/helper_provider_core.class.php#L746","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/522bdd65-8077-4cd4-800a-e6ef9a982d33?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-81543","sourceIdentifier":"security@wordfence.com","published":"2026-09-05T08:16:40.730","lastModified":"2026-09-05T08:16:40.730","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Abandoned Cart Pro for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10.7.1. This is due to missing capability checks and nonce verification on multiple AJAX actions including wcap_save_connector_settings, wcap_send_manual_email, wcap_abandoned_cart_info, and wcap_change_manual_email_data. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify SMTP connector settings to route administrator recovery emails through an attacker-controlled server and intercept auto-login links to gain full administrative access. The plugin's auto-login feature must be enabled, which is the default configuration."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"Tyche Softwares","product":"Abandoned Cart Pro for WooCommerce","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"10.7.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-269"}]}],"references":[{"url":"https://woocommerce.com/products/abandoned-cart-pro/","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b8d8aa73-2e68-4353-a603-6fb61ab3406b?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-83625","sourceIdentifier":"security@wordfence.com","published":"2026-09-05T08:16:40.857","lastModified":"2026-09-05T08:16:40.857","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Contact Form by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via IP Address Header in all versions up to, and including, 1.10.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. An unauthenticated attacker can first call the 'updateNonce' action — which is accessible without authentication due to its absence from the plugin's permission list — to obtain a valid nonce, then submit a contact form with a malicious payload in a spoofed IP header such as X-Forwarded-For."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"supsysticcom","product":"Contact Form by Supsystic","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"1.10.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N","baseScore":7.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":2.7}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/contact-form-by-supsystic/tags/1.10.2/classes/utils.php#L77","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/contact-form-by-supsystic/tags/1.10.2/modules/forms/controller.php#L390","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/contact-form-by-supsystic/tags/1.10.2/modules/forms/controller.php#L411","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/contact-form-by-supsystic/tags/1.10.2/modules/forms/js/admin.forms.contacts.list.js#L204","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/contact-form-by-supsystic/tags/1.10.2/modules/forms/models/forms.php#L103","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/contact-form-by-supsystic/tags/1.8.1/classes/utils.php#L77","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/contact-form-by-supsystic/tags/1.8.1/modules/forms/controller.php#L390","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/contact-form-by-supsystic/tags/1.8.1/modules/forms/controller.php#L411","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/contact-form-by-supsystic/tags/1.8.1/modules/forms/js/admin.forms.contacts.list.js#L204","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/contact-form-by-supsystic/tags/1.8.1/modules/forms/models/forms.php#L103","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?reponame=&old=3679442%40contact-form-by-supsystic&new=3679442%40contact-form-by-supsystic","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/aa65bced-a449-4ba5-accf-40a824ee464d?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-85414","sourceIdentifier":"security@wordfence.com","published":"2026-09-05T08:16:40.993","lastModified":"2026-09-05T08:16:40.993","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Gallery : FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'custom_settings' Shortcode Attribute in all versions up to, and including, 3.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"fooplugins","product":"Gallery : FooGallery","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"3.3.2","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":2.7}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/foogallery/tags/3.2.6/assets/js/foogallery.4cc6f51b.js#L6599","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/foogallery/tags/3.2.6/assets/js/foogallery.4cc6f51b.js#L7367","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/foogallery/tags/3.2.6/assets/js/foogallery.4cc6f51b.js#L8048","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/foogallery/tags/3.2.6/includes/class-gallery-advanced-settings.php#L138","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/foogallery/tags/3.2.6/includes/functions.php#L301","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/foogallery/trunk/assets/js/foogallery.4cc6f51b.js#L6599","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/foogallery/trunk/assets/js/foogallery.4cc6f51b.js#L7367","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/foogallery/trunk/assets/js/foogallery.4cc6f51b.js#L8048","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/foogallery/trunk/includes/class-gallery-advanced-settings.php#L138","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/foogallery/trunk/includes/functions.php#L301","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset/3680965/foogallery","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/859e78cd-3dfe-41b9-86dd-6f9db319cad8?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2024-11080","sourceIdentifier":"security@wordfence.com","published":"2026-09-05T09:16:48.880","lastModified":"2026-09-05T09:16:48.880","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to Unauthenticated Hook Injection in versions 2.2.32 to 2.3.1 via several functions in the ~/includes/blocks/form-wrap/function.php file. This makes it possible for unauthenticated attackers to execute actions with hooks in WordPress, granted no other security controls are present in the function."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"pickplugins","product":"Post Grid","defaultStatus":"unaffected","versions":[{"version":"2.2.85","lessThanOrEqual":"2.3.32","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-94"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/post-grid/trunk/includes/blocks/form-wrap/functions.php#L116","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/post-grid/trunk/includes/blocks/form-wrap/functions.php#L262","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/post-grid/trunk/includes/blocks/form-wrap/functions.php#L3249","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ec8666d4-042e-4cf4-86f5-474a69d90ff6?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-76573","sourceIdentifier":"security@wordfence.com","published":"2026-09-05T09:16:50.010","lastModified":"2026-09-05T09:16:50.010","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'not_found' Shortcode Attribute in all versions up to, and including, 3.3.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page."}],"affected":[{"source":"security@wordfence.com","affectedData":[{"vendor":"sc0ttkclark","product":"Pods – Custom Content Types and Fields","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"3.3.9.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":2.7}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/pods/tags/3.3.9.1/classes/PodsInit.php#L514","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/pods/tags/3.3.9.1/includes/general.php#L1399","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/pods/tags/3.3.9.1/includes/general.php#L2535","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/pods/tags/3.3.9.1/includes/general.php#L2539","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?reponame=&old=3674726%40pods&new=3674726%40pods","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/82ca2dfc-a820-49d7-bb73-38dbb8406841?source=cve","source":"security@wordfence.com"}]}},{"cve":{"id":"CVE-2026-86111","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-05T10:16:40.963","lastModified":"2026-09-05T10:16:40.963","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"BookWyrm through 0.9.1 fails to validate user visibility permissions in the status edit endpoint, allowing authenticated attackers to read followers-only and direct-message reviews by enumerating sequential status IDs. Attackers can access the raw content of restricted statuses through the edit view, bypassing the privacy protections documented for these message types."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"bookwyrm-social","product":"bookwyrm","defaultStatus":"unaffected","repo":"https://github.com/bookwyrm-social/bookwyrm","packageURL":"pkg:github/bookwyrm-social/bookwyrm","versions":[{"version":"0","lessThanOrEqual":"0.9.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Primary","description":[{"lang":"en","value":"CWE-639"}]}],"references":[{"url":"https://github.com/bookwyrm-social/bookwyrm","source":"disclosure@vulncheck.com"},{"url":"https://github.com/bookwyrm-social/bookwyrm/blob/v0.9.1/bookwyrm/templates/snippets/create_status/content_field.html","source":"disclosure@vulncheck.com"},{"url":"https://github.com/bookwyrm-social/bookwyrm/blob/v0.9.1/bookwyrm/views/status.py","source":"disclosure@vulncheck.com"},{"url":"https://github.com/geo-chen/oss/blob/main/bookwyrm.md#finding-1-authenticated-idor-in-editstatus-exposes-private-review-comment-and-quotation-content","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/bookwyrm-through-0.9.1-insecure-direct-object-reference-in-editstatus-exposes-followers-only-and-direct-statuses","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-86112","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-05T10:16:42.130","lastModified":"2026-09-05T10:16:42.130","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"BookWyrm through 0.9.1 fails to validate user visibility permissions in the Favorite and Unfavorite views, allowing authenticated attackers to favorite or unfavorite followers-only and direct statuses they cannot access. Attackers can POST to the favorite endpoint with a status ID to create unauthorized interactions, trigger ActivityPub broadcasts, and enumerate private status IDs through response differentiation."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"bookwyrm-social","product":"bookwyrm","defaultStatus":"unaffected","repo":"https://github.com/bookwyrm-social/bookwyrm","packageURL":"pkg:github/bookwyrm-social/bookwyrm","versions":[{"version":"0","lessThanOrEqual":"0.9.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.5}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Primary","description":[{"lang":"en","value":"CWE-639"}]}],"references":[{"url":"https://github.com/bookwyrm-social/bookwyrm","source":"disclosure@vulncheck.com"},{"url":"https://github.com/bookwyrm-social/bookwyrm/blob/v0.9.1/bookwyrm/views/interaction.py","source":"disclosure@vulncheck.com"},{"url":"https://github.com/geo-chen/oss/blob/main/bookwyrm.md#finding-2-authenticated-idor-in-favoriteunfavorite-allows-interaction-with-private-statuses","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/bookwyrm-through-0.9.1-missing-authorization-on-the-favorite-and-unfavorite-endpoints","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-86113","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-05T10:16:42.273","lastModified":"2026-09-05T10:16:42.273","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"BookWyrm through 0.9.1 contains an authorization bypass vulnerability in the edit_readthrough function that allows authenticated users to modify other users' reading records. Attackers can exploit sequential ReadThrough IDs to overwrite arbitrary users' start dates, finish dates, progress, and progress mode, affecting reading statistics and exported data."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"bookwyrm-social","product":"bookwyrm","defaultStatus":"unaffected","repo":"https://github.com/bookwyrm-social/bookwyrm","packageURL":"pkg:github/bookwyrm-social/bookwyrm","versions":[{"version":"0","lessThanOrEqual":"0.9.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Primary","description":[{"lang":"en","value":"CWE-639"}]}],"references":[{"url":"https://github.com/bookwyrm-social/bookwyrm","source":"disclosure@vulncheck.com"},{"url":"https://github.com/bookwyrm-social/bookwyrm/blob/v0.9.1/bookwyrm/views/status.py","source":"disclosure@vulncheck.com"},{"url":"https://github.com/geo-chen/oss/blob/main/bookwyrm.md#finding-3-authenticated-idor-in-edit-readthrough-allows-tampering-with-other-users-reading-progress","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/bookwyrm-through-0.9.1-insecure-direct-object-reference-in-edit-readthrough-allows-tampering-with-other-users-reading-records","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-86114","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-05T10:16:42.423","lastModified":"2026-09-05T10:16:42.423","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Arcane versions before 2.0.0 fail to properly restrict template operations, allowing default user role accounts to create, modify, and delete compose templates including instance-wide defaults. Attackers can inject malicious container configurations with privileged settings or host path mounts that execute with administrative privileges when deployed by administrators."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"getarcaneapp","product":"arcane","defaultStatus":"unaffected","repo":"https://github.com/getarcaneapp/arcane","packageURL":"pkg:github/getarcaneapp/arcane","versions":[{"version":"1.19.1","lessThan":"2.0.0","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Primary","description":[{"lang":"en","value":"CWE-862"}]}],"references":[{"url":"https://github.com/geo-chen/oss/blob/main/arcane.md","source":"disclosure@vulncheck.com"},{"url":"https://github.com/getarcaneapp/arcane","source":"disclosure@vulncheck.com"},{"url":"https://github.com/getarcaneapp/arcane/blob/v1.19.5/backend/api/handlers/templates.go","source":"disclosure@vulncheck.com"},{"url":"https://github.com/getarcaneapp/arcane/commit/1500646aa91f","source":"disclosure@vulncheck.com"},{"url":"https://github.com/getarcaneapp/arcane/releases/tag/v2.0.0","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/arcane-before-2.0.0-missing-administrator-authorization-on-the-compose-template-mutation-endpoints","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-86115","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-05T10:16:42.567","lastModified":"2026-09-05T10:16:42.567","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Sim before 0.8.14 classifies tool requests as internal based on URL prefix matching without scheme normalization, skipping SSRF validation and minting internal authentication tokens. Authenticated workflow authors can bypass external URL validation by supplying paths starting with /api/ in HTTP blocks to reach internal-only endpoints like POST /api/function/execute."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"simstudioai","product":"sim","defaultStatus":"unaffected","repo":"https://github.com/simstudioai/sim","packageURL":"pkg:github/simstudioai/sim","versions":[{"version":"0","lessThan":"0.8.14","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"LOW","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N","baseScore":5.0,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":1.4}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Primary","description":[{"lang":"en","value":"CWE-441"}]}],"references":[{"url":"https://github.com/geo-chen/oss/blob/main/sim.md","source":"disclosure@vulncheck.com"},{"url":"https://github.com/simstudioai/sim","source":"disclosure@vulncheck.com"},{"url":"https://github.com/simstudioai/sim/blob/v0.8.13/apps/sim/lib/auth/hybrid.ts","source":"disclosure@vulncheck.com"},{"url":"https://github.com/simstudioai/sim/blob/v0.8.13/apps/sim/tools/index.ts","source":"disclosure@vulncheck.com"},{"url":"https://github.com/simstudioai/sim/pull/7179","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/sim-before-0.8.14-confused-deputy-in-tool-url-routing-mints-an-internal-token-for-a-user-supplied-api-path","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-86116","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-05T10:16:42.713","lastModified":"2026-09-05T10:16:42.713","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Metabase versions before 0.63.1 fail to enforce data analyst permission checks on glossary API endpoints, allowing any authenticated user to create, modify, and delete glossary entries. Attackers can submit requests to POST, PUT, and DELETE glossary endpoints to tamper with instance-wide business glossary data without proper authorization."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"metabase","product":"metabase","defaultStatus":"unaffected","repo":"https://github.com/metabase/metabase","packageURL":"pkg:github/metabase/metabase","versions":[{"version":"0.57.0","lessThan":"0.63.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Primary","description":[{"lang":"en","value":"CWE-862"}]}],"references":[{"url":"https://github.com/geo-chen/oss/blob/main/metabase.md","source":"disclosure@vulncheck.com"},{"url":"https://github.com/metabase/metabase","source":"disclosure@vulncheck.com"},{"url":"https://github.com/metabase/metabase/blob/v0.62.1/src/metabase/glossary/api.clj","source":"disclosure@vulncheck.com"},{"url":"https://github.com/metabase/metabase/commit/0a0589299cfd","source":"disclosure@vulncheck.com"},{"url":"https://github.com/metabase/metabase/releases/tag/v0.63.1","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/metabase-before-0.63.1-missing-function-level-authorization-on-the-glossary-management-api","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-86117","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-05T10:16:42.860","lastModified":"2026-09-05T10:16:42.860","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Coolify through 4.3.17 contains an authentication bypass vulnerability in the OAuth callback handler that signs users into existing accounts based solely on email address without verifying provider assertions or binding OAuth identities. Attackers can register a victim's email address on any enabled OAuth provider to obtain authenticated sessions as that user, bypassing password requirements and two-factor authentication."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"coollabsio","product":"coolify","defaultStatus":"unaffected","repo":"https://github.com/coollabsio/coolify","packageURL":"pkg:github/coollabsio/coolify","versions":[{"version":"0","lessThanOrEqual":"4.3.17","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":9.2,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"HIGH","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.2,"impactScore":5.9}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Primary","description":[{"lang":"en","value":"CWE-287"}]}],"references":[{"url":"https://github.com/coollabsio/coolify","source":"disclosure@vulncheck.com"},{"url":"https://github.com/coollabsio/coolify/blob/v4.3.17/app/Http/Controllers/OauthController.php","source":"disclosure@vulncheck.com"},{"url":"https://github.com/coollabsio/coolify/blob/v4.3.17/routes/web.php","source":"disclosure@vulncheck.com"},{"url":"https://github.com/geo-chen/oss/blob/main/coolify.md","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/coolify-through-4.3.17-oauth-account-takeover-via-unverified-email-matching","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-86118","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-05T10:16:43.007","lastModified":"2026-09-05T10:16:43.007","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"gonic versions before 0.22.0 fail to validate administrator privileges in the startScan endpoint, allowing any authenticated user to trigger media library rescans. Attackers can repeatedly call the startScan endpoint to force CPU and I/O-intensive filesystem operations, causing denial of service on multi-user instances."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"sentriz","product":"gonic","defaultStatus":"unaffected","repo":"https://github.com/sentriz/gonic","packageURL":"pkg:golang/go.senan.xyz/gonic","versions":[{"version":"0","lessThan":"0.22.0","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"LOW","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":1.4}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Primary","description":[{"lang":"en","value":"CWE-862"}]}],"references":[{"url":"https://github.com/sentriz/gonic","source":"disclosure@vulncheck.com"},{"url":"https://github.com/sentriz/gonic/blob/v0.21.0/server/ctrlsubsonic/ctrl.go","source":"disclosure@vulncheck.com"},{"url":"https://github.com/sentriz/gonic/blob/v0.21.0/server/ctrlsubsonic/handlers_common.go","source":"disclosure@vulncheck.com"},{"url":"https://github.com/sentriz/gonic/releases/tag/v0.22.0","source":"disclosure@vulncheck.com"},{"url":"https://github.com/sentriz/gonic/security/advisories/GHSA-453r-pgfw-h3pq","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/gonic-before-0.22.0-missing-administrator-check-on-the-subsonic-startscan-endpoint","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-86119","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-05T10:16:43.157","lastModified":"2026-09-05T10:16:43.157","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Webstudio through 0.296.0 contains an unauthenticated server-side request forgery vulnerability in the /cgi/image, /cgi/video, and /cgi/asset proxy routes when RESIZE_ORIGIN environment variable is unset. Attackers can supply arbitrary URLs to these endpoints to read cloud instance metadata, access internal services, and perform network reconnaissance on the instance infrastructure."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"webstudio-is","product":"webstudio","defaultStatus":"unaffected","repo":"https://github.com/webstudio-is/webstudio","packageURL":"pkg:github/webstudio-is/webstudio","versions":[{"version":"0","lessThanOrEqual":"0.296.0","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":9.2,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"HIGH","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N","baseScore":8.6,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":4.0}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Primary","description":[{"lang":"en","value":"CWE-918"}]}],"references":[{"url":"https://github.com/webstudio-is/webstudio","source":"disclosure@vulncheck.com"},{"url":"https://github.com/webstudio-is/webstudio/blob/55920c57c4d3e128a0fa48fceabbbc3a1d73f1ef/apps/builder/app/routes/cgi.asset.$.ts","source":"disclosure@vulncheck.com"},{"url":"https://github.com/webstudio-is/webstudio/blob/55920c57c4d3e128a0fa48fceabbbc3a1d73f1ef/apps/builder/app/routes/cgi.image.$.ts","source":"disclosure@vulncheck.com"},{"url":"https://github.com/webstudio-is/webstudio/blob/55920c57c4d3e128a0fa48fceabbbc3a1d73f1ef/apps/builder/app/routes/cgi.video.$.ts","source":"disclosure@vulncheck.com"},{"url":"https://github.com/webstudio-is/webstudio/issues/5816","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/webstudio-through-0.296.0-ssrf-via-cgi-proxy-routes","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-86120","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-05T10:16:43.307","lastModified":"2026-09-05T10:16:43.307","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"APITable through 1.13.0-beta.1 contains an incorrect authorization vulnerability in NodePermissionGuard that fails to enforce node-level access control when permission lookups throw exceptions. Attackers with valid Fusion API tokens can write attachments to private datasheets they have been explicitly denied access to by exploiting the unhandled exception in the permission guard."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"apitable","product":"apitable","defaultStatus":"unaffected","repo":"https://github.com/apitable/apitable","packageURL":"pkg:github/apitable/apitable","versions":[{"version":"0","lessThanOrEqual":"1.13.0-beta.1","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Primary","description":[{"lang":"en","value":"CWE-636"}]}],"references":[{"url":"https://github.com/apitable/apitable","source":"disclosure@vulncheck.com"},{"url":"https://github.com/apitable/apitable/blob/88b24ce9f359/packages/room-server/src/fusion/middleware/guard/node.permission.guard.ts","source":"disclosure@vulncheck.com"},{"url":"https://github.com/apitable/apitable/issues/1814","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/apitable-through-1.13.0-beta.1-fail-open-authorization-in-the-fusion-api-node-permission-guard","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-86121","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-05T10:16:43.463","lastModified":"2026-09-05T10:16:43.463","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Cua computer-server versions before 0.3.42 skip authentication when the CONTAINER_NAME environment variable is unset and bind to all interfaces by default, allowing unauthenticated attackers to execute arbitrary commands. Attackers can reach TCP port 8000 to run shell commands via the run_command endpoint, read and write arbitrary files through file operation endpoints, and access interactive PTY shells without authentication."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"trycua","product":"cua-computer-server","defaultStatus":"unaffected","repo":"https://github.com/trycua/cua","packageURL":"pkg:pypi/cua-computer-server","versions":[{"version":"0","lessThan":"0.3.42","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":9.3,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Primary","description":[{"lang":"en","value":"CWE-306"}]}],"references":[{"url":"https://github.com/trycua/cua","source":"disclosure@vulncheck.com"},{"url":"https://github.com/trycua/cua/blob/10a2e71792db/libs/python/computer-server/computer_server/cli.py","source":"disclosure@vulncheck.com"},{"url":"https://github.com/trycua/cua/blob/10a2e71792db/libs/python/computer-server/computer_server/main.py","source":"disclosure@vulncheck.com"},{"url":"https://github.com/trycua/cua/commit/59cf25c0ec54","source":"disclosure@vulncheck.com"},{"url":"https://github.com/trycua/cua/issues/1892","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/cua-computer-server-before-0.3.42-unauthenticated-rce-via-desktop-control","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-86122","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-05T10:16:43.610","lastModified":"2026-09-05T10:16:43.610","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"Rowboat through 0.9.1 fails to validate custom MCP server and webhook URLs, allowing authenticated users to configure arbitrary destinations. Attackers can point these URLs at internal services and cloud metadata endpoints to perform server-side request forgery and enumerate internal network topology."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"rowboatlabs","product":"rowboat","defaultStatus":"unaffected","repo":"https://github.com/rowboatlabs/rowboat","packageURL":"pkg:github/rowboatlabs/rowboat","versions":[{"version":"0","lessThanOrEqual":"0.9.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"LOW","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N","baseScore":5.0,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":1.4}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Primary","description":[{"lang":"en","value":"CWE-918"}]}],"references":[{"url":"https://github.com/rowboatlabs/rowboat","source":"disclosure@vulncheck.com"},{"url":"https://github.com/rowboatlabs/rowboat/blob/v0.9.1/apps/rowboat/src/application/lib/agents-runtime/agent-tools.ts","source":"disclosure@vulncheck.com"},{"url":"https://github.com/rowboatlabs/rowboat/blob/v0.9.1/apps/rowboat/src/application/use-cases/projects/add-custom-mcp-server.use-case.ts","source":"disclosure@vulncheck.com"},{"url":"https://github.com/rowboatlabs/rowboat/issues/621","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/rowboat-through-0.9.1-server-side-request-forgery-via-custom-mcp-server","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-86123","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-05T10:16:43.750","lastModified":"2026-09-05T10:16:43.750","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"SQL Chat contains four unauthenticated API endpoints that accept client-supplied database connection parameters and execute arbitrary SQL queries against attacker-specified hosts. Attackers can connect to internal databases, execute SQL commands, enumerate schemas, and pivot into the server's network without authentication."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"sqlchat","product":"sqlchat","defaultStatus":"unaffected","repo":"https://github.com/sqlchat/sqlchat","packageURL":"pkg:github/sqlchat/sqlchat","versions":[{"version":"0","lessThanOrEqual":"665af875413affadfeefff81794f1d7758782bc2","versionType":"git","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":9.4,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"HIGH","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"HIGH","subIntegrityImpact":"HIGH","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":5.8}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Primary","description":[{"lang":"en","value":"CWE-918"}]}],"references":[{"url":"https://github.com/sqlchat/sqlchat","source":"disclosure@vulncheck.com"},{"url":"https://github.com/sqlchat/sqlchat/blob/665af875413affadfeefff81794f1d7758782bc2/src/pages/api/connection/execute.ts","source":"disclosure@vulncheck.com"},{"url":"https://github.com/sqlchat/sqlchat/blob/665af875413affadfeefff81794f1d7758782bc2/src/pages/api/connection/test.ts","source":"disclosure@vulncheck.com"},{"url":"https://github.com/sqlchat/sqlchat/issues/189","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/sql-chat-unauthenticated-database-connection-proxy-in-the-api-connection-endpoints","source":"disclosure@vulncheck.com"}]}},{"cve":{"id":"CVE-2026-86124","sourceIdentifier":"disclosure@vulncheck.com","published":"2026-09-05T10:16:43.900","lastModified":"2026-09-05T10:16:43.900","vulnStatus":"Received","cveTags":[],"descriptions":[{"lang":"en","value":"AutoAgent contains an unauthenticated remote code execution vulnerability in the TCP server that binds to all interfaces and executes attacker-supplied commands as root. Attackers can connect to the exposed communication port and execute arbitrary bash commands within the container, gaining access to bind-mounted host workspace directories."}],"affected":[{"source":"disclosure@vulncheck.com","affectedData":[{"vendor":"HKUDS","product":"AutoAgent","defaultStatus":"unaffected","repo":"https://github.com/HKUDS/AutoAgent","packageURL":"pkg:github/HKUDS/AutoAgent","versions":[{"version":"0","lessThanOrEqual":"16c12b052ef2330a198063c62a07a7f9723031e3","versionType":"git","status":"affected"}]}]}],"metrics":{"cvssMetricV40":[{"source":"disclosure@vulncheck.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":9.3,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"disclosure@vulncheck.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}]},"weaknesses":[{"source":"disclosure@vulncheck.com","type":"Primary","description":[{"lang":"en","value":"CWE-306"}]}],"references":[{"url":"https://github.com/HKUDS/AutoAgent","source":"disclosure@vulncheck.com"},{"url":"https://github.com/HKUDS/AutoAgent/blob/16c12b052ef2330a198063c62a07a7f9723031e3/autoagent/environment/docker_env.py","source":"disclosure@vulncheck.com"},{"url":"https://github.com/HKUDS/AutoAgent/blob/16c12b052ef2330a198063c62a07a7f9723031e3/autoagent/environment/tcp_server.py","source":"disclosure@vulncheck.com"},{"url":"https://github.com/HKUDS/AutoAgent/issues/96","source":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/autoagent-unauthenticated-remote-code-execution-via-the-sandbox-tcp-command-server","source":"disclosure@vulncheck.com"}]}}]}