<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Ionic Framework</title>
  <link>https://cvedaily.com/pages/tags/ionic.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/ionic.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Ionic Framework</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:48 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2025-62627 – An untrusted pointer dereference in the ionic cloud driver for VMWare ESXi could...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62627</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62627</guid>
    <pubDate>Wed, 13 May 2026 04:17:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-62627</strong></p>
  <p>An untrusted pointer dereference in the ionic cloud driver for VMWare ESXi could allow an attacker with an unprivileged VM to read kernel memory or co-located guest VM memory, potentially resulting in loss of confidentiality or availability.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-822</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62627">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-62624 – A heap-based buffer overflow in the ionic cloud driver for VMware ESXi could all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62624</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62624</guid>
    <pubDate>Wed, 13 May 2026 04:17:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-62624</strong></p>
  <p>A heap-based buffer overflow in the ionic cloud driver for VMware ESXi could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62624">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-62623 – A heap-based buffer overflow in the ionic cloud driver for VMware ESXi could all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62623</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62623</guid>
    <pubDate>Wed, 13 May 2026 04:17:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-62623</strong></p>
  <p>A heap-based buffer overflow in the ionic cloud driver for VMware ESXi could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62623">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-43282 – In the Linux kernel, the following vulnerability has been resolved:

RDMA/ionic:...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43282</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43282</guid>
    <pubDate>Wed, 06 May 2026 12:16:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-43282</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  RDMA/ionic: Fix potential NULL pointer dereference in ionic_query_port  The function ionic_query_port() calls ib_device_get_netdev() without checking the return value which could lead to NULL pointer dereference, Fix it by checking the return value and return -ENODEV if the 'ndev' is NULL.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43282">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-23384 – In the Linux kernel, the following vulnerability has been resolved:

RDMA/ionic:...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23384</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23384</guid>
    <pubDate>Wed, 25 Mar 2026 11:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-23384</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  RDMA/ionic: Fix kernel stack leak in ionic_create_cq()  struct ionic_cq_resp resp {     __u32 cqid[2];         // offset 0 - PARTIALLY SET (see below)     __u8  udma_mask;       // offset 8 - SET (resp.udma_mask = vcq->udma_mask)     __u8  rsvd[7];         // offset 9 - NEVER SET <- LEAK };  rsvd[7]: 7 bytes of stack memory leak…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-401</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23384">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Unknown] CVE-2023-53994 – In the Linux kernel, the following vulnerability has been resolved:

ionic: remo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-53994</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-53994</guid>
    <pubDate>Wed, 24 Dec 2025 11:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk unknown">Unknown</span> CVE-2023-53994</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  ionic: remove WARN_ON to prevent panic_on_warn  Remove unnecessary early code development check and the WARN_ON that it uses.  The irq alloc and free paths have long been cleaned up and this check shouldn't have stuck around so long.</p>
  <p><strong>CVSS:</strong> N/A · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-53994">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-53470 – In the Linux kernel, the following vulnerability has been resolved:

ionic: catc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-53470</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-53470</guid>
    <pubDate>Wed, 01 Oct 2025 12:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-53470</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  ionic: catch failure from devlink_alloc  Add a check for NULL on the alloc return.  If devlink_alloc() fails and we try to use devlink_priv() on the NULL return, the kernel gets very unhappy and panics. With this fix, the driver load will still fail, but at least it won't panic the kernel.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-53470">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-56715 – In the Linux kernel, the following vulnerability has been resolved:

ionic: Fix ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-56715</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-56715</guid>
    <pubDate>Sun, 29 Dec 2024 09:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-56715</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  ionic: Fix netdev notifier unregister on failure  If register_netdev() fails, then the driver leaks the netdev notifier. Fix this by calling ionic_lif_unregister() on register_netdev() failure. This will also call ionic_lif_unregister_phc() if it has already been registered.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-401</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-56715">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-56714 – In the Linux kernel, the following vulnerability has been resolved:

ionic: no d...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-56714</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-56714</guid>
    <pubDate>Sun, 29 Dec 2024 09:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-56714</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  ionic: no double destroy workqueue  There are some FW error handling paths that can cause us to try to destroy the workqueue more than once, so let's be sure we're checking for that.  The case where this popped up was in an AER event where the handlers got called in such a way that ionic_reset_prepare() and thus ionic_dev_teardo…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-56714">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-42083 – In the Linux kernel, the following vulnerability has been resolved:

ionic: fix ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-42083</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-42083</guid>
    <pubDate>Mon, 29 Jul 2024 16:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-42083</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  ionic: fix kernel panic due to multi-buffer handling  Currently, the ionic_run_xdp() doesn't handle multi-buffer packets properly for XDP_TX and XDP_REDIRECT. When a jumbo frame is received, the ionic_run_xdp() first makes xdp frame with all necessary pages in the rx descriptor. And if the action is either XDP_TX or XDP_REDIRECT…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-42083">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-42071 – In the Linux kernel, the following vulnerability has been resolved:

ionic: use ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-42071</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-42071</guid>
    <pubDate>Mon, 29 Jul 2024 16:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-42071</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  ionic: use dev_consume_skb_any outside of napi  If we're not in a NAPI softirq context, we need to be careful about how we call napi_consume_skb(), specifically we need to call it with budget==0 to signal to it that we're not in a safe context.  This was found while running some configuration stress testing of traffic and a chan…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-834</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-42071">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-40907 – In the Linux kernel, the following vulnerability has been resolved:

ionic: fix ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-40907</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-40907</guid>
    <pubDate>Fri, 12 Jul 2024 13:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-40907</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  ionic: fix kernel panic in XDP_TX action  In the XDP_TX path, ionic driver sends a packet to the TX path with rx page and corresponding dma address. After tx is done, ionic_tx_clean() frees that page. But RX ring buffer isn't reset to NULL. So, it uses a freed page, which causes kernel panic.  BUG: unable to handle page fault fo…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-40907">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-39502 – In the Linux kernel, the following vulnerability has been resolved:

ionic: fix ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-39502</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-39502</guid>
    <pubDate>Fri, 12 Jul 2024 13:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-39502</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  ionic: fix use after netif_napi_del()  When queues are started, netif_napi_add() and napi_enable() are called. If there are 4 queues and only 3 queues are used for the current configuration, only 3 queues' napi should be registered and enabled. The ionic_qcq_enable() checks whether the .poll pointer is not NULL for enabling only…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-39502">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-44033 – In Ionic Identity Vault before 5.0.5, the protection mechanism for invalid unloc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-44033</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-44033</guid>
    <pubDate>Fri, 19 Nov 2021 05:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-44033</strong></p>
  <p>In Ionic Identity Vault before 5.0.5, the protection mechanism for invalid unlock attempts can be bypassed.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-307</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-44033">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-3145 – In Ionic Identity Vault before 5, a local root attacker on an Android device can...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-3145</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-3145</guid>
    <pubDate>Fri, 10 Sep 2021 19:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-3145</strong></p>
  <p>In Ionic Identity Vault before 5, a local root attacker on an Android device can bypass biometric authentication.</p>
  <p><strong>CVSS:</strong> 6.7 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3145">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-16202 – Directory traversal vulnerability in cordova-plugin-ionic-webview versions prior...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-16202</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-16202</guid>
    <pubDate>Wed, 09 Jan 2019 23:29:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-16202</strong></p>
  <p>Directory traversal vulnerability in cordova-plugin-ionic-webview versions prior to 2.2.0 (not including 2.0.0-beta.0, 2.0.0-beta.1, 2.0.0-beta.2, and 2.1.0-0) allows remote attackers to access arbitrary files via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-16202">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-1000123 – Ionic Team Cordova plugin iOS Keychain version before commit 18233ca25dfa92cca01...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1000123</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1000123</guid>
    <pubDate>Tue, 13 Mar 2018 21:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-1000123</strong></p>
  <p>Ionic Team Cordova plugin iOS Keychain version before commit 18233ca25dfa92cca018b9c0935f43f78fd77fbf contains an Information Exposure Through Log Files (CWE-532) vulnerability in CDVKeychain.m that can result in login, password and other sensitive data leakage. This attack appear to be exploitable via Attacker must have access to victim's iOS logs. This vulnerability appears to have been fixed i…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1000123">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2014-7475 – The Ionic View (aka com.ionic.viewapp) application 0.0.2 for Android does not ve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-7475</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-7475</guid>
    <pubDate>Sun, 19 Oct 2014 10:55:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2014-7475</strong></p>
  <p>The Ionic View (aka com.ionic.viewapp) application 0.0.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-310</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-7475">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
