VulnSea

Tagged “csaf”

CVEs tagged csaf, newest first.

3093 CVEsRSS

CVE-2026-80956Medium· 5.5
2w ago

kernel: dm-pcache: only hand out initialized cache segments (CVE-2026-80956)

A flaw was found in the Linux kernel's `dm-pcache` component. A crafted image can cause the `get_cache_segment()` function to return an uninitialized cache segment. This uninitialized segment, containing a null data pointer, is then used b…

▾ SunlitRed Hat · LinuxEPSS 0.21%via CSAF
CVE-2026-80946Medium· 5.5
2w ago

kernel: fuse: copy request headers via a stack buffer for io-uring (CVE-2026-80946)

A flaw was found in the Linux kernel's FUSE (Filesystem in Userspace) component. The `io-uring` transport attempts to copy request headers directly to or from user space without proper memory validation. A local attacker could exploit this…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.21%via CSAF
CVE-2026-80940Medium· 5.5
2w ago

kernel: wifi: rtw88: pci: fix resource leak on failed NAPI setup (CVE-2026-80940)

A flaw was found in the Linux kernel's rtw88 PCI driver. During the probe process, if the NAPI (Networked Attached Peripheral Interface) setup fails, allocated PCI resources are not properly released. This resource leak could potentially l…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.21%via CSAF
CVE-2026-80934Medium· 5.5
2w ago

kernel: wifi: mt76: mt7996: fix TX DMA mapping leak for AddBA req frames (CVE-2026-80934)

A flaw was found in the Linux kernel's mt76: mt7996 Wi-Fi driver. The driver incorrectly manages Direct Memory Access (DMA) mappings when processing AddBA request frames, causing a continuous leak of these mappings. Over time, this resourc…

▾ SunlitRed Hat · LinuxEPSS 0.21%via CSAF
CVE-2026-80927Medium· 5.5
2w ago

kernel: timekeeping: Check the return value of tk_get_aux_ts64 in __do_adjtimex() (CVE-2026-80927)

A flaw was found in the Linux kernel. A race condition in the timekeeping subsystem, specifically within the __do_adjtimex() function, can occur when the auxiliary clock is handled. This allows uninitialized stack data to be used in calcul…

▾ SunlitRed Hat · Red Hat Enterprise Linux 10EPSS 0.21%via CSAF
CVE-2026-89455Medium· 5.5
2w ago

kernel: PCI: plda: Fix use-after-free of event IRQs during teardown (CVE-2026-89455)

A flaw was found in the Linux kernel's PCI PLDA driver. During the teardown of Interrupt Request (IRQ) domains, the system can attempt to access memory that has already been freed. This 'use-after-free' vulnerability occurs because the dom…

▾ SunlitRed Hat · Red Hat Enterprise Linux 10EPSS 0.21%via CSAF
CVE-2026-89451Medium· 5.5
2w ago

kernel: iommu/sva: Set handle->dev before the SVA handle is visible (CVE-2026-89451)

A flaw was found in the Linux kernel's IOMMU (Input/Output Memory Management Unit) SVA (Shared Virtual Addressing) component. A race condition during the attachment of an SVA handle can lead to a situation where a device pointer is not pro…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.21%via CSAF
CVE-2026-89449Medium· 5.5
2w ago

kernel: iommu: Fix dev_iommu memory leak when device_add fails in iommu_mock_device_add (CVE-2026-89449)

A flaw was found in the Linux kernel's Input-Output Memory Management Unit (IOMMU) subsystem. When a device addition fails during the `iommu_mock_device_add()` operation, the allocated device IOMMU structure is not properly deallocated. Th…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.21%via CSAF
CVE-2026-89446Medium· 5.5
2w ago

kernel: iommufd: Release current IOAS on xa_store() failure (CVE-2026-89446)

A flaw was found in the Linux kernel's iommufd component. When the system attempts to store an Input/Output Address Space (IOAS) object and the storage operation fails, the IOAS object's associated resources, such as its write lock and obj…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.21%via CSAF
CVE-2026-89439Medium· 5.5
2w ago

kernel: platform/x86: ISST: Add a NULL check for sst_inst[] (CVE-2026-89439)

A flaw was found in the Linux kernel's Intel Speed Select Technology (ISST) driver. A missing NULL check for `isst_common.sst_inst[]` during failed socket loading could allow a local attacker to trigger a NULL pointer dereference. This vul…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.21%via CSAF
CVE-2026-81018Medium· 5.5
2w ago

kernel: platform/x86: think-lmi: Free system certificate signatures (CVE-2026-81018)

A flaw was found in the Linux kernel's `think-lmi` driver. When the driver is removed, the system authentication object fails to free stored certificate signatures, leading to a memory leak. This can result in system instability or denial …

▾ SunlitRed Hat · LinuxEPSS 0.16%via CSAF
CVE-2026-80999Medium· 5.5
2w ago

kernel: net: dsa: realtek: use gpiod_set_value_cansleep for reset GPIO (CVE-2026-80999)

A flaw was found in the Linux kernel's Realtek Digital Subscriber Line (DSA) driver. The driver incorrectly uses gpiod_set_value() instead of gpiod_set_value_cansleep() for reset GPIO operations. This can lead to system warnings when the r…

▾ SunlitRed Hat · LinuxEPSS 0.21%via CSAF
CVE-2026-80996Medium· 5.5
2w ago

kernel: net: l2tp: do not propagate multicast notification errors (CVE-2026-80996)

A flaw was found in the Linux kernel's L2TP (Layer 2 Tunneling Protocol) networking component. Specifically, the netlink handlers responsible for creating and modifying L2TP tunnels and sessions may fail to propagate multicast notification…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.21%via CSAF
CVE-2026-80993Medium· 5.5
2w ago

kernel: net: phylink: correctly validate returned PCS in phylink_inband_caps (CVE-2026-80993)

A flaw was found in the Linux kernel's `net: phylink` component. The `phylink_inband_caps()` function does not correctly validate the return value from `mac_select_pcs`, which can return an error pointer instead of a valid Physical Coding …

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.21%via CSAF
CVE-2026-80974Medium· 5.5
2w ago

kernel: mfd: sm501: Fix potential memory leaks during remove (CVE-2026-80974)

A flaw was found in the `mfd: sm501` component of the Linux kernel. This vulnerability arises from a failure to properly free allocated memory for `struct sm501_devdata` during the device removal process. A local attacker could potentially…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.21%via CSAF
CVE-2026-89484Medium· 5.5
2w ago

kernel: lockd: fix NULL dereference on lockowner allocation failure (CVE-2026-89484)

A flaw was found in the Linux kernel's `lockd` component. This vulnerability occurs when the Network Lock Manager (NLM) client attempts to initialize file lock operations without successfully allocating a lockowner. This can lead to a NULL…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.21%via CSAF
CVE-2026-89468Medium· 5.5
2w ago

kernel: power: supply: lp8788-charger: fix use-after-free on remove (CVE-2026-89468)

A flaw was found in the Linux kernel's lp8788-charger component. During the removal of the lp8788-charger, a race condition can occur where work can be queued and executed after the associated memory has been freed. This use-after-free vul…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.21%via CSAF
CVE-2026-89467Medium· 5.5
2w ago

kernel: power: supply: qcom_battmgr: fix use-after-free (CVE-2026-89467)

A flaw was found in the Linux kernel's `qcom_battmgr` component. This flaw is a use-after-free vulnerability that occurs because the `qcom_battmgr_pdr_notify()` function can queue `enable_work` even after the associated `battmgr` object ha…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.21%via CSAF
CVE-2026-89462Medium· 5.5
2w ago

kernel: power: supply: max17040: propagate register read errors (CVE-2026-89462)

A flaw was found in the Linux kernel's power supply subsystem, specifically within the max17040 driver. This vulnerability occurs when the `max17040_get_vcell()` and `max17040_get_soc()` functions fail to properly handle errors returned by…

▾ SunlitRed Hat · LinuxEPSS 0.21%via CSAF
CVE-2026-89090Medium· 5.9
2w ago

An unrecovered panic in the event stream header decoder in Amazon AWS SDK for Go v2 before release-2026-03-23 might allow an unauthenticated remote actor to terminate the consuming application process via a crafted event stream response …

An unrecovered panic in the event stream header decoder in Amazon AWS SDK for Go v2 before release-2026-03-23 might allow an unauthenticated remote actor to terminate the consuming application process via a crafted event stream response …

▾ SunlitAWS · AWS SDK for Go v2EPSS 0.30%via NVD
CVE-2026-87859Medium· 5.3
2w ago

morgan is an HTTP request logger middleware for Node.js

morgan is an HTTP request logger middleware for Node.js. In versions before 1.12.1, its escapeLogField() function does not escape the double quote character, which delimits the quoted fields of the Apache combined log format that morgan …

▾ SunlitRed Hat · Red Hat Enterprise Linux 10EPSS 0.41%via NVD
CVE-2026-89162Low· 2.9
2w ago

In PCRE2 before 10.48, pcre2_serialize_encode might disclose two bytes to an adversary, typically in a situation where the access available to the adversary is already unsafe.

In PCRE2 before 10.48, pcre2_serialize_encode might disclose two bytes to an adversary, typically in a situation where the access available to the adversary is already unsafe.

▾ Sunlitpcre · pcre2EPSS 0.16%via NVD
CVE-2026-87908High· 7.5
2w ago

multiparty is a Node.js library for parsing multipart/form-data request bodies

multiparty is a Node.js library for parsing multipart/form-data request bodies. In versions from 2.1.0 up to but not including 4.3.1, the parser does not bound the amount of memory used while accumulating the headers of a single multipar…

▾ Twilightmultiparty · multipartyEPSS 0.51%via NVD
CVE-2026-87776High· 7.5
2w ago

compression is a Node.js and Express compression middleware

compression is a Node.js and Express compression middleware. In versions before 1.8.2, when a client aborts the connection while a compressed response is still being sent, the zlib stream created to compress that response is never destro…

▾ Twilightcompression · compressionEPSS 0.61%via NVD
CVE-2026-89160Low· 3.7PoC
2w ago

PCRE2 before 10.48 has a pcre2_match out-of-bounds read during the PCRE2_MATCH_INVALID_UTF matching of an invalid UTF subject.

PCRE2 before 10.48 has a pcre2_match out-of-bounds read during the PCRE2_MATCH_INVALID_UTF matching of an invalid UTF subject.

▾ Twilightpcre · pcre2EPSS 0.27%via NVD
CVE-2026-89157Medium· 5.7PoC
2w ago

PCRE2 before 10.48, on 32-bit platforms, has a pcre2_pattern_convert out-of-bounds write when an attacker can provide a large pattern.

PCRE2 before 10.48, on 32-bit platforms, has a pcre2_pattern_convert out-of-bounds write when an attacker can provide a large pattern.

▾ Twilightpcre · pcre2EPSS 0.28%via NVD
CVE-2026-89156Low· 2.9
2w ago

PCRE2 before 10.48 has a pcre2_match out-of-bounds read after a JIT fallback when an attacker can provide invalid UTF data.

PCRE2 before 10.48 has a pcre2_match out-of-bounds read after a JIT fallback when an attacker can provide invalid UTF data.

▾ Sunlitpcre · pcre2EPSS 0.29%via NVD
CVE-2026-88888High· 7.0
2w ago

Renovate before 44.14.7 contains a command injection vulnerability in the Mix manager when processing private dependencies with unescaped organization parameters

Renovate before 44.14.7 contains a command injection vulnerability in the Mix manager when processing private dependencies with unescaped organization parameters. Attackers can inject shell metacharacters through malicious package names …

▾ Twilightrenovatebot · renovateEPSS 0.89%via NVD
CVE-2026-88053High· 7.8PoC
2w ago

Tesseract is an open source OCR engine

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, Classify::ReadIntTemplates in src/classify/intproto.cpp reads NumClassPruners, NumClasses, and NumProtoSets from the TESSDATA_INTTEMP component of a crafted .trainedda…

▾ Midnighttesseract-ocr · tesseract_ocrEPSS 0.18%via NVD
CVE-2026-88018Critical· 9.8PoC
2w ago

rclone is a command-line program to sync files and directories to and from different cloud storage providers

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, rclone serve s3 configured with --auth-proxy but without --auth-key allows authPairMiddleware to register any …

▾ Abyssalrclone · rcloneEPSS 0.75%via NVD
CVEs tagged “csaf” — page 42 · VulnSea