VulnSea

Weekly digest

Week 8, 2024 (19–25 Feb)

A busier-than-usual week with 31 new CVEs (recent average about 20). Severity skewed high: 10 critical and 18 high, 90% of the total. 2 arrived with exploitation evidence or public exploit code already attached. No new KEV entries. linux was the most-affected vendor with 22.

31
New CVEs
10
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 12 that matter most of the 31 published.

CVE-2024-1212Critical· 10.0CISA KEVPoC
2y ago

Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution.

Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution.

▾ Hadalprogress · loadmasterEPSS 95%via NVD
CVE-2023-52440Critical· 9.8PoC
2y ago

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix slub overflow in ksmbd_decode_ntlmssp_auth_blob() If authblob->SessionKey.Length is bigger than session key size(CIFS_KEY_SIZE), slub overflow can happen in…

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix slub overflow in ksmbd_decode_ntlmssp_auth_blob() If authblob->SessionKey.Length is bigger than session key size(CIFS_KEY_SIZE), slub overflow can happen in…

▾ Abyssallinux · linux_kernelEPSS 22%via NVD
CVE-2024-26594Critical· 9.1
2y ago

In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate mech token in session setup If client send invalid mech token in session setup request, ksmbd validate and make the error if it is invalid.

In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate mech token in session setup If client send invalid mech token in session setup request, ksmbd validate and make the error if it is invalid.

▾ Midnightlinux · linux_kernelEPSS 51%via NVD
CVE-2023-52442Critical· 9.1
2y ago

In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate session id and tree id in compound request `smb2_get_msg()` in smb2_get_ksmbd_tcon() and smb2_check_user_session() will always return the first request…

In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate session id and tree id in compound request `smb2_get_msg()` in smb2_get_ksmbd_tcon() and smb2_check_user_session() will always return the first request…

▾ Midnightlinux · linux_kernelEPSS 30%via NVD
CVE-2024-26592Critical· 9.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix UAF issue in ksmbd_tcp_new_connection() The race is between the handling of a new TCP connection and its disconnection

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix UAF issue in ksmbd_tcp_new_connection() The race is between the handling of a new TCP connection and its disconnection. It leads to UAF on `struct tcp_trans…

▾ Midnightlinux · linux_kernelEPSS 0.97%via NVD
CVE-2024-26585Critical· 9.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: tls: fix race between tx work scheduling and socket close Similarly to previous commit, the submitting thread (recvmsg/sendmsg) may exit as soon as the async crypto ha…

In the Linux kernel, the following vulnerability has been resolved: tls: fix race between tx work scheduling and socket close Similarly to previous commit, the submitting thread (recvmsg/sendmsg) may exit as soon as the async crypto ha…

▾ Midnightlinux · linux_kernelEPSS 0.59%via NVD
CVE-2024-26584Critical· 9.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: net: tls: handle backlogging of crypto requests Since we're setting the CRYPTO_TFM_REQ_MAY_BACKLOG flag on our requests to the crypto API, crypto_aead_{encrypt,decrypt…

In the Linux kernel, the following vulnerability has been resolved: net: tls: handle backlogging of crypto requests Since we're setting the CRYPTO_TFM_REQ_MAY_BACKLOG flag on our requests to the crypto API, crypto_aead_{encrypt,decrypt…

▾ Midnightlinux · linux_kernelEPSS 0.75%via NVD
CVE-2024-26583Critical· 9.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: tls: fix race between async notify and socket close The submitting thread (one which called recvmsg/sendmsg) may exit as soon as the async crypto handler calls complet…

In the Linux kernel, the following vulnerability has been resolved: tls: fix race between async notify and socket close The submitting thread (one which called recvmsg/sendmsg) may exit as soon as the async crypto handler calls complet…

▾ Midnightlinux · linux_kernelEPSS 0.55%via NVD
CVE-2024-26582Critical· 9.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: net: tls: fix use-after-free with partial reads and async decrypt tls_decrypt_sg doesn't take a reference on the pages from clear_skb, so the put_page() in tls_decrypt…

In the Linux kernel, the following vulnerability has been resolved: net: tls: fix use-after-free with partial reads and async decrypt tls_decrypt_sg doesn't take a reference on the pages from clear_skb, so the put_page() in tls_decrypt…

▾ Midnightlinux · linux_kernelEPSS 0.71%via NVD
CVE-2023-52441Critical· 9.1
2y ago

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix out of bounds in init_smb2_rsp_hdr() If client send smb2 negotiate request and then send smb1 negotiate request, init_smb2_rsp_hdr is called for smb1 negoti…

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix out of bounds in init_smb2_rsp_hdr() If client send smb2 negotiate request and then send smb1 negotiate request, init_smb2_rsp_hdr is called for smb1 negoti…

▾ Midnightlinux · linux_kernelEPSS 0.68%via NVD
CVE-2024-26598High· 8.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Avoid potential UAF in LPI translation cache There is a potential UAF scenario in the case of an LPI translation cache hit racing with an operati…

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Avoid potential UAF in LPI translation cache There is a potential UAF scenario in the case of an LPI translation cache hit racing with an operati…

▾ Twilightlinux · linux_kernelEPSS 0.24%via NVD
CVE-2024-26151High· 8.2
2y ago

Potentially untrusted input is rendered as HTML in final output

Potentially untrusted input is rendered as HTML in final output

▾ Twilightmjml · mjmlEPSS 0.62%via OSV

Most-affected vendors

By CVEs published in the period.