VulnSea

Weekly digest

Week 14, 2024 (1–7 Apr)

A heavy week: 61 new CVEs, well above the recent average of about 35. Severity skewed high: 4 critical and 50 high, 89% of the total. 2 arrived with exploitation evidence or public exploit code already attached. No new KEV entries. linux was the most-affected vendor with 50.

61
New CVEs
4
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 12 that matter most of the 61 published.

CVE-2024-3116High· 7.4PoC
2y ago

pgAdmin Remote Code Execution (RCE) vulnerability

pgAdmin Remote Code Execution (RCE) vulnerability

▾ Midnightpgadmin4 · pgadmin4EPSS 66%via OSV
CVE-2023-45288Medium· 5.3PoC
2y ago

net/http, x/net/http2: close connections when receiving too many headers

net/http, x/net/http2: close connections when receiving too many headers

▾ Twilightnet · net/httpEPSS 92%via OSV
CVE-2024-26800Critical· 9.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: tls: fix use-after-free on failed backlog decryption When the decrypt request goes to the backlog and crypto_aead_decrypt returns -EBUSY, tls_do_decryption will wait u…

In the Linux kernel, the following vulnerability has been resolved: tls: fix use-after-free on failed backlog decryption When the decrypt request goes to the backlog and crypto_aead_decrypt returns -EBUSY, tls_do_decryption will wait u…

▾ Midnightlinux · linux_kernelEPSS 0.74%via NVD
CVE-2024-26782Critical· 9.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: mptcp: fix double-free on socket dismantle when MPTCP server accepts an incoming connection, it clones its listener socket

In the Linux kernel, the following vulnerability has been resolved: mptcp: fix double-free on socket dismantle when MPTCP server accepts an incoming connection, it clones its listener socket. However, the pointer to 'inet_opt' for the …

▾ Midnightlinux · linux_kernelEPSS 0.71%via NVD
CVE-2024-26760Critical· 9.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: scsi: target: pscsi: Fix bio_put() for error case As of commit 066ff571011d ("block: turn bio_kmalloc into a simple kmalloc wrapper"), a bio allocated by bio_kmalloc()…

In the Linux kernel, the following vulnerability has been resolved: scsi: target: pscsi: Fix bio_put() for error case As of commit 066ff571011d ("block: turn bio_kmalloc into a simple kmalloc wrapper"), a bio allocated by bio_kmalloc()…

▾ Midnightlinux · linux_kernelEPSS 0.64%via NVD
CVE-2024-26665Critical· 9.1
2y ago

In the Linux kernel, the following vulnerability has been resolved: tunnels: fix out of bounds access when building IPv6 PMTU error If the ICMPv6 error is built from a non-linear skb we get the following splat, BUG: KASAN: slab-out-…

In the Linux kernel, the following vulnerability has been resolved: tunnels: fix out of bounds access when building IPv6 PMTU error If the ICMPv6 error is built from a non-linear skb we get the following splat, BUG: KASAN: slab-out-…

▾ Midnightlinux · linux_kernelEPSS 0.68%via NVD
CVE-2024-26689High· 8.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: ceph: prevent use-after-free in encode_cap_msg() In fs/ceph/caps.c, in encode_cap_msg(), "use after free" error was caught by KASAN at this line - 'ceph_buffer_get(arg…

In the Linux kernel, the following vulnerability has been resolved: ceph: prevent use-after-free in encode_cap_msg() In fs/ceph/caps.c, in encode_cap_msg(), "use after free" error was caught by KASAN at this line - 'ceph_buffer_get(arg…

▾ Twilightlinux · linux_kernelEPSS 0.70%via NVD
CVE-2024-26801High· 8.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Avoid potential use-after-free in hci_error_reset While handling the HCI_EV_HARDWARE_ERROR event, if the underlying BT controller is not responding, the GPI…

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Avoid potential use-after-free in hci_error_reset While handling the HCI_EV_HARDWARE_ERROR event, if the underlying BT controller is not responding, the GPI…

▾ Twilightlinux · linux_kernelEPSS 0.42%via NVD
CVE-2024-26779High· 8.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix race condition on enabling fast-xmit fast-xmit must only be enabled after the sta has been uploaded to the driver, otherwise it could end up passin…

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix race condition on enabling fast-xmit fast-xmit must only be enabled after the sta has been uploaded to the driver, otherwise it could end up passin…

▾ Twilightlinux · linux_kernelEPSS 0.28%via NVD
CVE-2024-26692High· 8.3
2y ago

In the Linux kernel, the following vulnerability has been resolved: smb: Fix regression in writes when non-standard maximum write size negotiated The conversion to netfs in the 6.3 kernel caused a regression when maximum write size is …

In the Linux kernel, the following vulnerability has been resolved: smb: Fix regression in writes when non-standard maximum write size negotiated The conversion to netfs in the 6.3 kernel caused a regression when maximum write size is …

▾ Twilightlinux · linux_kernelEPSS 0.53%via NVD
CVE-2024-26736High· 8.1
2y ago

In the Linux kernel, the following vulnerability has been resolved: afs: Increase buffer size in afs_update_volume_status() The max length of volume->vid value is 20 characters. So increase idbuf[] size up to 24 to avoid overflow. Fou…

In the Linux kernel, the following vulnerability has been resolved: afs: Increase buffer size in afs_update_volume_status() The max length of volume->vid value is 20 characters. So increase idbuf[] size up to 24 to avoid overflow. Fou…

▾ Twilightlinux · linux_kernelEPSS 0.72%via NVD
CVE-2024-26812High· 7.8
2y ago

In the Linux kernel, the following vulnerability has been resolved: vfio/pci: Create persistent INTx handler A vulnerability exists where the eventfd for INTx signaling can be deconfigured, which unregisters the IRQ handler but still a…

In the Linux kernel, the following vulnerability has been resolved: vfio/pci: Create persistent INTx handler A vulnerability exists where the eventfd for INTx signaling can be deconfigured, which unregisters the IRQ handler but still a…

▾ Twilightlinux · linux_kernelEPSS 0.25%via NVD

Most-affected vendors

By CVEs published in the period.