<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Out-of-Bounds Read (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/oob-read.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/oob-read-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Out-of-Bounds Read (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:28 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-0076 – In validateNode of ResourceTypes.cpp, there is a possible out of bounds read due...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0076</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0076</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-0076</strong></p>
  <p>In validateNode of ResourceTypes.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0076">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-37228 – FlexRIC v2.0.0 contains a reachable assertion in e2ap_recv_sctp_msg() (src/lib/e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-37228</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-37228</guid>
    <pubDate>Mon, 01 Jun 2026 19:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-37228</strong></p>
  <p>FlexRIC v2.0.0 contains a reachable assertion in e2ap_recv_sctp_msg() (src/lib/ep/e2ap_ep.c). The function allocates a fixed 32KB receive buffer and enforces assert(rc < len) on the sctp_recvmsg() return value. A remote unauthenticated attacker can send a single SCTP message with payload >= 32,768 bytes to crash the near-RT RIC, iApp, E2 Agent, or xApp process via SIGABRT. No valid E2AP PDU is re…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-617</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-37228">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8796 – Sereal::Decoder versions before 5.005 for Perl allow heap out-of-bounds read via...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8796</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8796</guid>
    <pubDate>Sun, 31 May 2026 20:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8796</strong></p>
  <p>Sereal::Decoder versions before 5.005 for Perl allow heap out-of-bounds read via crafted input.  In Perl/Decoder/srl_decoder.c, srl_read_object() and srl_read_hash() process a COPY tag, a back-reference whose target byte the decoder re-decodes as a fresh tag. When that target byte matches the SHORT_BINARY pattern (an inline string whose length is encoded in the low bits of the tag), the resulting…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8796">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-41278 – Nozomi Networks Labs identified a CWE-125: Out-of-bounds Read in Waterfall WF-50...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41278</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41278</guid>
    <pubDate>Fri, 29 May 2026 12:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-41278</strong></p>
  <p>Nozomi Networks Labs identified a CWE-125: Out-of-bounds Read in Waterfall WF-500 RX Host in version 7.10.0.0 R2601141040 that allows attackers with access to the TX Host to execute code on the RX Host.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41278">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9975 – Out of bounds read and write in ANGLE in Google Chrome prior to 148.0.7778.216 a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9975</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9975</guid>
    <pubDate>Thu, 28 May 2026 23:16:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9975</strong></p>
  <p>Out of bounds read and write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9975">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9928 – Out of bounds read in ANGLE in Google Chrome on Windows prior to 148.0.7778.216 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9928</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9928</guid>
    <pubDate>Thu, 28 May 2026 23:16:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9928</strong></p>
  <p>Out of bounds read in ANGLE in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9928">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9895 – Out of bounds read in GPU in Google Chrome prior to 148.0.7778.216 allowed a rem...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9895</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9895</guid>
    <pubDate>Thu, 28 May 2026 23:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9895</strong></p>
  <p>Out of bounds read in GPU in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9895">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9889 – Out of bounds read and write in Dawn in Google Chrome on Android prior to 148.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9889</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9889</guid>
    <pubDate>Thu, 28 May 2026 23:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9889</strong></p>
  <p>Out of bounds read and write in Dawn in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9889">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-9875 – Out of bounds read in WebGL in Google Chrome on Android prior to 148.0.7778.216 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9875</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9875</guid>
    <pubDate>Thu, 28 May 2026 23:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9875</strong></p>
  <p>Out of bounds read in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9875">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10017 – Out of bounds read in Headless in Google Chrome prior to 148.0.7778.216 allowed ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10017</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10017</guid>
    <pubDate>Thu, 28 May 2026 23:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10017</strong></p>
  <p>Out of bounds read in Headless in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10017">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-39929 – Lakeside SysTrack Agent versions prior to 11.2.1.28, 11.3.0.38, 11.4.0.24, 11.5...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39929</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39929</guid>
    <pubDate>Thu, 28 May 2026 22:16:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-39929</strong></p>
  <p>Lakeside SysTrack Agent versions prior to 11.2.1.28, 11.3.0.38, 11.4.0.24, 11.5.0.15 contain an out-of-bounds read vulnerability in the Command ID 30 UDP packet handler that allows remote attackers to crash the application by sending a specially crafted UDP packet. Attackers can send a malformed packet with an invalid memory address at offset 0x4 in the payload to trigger an access violation and…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39929">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-47333 – Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which can potentia...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-47333</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-47333</guid>
    <pubDate>Thu, 28 May 2026 19:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-47333</strong></p>
  <p>Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which can potentially incorrectly compute the size of an internal buffer, leading to a heap memory out-of-bounds read in notification handling code. The bug can be triggered by an unprivileged local user and can result in invalid data being processed by the AppArmor DFA policy engine.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-47333">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46190 – In the Linux kernel, the following vulnerability has been resolved:

mtd: spi-no...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46190</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46190</guid>
    <pubDate>Thu, 28 May 2026 10:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46190</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  mtd: spi-nor: debugfs: fix out-of-bounds read in spi_nor_params_show()  Sashiko noticed an out-of-bounds read [1].  In spi_nor_params_show(), the snor_f_names array is passed to spi_nor_print_flags() using sizeof(snor_f_names).  Since snor_f_names is an array of pointers, sizeof() returns the total number of bytes occupied by th…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46190">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-46185 – In the Linux kernel, the following vulnerability has been resolved:

smb/client:...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46185</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46185</guid>
    <pubDate>Thu, 28 May 2026 10:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-46185</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  smb/client: fix out-of-bounds read in symlink_data()  Since smb2_check_message() returns success without length validation for the symlink error response, in symlink_data() it is possible for iov->iov_len to be smaller than sizeof(struct smb2_err_rsp). If the buffer only contains the base SMB2 header (64 bytes), accessing err->E…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46185">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-46155 – In the Linux kernel, the following vulnerability has been resolved:

smb/client:...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46155</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46155</guid>
    <pubDate>Thu, 28 May 2026 10:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-46155</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  smb/client: fix out-of-bounds read in smb2_compound_op()  If a server sends a truncated response but a large OutputBufferLength, and terminates the EA list early, check_wsl_eas() returns success without validating that the entire OutputBufferLength fits within iov_len.  Then smb2_compound_op() does:     memcpy(idata->wsl.eas, da…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46155">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46133 – In the Linux kernel, the following vulnerability has been resolved:

RDMA/rxe: R...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46133</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46133</guid>
    <pubDate>Thu, 28 May 2026 10:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46133</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  RDMA/rxe: Reject unknown opcodes before ICRC processing  Even after applying commit 7244491dab34 ("RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv"), a single unauthenticated UDP packet can still trigger panic.  That patch handled payload_size() underflow only for valid opcodes with short packets, not for packet…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46133">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-46119 – In the Linux kernel, the following vulnerability has been resolved:

libceph: Fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46119</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46119</guid>
    <pubDate>Thu, 28 May 2026 10:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-46119</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  libceph: Fix slab-out-of-bounds access in auth message processing  If a (potentially corrupted) message of type CEPH_MSG_AUTH_REPLY contains a positive value in its result field, it is treated as an error code by ceph_handle_auth_reply() and returned to handle_auth_reply(). Thereafter, an attempt is made to send the preallocated…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46119">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46070 – In the Linux kernel, the following vulnerability has been resolved:

md/raid5: v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46070</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46070</guid>
    <pubDate>Wed, 27 May 2026 14:17:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46070</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  md/raid5: validate payload size before accessing journal metadata  r5c_recovery_analyze_meta_block() and r5l_recovery_verify_data_checksum_for_mb() iterate over payloads in a journal metadata block using on-disk payload size fields without validating them against the remaining space in the metadata block.  A corrupted journal co…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46070">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45935 – In the Linux kernel, the following vulnerability has been resolved:

fs/ntfs3: F...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45935</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45935</guid>
    <pubDate>Wed, 27 May 2026 14:17:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45935</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  fs/ntfs3: Fix slab-out-of-bounds read in DeleteIndexEntryRoot  In the 'DeleteIndexEntryRoot' case of the 'do_action' function, the entry size ('esize') is retrieved from the log record without adequate bounds checking.  Specifically, the code calculates the end of the entry ('e2') using:     e2 = Add2Ptr(e1, esize);  It then cal…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45935">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45856 – In the Linux kernel, the following vulnerability has been resolved:

RDMA/uverbs...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45856</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45856</guid>
    <pubDate>Wed, 27 May 2026 14:16:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45856</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  RDMA/uverbs: Validate wqe_size before using it in ib_uverbs_post_send  ib_uverbs_post_send() uses cmd.wqe_size from userspace without any validation before passing it to kmalloc() and using the allocated buffer as struct ib_uverbs_send_wr.  If a user provides a small wqe_size value (e.g., 1), kmalloc() will succeed, but subseque…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45856">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24196 – NVIDIA Display Driver for Linux contains a vulnerability where a user could caus...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24196</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24196</guid>
    <pubDate>Tue, 26 May 2026 18:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24196</strong></p>
  <p>NVIDIA Display Driver for Linux contains a vulnerability where a user could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to denial of service and information disclosure.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24196">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-48688 – FastNetMon Community Edition through 1.2.9 contains multiple out-of-bounds reads...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-48688</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-48688</guid>
    <pubDate>Tue, 26 May 2026 16:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-48688</strong></p>
  <p>FastNetMon Community Edition through 1.2.9 contains multiple out-of-bounds reads in the BGP MP_REACH_NLRI IPv6 attribute decoder. The function decode_mp_reach_ipv6() in src/bgp_protocol.cpp contains a TODO comment at line 156 explicitly acknowledging 'we should add sanity checks to avoid reads after attribute memory block.' The function casts raw pointers to structure types without verifying suff…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48688">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41071 – libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41071</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41071</guid>
    <pubDate>Fri, 22 May 2026 22:16:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41071</strong></p>
  <p>libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a crafted HEIF sequence file where the saiz box declares more samples than actually exist in the track's chunk table causes a heap-buffer-overflow (out-of-bounds read) in the SampleAuxInfoReader constructor. The SampleAuxInfoReader constructor iterates over saiz->get_num_samples() samples but doesn't validat…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41071">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43495 – In the Linux kernel, the following vulnerability has been resolved:

net: wwan: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43495</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43495</guid>
    <pubDate>Thu, 21 May 2026 13:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43495</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handler  t7xx_port_enum_msg_handler() uses the modem-supplied port_count field as a loop bound over port_msg->data[] without checking that the message buffer contains sufficient data. A modem sending port_count=65535 in a 12-byte buffer triggers a…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43495">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44066 – Multiple heap out-of-bounds reads in the Spotlight RPC unmarshalling code in Net...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44066</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44066</guid>
    <pubDate>Thu, 21 May 2026 08:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44066</strong></p>
  <p>Multiple heap out-of-bounds reads in the Spotlight RPC unmarshalling code in Netatalk 3.1.0 through 4.4.2 allow a remote authenticated attacker to obtain sensitive information or cause a minor service disruption.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44066">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44064 – An out-of-bounds read in ASP session ID handling in Netatalk 1.3 through 4.4.2 a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44064</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44064</guid>
    <pubDate>Thu, 21 May 2026 08:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44064</strong></p>
  <p>An out-of-bounds read in ASP session ID handling in Netatalk 1.3 through 4.4.2 allows an adjacent network attacker to obtain limited information or cause a denial of service via a crafted ASP request.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44064">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9121 – Out of bounds read in GPU in Google Chrome on prior to 148.0.7778.179 allowed a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9121</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9121</guid>
    <pubDate>Wed, 20 May 2026 20:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9121</strong></p>
  <p>Out of bounds read in GPU in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9121">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24213 – NVIDIA Triton Inference Server contains a vulnerability in the DALI backend wher...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24213</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24213</guid>
    <pubDate>Wed, 20 May 2026 04:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24213</strong></p>
  <p>NVIDIA Triton Inference Server contains a vulnerability in the DALI backend where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, or information disclosure.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24213">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43909 – OpenImageIO is a toolset for reading, writing, and manipulating image files of a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43909</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43909</guid>
    <pubDate>Thu, 14 May 2026 20:17:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43909</strong></p>
  <p>OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and 3.1.13.0, a signed 32-bit integer overflow in the loop index expression i * 4 inside SwapRGBABytes() causes the function to compute a large negative pointer offset when processing kABGR DPX images with large dimensions. The immediate crash is an o…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43909">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8449 – Linux ksmbd contains a remote memory corruption vulnerability in the ACL inherit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8449</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8449</guid>
    <pubDate>Tue, 12 May 2026 22:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8449</strong></p>
  <p>Linux ksmbd contains a remote memory corruption vulnerability in the ACL inheritance path that allows remote clients with directory creation permissions to trigger a heap out-of-bounds read and subsequent heap corruption by setting a crafted DACL with a malformed SID containing an inflated num_subauth field. Attackers can exploit this vulnerability by creating a directory, setting the malicious D…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8449">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-65088 – An Out-of-Bounds Read vulnerability is present in Ashlar-Vellum Cobalt, Xenon, A...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-65088</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-65088</guid>
    <pubDate>Tue, 12 May 2026 21:16:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-65088</strong></p>
  <p>An Out-of-Bounds Read vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions 12.6.1204.216 and prior that could allow an attacker to disclose information or execute arbitrary code when a specially crafted VC6 file is being parsed.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-65088">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-65087 – An Out-of-Bounds Read vulnerability is present in Ashlar-Vellum Cobalt, Xenon, A...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-65087</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-65087</guid>
    <pubDate>Tue, 12 May 2026 21:16:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-65087</strong></p>
  <p>An Out-of-Bounds Read vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions 12.6.1204.216 and prior that could allow an attacker to disclose information or execute arbitrary code when a specially crafted VC6 file is being parsed.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-65087">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40360 – Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40360</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40360</guid>
    <pubDate>Tue, 12 May 2026 18:17:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40360</strong></p>
  <p>Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40360">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5089 – YAML::Syck versions before 1.38 for Perl  has an out-of-bounds read.

The base60...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5089</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5089</guid>
    <pubDate>Tue, 12 May 2026 17:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5089</strong></p>
  <p>YAML::Syck versions before 1.38 for Perl  has an out-of-bounds read.  The base60 (sexagesimal) parsing code in perl_syck.h has a buffer underflow bug in both int#base60 and float#base60 handlers. When processing the leftmost segment of a colon-separated value (e.g., the 1 in 1:30:45), the inner while loop can decrement a pointer past the start of the string buffer:      while ( colon >= ptr && *c…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-124</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5089">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20751 – Out-of-bounds read for the Intel(R) Data Center Graphics Driver for VMware ESXi ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20751</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20751</guid>
    <pubDate>Tue, 12 May 2026 17:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20751</strong></p>
  <p>Out-of-bounds read for the Intel(R) Data Center Graphics Driver for VMware ESXi software before version 2.0.2 within Ring 1: Device Drivers may allow a denial of service. System software adversary with a privileged user combined with a low complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are not present without special interna…</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20751">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34963 – barebox version prior to 2026.04.0 contains multiple memory-safety vulnerabiliti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34963</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34963</guid>
    <pubDate>Mon, 11 May 2026 23:19:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34963</strong></p>
  <p>barebox version prior to 2026.04.0 contains multiple memory-safety vulnerabilities in the EFI PE loader in efi/loader/pe.c where integer overflow in virtual image size computation using 32-bit arithmetic on section VirtualAddress and size values allows undersized heap allocation, and PE section loading logic fails to validate that PointerToRawData plus copied size remains within the PE file buffe…</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34963">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43655 – An out-of-bounds read was addressed with improved bounds checking. This issue is...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43655</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43655</guid>
    <pubDate>Mon, 11 May 2026 21:19:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43655</strong></p>
  <p>An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, watchOS 26.5. An app may be able to cause unexpected system termination or read kernel memory.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43655">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28991 – An out-of-bounds read was addressed with improved bounds checking. This issue is...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28991</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28991</guid>
    <pubDate>Mon, 11 May 2026 21:18:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28991</strong></p>
  <p>An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An app may be able to cause a denial-of-service.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28991">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5172 – A buffer overflow in dnsmasq’s extract_addresses() function allows an attacker t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5172</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5172</guid>
    <pubDate>Mon, 11 May 2026 18:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5172</strong></p>
  <p>A buffer overflow in dnsmasq’s extract_addresses() function allows an attacker to trigger a heap out-of-bounds read and crash by exploiting a malformed DNS response, enabling extract_name() to advance the pointer past the record’s end.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5172">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-6104 – In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an encoding nam...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6104</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6104</guid>
    <pubDate>Sun, 10 May 2026 06:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-6104</strong></p>
  <p>In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an encoding name containing an embedded NUL byte is passed to mb_convert_encoding() or related mbstring functions, the code incorrectly assumes that when strncasecmp() returns 0 it means the strings have the same length. This can lead to out-of-bounds read of global memory, potentially causing a crash or information disclosure or cr…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6104">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7568 – In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7568</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7568</guid>
    <pubDate>Sun, 10 May 2026 05:16:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7568</strong></p>
  <p>In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the metaphone() function in ext/standard/metaphone.c uses a signed int variable to track the current position within the input string. If a string longer than 2,147,483,647 bytes is passed, a signed integer overflow occurs, resulting in undefined behavior. This can lead to an out-of-bounds read,…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7568">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43453 – In the Linux kernel, the following vulnerability has been resolved:

netfilter: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43453</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43453</guid>
    <pubDate>Fri, 08 May 2026 15:16:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43453</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  netfilter: nft_set_pipapo: fix stack out-of-bounds read in pipapo_drop()  pipapo_drop() passes rulemap[i + 1].n to pipapo_unmap() as the to_offset argument on every iteration, including the last one where i == m->field_count - 1. This reads one element past the end of the stack-allocated rulemap array (declared as rulemap[NFT_PI…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43453">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43450 – In the Linux kernel, the following vulnerability has been resolved:

netfilter: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43450</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43450</guid>
    <pubDate>Fri, 08 May 2026 15:16:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43450</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  netfilter: nfnetlink_cthelper: fix OOB read in nfnl_cthelper_dump_table()  nfnl_cthelper_dump_table() has a 'goto restart' that jumps to a label inside the for loop body.  When the "last" helper saved in cb->args[1] is deleted between dump rounds, every entry fails the (cur != last) check, so cb->args[1] is never cleared.  The f…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43450">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-43407 – In the Linux kernel, the following vulnerability has been resolved:

libceph: Fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43407</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43407</guid>
    <pubDate>Fri, 08 May 2026 15:16:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-43407</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  libceph: Fix potential out-of-bounds access in ceph_handle_auth_reply()  This patch fixes an out-of-bounds access in ceph_handle_auth_reply() that can be triggered by a message of type CEPH_MSG_AUTH_REPLY. In ceph_handle_auth_reply(), the value of the payload_len field of such a message is stored in a variable of type int. A val…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43407">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-43406 – In the Linux kernel, the following vulnerability has been resolved:

libceph: pr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43406</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43406</guid>
    <pubDate>Fri, 08 May 2026 15:16:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-43406</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  libceph: prevent potential out-of-bounds reads in process_message_header()  If the message frame is (maliciously) corrupted in a way that the length of the control segment ends up being less than the size of the message header or a different frame is made to look like a message frame, out-of-bounds reads may ensue in process_mes…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43406">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43386 – In the Linux kernel, the following vulnerability has been resolved:

staging: rt...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43386</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43386</guid>
    <pubDate>Fri, 08 May 2026 15:16:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43386</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  staging: rtl8723bs: fix potential out-of-bounds read in rtw_restruct_wmm_ie  The current code checks 'i + 5 < in_len' at the end of the if statement. However, it accesses 'in_ie[i + 5]' before that check, which can lead to an out-of-bounds read. Move the length check to the beginning of the conditional to ensure the index is wit…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43386">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7995 – Out of bounds read in AdFilter in Google Chrome prior to 148.0.7778.96 allowed a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7995</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7995</guid>
    <pubDate>Wed, 06 May 2026 19:16:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7995</strong></p>
  <p>Out of bounds read in AdFilter in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7995">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7981 – Out of bounds read in Codecs in Google Chrome prior to 148.0.7778.96 allowed a r...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7981</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7981</guid>
    <pubDate>Wed, 06 May 2026 19:16:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7981</strong></p>
  <p>Out of bounds read in Codecs in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to obtain potentially sensitive information from process memory via a malicious file. (Chromium security severity: Medium)</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7981">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7899 – Out of bounds read and write in V8 in Google Chrome prior to 148.0.7778.96 allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7899</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7899</guid>
    <pubDate>Wed, 06 May 2026 19:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7899</strong></p>
  <p>Out of bounds read and write in V8 in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7899">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43281 – In the Linux kernel, the following vulnerability has been resolved:

mailbox: Pr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43281</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43281</guid>
    <pubDate>Wed, 06 May 2026 12:16:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43281</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  mailbox: Prevent out-of-bounds access in fw_mbox_index_xlate()  Although it is guided that `#mbox-cells` must be at least 1, there are many instances of `#mbox-cells = <0>;` in the device tree. If that is the case and the corresponding mailbox controller does not provide `fw_xlate` and of_xlate` function pointers, `fw_mbox_index…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43281">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43274 – In the Linux kernel, the following vulnerability has been resolved:

mailbox: mc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43274</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43274</guid>
    <pubDate>Wed, 06 May 2026 12:16:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43274</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  mailbox: mchp-ipc-sbi: fix out-of-bounds access in mchp_ipc_get_cluster_aggr_irq()  The cluster_cfg array is dynamically allocated to hold per-CPU configuration structures, with its size based on the number of online CPUs. Previously, this array was indexed using hartid, which may be non-contiguous or exceed the bounds of the ar…</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43274">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43256 – In the Linux kernel, the following vulnerability has been resolved:

media: qcom...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43256</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43256</guid>
    <pubDate>Wed, 06 May 2026 12:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43256</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  media: qcom: camss: vfe: Fix out-of-bounds access in vfe_isr_reg_update()  vfe_isr() iterates using MSM_VFE_IMAGE_MASTERS_NUM(7) as the loop bound and passes the index to vfe_isr_reg_update(). However, vfe->line[] array is defined with VFE_LINE_NUM_MAX(4):      struct vfe_line line[VFE_LINE_NUM_MAX];  When index is 4, 5, 6, the…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43256">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43241 – In the Linux kernel, the following vulnerability has been resolved:

ntb: ntb_hw...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43241</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43241</guid>
    <pubDate>Wed, 06 May 2026 12:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43241</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  ntb: ntb_hw_switchtec: Fix array-index-out-of-bounds access  Number of MW LUTs depends on NTB configuration and can be set to MAX_MWS, This patch protects against invalid index out of bounds access to mw_sizes When invalid access print message to user that configuration is not valid.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43241">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43190 – In the Linux kernel, the following vulnerability has been resolved:

netfilter: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43190</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43190</guid>
    <pubDate>Wed, 06 May 2026 12:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43190</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  netfilter: xt_tcpmss: check remaining length before reading optlen  Quoting reporter:   In net/netfilter/xt_tcpmss.c (lines 53-68), the TCP option parser reads  op[i+1] directly without validating the remaining option length.    If the last byte of the option field is not EOL/NOP (0/1), the code attempts   to index op[i+1]. In t…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43190">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43112 – In the Linux kernel, the following vulnerability has been resolved:

fs/smb/clie...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43112</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43112</guid>
    <pubDate>Wed, 06 May 2026 10:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43112</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath  When cifs_sanitize_prepath is called with an empty string or a string containing only delimiters (e.g., "/"), the current logic attempts to check *(cursor2 - 1) before cursor2 has advanced. This results in an out-of-bounds read.  This patch adds an early exit check…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43112">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-43083 – In the Linux kernel, the following vulnerability has been resolved:

net: ioam6:...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43083</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43083</guid>
    <pubDate>Wed, 06 May 2026 10:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-43083</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  net: ioam6: fix OOB and missing lock  When trace->type.bit6 is set:      if (trace->type.bit6) {         ...         queue = skb_get_tx_queue(dev, skb);         qdisc = rcu_dereference(queue->qdisc);  This code can lead to an out-of-bounds access of the dev->_tx[] array when is_input is true. In such a case, the packet is on the…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43083">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-37461 – An out-of-bounds read in the ParseIP6Extended function (/bgp/bgp.go) of gobgp v4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-37461</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-37461</guid>
    <pubDate>Mon, 04 May 2026 17:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-37461</strong></p>
  <p>An out-of-bounds read in the ParseIP6Extended function (/bgp/bgp.go) of gobgp v4.3.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-37461">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-7482 – Ollama before 0.17.1 contains a heap out-of-bounds read vulnerability in the GGU...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7482</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7482</guid>
    <pubDate>Mon, 04 May 2026 13:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-7482</strong></p>
  <p>Ollama before 0.17.1 contains a heap out-of-bounds read vulnerability in the GGUF model loader. The /api/create endpoint accepts an attacker-supplied GGUF file in which the declared tensor offset and size exceed the file's actual length; during quantization in fs/ggml/gguf.go and server/quantization.go (WriteTo()), the server reads past the allocated heap buffer. The leaked memory contents may in…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7482">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7668 – A vulnerability was identified in MikroTik RouterOS 6.49.8. This vulnerability a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7668</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7668</guid>
    <pubDate>Sat, 02 May 2026 21:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7668</strong></p>
  <p>A vulnerability was identified in MikroTik RouterOS 6.49.8. This vulnerability affects the function ASN1_STRING_data in the library nova/lib/www/scep.p of the component SCEP Endpoint. The manipulation of the argument transactionID/messageType leads to out-of-bounds read. The attack may be initiated remotely. The exploit is publicly available and might be used. You should upgrade the affected comp…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7668">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-37535 – openxc/isotp-c thru commit 5a5d19245f65189202719321facd49ce6f5d46ac (2021-08-09)...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-37535</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-37535</guid>
    <pubDate>Fri, 01 May 2026 17:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-37535</strong></p>
  <p>openxc/isotp-c thru commit 5a5d19245f65189202719321facd49ce6f5d46ac (2021-08-09) contains an out-of-bounds read in the ISO-TP Single Frame receive handler, where the 4-bit payload length nibble is used directly as the memcpy size without validating it against the actual CAN data length. A malicious CAN frame with an oversized length nibble can cause memory reads beyond the buffer, allowing attack…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-37535">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43051 – In the Linux kernel, the following vulnerability has been resolved:

HID: wacom:...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43051</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43051</guid>
    <pubDate>Fri, 01 May 2026 15:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43051</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq  The wacom_intuos_bt_irq() function processes Bluetooth HID reports without sufficient bounds checking. A maliciously crafted short report can trigger an out-of-bounds read when copying data into the wacom structure.  Specifically, report 0x03 requires at least 22 bytes t…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43051">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42477 – A heap-based out-of-bounds read vulnerability in RWObj_Reader::read in the OBJ f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42477</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42477</guid>
    <pubDate>Fri, 01 May 2026 15:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42477</strong></p>
  <p>A heap-based out-of-bounds read vulnerability in RWObj_Reader::read in the OBJ file parser in Open CASCADE Technology (OCCT) V8_0_0_rc5 allows user-assisted attackers to cause a denial of service or obtain sensitive information by persuading a victim to open a crafted OBJ file. The issue occurs because Standard_ReadLineBuffer::ReadLine() can return a 1-byte buffer for a minimal OBJ line, and RWOb…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42477">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42476 – Two heap-based out-of-bounds read vulnerabilities in the STL ASCII file parser i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42476</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42476</guid>
    <pubDate>Fri, 01 May 2026 15:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42476</strong></p>
  <p>Two heap-based out-of-bounds read vulnerabilities in the STL ASCII file parser in Open CASCADE Technology (OCCT) V8_0_0_rc5 exist in RWStl_Reader::ReadAscii because buffers returned by Standard_ReadLineBuffer::ReadLine() are not properly length-validated before strncasecmp or direct byte access. User-assisted attackers can trigger these issues by persuading a victim to open a crafted STL file wit…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42476">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-31779 – In the Linux kernel, the following vulnerability has been resolved:

wifi: iwlwi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31779</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31779</guid>
    <pubDate>Fri, 01 May 2026 15:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-31779</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  wifi: iwlwifi: mvm: fix potential out-of-bounds read in iwl_mvm_nd_match_info_handler()  The memcpy function assumes the dynamic array notif->matches is at least as large as the number of bytes to copy. Otherwise, results->matches may contain unwanted data. To guarantee safety, extend the validation in one of the checks to ensur…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31779">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-31778 – In the Linux kernel, the following vulnerability has been resolved:

ALSA: caiaq...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31778</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31778</guid>
    <pubDate>Fri, 01 May 2026 15:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-31778</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  ALSA: caiaq: fix stack out-of-bounds read in init_card  The loop creates a whitespace-stripped copy of the card shortname where `len < sizeof(card->id)` is used for the bounds check. Since sizeof(card->id) is 16 and the local id buffer is also 16 bytes, writing 16 non-space characters fills the entire buffer, overwriting the ter…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31778">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-31774 – In the Linux kernel, the following vulnerability has been resolved:

io_uring/ne...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31774</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31774</guid>
    <pubDate>Fri, 01 May 2026 15:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-31774</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  io_uring/net: fix slab-out-of-bounds read in io_bundle_nbufs()  sqe->len is __u32 but gets stored into sr->len which is int. When userspace passes sqe->len values exceeding INT_MAX (e.g. 0xFFFFFFFF), sr->len overflows to a negative value. This negative value propagates through the bundle recv/send path:    1. io_recv(): sel.val…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31774">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-31764 – In the Linux kernel, the following vulnerability has been resolved:

iio: imu: s...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31764</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31764</guid>
    <pubDate>Fri, 01 May 2026 15:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-31764</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  iio: imu: st_lsm6dsx: Set buffer sampling frequency for accelerometer only  The st_lsm6dsx_hwfifo_odr_store() function, which is called when userspace writes the buffer sampling frequency sysfs attribute, calls st_lsm6dsx_check_odr(), which accesses the odr_table array at index `sensor->id`; since this array is only 2 entries lo…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-129</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31764">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-31716 – In the Linux kernel, the following vulnerability has been resolved:

fs/ntfs3: v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31716</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31716</guid>
    <pubDate>Fri, 01 May 2026 14:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-31716</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  fs/ntfs3: validate rec->used in journal-replay file record check  check_file_record() validates rec->total against the record size but never validates rec->used.  The do_action() journal-replay handlers read rec->used from disk and use it to compute memmove lengths:    DeleteAttribute:    memmove(attr, ..., used - asize - roff)…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31716">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33845 – A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero len...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33845</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33845</guid>
    <pubDate>Thu, 30 Apr 2026 18:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33845</strong></p>
  <p>A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause information disclosure or denial of service.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-191</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33845">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42799 – Out-of-bounds read vulnerability in ASR Kestrel (nr_fw modules) allows Overflow ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42799</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42799</guid>
    <pubDate>Thu, 30 Apr 2026 09:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42799</strong></p>
  <p>Out-of-bounds read vulnerability in ASR Kestrel (nr_fw modules) allows Overflow Buffers.   This vulnerability is associated with program files Code/Nr/nr_fw/RA/src/NrPwrCtrl.C.    This issue affects Kestrel: before 2026/02/10.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42799">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7354 – Out of bounds read and write in Angle in Google Chrome prior to 147.0.7727.138 a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7354</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7354</guid>
    <pubDate>Tue, 28 Apr 2026 23:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7354</strong></p>
  <p>Out of bounds read and write in Angle in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7354">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41604 – Out-of-bounds Read vulnerability in Apache Thrift.

This issue affects Apache Th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41604</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41604</guid>
    <pubDate>Tue, 28 Apr 2026 10:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41604</strong></p>
  <p>Out-of-bounds Read vulnerability in Apache Thrift.  This issue affects Apache Thrift: before 0.23.0.  Users are recommended to upgrade to version 0.23.0, which fixes the issue.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41604">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-31675 – In the Linux kernel, the following vulnerability has been resolved:

net/sched: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31675</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31675</guid>
    <pubDate>Sat, 25 Apr 2026 09:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-31675</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  net/sched: sch_netem: fix out-of-bounds access in packet corruption  In netem_enqueue(), the packet corruption logic uses get_random_u32_below(skb_headlen(skb)) to select an index for modifying skb->data. When an AF_PACKET TX_RING sends fully non-linear packets over an IPIP tunnel, skb_headlen(skb) evaluates to 0.  Passing 0 to…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31675">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41503 – BACnet Stack is a BACnet open source protocol stack C library for embedded syste...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41503</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41503</guid>
    <pubDate>Fri, 24 Apr 2026 20:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41503</strong></p>
  <p>BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.4.3, an out-of-bounds read vulnerability in bacnet-stack's ReadPropertyMultiple service property decoder allows unauthenticated remote attackers to read past allocated buffer boundaries by sending an RPM request with a truncated property list. The vulnerability stems from rpm_decode_object_property() ca…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41503">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41502 – BACnet Stack is a BACnet open source protocol stack C library for embedded syste...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41502</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41502</guid>
    <pubDate>Fri, 24 Apr 2026 20:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41502</strong></p>
  <p>BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.4.3, an off-by-one out-of-bounds read vulnerability in bacnet-stack's ReadPropertyMultiple service decoder allows unauthenticated remote attackers to read one byte past an allocated buffer boundary by sending a crafted RPM request with a truncated object identifier. The vulnerability is in rpm_decode_ob…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41502">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41476 – Deskflow is a keyboard and mouse sharing app.  Prior to 1.26.0.138, a remote mem...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41476</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41476</guid>
    <pubDate>Fri, 24 Apr 2026 20:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41476</strong></p>
  <p>Deskflow is a keyboard and mouse sharing app.  Prior to 1.26.0.138, a remote memory-safety vulnerability in Deskflow's clipboard deserialization allows a connected peer to trigger an out-of-bounds read by sending a malformed clipboard update. The issue is in the implementation of src/lib/deskflow/IClipboard.cpp. This is reachable because ClipboardChunk::assemble() in src/lib/deskflow/ClipboardChu…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41476">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-41475 – BACnet Stack is a BACnet open source protocol stack C library for embedded syste...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41475</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41475</guid>
    <pubDate>Fri, 24 Apr 2026 20:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-41475</strong></p>
  <p>BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.4.3, an out-of-bounds read vulnerability in bacnet-stack's WritePropertyMultiple service decoder allows unauthenticated remote attackers to read past allocated buffer boundaries by sending a truncated WPM request. The vulnerability stems from wpm_decode_object_property() calling the deprecated decode_ta…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41475">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-41415 – PJSIP is a free and open source multimedia communication library written in C. I...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41415</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41415</guid>
    <pubDate>Fri, 24 Apr 2026 19:17:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-41415</strong></p>
  <p>PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, there is an out-of-bounds read when parsing a malformed Content-ID URI in SIP multipart message body. Insufficient length validation can cause reads beyond the intended buffer bounds. This vulnerability is fixed in 2.17.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41415">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-31569 – In the Linux kernel, the following vulnerability has been resolved:

LoongArch: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31569</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31569</guid>
    <pubDate>Fri, 24 Apr 2026 15:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-31569</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  LoongArch: KVM: Handle the case that EIOINTC's coremap is empty  EIOINTC's coremap in eiointc_update_sw_coremap() can be empty, currently we get a cpuid with -1 in this case, but we actually need 0 because it's similar as the case that cpuid >= 4.  This fix an out-of-bounds access to kvm_arch::phyid_map::phys_map[].</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31569">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-31558 – In the Linux kernel, the following vulnerability has been resolved:

LoongArch: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31558</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31558</guid>
    <pubDate>Fri, 24 Apr 2026 15:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-31558</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  LoongArch: KVM: Make kvm_get_vcpu_by_cpuid() more robust  kvm_get_vcpu_by_cpuid() takes a cpuid parameter whose type is int, so cpuid can be negative. Let kvm_get_vcpu_by_cpuid() return NULL for this case so as to make it more robust.  This fix an out-of-bounds access to kvm_arch::phyid_map::phys_map[].</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31558">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5367 – A flaw was found in OVN (Open Virtual Network). A remote attacker, by sending cr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5367</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5367</guid>
    <pubDate>Fri, 24 Apr 2026 13:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5367</strong></p>
  <p>A flaw was found in OVN (Open Virtual Network). A remote attacker, by sending crafted DHCPv6 (Dynamic Host Configuration Protocol for IPv6) SOLICIT packets with an inflated Client ID length, could cause the ovn-controller to read beyond the bounds of a packet. This out-of-bounds read can lead to the disclosure of sensitive information stored in heap memory, which is then returned to the attacker'…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-130</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5367">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33317 – OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-s...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33317</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33317</guid>
    <pubDate>Fri, 24 Apr 2026 03:16:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33317</strong></p>
  <p>OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. In versions 3.13.0 through 4.10.0, missing checks in `entry_get_attribute_value()`  in `ta/pkcs11/src/object.c` can lead to out-of-bounds read from the PKCS#11 TA heap or a crash. When chained with the OOB read, the PKCS#11 TA function `…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33317">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-6920 – Out of bounds read in GPU in Google Chrome on Android prior to 147.0.7727.117 al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6920</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6920</guid>
    <pubDate>Thu, 23 Apr 2026 18:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-6920</strong></p>
  <p>Out of bounds read in GPU in Google Chrome on Android prior to 147.0.7727.117 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6920">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-31513 – In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31513</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31513</guid>
    <pubDate>Wed, 22 Apr 2026 14:16:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-31513</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  Bluetooth: L2CAP: Fix stack-out-of-bounds read in l2cap_ecred_conn_req  Syzbot reported a KASAN stack-out-of-bounds read in l2cap_build_cmd() that is triggered by a malformed Enhanced Credit Based Connection Request.  The vulnerability stems from l2cap_ecred_conn_req(). The function allocates a local stack buffer (`pdu`) designe…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31513">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-31449 – In the Linux kernel, the following vulnerability has been resolved:

ext4: valid...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31449</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31449</guid>
    <pubDate>Wed, 22 Apr 2026 14:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-31449</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  ext4: validate p_idx bounds in ext4_ext_correct_indexes  ext4_ext_correct_indexes() walks up the extent tree correcting index entries when the first extent in a leaf is modified. Before accessing path[k].p_idx->ei_block, there is no validation that p_idx falls within the valid range of index entries for that level.  If the on-di…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31449">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40890 – The package `github.com/gomarkdown/markdown` is a Go library for parsing Markdow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40890</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40890</guid>
    <pubDate>Tue, 21 Apr 2026 20:17:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40890</strong></p>
  <p>The package `github.com/gomarkdown/markdown` is a Go library for parsing Markdown text and rendering as HTML. Processing a malformed input containing a < character that is not followed by a > character anywhere in the remaining text with a SmartypantsRenderer will lead to Out of Bounds read or a panic. This vulnerability is fixed with commit 759bbc3e32073c3bc4e25969c132fc520eda2778.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40890">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24189 – NVIDIA CUDA-Q contains a vulnerability in an endpoint, where an unauthenticated ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24189</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24189</guid>
    <pubDate>Tue, 21 Apr 2026 17:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24189</strong></p>
  <p>NVIDIA CUDA-Q contains a vulnerability in an endpoint, where an unauthenticated attacker could cause an out-of-bounds read by sending a maliciously crafted request. A successful exploit of this vulnerability might lead to denial of service and information disclosure.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24189">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-31430 – In the Linux kernel, the following vulnerability has been resolved:

X.509: Fix ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31430</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31430</guid>
    <pubDate>Mon, 20 Apr 2026 10:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-31430</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  X.509: Fix out-of-bounds access when parsing extensions  Leo reports an out-of-bounds access when parsing a certificate with empty Basic Constraints or Key Usage extension because the first byte of the extension is read before checking its length.  Fix it.  The bug can be triggered by an unprivileged user by submitting a special…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31430">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-29013 – libcoap contains out-of-bounds read vulnerabilities in OSCORE Appendix B.2 CBOR ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-29013</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-29013</guid>
    <pubDate>Fri, 17 Apr 2026 22:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-29013</strong></p>
  <p>libcoap contains out-of-bounds read vulnerabilities in OSCORE Appendix B.2 CBOR unwrap handling where get_byte_inc() in src/oscore/oscore_cbor.c relies solely on assert() for bounds checking, which is removed in release builds compiled with NDEBUG. Attackers can send crafted CoAP requests with malformed OSCORE options or responses during OSCORE negotiation to trigger out-of-bounds reads during CB…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-29013">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-33689 – xrdp is an open source RDP server. Versions through 0.10.5 have an out-of-bounds...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33689</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33689</guid>
    <pubDate>Fri, 17 Apr 2026 21:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-33689</strong></p>
  <p>xrdp is an open source RDP server. Versions through 0.10.5 have an out-of-bounds read vulnerability in the pre-authentication RDP message parsing logic. A remote, unauthenticated attacker can trigger this flaw by sending a specially crafted sequence of packets during the initial connection phase. This vulnerability results from insufficient validation of input buffer lengths before processing dyn…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33689">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-33516 – xrdp is an open source RDP server. Versions through 0.10.5 contain an out-of-bou...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33516</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33516</guid>
    <pubDate>Fri, 17 Apr 2026 20:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-33516</strong></p>
  <p>xrdp is an open source RDP server. Versions through 0.10.5 contain an out-of-bounds read vulnerability during the RDP capability exchange phase. The issue occurs when memory is accessed before validating the remaining buffer length. A remote, unauthenticated attacker can trigger this vulnerability by sending a specially crafted Confirm Active PDU. Successful exploitation could lead to a denial of…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33516">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6308 – Out of bounds read in Media in Google Chrome prior to 147.0.7727.101 allowed a r...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6308</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6308</guid>
    <pubDate>Wed, 15 Apr 2026 20:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6308</strong></p>
  <p>Out of bounds read in Media in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6308">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-27294 – Adobe Framemaker versions 2022.8 and earlier are affected by an out-of-bounds re...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27294</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27294</guid>
    <pubDate>Tue, 14 Apr 2026 23:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-27294</strong></p>
  <p>Adobe Framemaker versions 2022.8 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27294">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33019 – libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. V...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33019</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33019</guid>
    <pubDate>Tue, 14 Apr 2026 22:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33019</strong></p>
  <p>libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain an integer overflow leading to an out-of-bounds heap read in the --crop option handling of img2sixel, where positive coordinates up to INT_MAX are accepted without overflow-safe bounds checking. In sixel_encoder_do_clip(), the expression clip_w + clip_x overflows to a large negative val…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33019">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-27287 – InCopy versions 20.5.2, 21.2 and earlier are affected by an out-of-bounds read v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27287</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27287</guid>
    <pubDate>Tue, 14 Apr 2026 21:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-27287</strong></p>
  <p>InCopy versions 20.5.2, 21.2 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27287">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-27289 – Photoshop Desktop versions 27.4 and earlier are affected by an out-of-bounds rea...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27289</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27289</guid>
    <pubDate>Tue, 14 Apr 2026 20:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-27289</strong></p>
  <p>Photoshop Desktop versions 27.4 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27289">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33096 – Out-of-bounds read in Windows HTTP.sys allows an unauthorized attacker to deny s...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33096</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33096</guid>
    <pubDate>Tue, 14 Apr 2026 18:17:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33096</strong></p>
  <p>Out-of-bounds read in Windows HTTP.sys allows an unauthorized attacker to deny service over a network.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33096">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32188 – Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32188</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32188</guid>
    <pubDate>Tue, 14 Apr 2026 18:17:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32188</strong></p>
  <p>Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32188">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32076 – Out-of-bounds read in Windows Storage Spaces Controller allows an authorized att...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32076</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32076</guid>
    <pubDate>Tue, 14 Apr 2026 18:17:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32076</strong></p>
  <p>Out-of-bounds read in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32076">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-26153 – Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26153</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26153</guid>
    <pubDate>Tue, 14 Apr 2026 18:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-26153</strong></p>
  <p>Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26153">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
