Tagged “csaf”
CVEs tagged csaf, newest first.
3093 CVEsRSS
CVE-2026-89693High· 7.0In the Linux kernel, the following vulnerability has been resolved: nfsd: check nfsd4_acl_to_attr() return value in nfsd4_create() nfsd4_create() stores the return value of nfsd4_acl_to_attr() in status, but the switch(create->cr_type)…
In the Linux kernel, the following vulnerability has been resolved: nfsd: check nfsd4_acl_to_attr() return value in nfsd4_create() nfsd4_create() stores the return value of nfsd4_acl_to_attr() in status, but the switch(create->cr_type)…
CVE-2026-89683High· 7.0kernel: nfsd: fix dentry ref leak on V4ROOT export filehandle lookup (CVE-2026-89683)
A flaw was found in the Linux kernel's nfsd (NFS daemon). A remote attacker could exploit this vulnerability by sending a specially crafted NFSv3 filehandle targeting a V4ROOT export's file system identifier (fsid). This action triggers a …
CVE-2026-89666High· 7.0kernel: nfsd: reject out-of-range nseconds in NFSv3 SETATTR and create ops (CVE-2026-89666)
A flaw was found in the kernel. A remote attacker, acting as an NFSv3 client, can send malformed time values during SETATTR or create operations. This can lead to the corruption of on-disk metadata, resulting in incorrect timestamps for fi…
CVE-2026-89645Medium· 5.5kernel: btrfs: drop recovered reloc root refs on recovery failure (CVE-2026-89645)
A flaw was found in the btrfs file system in the Linux kernel. During relocation recovery, if an error occurs, such as a memory allocation failure, the system may not properly drop references to relocation roots. This oversight can lead to…
CVE-2026-89644Medium· 5.5In the Linux kernel, the following vulnerability has been resolved: btrfs: fix extent map leak in NOCOW direct I/O write btrfs_dio_iomap_begin() calls btrfs_get_extent(), which returns an extent map reference that must be dropped on al…
In the Linux kernel, the following vulnerability has been resolved: btrfs: fix extent map leak in NOCOW direct I/O write btrfs_dio_iomap_begin() calls btrfs_get_extent(), which returns an extent map reference that must be dropped on al…
CVE-2026-89629Medium· 5.5kernel: HID: corsair-void: Check size of status and firmware events before reading them (CVE-2026-89629)
A flaw was found in the Linux kernel, specifically within the `corsair-void` driver for Human Interface Devices (HID). This vulnerability allows an attacker to cause an out-of-bounds read by sending malformed status and firmware events. Th…
CVE-2026-89625High· 7.0In the Linux kernel, the following vulnerability has been resolved: HID: sony: fix UAF of ghl_poke_timer / ghl_urb at driver unbind For GHL (Guitar Hero Live) dongles, sony_probe() arms a periodic timer: ghl_magic_poke() (the timer cal…
In the Linux kernel, the following vulnerability has been resolved: HID: sony: fix UAF of ghl_poke_timer / ghl_urb at driver unbind For GHL (Guitar Hero Live) dongles, sony_probe() arms a periodic timer: ghl_magic_poke() (the timer cal…
CVE-2026-89772High· 7.0kernel: btrfs: write-protect folios during data writeback (CVE-2026-89772)
A flaw was found in the Btrfs filesystem of the Linux kernel. This vulnerability allows a local attacker with write access to a memory-mapped file to modify data while it is being written to disk. This can lead to data corruption, where th…
CVE-2026-89770Medium· 5.5kernel: iomap: don't free integrity payload that doesn't exist (CVE-2026-89770)
A flaw was found in the `iomap` component of the Linux kernel. This vulnerability occurs when Protection Information (PI) verification is disabled on a block device, causing `fs_bio_integrity_alloc` to not allocate a bio integrity payload.…
CVE-2026-89768Medium· 5.5kernel: fs: fix user path of nested backing files (CVE-2026-89768)
A flaw was found in the Linux kernel's filesystem (fs) component. When using nested overlay filesystems (overlayfs), a local user could exploit an issue where the backing_file_open() function incorrectly derives the path for mapped files. …
CVE-2026-89766High· 7.0kernel: pidfd: hold exec_update_lock around namespace ioctl (CVE-2026-89766)
A flaw was found in the Linux kernel. A local attacker could exploit a race condition in the `pidfd` subsystem, specifically within the `PIDFD_GET_*_NAMESPACE` ioctls. This vulnerability occurs because the system does not properly hold a l…
CVE-2026-89759Medium· 5.5kernel: mm/kmemleak: avoid soft lockup when scanning task stacks (CVE-2026-89759)
A flaw was found in the Linux kernel's memory leak detector (kmemleak). When kmemleak_scan() attempts to scan task stacks on systems with a large number of threads, it can hold a CPU for an extended period without allowing other processes …
CVE-2026-89757Medium· 5.5kernel: mm/mglru: fix and remove redundant unevictable folio handling (CVE-2026-89757)
A flaw was found in the Linux kernel's memory management unit (MMU), specifically within the multi-generational Least Recently Used (mglru) mechanism. A bug in how the kernel handles unevictable memory pages can lead to these pages remaini…
CVE-2026-89745High· 7.0kernel: debugfs: Fix lockdown check for mmap_prepare (CVE-2026-89745)
A flaw was found in the Linux kernel's debugfs component. The lockdown mechanism, designed to enhance system integrity, did not properly account for files using the `mmap_prepare` operation. This oversight could allow an attacker to bypass…
CVE-2026-89740Medium· 5.5kernel: serial: imx: serialize imx_uart_ports[] lifetime (CVE-2026-89740)
A flaw was found in the Linux kernel's `serial: imx` component. The `imx_uart_probe()` function publishes a device-managed allocated port in the `imx_uart_ports[]` array before it is fully added. If the port addition fails or the port is r…
CVE-2026-89161High· 7.4In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context
In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context. An incorrect free operation can occur.
CVE-2026-89060High· 7.7A cross-namespace authorization flaw in multicluster-observability-addon allows a user with permission to modify a managed cluster’s ManagedClusterAddOn configuration to reference ClusterLogForwarder or OpenTelemetryCollector resources o…
A cross-namespace authorization flaw in multicluster-observability-addon allows a user with permission to modify a managed cluster’s ManagedClusterAddOn configuration to reference ClusterLogForwarder or OpenTelemetryCollector resources o…
CVE-2026-45057Medium· 4.9matrix-sdk-ui provides GUI-centric utilities on top of matrix-rust-sdk
matrix-sdk-ui provides GUI-centric utilities on top of matrix-rust-sdk. The message edit validation logic in the `matrix-sdk-ui` crate prior to 0.17.0 is missing a check: when replacing an encrypted event, the replacement event itself i…
CVE-2026-45056Medium· 6.9⚖ disputedmatrix-sdk-crypto is a no-network-IO implementation of a state machine that handles end-to-end encryption for Matrix clients
matrix-sdk-crypto is a no-network-IO implementation of a state machine that handles end-to-end encryption for Matrix clients. Starting in version 0.12.0 and prior to version 0.17.0, the matrix-sdk-crypto crate was missing a check for the…
CVE-2026-90461Medium· 6.3OpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is configured for HTTP(S) Basic Authentication.
OpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is configured for HTTP(S) Basic Authentication.
CVE-2026-78807High· 7.1An issue in wpa_supplicant all versions before v.2.12 allows a local attacker to bypass proper network context and AKMP matching for PMKSA caching via missing validation in the driver based PMKSA selection path in wpa.c
An issue in wpa_supplicant all versions before v.2.12 allows a local attacker to bypass proper network context and AKMP matching for PMKSA caching via missing validation in the driver based PMKSA selection path in wpa.c
CVE-2026-68497High· 7.5PoCjackson-databind binds a JSON string to a javax.xml.datatype.Duration or javax.xml.datatype.XMLGregorianCalendar field by passing the raw string verbatim to DatatypeFactory.newDuration(value) or newXMLGregorianCalendar(value) in CoreXMLD…
jackson-databind binds a JSON string to a javax.xml.datatype.Duration or javax.xml.datatype.XMLGregorianCalendar field by passing the raw string verbatim to DatatypeFactory.newDuration(value) or newXMLGregorianCalendar(value) in CoreXMLD…
CVE-2026-80942Medium· 5.5In the Linux kernel, the following vulnerability has been resolved: wifi: rtlwifi: rtl8192du: Fix possible memory leak in rtl92du_init_sw_vars() The memory allocated inside rtl92du_init_shared_data() is not freed in any of the subseque…
In the Linux kernel, the following vulnerability has been resolved: wifi: rtlwifi: rtl8192du: Fix possible memory leak in rtl92du_init_sw_vars() The memory allocated inside rtl92du_init_shared_data() is not freed in any of the subseque…
CVE-2026-89454Medium· 4.4In the Linux kernel, the following vulnerability has been resolved: PCI: plda: Fix IRQ domain leaks in the error paths of plda_init_interrupts() plda_init_interrupts() initializes IRQ domains and creates IRQ mapping but does not unwind…
In the Linux kernel, the following vulnerability has been resolved: PCI: plda: Fix IRQ domain leaks in the error paths of plda_init_interrupts() plda_init_interrupts() initializes IRQ domains and creates IRQ mapping but does not unwind…
CVE-2026-89453Medium· 5.5In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Put PCI device after handling PPR faults iommu_call_iopf_notifier() looks up the requester with pci_get_domain_bus_and_slot(), which returns a PCI device wi…
In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Put PCI device after handling PPR faults iommu_call_iopf_notifier() looks up the requester with pci_get_domain_bus_and_slot(), which returns a PCI device wi…
CVE-2026-81009Medium· 5.5In the Linux kernel, the following vulnerability has been resolved: io_uring/query: cap user size passed to copy_struct_to_user io_handle_query_entry() clamps hdr.size for the inbound copy_from_user() but keeps the original user value …
In the Linux kernel, the following vulnerability has been resolved: io_uring/query: cap user size passed to copy_struct_to_user io_handle_query_entry() clamps hdr.size for the inbound copy_from_user() but keeps the original user value …
CVE-2026-89158Medium· 6.5PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 integer overflow and resultant out-of-bounds write.
PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 integer overflow and resultant out-of-bounds write.
CVE-2026-89092Medium· 4.2glibc: nscd stack overflow leads to degraded DNS resolution (CVE-2026-89092)
A flaw was found in glibc, specifically within the nscd service. A remote attacker, operating a malicious Domain Name System (DNS) server, could send an overly large DNS response. This could trigger a stack overflow in the nscd service, ca…
CVE-2026-80960Medium· 5.5kernel: dm-pcache: validate on-media seg_num against the cache device size (CVE-2026-80960)
A flaw was found in the Linux kernel's dm-pcache component. A local attacker with CAP_SYS_ADMIN capabilities can exploit this vulnerability by supplying a specially crafted cache device. The seg_num value, which dictates the size of cache …
CVE-2026-80957Medium· 5.5kernel: dm-pcache: detect a cycle in the last-kset chain during replay (CVE-2026-80957)
A flaw was found in the `dm-pcache` component of the Linux kernel. A local attacker could exploit a vulnerability in the `cache_replay()` function, which does not properly handle a forged `last-kset` chain. By crafting a malicious chain th…