VulnSea

CWE-666

CVEs classified under CWE-666, newest first.

4 CVEsRSS

CVE-2026-16148Medium· 4.6
1w ago

The ITE it82xx2 USB device-controller driver initialized its bus-suspend detection work with k_work_init_delayable(&priv->suspended_work, suspended_handler) inside it82xx2_enable() (the driver's .enable op) in drivers/usb/udc/udc_it82xx2…

The ITE it82xx2 USB device-controller driver initialized its bus-suspend detection work with k_work_init_delayable(&priv->suspended_work, suspended_handler) inside it82xx2_enable() (the driver's .enable op) in drivers/usb/udc/udc_it82xx2…

Sunlitzephyrproject · zephyrEPSS 0.17%via NVD
CVE-2026-15460Medium· 5.4
1w ago

Missing channel-state validation in Zephyr Bluetooth Classic L2CAP receive path

The Bluetooth Classic (BR/EDR) L2CAP receive handler bt_l2cap_br_recv() in subsys/bluetooth/host/classic/l2cap_br.c dispatched inbound data PDUs based only on the destination channel ID, without checking that the target channel had reach…

Sunlitzephyrproject · zephyrEPSS 0.16%via CVEORG
CVE-2026-68930Medium· 6.5
1mo ago

Russh is a Rust SSH client & server library

Russh is a Rust SSH client & server library. Prior to 0.62.5, russh dispatches channel-scoped Handler callbacks for recipient channel IDs that were never opened or confirmed in russh/src/server/encrypted.rs, server_read_authenticated, an…

Sunlitrussh · russhEPSS 0.26%via NVD
CVE-2024-46754High· 7.8⚖ disputed
2y ago

In the Linux kernel, the following vulnerability has been resolved: bpf: Remove tst_run from lwt_seg6local_prog_ops. The syzbot reported that the lwt_seg6 related BPF ops can be invoked via bpf_test_run() without without entering input…

In the Linux kernel, the following vulnerability has been resolved: bpf: Remove tst_run from lwt_seg6local_prog_ops. The syzbot reported that the lwt_seg6 related BPF ops can be invoked via bpf_test_run() without without entering input…

Twilightlinux · linux_kernelEPSS 0.25%via NVD
CWE-666 vulnerabilities (CVEs) · VulnSea