Weekly digest
Week 10, 2024 (4–10 Mar)
A busier-than-usual week with 43 new CVEs (recent average about 32). Severity skewed high: 4 critical and 28 high, 74% of the total. 2 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. linux was the most-affected vendor with 23.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
New this week, ranked by depth score
The 12 that matter most of the 43 published.
CVE-2024-27304High· 8.1PoCpgx: SQL Injection via Protocol Message Size Overflow (CVE-2024-27304)
pgx is a PostgreSQL driver and toolkit for Go. SQL injection can occur if an attacker can cause a single query or bind message to exceed 4 GB in size. An integer overflow in the calculated message size can cause the one large message to be…
CVE-2024-0917Critical· 9.8PaddlePaddle vulnerable to remote code execution
PaddlePaddle vulnerable to remote code execution
CVE-2021-47107Critical· 9.8In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix READDIR buffer overflow If a client sends a READDIR count argument that is too small (say, zero), then the buffer size calculation in the new init_dirlist he…
In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix READDIR buffer overflow If a client sends a READDIR count argument that is too small (say, zero), then the buffer size calculation in the new init_dirlist he…
CVE-2021-47103Critical· 9.8In the Linux kernel, the following vulnerability has been resolved: inet: fully convert sk->sk_rx_dst to RCU rules syzbot reported various issues around early demux, one being included in this changelog [1] sk->sk_rx_dst is using RCU …
In the Linux kernel, the following vulnerability has been resolved: inet: fully convert sk->sk_rx_dst to RCU rules syzbot reported various issues around early demux, one being included in this changelog [1] sk->sk_rx_dst is using RCU …
CVE-2024-0818Critical· 9.1PaddlePaddle Path Traversal vulnerability
PaddlePaddle Path Traversal vulnerability
CVE-2024-0815High· 8.8PaddlePaddle command injection in paddle.utils.download._wget_download
PaddlePaddle command injection in paddle.utils.download._wget_download
CVE-2024-27758High· 8.5RPyC's missing security check results in code execution when using numpy.array on the server-side.
RPyC's missing security check results in code execution when using numpy.array on the server-side.
CVE-2022-48629High· 8.1In the Linux kernel, the following vulnerability has been resolved: crypto: qcom-rng - ensure buffer for generate is completely filled The generate function in struct rng_alg expects that the destination buffer is completely filled if …
In the Linux kernel, the following vulnerability has been resolved: crypto: qcom-rng - ensure buffer for generate is completely filled The generate function in struct rng_alg expects that the destination buffer is completely filled if …
CVE-2024-27918High· 8.2Coder's OIDC authentication allows email with partially matching domain to register
Coder's OIDC authentication allows email with partially matching domain to register
CVE-2024-0817High· 7.8PaddlePaddle command injection vulnerability
PaddlePaddle command injection vulnerability
CVE-2024-26625High· 7.8In the Linux kernel, the following vulnerability has been resolved: llc: call sock_orphan() at release time syzbot reported an interesting trace [1] caused by a stale sk->sk_wq pointer in a closed llc socket. In commit ff7b11aa481f ("…
In the Linux kernel, the following vulnerability has been resolved: llc: call sock_orphan() at release time syzbot reported an interesting trace [1] caused by a stale sk->sk_wq pointer in a closed llc socket. In commit ff7b11aa481f ("…
CVE-2024-26623High· 7.8In the Linux kernel, the following vulnerability has been resolved: pds_core: Prevent race issues involving the adminq There are multiple paths that can result in using the pdsc's adminq. [1] pdsc_adminq_isr and the resulting work fro…
In the Linux kernel, the following vulnerability has been resolved: pds_core: Prevent race issues involving the adminq There are multiple paths that can result in using the pdsc's adminq. [1] pdsc_adminq_isr and the resulting work fro…
Most-affected vendors
By CVEs published in the period.