<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Out-of-Bounds Access</title>
  <link>https://cvedaily.com/pages/tags/oob.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/oob.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Out-of-Bounds Access</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:28 +0000</lastBuildDate>
  <item>
    <title>[Unknown] CVE-2026-46260 – In the Linux kernel, the following vulnerability has been resolved:

ipv6: Fix o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46260</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46260</guid>
    <pubDate>Wed, 03 Jun 2026 18:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk unknown">Unknown</span> CVE-2026-46260</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  ipv6: Fix out-of-bound access in fib6_add_rt2node().  syzbot reported out-of-bound read in fib6_add_rt2node(). [0]  When IPv6 route is created with RTA_NH_ID, struct fib6_info does not have the trailing struct fib6_nh.  The cited commit started to check !iter->fib6_nh->fib_nh_gw_family to ensure that rt6_qualify_for_ecmp() will…</p>
  <p><strong>CVSS:</strong> N/A · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46260">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Unknown] CVE-2026-46253 – In the Linux kernel, the following vulnerability has been resolved:

pstore/ram:...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46253</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46253</guid>
    <pubDate>Wed, 03 Jun 2026 18:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk unknown">Unknown</span> CVE-2026-46253</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  pstore/ram: fix buffer overflow in persistent_ram_save_old()  persistent_ram_save_old() can be called multiple times for the same persistent_ram_zone (e.g., via ramoops_pstore_read -> ramoops_get_next_prz for PSTORE_TYPE_DMESG records).  Currently, the function only allocates prz->old_log when it is NULL, but it unconditionally…</p>
  <p><strong>CVSS:</strong> N/A · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46253">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45615 – mouse07410/asn1c is an ASN.1 compiler. In 1.4 and earlier, a memory safety vulne...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45615</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45615</guid>
    <pubDate>Fri, 29 May 2026 14:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45615</strong></p>
  <p>mouse07410/asn1c is an ASN.1 compiler. In 1.4 and earlier, a memory safety vulnerability was identified in the OER decoding skeleton files generated by asn1c (specifically INTEGER_oer.c). When parsing a maliciously crafted, zero-length OER payload for a variable-length, non-negative INTEGER type, the decoder fails to validate the required bytes before extracting the Most Significant Bit (MSB). Th…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45615">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46230 – In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu/...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46230</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46230</guid>
    <pubDate>Thu, 28 May 2026 10:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46230</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg  Check bounds against the end of the BO whenever we access the msg.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46230">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46204 – In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu/...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46204</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46204</guid>
    <pubDate>Thu, 28 May 2026 10:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46204</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  drm/amdgpu/vcn4: Prevent OOB reads when parsing IB  Rewrite the IB parsing to use amdgpu_ib_get_value() which handles the bounds checks.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46204">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46199 – In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu/...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46199</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46199</guid>
    <pubDate>Thu, 28 May 2026 10:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46199</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg  Check bounds against the end of the BO whenever we access the msg.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46199">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Unknown] CVE-2026-46191 – In the Linux kernel, the following vulnerability has been resolved:

fbcon: Avoi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46191</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46191</guid>
    <pubDate>Thu, 28 May 2026 10:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk unknown">Unknown</span> CVE-2026-46191</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  fbcon: Avoid OOB font access if console rotation fails  Clear the font buffer if the reallocation during console rotation fails in fbcon_rotate_font(). The putcs implementations for the rotated buffer will return early in this case. See [1] for an example.  Currently, fbcon_rotate_font() keeps the old buffer, which is too small…</p>
  <p><strong>CVSS:</strong> N/A · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46191">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46138 – In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46138</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46138</guid>
    <pubDate>Thu, 28 May 2026 10:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46138</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  Bluetooth: hci_event: Fix OOB read and infinite loop in hci_le_create_big_complete_evt  hci_le_create_big_complete_evt() iterates over BT_BOUND connections for a BIG handle using a while loop, accessing ev->bis_handle[i++] on each iteration.  However, there is no check that i stays within ev->num_bis before the array access.  Wh…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46138">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46133 – In the Linux kernel, the following vulnerability has been resolved:

RDMA/rxe: R...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46133</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46133</guid>
    <pubDate>Thu, 28 May 2026 10:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46133</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  RDMA/rxe: Reject unknown opcodes before ICRC processing  Even after applying commit 7244491dab34 ("RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv"), a single unauthenticated UDP packet can still trigger panic.  That patch handled payload_size() underflow only for valid opcodes with short packets, not for packet…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46133">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46116 – In the Linux kernel, the following vulnerability has been resolved:

xfrm: defen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46116</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46116</guid>
    <pubDate>Thu, 28 May 2026 10:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46116</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete  KASAN reproduces a slab-use-after-free in __xfrm_state_delete()'s hlist_del_rcu calls under syzkaller load on linux-6.12.y stable (reproduced on 6.12.47, also reachable via the same code path on torvalds/master and on the ipsec tree). Nine unique signatures cluste…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46116">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Unknown] CVE-2026-46072 – In the Linux kernel, the following vulnerability has been resolved:

ntfs3: add ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46072</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46072</guid>
    <pubDate>Wed, 27 May 2026 14:17:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk unknown">Unknown</span> CVE-2026-46072</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  ntfs3: add buffer boundary checks to run_unpack()  run_unpack() checks `run_buf < run_last` at the top of the while loop but then reads size_size and offset_size bytes via run_unpack_s64() without verifying they fit within the remaining buffer.  A crafted NTFS image with truncated run data in an MFT attribute triggers an OOB hea…</p>
  <p><strong>CVSS:</strong> N/A · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46072">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Unknown] CVE-2026-46022 – In the Linux kernel, the following vulnerability has been resolved:

misc: ibmas...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46022</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46022</guid>
    <pubDate>Wed, 27 May 2026 14:17:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk unknown">Unknown</span> CVE-2026-46022</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  misc: ibmasm: fix OOB MMIO read in ibmasm_handle_mouse_interrupt()  ibmasm_handle_mouse_interrupt() performs an out-of-bounds MMIO read when the queue reader or writer index from hardware exceeds REMOTE_QUEUE_SIZE (60).  A compromised service processor can trigger this by writing an out-of-range value to the reader or writer MMI…</p>
  <p><strong>CVSS:</strong> N/A · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46022">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Unknown] CVE-2026-45994 – In the Linux kernel, the following vulnerability has been resolved:

ibmasm: fix...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45994</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45994</guid>
    <pubDate>Wed, 27 May 2026 14:17:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk unknown">Unknown</span> CVE-2026-45994</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  ibmasm: fix OOB reads in command_file_write due to missing size checks  The command_file_write() handler allocates a kernel buffer of exactly count bytes and copies user data into it, but does not validate the buffer against the dot command protocol before passing it to get_dot_command_size() and get_dot_command_timeout().  Sinc…</p>
  <p><strong>CVSS:</strong> N/A · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45994">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-43501 – In the Linux kernel, the following vulnerability has been resolved:

ipv6: rpl: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43501</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43501</guid>
    <pubDate>Thu, 21 May 2026 13:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-43501</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  ipv6: rpl: reserve mac_len headroom when recompressed SRH grows  ipv6_rpl_srh_rcv() decompresses an RFC 6554 Source Routing Header, swaps the next segment into ipv6_hdr->daddr, recompresses, then pulls the old header and pushes the new one plus the IPv6 header back.  The recompressed header can be larger than the received one wh…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43501">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43495 – In the Linux kernel, the following vulnerability has been resolved:

net: wwan: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43495</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43495</guid>
    <pubDate>Thu, 21 May 2026 13:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43495</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handler  t7xx_port_enum_msg_handler() uses the modem-supplied port_count field as a loop bound over port_msg->data[] without checking that the message buffer contains sufficient data. A modem sending port_count=65535 in a 12-byte buffer triggers a…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43495">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-8507 – Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl have out-of-bounds (OOB) w...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8507</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8507</guid>
    <pubDate>Sun, 17 May 2026 19:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-8507</strong></p>
  <p>Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl have out-of-bounds (OOB) write flaws.  When parsing a PKCS12 file, with a >= 1 GiB OCTET STRING (or BIT STRING) attribute on a SAFEBAG, via info() or info_as_hash(), a heap out-of-bounds write would be triggered with remote-code-execution potential (RCE) due to a signed integer overflow in the size calculation passed to Renew().</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8507">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8669 – Imager versions through 1.030 for Perl allow a heap out of bounds (OOB) write on...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8669</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8669</guid>
    <pubDate>Fri, 15 May 2026 15:16:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8669</strong></p>
  <p>Imager versions through 1.030 for Perl allow a heap out of bounds (OOB) write on crafted multi-frame GIF files.  Imager::File::GIF's i_readgif_multi_low allocates a single per-row buffer GifRow sized for the GIF's global screen width 'SWidth' and reuses it across every image in the file.  The page-match branch validates Image.Width + Image.Left > SWidth before each DGifGetLine write, but the para…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8669">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-8454 – Imager::File::GIF versions through 1.002 for Perl allow a heap out of bounds (OO...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8454</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8454</guid>
    <pubDate>Fri, 15 May 2026 12:17:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8454</strong></p>
  <p>Imager::File::GIF versions through 1.002 for Perl allow a heap out of bounds (OOB) write on crafted multi-frame GIF files.  Imager::File::GIF's i_readgif_multi_low allocates a single per-row buffer GifRow sized for the GIF's global screen width 'SWidth' and reuses it across every image in the file.  The page-match branch validates Image.Width + Image.Left > SWidth before each DGifGetLine write, b…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8454">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43909 – OpenImageIO is a toolset for reading, writing, and manipulating image files of a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43909</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43909</guid>
    <pubDate>Thu, 14 May 2026 20:17:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43909</strong></p>
  <p>OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and 3.1.13.0, a signed 32-bit integer overflow in the loop index expression i * 4 inside SwapRGBABytes() causes the function to compute a large negative pointer offset when processing kABGR DPX images with large dimensions. The immediate crash is an o…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43909">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43450 – In the Linux kernel, the following vulnerability has been resolved:

netfilter: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43450</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43450</guid>
    <pubDate>Fri, 08 May 2026 15:16:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43450</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  netfilter: nfnetlink_cthelper: fix OOB read in nfnl_cthelper_dump_table()  nfnl_cthelper_dump_table() has a 'goto restart' that jumps to a label inside the for loop body.  When the "last" helper saved in cb->args[1] is deleted between dump rounds, every entry fails the (cur != last) check, so cb->args[1] is never cleared.  The f…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43450">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41142 – OpenEXR provides the specification and reference implementation of the EXR file ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41142</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41142</guid>
    <pubDate>Thu, 07 May 2026 04:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41142</strong></p>
  <p>OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, there is an integer overflow in ImageChannel::resize that leads to heap OOB write via OpenEXRUtil public API. This issue has been patched in versions 3.2.9, 3.3.11,…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41142">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43280 – In the Linux kernel, the following vulnerability has been resolved:

drm/xe: Add...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43280</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43280</guid>
    <pubDate>Wed, 06 May 2026 12:16:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43280</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  drm/xe: Add bounds check on pat_index to prevent OOB kernel read in madvise  When user provides a bogus pat_index value through the madvise IOCTL, the xe_pat_index_get_coh_mode() function performs an array access without validating bounds. This allows a malicious user to trigger an out-of-bounds kernel read from the xe->pat.tabl…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43280">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43279 – In the Linux kernel, the following vulnerability has been resolved:

ALSA: usb-a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43279</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43279</guid>
    <pubDate>Wed, 06 May 2026 12:16:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43279</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  ALSA: usb-audio: Add sanity check for OOB writes at silencing  At silencing the playback URB packets in the implicit fb mode before the actual playback, we blindly assume that the received packets fit with the buffer size.  But when the setup in the capture stream differs from the playback stream (e.g. due to the USB core limita…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43279">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43233 – In the Linux kernel, the following vulnerability has been resolved:

netfilter: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43233</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43233</guid>
    <pubDate>Wed, 06 May 2026 12:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43233</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  netfilter: nf_conntrack_h323: fix OOB read in decode_choice()  In decode_choice(), the boundary check before get_len() uses the variable `len`, which is still 0 from its initialization at the top of the function:      unsigned int type, ext, len = 0;     ...     if (ext || (son->attr & OPEN)) {         BYTE_ALIGN(bs);         if…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43233">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-43197 – In the Linux kernel, the following vulnerability has been resolved:

netconsole:...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43197</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43197</guid>
    <pubDate>Wed, 06 May 2026 12:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-43197</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  netconsole: avoid OOB reads, msg is not nul-terminated  msg passed to netconsole from the console subsystem is not guaranteed to be nul-terminated. Before recent commit 7eab73b18630 ("netconsole: convert to NBCON console infrastructure") the message would be placed in printk_shared_pbufs, a static global buffer, so KASAN had har…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43197">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43166 – In the Linux kernel, the following vulnerability has been resolved:

erofs: fix ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43166</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43166</guid>
    <pubDate>Wed, 06 May 2026 12:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43166</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  erofs: fix interlaced plain identification for encoded extents  Only plain data whose start position and on-disk physical length are both aligned to the block size should be classified as interlaced plain extents. Otherwise, it must be treated as shifted plain extents.  This issue was found by syzbot using a crafted compressed i…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43166">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-43083 – In the Linux kernel, the following vulnerability has been resolved:

net: ioam6:...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43083</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43083</guid>
    <pubDate>Wed, 06 May 2026 10:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-43083</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  net: ioam6: fix OOB and missing lock  When trace->type.bit6 is set:      if (trace->type.bit6) {         ...         queue = skb_get_tx_queue(dev, skb);         qdisc = rcu_dereference(queue->qdisc);  This code can lead to an out-of-bounds access of the dev->_tx[] array when is_input is true. In such a case, the packet is on the…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43083">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43075 – In the Linux kernel, the following vulnerability has been resolved:

ocfs2: fix ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43075</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43075</guid>
    <pubDate>Wed, 06 May 2026 10:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43075</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  ocfs2: fix out-of-bounds write in ocfs2_write_end_inline  KASAN reports a use-after-free write of 4086 bytes in ocfs2_write_end_inline, called from ocfs2_write_end_nolock during a copy_file_range splice fallback on a corrupted ocfs2 filesystem mounted on a loop device.  The actual bug is an out-of-bounds write past the inode blo…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43075">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-43071 – In the Linux kernel, the following vulnerability has been resolved:

dcache: Lim...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43071</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43071</guid>
    <pubDate>Tue, 05 May 2026 16:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-43071</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  dcache: Limit the minimal number of bucket to two  There is an OOB read problem on dentry_hashtable when user sets 'dhash_entries=1':   BUG: unable to handle page fault for address: ffff888b30b774b0   #PF: supervisor read access in kernel mode   #PF: error_code(0x0000) - not-present page   Oops: Oops: 0000 [#1] SMP PTI   RIP: 00…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43071">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43048 – In the Linux kernel, the following vulnerability has been resolved:

HID: core: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43048</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43048</guid>
    <pubDate>Fri, 01 May 2026 15:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43048</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  HID: core: Mitigate potential OOB by removing bogus memset()  The memset() in hid_report_raw_event() has the good intention of clearing out bogus data by zeroing the area from the end of the incoming data string to the assumed end of the buffer.  However, as we have previously seen, doing so can easily result in OOB reads and wr…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43048">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43047 – In the Linux kernel, the following vulnerability has been resolved:

HID: multit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43047</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43047</guid>
    <pubDate>Fri, 01 May 2026 15:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43047</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  HID: multitouch: Check to ensure report responses match the request  It is possible for a malicious (or clumsy) device to respond to a specific report's feature request using a completely different report ID.  This can cause confusion in the HID core resulting in nasty side-effects such as OOB writes.  Add a check to ensure that…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43047">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43042 – In the Linux kernel, the following vulnerability has been resolved:

mpls: add s...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43042</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43042</guid>
    <pubDate>Fri, 01 May 2026 15:16:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43042</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  mpls: add seqcount to protect the platform_label{,s} pair  The RCU-protected codepaths (mpls_forward, mpls_dump_routes) can have an inconsistent view of platform_labels vs platform_label in case of a concurrent resize (resize_platform_label_table, under platform_mutex). This can lead to OOB accesses.  This patch adds a seqcount,…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43042">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-31712 – In the Linux kernel, the following vulnerability has been resolved:

ksmbd: requ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31712</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31712</guid>
    <pubDate>Fri, 01 May 2026 14:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-31712</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  ksmbd: require minimum ACE size in smb_check_perm_dacl()  Both ACE-walk loops in smb_check_perm_dacl() only guard against an under-sized remaining buffer, not against an ACE whose declared `ace->size` is smaller than the struct it claims to describe:    if (offsetof(struct smb_ace, access_req) > aces_size)       break;   ace_siz…</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31712">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-31709 – In the Linux kernel, the following vulnerability has been resolved:

smb: client...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31709</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31709</guid>
    <pubDate>Fri, 01 May 2026 14:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-31709</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  smb: client: validate the whole DACL before rewriting it in cifsacl  build_sec_desc() and id_mode_to_cifs_acl() derive a DACL pointer from a server-supplied dacloffset and then use the incoming ACL to rebuild the chmod/chown security descriptor.  The original fix only checked that the struct smb_acl header fits before reading da…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31709">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-31708 – In the Linux kernel, the following vulnerability has been resolved:

smb: client...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31708</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31708</guid>
    <pubDate>Fri, 01 May 2026 14:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-31708</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  smb: client: fix OOB read in smb2_ioctl_query_info QUERY_INFO path  smb2_ioctl_query_info() has two response-copy branches: PASSTHRU_FSCTL and the default QUERY_INFO path.  The QUERY_INFO branch clamps qi.input_buffer_length to the server-reported OutputBufferLength and then copies qi.input_buffer_length bytes from qi_rsp->Buffe…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31708">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-31705 – In the Linux kernel, the following vulnerability has been resolved:

ksmbd: fix ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31705</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31705</guid>
    <pubDate>Fri, 01 May 2026 14:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-31705</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  ksmbd: fix out-of-bounds write in smb2_get_ea() EA alignment  smb2_get_ea() applies 4-byte alignment padding via memset() after writing each EA entry. The bounds check on buf_free_len is performed before the value memcpy, but the alignment memset fires unconditionally afterward with no check on remaining space.  When the EA valu…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31705">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41502 – BACnet Stack is a BACnet open source protocol stack C library for embedded syste...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41502</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41502</guid>
    <pubDate>Fri, 24 Apr 2026 20:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41502</strong></p>
  <p>BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.4.3, an off-by-one out-of-bounds read vulnerability in bacnet-stack's ReadPropertyMultiple service decoder allows unauthenticated remote attackers to read one byte past an allocated buffer boundary by sending a crafted RPM request with a truncated object identifier. The vulnerability is in rpm_decode_ob…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41502">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-31636 – In the Linux kernel, the following vulnerability has been resolved:

rxrpc: fix ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31636</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31636</guid>
    <pubDate>Fri, 24 Apr 2026 15:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-31636</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  rxrpc: fix RESPONSE authenticator parser OOB read  rxgk_verify_authenticator() copies auth_len bytes into a temporary buffer and then passes p + auth_len as the parser limit to rxgk_do_verify_authenticator(). Since p is a __be32 *, that inflates the parser end pointer by a factor of four and lets malformed RESPONSE authenticator…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31636">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-31613 – In the Linux kernel, the following vulnerability has been resolved:

smb: client...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31613</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31613</guid>
    <pubDate>Fri, 24 Apr 2026 15:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-31613</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  smb: client: fix OOB reads parsing symlink error response  When a CREATE returns STATUS_STOPPED_ON_SYMLINK, smb2_check_message() returns success without any length validation, leaving the symlink parsers as the only defense against an untrusted server.  symlink_data() walks SMB 3.1.1 error contexts with the loop test "p < end",…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31613">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-31570 – In the Linux kernel, the following vulnerability has been resolved:

can: gw: fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31570</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31570</guid>
    <pubDate>Fri, 24 Apr 2026 15:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-31570</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  can: gw: fix OOB heap access in cgw_csum_crc8_rel()  cgw_csum_crc8_rel() correctly computes bounds-safe indices via calc_idx():      int from = calc_idx(crc8->from_idx, cf->len);     int to   = calc_idx(crc8->to_idx,   cf->len);     int res  = calc_idx(crc8->result_idx, cf->len);      if (from < 0 || to < 0 || res < 0)         r…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31570">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33317 – OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-s...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33317</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33317</guid>
    <pubDate>Fri, 24 Apr 2026 03:16:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33317</strong></p>
  <p>OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. In versions 3.13.0 through 4.10.0, missing checks in `entry_get_attribute_value()`  in `ta/pkcs11/src/object.c` can lead to out-of-bounds read from the PKCS#11 TA heap or a crash. When chained with the OOB read, the PKCS#11 TA function `…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33317">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-31494 – In the Linux kernel, the following vulnerability has been resolved:

net: macb: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31494</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31494</guid>
    <pubDate>Wed, 22 Apr 2026 14:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-31494</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  net: macb: use the current queue number for stats  There's a potential mismatch between the memory reserved for statistics and the amount of memory written.  gem_get_sset_count() correctly computes the number of stats based on the active queues, whereas gem_get_ethtool_stats() indiscriminately copies data using the maximum numbe…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31494">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-31484 – In the Linux kernel, the following vulnerability has been resolved:

io_uring/fd...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31484</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31484</guid>
    <pubDate>Wed, 22 Apr 2026 14:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-31484</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  io_uring/fdinfo: fix OOB read in SQE_MIXED wrap check  __io_uring_show_fdinfo() iterates over pending SQEs and, for 128-byte SQEs on an IORING_SETUP_SQE_MIXED ring, needs to detect when the second half of the SQE would be past the end of the sq_sqes array. The current check tests (++sq_head & sq_mask) == 0, but sq_head is only i…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31484">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-31464 – In the Linux kernel, the following vulnerability has been resolved:

scsi: ibmvf...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31464</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31464</guid>
    <pubDate>Wed, 22 Apr 2026 14:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-31464</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  scsi: ibmvfc: Fix OOB access in ibmvfc_discover_targets_done()  A malicious or compromised VIO server can return a num_written value in the discover targets MAD response that exceeds max_targets. This value is stored directly in vhost->num_targets without validation, and is then used as the loop bound in ibmvfc_alloc_targets() t…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31464">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-31433 – In the Linux kernel, the following vulnerability has been resolved:

ksmbd: fix ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31433</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31433</guid>
    <pubDate>Wed, 22 Apr 2026 09:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-31433</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  ksmbd: fix potencial OOB in get_file_all_info() for compound requests  When a compound request consists of QUERY_DIRECTORY + QUERY_INFO (FILE_ALL_INFORMATION) and the first command consumes nearly the entire max_trans_size, get_file_all_info() would blindly call smbConvertToUTF16() with PATH_MAX, causing out-of-bounds write beyo…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31433">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-31432 – In the Linux kernel, the following vulnerability has been resolved:

ksmbd: fix ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31432</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31432</guid>
    <pubDate>Wed, 22 Apr 2026 09:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-31432</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  ksmbd: fix OOB write in QUERY_INFO for compound requests  When a compound request such as READ + QUERY_INFO(Security) is received, and the first command (READ) consumes most of the response buffer, ksmbd could write beyond the allocated buffer while building a security descriptor.  The root cause was that smb2_get_info_sec() che…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31432">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-5392 – Heap out-of-bounds read in PKCS7 parsing. A crafted PKCS7 message can trigger an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5392</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5392</guid>
    <pubDate>Fri, 10 Apr 2026 00:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-5392</strong></p>
  <p>Heap out-of-bounds read in PKCS7 parsing. A crafted PKCS7 message can trigger an OOB read on the heap. The missing bounds check is in the indefinite-length end-of-content verification loop in PKCS7_VerifySignedData().</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5392">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-31405 – In the Linux kernel, the following vulnerability has been resolved:

media: dvb-...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31405</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31405</guid>
    <pubDate>Mon, 06 Apr 2026 08:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-31405</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  media: dvb-net: fix OOB access in ULE extension header tables  The ule_mandatory_ext_handlers[] and ule_optional_ext_handlers[] tables in handle_one_ule_extension() are declared with 255 elements (valid indices 0-254), but the index htype is derived from network-controlled data as (ule_sndu_type & 0x00FF), giving a range of 0-25…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31405">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-31395 – In the Linux kernel, the following vulnerability has been resolved:

bnxt_en: fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31395</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31395</guid>
    <pubDate>Fri, 03 Apr 2026 16:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-31395</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  bnxt_en: fix OOB access in DBG_BUF_PRODUCER async event handler  The ASYNC_EVENT_CMPL_EVENT_ID_DBG_BUF_PRODUCER handler in bnxt_async_event_process() uses a firmware-supplied 'type' field directly as an index into bp->bs_trace[] without bounds validation.  The 'type' field is a 16-bit value extracted from DMA-mapped completion r…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31395">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-23456 – In the Linux kernel, the following vulnerability has been resolved:

netfilter: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23456</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23456</guid>
    <pubDate>Fri, 03 Apr 2026 16:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-23456</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  netfilter: nf_conntrack_h323: fix OOB read in decode_int() CONS case  In decode_int(), the CONS case calls get_bits(bs, 2) to read a length value, then calls get_uint(bs, len) without checking that len bytes remain in the buffer. The existing boundary check only validates the 2 bits for get_bits(), not the subsequent 1-4 bytes t…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23456">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-34608 – NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34608</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34608</guid>
    <pubDate>Thu, 02 Apr 2026 18:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-34608</strong></p>
  <p>NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to version 0.24.10, in NanoMQ's webhook_inproc.c, the hook_work_cb() function processes nng messages by parsing the message body with cJSON_Parse(body). The body is obtained from nng_msg_body(msg), which is a binary buffer without a guaranteed null terminator. This leads to an out-of-bounds read (OOB read) as cJSON_Parse…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34608">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-25627 – NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25627</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25627</guid>
    <pubDate>Mon, 30 Mar 2026 21:17:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-25627</strong></p>
  <p>NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to version 0.24.8, NanoMQ’s MQTT-over-WebSocket transport can be crashed by sending an MQTT packet with a deliberately large Remaining Length in the fixed header while providing a much shorter actual payload. The code path copies Remaining Length bytes without verifying that the current receive buffer contains that many b…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25627">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33636 – LIBPNG is a reference library for use in applications that read, create, and man...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33636</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33636</guid>
    <pubDate>Thu, 26 Mar 2026 17:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33636</strong></p>
  <p>LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. In versions 1.6.36 through 1.6.55, an out-of-bounds read and write exists in libpng's ARM/AArch64 Neon-optimized palette expansion path. When expanding 8-bit paletted rows to RGB or RGBA, the Neon loop processes a final partial chunk without verifying that en…</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33636">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-23363 – In the Linux kernel, the following vulnerability has been resolved:

wifi: mt76:...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23363</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23363</guid>
    <pubDate>Wed, 25 Mar 2026 11:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-23363</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  wifi: mt76: mt7925: Fix possible oob access in mt7925_mac_write_txwi_80211()  Check frame length before accessing the mgmt fields in mt7925_mac_write_txwi_80211 in order to avoid a possible oob access.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23363">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-23325 – In the Linux kernel, the following vulnerability has been resolved:

wifi: mt76:...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23325</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23325</guid>
    <pubDate>Wed, 25 Mar 2026 11:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-23325</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  wifi: mt76: mt7996: Fix possible oob access in mt7996_mac_write_txwi_80211()  Check frame length before accessing the mgmt fields in mt7996_mac_write_txwi_80211 in order to avoid a possible oob access.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23325">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-23317 – In the Linux kernel, the following vulnerability has been resolved:

drm/vmwgfx:...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23317</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23317</guid>
    <pubDate>Wed, 25 Mar 2026 11:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-23317</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  drm/vmwgfx: Return the correct value in vmw_translate_ptr functions  Before the referenced fixes these functions used a lookup function that returned a pointer. This was changed to another lookup function that returned an error code with the pointer becoming an out parameter.  The error path when the lookup failed was not change…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-908</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23317">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-23315 – In the Linux kernel, the following vulnerability has been resolved:

wifi: mt76:...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23315</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23315</guid>
    <pubDate>Wed, 25 Mar 2026 11:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-23315</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  wifi: mt76: Fix possible oob access in mt76_connac2_mac_write_txwi_80211()  Check frame length before accessing the mgmt fields in mt76_connac2_mac_write_txwi_80211 in order to avoid a possible oob access.  [fix check to also cover mgmt->u.action.u.addba_req.capab, correct Fixes tag]</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23315">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-1940 – An incomplete fix for CVE-2024-47778 allows an out-of-bounds read in gst_wavpars...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1940</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1940</guid>
    <pubDate>Mon, 23 Mar 2026 22:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-1940</strong></p>
  <p>An incomplete fix for CVE-2024-47778 allows an out-of-bounds read in gst_wavparse_adtl_chunk() function. The patch added a size validation check lsize + 8 > size, but it does not account for the GST_ROUND_UP_2(lsize) used in the actual offset calculation. When lsize is an odd number, the parser advances more bytes than validated, causing OOB read.</p>
  <p><strong>CVSS:</strong> 5.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1940">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-4159 – 1-byte OOB heap read in wc_PKCS7_DecodeEnvelopedData via zero-length encrypted c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4159</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4159</guid>
    <pubDate>Thu, 19 Mar 2026 22:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-4159</strong></p>
  <p>1-byte OOB heap read in wc_PKCS7_DecodeEnvelopedData via zero-length encrypted content. A vulnerability existed in wolfSSL 5.8.4 and earlier, where a 1-byte out-of-bounds heap read in wc_PKCS7_DecodeEnvelopedData could be triggered by a crafted CMS EnvelopedData message with zero-length encrypted content. Note that PKCS7 support is disabled by default.</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4159">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33321 – OpenEMR is a free and open source electronic health records and medical practice...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33321</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33321</guid>
    <pubDate>Thu, 19 Mar 2026 21:17:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33321</strong></p>
  <p>OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, users with the `Notes - my encounters` role can fill Eye Exam forms in patient encounters. The answers to the form can be printed out in PDF form. An Out-of-Band Server-Side Request Forgery (OOB SSRF) vulnerability was identified in the PDF creation function where the form an…</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33321">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-69808 – An out-of-bounds memory access (OOB) in p2r3 Bareiron commit 8e4d40 allows unaut...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-69808</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-69808</guid>
    <pubDate>Mon, 16 Mar 2026 19:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-69808</strong></p>
  <p>An out-of-bounds memory access (OOB) in p2r3 Bareiron commit 8e4d40 allows unauthenticated attackers to access sensitive information and cause a Denial of Service (DoS) via supplying a crafted packet.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-69808">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-21888 – NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. MQTT v5 Va...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21888</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21888</guid>
    <pubDate>Wed, 11 Mar 2026 16:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-21888</strong></p>
  <p>NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. MQTT v5 Variable Byte Integer parsing out-of-bounds: get_var_integer() accepts 5-byte varints without bounds checks; reliably triggers OOB read / crash when built with ASan. This affects 0.24.6 and earlier.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21888">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-13350 – Ubuntu Linux 6.8 GA retains the legacy AF_UNIX garbage collector but backports u...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13350</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13350</guid>
    <pubDate>Thu, 05 Mar 2026 20:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-13350</strong></p>
  <p>Ubuntu Linux 6.8 GA retains the legacy AF_UNIX garbage collector but backports upstream commit 8594d9b85c07 ("af_unix: Don’t call skb_get() for OOB skb"). When orphaned MSG_OOB sockets hit unix_gc(), the garbage collector still calls kfree_skb() as if OOB SKBs held two references; on Ubuntu Linux 6.8 (Noble Numbat) kernel tree, they have only the queue reference, so the buffer is freed while stil…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13350">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-26965 – FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to versio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26965</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26965</guid>
    <pubDate>Wed, 25 Feb 2026 21:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-26965</strong></p>
  <p>FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, in the RLE planar decode path, `planar_decompress_plane_rle()` writes into `pDstData` at `((nYDst+y) * nDstStep) + (4*nXDst) + nChannel` without verifying that `(nYDst+nSrcHeight)` fits in the destination height or that `(nXDst+nSrcWidth)` fits in the destination stride. When `TempFormat != DstFormat`, `pDst…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26965">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-26955 – FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to versio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26955</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26955</guid>
    <pubDate>Wed, 25 Feb 2026 21:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-26955</strong></p>
  <p>FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, a malicious RDP server can trigger a heap buffer overflow in FreeRDP clients using the GDI surface pipeline (e.g., `xfreerdp`) by sending an RDPGFX ClearCodec surface command with an out-of-bounds destination rectangle. The `gdi_SurfaceCommand_ClearCodec()` handler does not call `is_within_surface()` to vali…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26955">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20033 – A vulnerability in Cisco Nexus 9000 Series Fabric Switches in ACI mode could all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20033</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20033</guid>
    <pubDate>Wed, 25 Feb 2026 17:25:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20033</strong></p>
  <p>A vulnerability in Cisco Nexus 9000 Series Fabric Switches in ACI mode could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device.  This vulnerability is due to insufficient validation when processing specific Ethernet frames. An attacker could exploit this vulnerability by sending a crafted Ethernet frame to the&nbsp;management interfac…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-805</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20033">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-26981 – OpenEXR provides the specification and reference implementation of the EXR file ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26981</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26981</guid>
    <pubDate>Tue, 24 Feb 2026 03:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-26981</strong></p>
  <p>OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In versions 3.3.0 through 3.3.6 and 3.4.0 through 3.4.4, a heap-buffer-overflow (OOB read) occurs in the `istream_nonparallel_read` function in `ImfContextInit.cpp` when parsing a malformed EXR file through a memory-mapped `IStream`. A signed integer sub…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-195</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26981">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-23208 – In the Linux kernel, the following vulnerability has been resolved:

ALSA: usb-a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23208</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23208</guid>
    <pubDate>Sat, 14 Feb 2026 17:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-23208</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  ALSA: usb-audio: Prevent excessive number of frames  In this case, the user constructed the parameters with maxpacksize 40 for rate 22050 / pps 1000, and packsize[0] 22 packsize[1] 23. The buffer size for each data URB is maxpacksize * packets, which in this example is 40 * 6 = 240; When the user performs a write operation to se…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23208">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-23194 – In the Linux kernel, the following vulnerability has been resolved:

rust_binder...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23194</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23194</guid>
    <pubDate>Sat, 14 Feb 2026 17:15:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-23194</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  rust_binder: correctly handle FDA objects of length zero  Fix a bug where an empty FDA (fd array) object with 0 fds would cause an out-of-bounds error. The previous implementation used `skip == 0` to mean "this is a pointer fixup", but 0 is also the correct skip length for an empty FDA. If the FDA is at the end of the buffer, th…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23194">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-23092 – In the Linux kernel, the following vulnerability has been resolved:

iio: dac: a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23092</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23092</guid>
    <pubDate>Wed, 04 Feb 2026 17:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-23092</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  iio: dac: ad3552r-hs: fix out-of-bound write in ad3552r_hs_write_data_source  When simple_write_to_buffer() succeeds, it returns the number of bytes actually copied to the buffer. The code incorrectly uses 'count' as the index for null termination instead of the actual bytes copied. If count exceeds the buffer size, this leads t…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23092">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-23076 – In the Linux kernel, the following vulnerability has been resolved:

ALSA: ctxfi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23076</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23076</guid>
    <pubDate>Wed, 04 Feb 2026 17:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-23076</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  ALSA: ctxfi: Fix potential OOB access in audio mixer handling  In the audio mixer handling code of ctxfi driver, the conf field is used as a kind of loop index, and it's referred in the index callbacks (amixer_index() and sum_index()).  As spotted recently by fuzzers, the current code causes OOB access at those functions. | UBSA…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23076">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1483 – An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the P...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1483</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1483</guid>
    <pubDate>Tue, 27 Jan 2026 17:16:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1483</strong></p>
  <p>An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluation (EDD) application developed by Gabinete Técnico de Programación. Exploiting this vulnerability in the parameter 'Id_usuario' in '/evaluacion_objetivos_ver_auto.aspx', could allow an attacker to extract sensitive information from the database through external channels, without the affected applica…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1483">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1482 – An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the P...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1482</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1482</guid>
    <pubDate>Tue, 27 Jan 2026 17:16:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1482</strong></p>
  <p>An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluation (EDD) application developed by Gabinete Técnico de Programación. Exploiting this vulnerability in the parameter 'Id_evaluacion' in '/evaluacion_objetivos_evalua_definido.aspx', could allow an attacker to extract sensitive information from the database through external channels, without the affect…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1482">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1481 – An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the P...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1481</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1481</guid>
    <pubDate>Tue, 27 Jan 2026 17:16:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1481</strong></p>
  <p>An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluation (EDD) application developed by Gabinete Técnico de Programación. Exploiting this vulnerability in the parameter 'Id_usuario' in '/evaluacion_objetivos_anyo_sig_ver_auto.aspx', could allow an attacker to extract sensitive information from the database through external channels, without the affecte…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1481">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1480 – An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the P...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1480</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1480</guid>
    <pubDate>Tue, 27 Jan 2026 17:16:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1480</strong></p>
  <p>An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluation (EDD) application developed by Gabinete Técnico de Programación. Exploiting this vulnerability in the parameter 'Id_usuario' in '/evaluacion_objetivos_anyo_sig_evalua.aspx', could allow an attacker to extract sensitive information from the database through external channels, without the affected…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1480">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1479 – An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the P...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1479</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1479</guid>
    <pubDate>Tue, 27 Jan 2026 17:16:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1479</strong></p>
  <p>An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluation (EDD) application developed by Gabinete Técnico de Programación. Exploiting this vulnerability in the parameters 'Id_usuario' and 'Id_evaluacion’ in ‘/evaluacion_hca_ver_auto.asp', could allow an attacker to extract sensitive information from the database through external channels, without the af…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1479">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1478 – An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the P...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1478</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1478</guid>
    <pubDate>Tue, 27 Jan 2026 17:16:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1478</strong></p>
  <p>An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluation (EDD) application developed by Gabinete Técnico de Programación. Exploiting this vulnerability in the parameter 'Id_usuario' and 'Id_evaluacion’ in ‘/evaluacion_hca_evalua.aspx’, could allow an attacker to extract sensitive information from the database through external channels, without the affe…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1478">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1477 – An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the P...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1477</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1477</guid>
    <pubDate>Tue, 27 Jan 2026 17:16:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1477</strong></p>
  <p>An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluation (EDD) application developed by Gabinete Técnico de Programación. Exploiting this vulnerability in the parameter 'Id_usuario' and 'Id_evaluacion’ in ‘/evaluacion_competencias_evalua_old.aspx’, could allow an attacker to extract sensitive information from the database through external channels, wit…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1477">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1476 – An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the P...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1476</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1476</guid>
    <pubDate>Tue, 27 Jan 2026 17:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1476</strong></p>
  <p>An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluation (EDD) application developed by Gabinete Técnico de Programación. Exploiting this vulnerability in the parameter 'Id_usuario' in ‘/evaluacion_acciones_ver_auto.aspx’, could allow an attacker to extract sensitive information from the database through external channels, without the affected applicat…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1476">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1475 – An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the P...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1475</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1475</guid>
    <pubDate>Tue, 27 Jan 2026 17:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1475</strong></p>
  <p>An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluation (EDD) application developed by Gabinete Técnico de Programación. Exploiting this vulnerability in the parameter ‘Id_usuario' in ‘/evaluacion_acciones_evalua.aspx’, could allow an attacker to extract sensitive information from the database through external channels, without the affected applicatio…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1475">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1474 – An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the P...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1474</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1474</guid>
    <pubDate>Tue, 27 Jan 2026 17:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1474</strong></p>
  <p>An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluation (EDD) application developed by Gabinete Técnico de Programación. Exploiting this vulnerability in the parameter 'Id_usuario' and 'Id_evaluacion' en ‘/evaluacion_inicio.aspx’, could allow an attacker to extract sensitive information from the database through external channels, without the affected…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1474">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1473 – An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the P...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1473</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1473</guid>
    <pubDate>Tue, 27 Jan 2026 17:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1473</strong></p>
  <p>An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluation (EDD) application developed by Gabinete Técnico de Programación. Exploiting this vulnerability in the parameter 'Id_usuario’ in '/evaluacion_competencias_evalua.aspx', could allow an attacker to extract sensitive information from the database through external channels, without the affected applic…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1473">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1472 – An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the P...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1472</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1472</guid>
    <pubDate>Tue, 27 Jan 2026 17:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1472</strong></p>
  <p>An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluation (EDD) application developed by Gabinete Técnico de Programación. Exploiting this vulnerability in the parameter 'txAny' in '/evaluacion_competencias_autoeval_list.aspx', could allow an attacker to extract sensitive information from the database through external channels, without the affected appl…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1472">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-71093 – In the Linux kernel, the following vulnerability has been resolved:

e1000: fix ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-71093</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-71093</guid>
    <pubDate>Tue, 13 Jan 2026 16:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-71093</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  e1000: fix OOB in e1000_tbi_should_accept()  In e1000_tbi_should_accept() we read the last byte of the frame via 'data[length - 1]' to evaluate the TBI workaround. If the descriptor- reported length is zero or larger than the actual RX buffer size, this read goes out of bounds and can hit unrelated slab objects. The issue is obs…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-71093">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-71092 – In the Linux kernel, the following vulnerability has been resolved:

RDMA/bnxt_r...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-71092</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-71092</guid>
    <pubDate>Tue, 13 Jan 2026 16:16:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-71092</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  RDMA/bnxt_re: Fix OOB write in bnxt_re_copy_err_stats()  Commit ef56081d1864 ("RDMA/bnxt_re: RoCE related hardware counters update") added three new counters and placed them after BNXT_RE_OUT_OF_SEQ_ERR.  BNXT_RE_OUT_OF_SEQ_ERR acts as a boundary marker for allocating hardware statistics with different num_counters values on chi…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-71092">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-21899 – CryptoLib provides a software-only solution using the CCSDS Space Data Link Secu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21899</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21899</guid>
    <pubDate>Sat, 10 Jan 2026 01:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-21899</strong></p>
  <p>CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. Prior to version 1.4.3, in base64urlDecode, padding-stripping dereferences input[inputLen - 1] before checking that inputLen > 0 or that input != NULL. For inputLen ==…</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21899">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-21433 – Emlog is an open source website building system. Versions up to and including 2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21433</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21433</guid>
    <pubDate>Fri, 02 Jan 2026 19:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-21433</strong></p>
  <p>Emlog is an open source website building system. Versions up to and including 2.5.19 are vulnerable to server-side Out-of-Band (OOB) requests / SSRF via uploaded SVG files. An attacker can upload a crafted SVG to http[:]//emblog/admin/media[.]php which contains external resource references. When the server processes/renders the SVG (thumbnailing, preview, or sanitization), it issues an HTTP reque…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21433">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Unknown] CVE-2023-54063 – In the Linux kernel, the following vulnerability has been resolved:

fs/ntfs3: F...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-54063</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-54063</guid>
    <pubDate>Wed, 24 Dec 2025 13:16:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk unknown">Unknown</span> CVE-2023-54063</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  fs/ntfs3: Fix OOB read in indx_insert_into_buffer  Syzbot reported a OOB read bug:  BUG: KASAN: slab-out-of-bounds in indx_insert_into_buffer+0xaa3/0x13b0 fs/ntfs3/index.c:1755 Read of size 17168 at addr ffff8880255e06c0 by task syz-executor308/3630  Call Trace:  <TASK>  memmove+0x25/0x60 mm/kasan/shadow.c:54  indx_insert_into_b…</p>
  <p><strong>CVSS:</strong> N/A · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-54063">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Unknown] CVE-2022-50747 – In the Linux kernel, the following vulnerability has been resolved:

hfs: Fix OO...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-50747</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-50747</guid>
    <pubDate>Wed, 24 Dec 2025 13:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk unknown">Unknown</span> CVE-2022-50747</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  hfs: Fix OOB Write in hfs_asc2mac  Syzbot reported a OOB Write bug:  loop0: detected capacity change from 0 to 64 ================================================================== BUG: KASAN: slab-out-of-bounds in hfs_asc2mac+0x467/0x9a0 fs/hfs/trans.c:133 Write of size 1 at addr ffff88801848314e by task syz-executor391/3632  C…</p>
  <p><strong>CVSS:</strong> N/A · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-50747">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Unknown] CVE-2023-54031 – In the Linux kernel, the following vulnerability has been resolved:

vdpa: Add q...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-54031</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-54031</guid>
    <pubDate>Wed, 24 Dec 2025 11:15:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk unknown">Unknown</span> CVE-2023-54031</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  vdpa: Add queue index attr to vdpa_nl_policy for nlattr length check  The vdpa_nl_policy structure is used to validate the nlattr when parsing the incoming nlmsg. It will ensure the attribute being described produces a valid nlattr pointer in info->attrs before entering into each handler in vdpa_nl_ops.  That is to say, the miss…</p>
  <p><strong>CVSS:</strong> N/A · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-54031">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Unknown] CVE-2025-68296 – In the Linux kernel, the following vulnerability has been resolved:

drm, fbcon,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-68296</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-68296</guid>
    <pubDate>Tue, 16 Dec 2025 16:16:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk unknown">Unknown</span> CVE-2025-68296</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  drm, fbcon, vga_switcheroo: Avoid race condition in fbcon setup  Protect vga_switcheroo_client_fb_set() with console lock. Avoids OOB access in fbcon_remap_all(). Without holding the console lock the call races with switching outputs.  VGA switcheroo calls fbcon_remap_all() when switching clients. The fbcon function uses struct…</p>
  <p><strong>CVSS:</strong> N/A · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68296">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Unknown] CVE-2025-68256 – In the Linux kernel, the following vulnerability has been resolved:

staging: rt...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-68256</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-68256</guid>
    <pubDate>Tue, 16 Dec 2025 15:15:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk unknown">Unknown</span> CVE-2025-68256</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  staging: rtl8723bs: fix out-of-bounds read in rtw_get_ie() parser  The Information Element (IE) parser rtw_get_ie() trusted the length byte of each IE without validating that the IE body (len bytes after the 2-byte header) fits inside the remaining frame buffer. A malformed frame can advertise an IE length larger than the availa…</p>
  <p><strong>CVSS:</strong> N/A · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68256">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Unknown] CVE-2025-68254 – In the Linux kernel, the following vulnerability has been resolved:

staging: rt...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-68254</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-68254</guid>
    <pubDate>Tue, 16 Dec 2025 15:15:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk unknown">Unknown</span> CVE-2025-68254</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  staging: rtl8723bs: fix out-of-bounds read in OnBeacon ESR IE parsing  The Extended Supported Rates (ESR) IE handling in OnBeacon accessed *(p + 1 + ielen) and *(p + 2 + ielen) without verifying that these offsets lie within the received frame buffer. A malformed beacon with an ESR IE positioned at the end of the buffer could ca…</p>
  <p><strong>CVSS:</strong> N/A · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68254">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Unknown] CVE-2023-53819 – In the Linux kernel, the following vulnerability has been resolved:

amdgpu: val...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-53819</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-53819</guid>
    <pubDate>Tue, 09 Dec 2025 01:16:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk unknown">Unknown</span> CVE-2023-53819</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  amdgpu: validate offset_in_bo of drm_amdgpu_gem_va  This is motivated by OOB access in amdgpu_vm_update_range when offset_in_bo+map_size overflows.  v2: keep the validations in amdgpu_vm_bo_map v3: add the validations to amdgpu_vm_bo_map/amdgpu_vm_bo_replace_map     rather than to amdgpu_gem_va_ioctl</p>
  <p><strong>CVSS:</strong> N/A · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-53819">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Unknown] CVE-2025-40294 – In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-40294</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-40294</guid>
    <pubDate>Mon, 08 Dec 2025 01:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk unknown">Unknown</span> CVE-2025-40294</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  Bluetooth: MGMT: Fix OOB access in parse_adv_monitor_pattern()  In the parse_adv_monitor_pattern() function, the value of the 'length' variable is currently limited to HCI_MAX_EXT_AD_LENGTH(251). The size of the 'value' array in the mgmt_adv_pattern structure is 31. If the value of 'pattern[i].length' is set in the user space an…</p>
  <p><strong>CVSS:</strong> N/A · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-40294">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Unknown] CVE-2025-40266 – In the Linux kernel, the following vulnerability has been resolved:

KVM: arm64:...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-40266</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-40266</guid>
    <pubDate>Thu, 04 Dec 2025 16:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk unknown">Unknown</span> CVE-2025-40266</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  KVM: arm64: Check the untrusted offset in FF-A memory share  Verify the offset to prevent OOB access in the hypervisor FF-A buffer in case an untrusted large enough value [U32_MAX - sizeof(struct ffa_composite_mem_region) + 1, U32_MAX] is set from the host kernel.</p>
  <p><strong>CVSS:</strong> N/A · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-40266">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-9558 – There is a potential OOB Write vulnerability in the gen_prov_start function in p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-9558</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-9558</guid>
    <pubDate>Wed, 26 Nov 2025 06:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-9558</strong></p>
  <p>There is a potential OOB Write vulnerability in the gen_prov_start function in pb_adv.c. The full length of the received data is copied into the link.rx.buf receiver buffer without any validation on the data size.</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9558">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-63917 – PDFPatcher thru 1.1.3.4663 executable's XML bookmark import functionality does n...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-63917</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-63917</guid>
    <pubDate>Mon, 17 Nov 2025 17:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-63917</strong></p>
  <p>PDFPatcher thru 1.1.3.4663 executable's XML bookmark import functionality does not restrict XML external entity (XXE) references. The application uses .NET's XmlDocument class without disabling external entity resolution, enabling attackers to: Read arbitrary files from the victim's filesystem, exfiltrate sensitive data via out-of-band (OOB) HTTP requests, perform SSRF attacks against internal ne…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-63917">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Unknown] CVE-2025-40154 – In the Linux kernel, the following vulnerability has been resolved:

ASoC: Intel...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-40154</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-40154</guid>
    <pubDate>Wed, 12 Nov 2025 11:15:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk unknown">Unknown</span> CVE-2025-40154</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  ASoC: Intel: bytcr_rt5640: Fix invalid quirk input mapping  When an invalid value is passed via quirk option, currently bytcr_rt5640 driver only shows an error message but leaves as is. This may lead to unepxected results like OOB access.  This patch corrects the input mapping to the certain default value if an invalid value is…</p>
  <p><strong>CVSS:</strong> N/A · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-40154">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Unknown] CVE-2025-40121 – In the Linux kernel, the following vulnerability has been resolved:

ASoC: Intel...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-40121</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-40121</guid>
    <pubDate>Wed, 12 Nov 2025 11:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk unknown">Unknown</span> CVE-2025-40121</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  ASoC: Intel: bytcr_rt5651: Fix invalid quirk input mapping  When an invalid value is passed via quirk option, currently bytcr_rt5640 driver just ignores and leaves as is, which may lead to unepxected results like OOB access.  This patch adds the sanity check and corrects the input mapping to the certain default value if an inval…</p>
  <p><strong>CVSS:</strong> N/A · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-40121">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
