4 hours 30 minutes ago
It was discovered that libXpm did not correctly handle XPM images with
zero-dimension values. A local attacker could possibly use this issue to
cause libXpm to use excessive resources, leading to a denial of service.
5 hours 19 minutes ago
It was discovered that OpenSSL had an inefficient algorithm in its QUIC
stream reassembly implementation. A remote attacker could possibly use this
issue to cause OpenSSL to use excessive CPU resources, leading to a denial
of service. (CVE-2026-42772)
It was discovered that OpenSSL did not properly limit memory allocated for
QUIC packet buffers. A remote attacker could possibly use this issue to
cause OpenSSL to use excessive memory resources, leading to a denial of
service. (CVE-2026-54873)
6 hours 4 minutes ago
It was discovered that OpenStack Designate did not properly validate
overlapping zones under certain circumstances. An authenticated user could
possibly use this issue to redirect DNS traffic to attacker-controlled
systems or cause a denial of service.
6 hours 32 minutes ago
It was discovered that KCoreAddons incorrectly handled shell argument
quoting in KShell::quoteArgs. The parsing did not adequately handle shell
metacharacters, which could lead to a shell escape. An attacker could
possibly use this issue to execute arbitrary commands in applications that
relied on this method to handle user input.
1 day ago
It was discovered that Authen::SASL, a Perl authentication library, did
not properly validate login attempts. An attacker could possibly use
this issue to gain unauthorized access.
1 day ago
It was discovered that ImageMagick did not correctly handle certain images.
An attacker could possibly use this issue to cause a denial of service or
obtain sensitive information. This issue only affected Ubuntu 16.04 LTS,
Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS.
(CVE-2026-56367)
It was discovered that ImageMagick did not correctly handle certain images.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2026-93586)
It was discovered that ImageMagick did not correctly handle certain images.
A local attacker could possibly use this issue to cause a denial of
service. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS,
Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-93587, CVE-2026-93588)
It was discovered that ImageMagick did not correctly handle certain images.
An attacker could possibly use this issue to cause a denial of service.
This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04
LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-93589)
It was discovered that ImageMagick did not correctly handle certain images.
An attacker could possibly use this issue to cause a denial of service.
This issue only affected Ubuntu 26.04 LTS. (CVE-2026-93590)
1 day 1 hour ago
It was discovered that GStreamer Bad Plugins incorrectly validated the size
of multi-channel audio blocks. An attacker could possibly use this issue
with a specially crafted WAV file to cause the program to crash, resulting
in a denial of service, or possibly execute arbitrary code.
1 day 1 hour ago
It was discovered that Kdenlive allowed dangerous proxy parameters when
processing attacker-controlled project files. An attacker could use this to
execute arbitrary commands via the MLT framework's ante/post consumer
properties.
1 day 1 hour ago
Keith Linneman discovered that GVfs did not properly validate data
received from SFTP servers. An attacker could possibly use this issue to
cause a heap buffer overflow, resulting in arbitrary code execution or a
denial of service. (CVE-2026-84268)
It was discovered that GVfs incorrectly handled file ownership when
creating private D-Bus sockets in the admin backend. A local attacker
could possibly use this issue to change the ownership of arbitrary
system files, resulting in privilege escalation to root. This issue only
affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS.
(CVE-2026-88924)
1 day 3 hours ago
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- ARM64 architecture;
- S390 architecture;
- x86 architecture;
- DRBD Distributed Replicated Block Device drivers;
- InfiniBand drivers;
- IOMMU subsystem;
- Multiple devices driver;
- Network drivers;
- Microsoft Azure Network Adapter (MANA) driver;
- NVME drivers;
- TCM subsystem;
- Virtio Host (VHOST) subsystem;
- Xen hypervisor drivers;
- AFS file system;
- File systems infrastructure;
- Network file systems library;
- Network file system (NFS) client;
- NTFS3 file system;
- OCFS2 file system;
- OrangeFS file system;
- SMB network file system;
- IPv4 networking;
- Sun RPC protocol;
- IPv6 networking;
- IP tunnels definitions;
- Netfilter;
- TCP network protocol;
- Locking primitives;
- 9P file system network protocol;
- B.A.T.M.A.N. meshing protocol;
- Networking core;
- IFE protocol;
- RxRPC session sockets;
- Network traffic control;
- SCTP protocol;
- SMC sockets;
- TIPC protocol;
- XFRM subsystem;
(CVE-2026-64530, CVE-2026-64534, CVE-2026-64535, CVE-2026-64541,
CVE-2026-64551, CVE-2026-68083, CVE-2026-68457, CVE-2026-68476,
CVE-2026-68477, CVE-2026-72014, CVE-2026-72020, CVE-2026-72033,
CVE-2026-72041, CVE-2026-72046, CVE-2026-72064, CVE-2026-72065,
CVE-2026-72069, CVE-2026-72083, CVE-2026-72084, CVE-2026-72085,
CVE-2026-72098, CVE-2026-72129, CVE-2026-72130, CVE-2026-72137,
CVE-2026-72139, CVE-2026-72191, CVE-2026-72192, CVE-2026-72194,
CVE-2026-72217, CVE-2026-72220, CVE-2026-72221, CVE-2026-72222,
CVE-2026-72226, CVE-2026-72234, CVE-2026-72248, CVE-2026-72249,
CVE-2026-72251, CVE-2026-72277, CVE-2026-72278, CVE-2026-72279,
CVE-2026-72287, CVE-2026-72288, CVE-2026-72289, CVE-2026-72296,
CVE-2026-72299, CVE-2026-72317, CVE-2026-72318, CVE-2026-72319,
CVE-2026-72320, CVE-2026-72322, CVE-2026-72323, CVE-2026-72329,
CVE-2026-72339, CVE-2026-72348, CVE-2026-72351, CVE-2026-72355,
CVE-2026-72366, CVE-2026-72381, CVE-2026-72393, CVE-2026-72398,
CVE-2026-72399, CVE-2026-72412, CVE-2026-72417, CVE-2026-72422,
CVE-2026-72429, CVE-2026-72436, CVE-2026-72442, CVE-2026-72451,
CVE-2026-72463, CVE-2026-72466, CVE-2026-72472, CVE-2026-72473,
CVE-2026-72477, CVE-2026-72491, CVE-2026-72493, CVE-2026-72494,
CVE-2026-72495, CVE-2026-72496, CVE-2026-72501, CVE-2026-74255,
CVE-2026-74267, CVE-2026-74268, CVE-2026-74269, CVE-2026-74287,
CVE-2026-74310, CVE-2026-74345, CVE-2026-74350, CVE-2026-74361,
CVE-2026-74376, CVE-2026-74384, CVE-2026-74394, CVE-2026-74398,
CVE-2026-74401, CVE-2026-74406, CVE-2026-74427, CVE-2026-74428,
CVE-2026-74433, CVE-2026-74434, CVE-2026-74436, CVE-2026-74439,
CVE-2026-80665)
1 day 3 hours ago
It was discovered that some Arm processors could complete a broadcast
translation lookaside buffer (TLB) invalidation before memory writes made
through the invalidated translation were globally observed. A local
attacker could possibly use this to write to memory after permission to do
so had been revoked, bypassing memory protections or escalating privileges.
(CVE-2025-10263)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- ARM64 architecture;
- InfiniBand drivers;
- Network drivers;
- TCM subsystem;
- B.A.T.M.A.N. meshing protocol;
- HSR network protocol;
- IPv4 networking;
- IPv6 networking;
- Netfilter;
- RDS protocol;
(CVE-2026-53131, CVE-2026-53186, CVE-2026-53216, CVE-2026-53221,
CVE-2026-53354, CVE-2026-53355, CVE-2026-63886, CVE-2026-63887,
CVE-2026-63888, CVE-2026-63912, CVE-2026-63922, CVE-2026-63924,
CVE-2026-63984, CVE-2026-63992, CVE-2026-63993, CVE-2026-63994,
CVE-2026-64000, CVE-2026-64007, CVE-2026-64091)
1 day 3 hours ago
It was discovered that some Arm processors could complete a broadcast
translation lookaside buffer (TLB) invalidation before memory writes made
through the invalidated translation were globally observed. A local
attacker could possibly use this to write to memory after permission to do
so had been revoked, bypassing memory protections or escalating privileges.
(CVE-2025-10263)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- ARM64 architecture;
- InfiniBand drivers;
- Network drivers;
- TCM subsystem;
- exFAT file system;
- Network file system (NFS) client;
- Network file system (NFS) server daemon;
- B.A.T.M.A.N. meshing protocol;
- IPv4 networking;
- IPv6 networking;
- Netfilter;
- RDS protocol;
(CVE-2026-53186, CVE-2026-53216, CVE-2026-53221, CVE-2026-53354,
CVE-2026-53355, CVE-2026-53398, CVE-2026-63800, CVE-2026-63808,
CVE-2026-63887, CVE-2026-63888, CVE-2026-63912, CVE-2026-63922,
CVE-2026-63924, CVE-2026-63984, CVE-2026-63992, CVE-2026-63993,
CVE-2026-63994, CVE-2026-64007, CVE-2026-64091)
1 day 4 hours ago
Grzegorz Grasza discovered that OpenStack Keystone did not consistently
enforce restrictions for delegated authentication tokens. An authenticated
attacker could possibly use this issue to create credentials or delegations
that outlasted the delegated token. (CVE-2026-80182)
It was discovered that OpenStack Keystone incorrectly handled role
assignment queries under certain circumstances. An authenticated attacker
could possibly use this issue to obtain sensitive information. This
issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04
LTS, and Ubuntu 26.04 LTS. (CVE-2026-80183)
Tim Shephard discovered that OpenStack Keystone did not properly
restrict reauthentication using delegated tokens. An authenticated
attacker could possibly use this issue to escape their intended
project scope and obtain unauthorized access. (CVE-2026-80184)
1 day 4 hours ago
It was discovered that OpenSBI did not properly validate the counter index
mask in SBI PMU extension requests. An attacker could use this issue to
cause a denial of service.
1 day 5 hours ago
It was discovered that OpenVPN had a use-after-free vulnerability in
its TLS session handling. An attacker could possibly use this issue
to cause OpenVPN to crash, resulting in a denial of service, or
execute arbitrary code. (CVE-2026-84471)
It was discovered that OpenVPN incorrectly handled retransmissions of
ACK packet IDs, which could trigger a timeout integer overflow. A
remote attacker could possibly use this issue to cause a denial of
service. (CVE-2026-84732)
1 day 7 hours ago
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Network file system (NFS) server daemon;
- IPv6 networking;
- Netfilter;
(CVE-2025-38724, CVE-2026-53131, CVE-2026-53221)
1 day 9 hours ago
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Network file system (NFS) server daemon;
- OCFS2 file system;
- IPv6 networking;
- Netfilter;
- SCTP protocol;
(CVE-2025-38724, CVE-2026-53043, CVE-2026-53131, CVE-2026-53221,
CVE-2026-53224, CVE-2026-53225, CVE-2026-53246, CVE-2026-53309)
1 day 9 hours ago
It was discovered that some Arm processors could complete a broadcast
translation lookaside buffer (TLB) invalidation before memory writes made
through the invalidated translation were globally observed. A local
attacker could possibly use this to write to memory after permission to do
so had been revoked, bypassing memory protections or escalating privileges.
(CVE-2025-10263)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- ARM64 architecture;
- InfiniBand drivers;
- Network drivers;
- TCM subsystem;
- exFAT file system;
- Network file system (NFS) server daemon;
- B.A.T.M.A.N. meshing protocol;
- IPv4 networking;
- IPv6 networking;
- Netfilter;
- RDS protocol;
(CVE-2026-53186, CVE-2026-53221, CVE-2026-53354, CVE-2026-53355,
CVE-2026-53398, CVE-2026-63808, CVE-2026-63887, CVE-2026-63888,
CVE-2026-63912, CVE-2026-63922, CVE-2026-63924, CVE-2026-63984,
CVE-2026-63992, CVE-2026-63993, CVE-2026-63994, CVE-2026-64007,
CVE-2026-64091)
1 day 9 hours ago
It was discovered that some Arm processors could complete a broadcast
translation lookaside buffer (TLB) invalidation before memory writes made
through the invalidated translation were globally observed. A local
attacker could possibly use this to write to memory after permission to do
so had been revoked, bypassing memory protections or escalating privileges.
(CVE-2025-10263)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- ARM64 architecture;
- InfiniBand drivers;
- Network drivers;
- TCM subsystem;
- exFAT file system;
- Network file system (NFS) client;
- Network file system (NFS) server daemon;
- B.A.T.M.A.N. meshing protocol;
- IPv4 networking;
- IPv6 networking;
- Netfilter;
- RDS protocol;
(CVE-2026-53186, CVE-2026-53216, CVE-2026-53221, CVE-2026-53354,
CVE-2026-53355, CVE-2026-53398, CVE-2026-63800, CVE-2026-63808,
CVE-2026-63887, CVE-2026-63888, CVE-2026-63912, CVE-2026-63922,
CVE-2026-63924, CVE-2026-63984, CVE-2026-63992, CVE-2026-63993,
CVE-2026-63994, CVE-2026-64007, CVE-2026-64091)
1 day 9 hours ago
It was discovered that some Arm processors could complete a broadcast
translation lookaside buffer (TLB) invalidation before memory writes made
through the invalidated translation were globally observed. A local
attacker could possibly use this to write to memory after permission to do
so had been revoked, bypassing memory protections or escalating privileges.
(CVE-2025-10263)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- ARM64 architecture;
- InfiniBand drivers;
- Network drivers;
- TCM subsystem;
- B.A.T.M.A.N. meshing protocol;
- HSR network protocol;
- IPv4 networking;
- IPv6 networking;
- Netfilter;
- RDS protocol;
(CVE-2026-53131, CVE-2026-53186, CVE-2026-53216, CVE-2026-53221,
CVE-2026-53354, CVE-2026-53355, CVE-2026-63886, CVE-2026-63887,
CVE-2026-63888, CVE-2026-63912, CVE-2026-63922, CVE-2026-63924,
CVE-2026-63984, CVE-2026-63992, CVE-2026-63993, CVE-2026-63994,
CVE-2026-64000, CVE-2026-64007, CVE-2026-64091)
Checked
3 minutes 46 seconds ago