THREAT OPS › Threat News
Threat Intelligence News
11576 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- [NVD] CVE-2026-77752 (HIGH 7.2) — The Temporary Login Without Password WordPress plugin before 1.9.9 does not verify that the user requesting a temporary login holds network super admin rights before granting the new account those rights, allowing an administrator of a single site on a multisite network to take onvd · 2026-09-12
- [NVD] CVE-2026-77705 (HIGH 7.2) — The Booking for Appointments and Events Calendar WordPress plugin before 2.4.10 does not verify that the user editing a customer or employee record is entitled to modify the WordPress account linked to it, allowing users holding Amelia's customer or employee management permissionvd · 2026-09-12
- [NVD] CVE-2026-77689 (MEDIUM 5.3) — The Booking for Appointments and Events Calendar WordPress plugin before 9.8.1 does not verify that a payment was actually taken before recording a booking as paid, trusting the payment gateway named in a public, unauthenticated booking request even when the site has never confinvd · 2026-09-12
- [NVD] CVE-2026-77006 (CRITICAL 9.6) — The WebTotem Backups WordPress plugin through 1.0.1 does not validate a user-supplied file path, does not check the capability of the user making the request, and discards the result of its own CSRF check, allowing any authenticated user, such as a subscriber, to delete arbitrarynvd · 2026-09-12
- [NVD] CVE-2026-77005 (CRITICAL 9.6) — The CODE MONKEYS PROPOSALS WordPress plugin through 1.0.1 does not validate a user-supplied file path before deleting a file, and does not check the capability of the user making the request, allowing any authenticated user, such as a subscriber, to delete arbitrary files on thenvd · 2026-09-12
- [NVD] CVE-2026-75800 (CRITICAL 9.8) — The Frontegg SAML SSO WordPress plugin through 1.0.1 does not verify the signature or issuer of SAML authentication responses before establishing a session, allowing unauthenticated attackers to log in as any user, including administrators, as well as to create arbitrary accountsnvd · 2026-09-12
- [NVD] CVE-2026-87719 (CRITICAL 9.9) — GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could allow an authenticated user with Duo Chat access to obtain Advanced Search instance configurations and sensitnvd · 2026-09-12
- [NVD] CVE-2026-90467 (MEDIUM 4.0) — aiosmtplib before 5.1.3 fails to properly validate email addresses supplied by callers, allowing attackers to inject ESMTP parameters into MAIL FROM and RCPT TO command lines. Attackers can craft malicious addresses containing spaces and angle brackets to append parameters like Anvd · 2026-09-12
- [NVD] CVE-2026-89268 (MEDIUM 5.4) — QloApps through 1.7.0 renders back-office list filter POST parameters into HTML input value attributes without escaping them in the list helper template. Attackers can induce authenticated users to submit crafted POST requests with malicious payloads to list controllers, executinnvd · 2026-09-12
- [NVD] CVE-2026-89267 (MEDIUM 4.3) — starlette-admin versions 0.16.1 through 0.17.1 fail to enforce the searchable_fields allowlist when configured as an empty list, allowing authenticated users to filter on non-searchable fields. Attackers can submit structured filter queries via the list API's where parameter to pnvd · 2026-09-12
- [securotrop] Shelco Filters posted to leak siteransomware_live · 2026-09-12
- [NVD] CVE-2026-89266 (HIGH 8.2) — stb_vorbis through 1.22 contains a heap buffer overflow in start_decoder() where the codebook multiplicands allocation size is truncated from size_t to int. Attackers can craft a malicious Ogg Vorbis file with large entries and dimensions values to trigger out-of-bounds writes, cnvd · 2026-09-12
- [NVD] CVE-2026-90452 — Requests from the reverse proxy to the identity-provider service for token discovery, introspection, and credential exchange do not verify the identity provider's server certificate. An attacker positioned on the network path between the proxy and the identity provider could impenvd · 2026-09-11
- [NVD] CVE-2026-90451 — An example environment-configuration file ships with a fixed, publicly-known secret value used to sign authentication cookies for a bundled packet-analysis component. A deployment that copies this example file into active configuration without running the setup routine that regennvd · 2026-09-11
- [NVD] CVE-2026-90450 — The application's role-authorization lookup defaults to granting access when a request handler's name is not present in its table of role requirements, rather than defaulting to deny. Any request handler that is not explicitly registered in this table is reachable by any authentinvd · 2026-09-11
- [NVD] CVE-2026-90449 — When a particular authentication mode is configured, the reverse proxy forwards requests for a bundled third-party administrative interface directly to that interface without applying the gateway's own authentication requirement first. All access control for this administrative invd · 2026-09-11
- [NVD] CVE-2026-90448 — A deployment mode intended to expose only read access to stored data proxies a set of application programming interface routes without restricting which request methods are allowed. One such route accepts a request that creates or overwrites a stored record, including an attackernvd · 2026-09-11
- [NVD] CVE-2026-90447 — A routing rule selects between two different authentication mechanisms for the same downstream service based on the value of a client-supplied request header, rather than on any property the client cannot control. An authenticated user in possession of a shared service credentialnvd · 2026-09-11
- [NVD] CVE-2026-90446 — An application programming interface endpoint accepts a user-supplied value and interpolates it directly into the path of a backend request to the underlying search and analytics data store, without restricting its contents. This allows an authenticated attacker to substitute an nvd · 2026-09-11
- [NVD] CVE-2026-90445 — An interface that accepts file uploads from authenticated users extracts the contents of uploaded archives without validating that extracted file paths remain within the intended destination directory. This allows an authenticated attacker to craft an archive whose entries travernvd · 2026-09-11
- [NVD] CVE-2026-90444 — A file-transfer interface that requires valid credentials accepts attacker-controlled filenames without restricting shell metacharacters. An automated process later constructs and runs a system command using the uploaded file's name, allowing an authenticated attacker to embed annvd · 2026-09-11
- [NVD] CVE-2026-90443 — A web interface reflects a portion of the request URL into a script context and a hyperlink attribute without adequate encoding, and does not require authentication to reach. This allows an unauthenticated network attacker to craft a link that, when visited by a user, executes arnvd · 2026-09-11
- [NVD] CVE-2026-54258 (MEDIUM 6.5) — ZoneMinder is a free, open source closed-circuit television software application. Versions prior to 1.36.39, 1.38.4, and 1.39.11 allow an authenticated low-privileged user with coarse `Events=View` and/or `Snapshots=View` permissions to directly fetch media for events belonging tnvd · 2026-09-11
- [NVD] CVE-2026-54248 (MEDIUM 6.5) — Doco-CD is a GitOps continuous delivery tool that automatically deploys and updates Docker Compose projects/services and Swarm stacks. Prior to version 0.90.1, a trust-boundary flaw in OCI artifact verification allowed artifact-provided deployment config to influence the policy unvd · 2026-09-11
- [NVD] CVE-2026-54241 (HIGH 7.4) — libde265 is an open source implementation of the h.265 video codec. Versions prior to 1.1.1 use signed 32-bit arithmetic to calculate the sample adaptive offset input-buffer size, allowing a crafted HEVC stream with large dimensions and 16-bit luma samples to cause an integer ovenvd · 2026-09-11
- [NVD] CVE-2026-54240 (HIGH 7.4) — libde265 is an open source implementation of the h.265 video codec. Versions prior to 1.1.1 use signed 32-bit arithmetic to calculate pixel offsets, allowing a crafted HEVC stream with large image dimensions to trigger an integer overflow and cause out-of-bounds heap reads or wrinvd · 2026-09-11
- [NVD] CVE-2026-50018 (MEDIUM 6.5) — Hoverfly is an open source API simulation tool. Prior to version 1.12.8, remote post-serve actions use `http.DefaultClient` without any timeout configuration. When the remote endpoint is unreachable or intentionally slow (accepts TCP connection but never responds), each triggerednvd · 2026-09-11
- [NVD] CVE-2026-50013 (HIGH 7.5) — Hoverfly is an open source API simulation tool. Prior to version 1.12.8, when Hoverfly is running in Diff mode, the `AddDiff()` function writes to the shared `responsesDiff` map without any synchronization (no mutex). When multiple proxy requests are processed concurrently (the nnvd · 2026-09-11
- [NVD] CVE-2026-49992 — Kimai is an open-source time tracking application. Versions prior to 2.58.0 contain authenticated cross-site request forgery issues in their default team creation shortcuts for projects, customers, and activities. These endpoints are exposed through `GET` routes and directly creanvd · 2026-09-11
- [NVD] CVE-2026-49846 (HIGH 7.5) — libks provides foundational support for signalwire C products. Prior to version 2.0.11, `clean_uri()` in libks's HTTP request parser fails to reject URIs whose path has more segments than its internal canonicalization buffer can hold. The canonicalization step silently passes sucnvd · 2026-09-11
- [NVD] CVE-2026-48496 (MEDIUM 6.2) — OpenTelemetry eBPF Profiler is a production-scale agent for profiling applications across multiple programming languages. Starting in version 0.0.202527 and prior to version 0.0.202622, an unprivileged process can cause the profiler to open a nonregular mapping file, such as a FInvd · 2026-09-11
- [NVD] CVE-2026-45056 — matrix-sdk-crypto is a no-network-IO implementation of a state machine that handles end-to-end encryption for Matrix clients. Starting in version 0.12.0 and prior to version 0.17.0, the matrix-sdk-crypto crate was missing a check for the user ID when decrypting an Olm-encrypted envd · 2026-09-11
- [NVD] CVE-2026-44715 — OpenMRS is an open source electronic medical record system platform. Prior to versions 1.23.0 and 2.10.0, an authenticated user can trigger administrative DWR services. Specifically, the `startHl7ArchiveMigration` method is accessible, which should be restricted to admin-level acnvd · 2026-09-11
- [GHSA] GHSA-992q-9gwp-7r79 (medium) — ZITADEL: Auto-linking by email: IdP-side email verification is not checkedgithub_advisories · 2026-09-11
- [GHSA] GHSA-325j-mg25-8q58 (critical) — yayson: Prototype pollution in Store/LegacyStore deserializationgithub_advisories · 2026-09-11
- [safepay] compunnel.com posted to leak siteransomware_live · 2026-09-11
- [GHSA] GHSA-rqx4-3f6q-3x2v (high) — @Mockoon/commons-server: Unauthenticated admin API + wildcard CORS allows mock-state hijack and secret theftgithub_advisories · 2026-09-11
- [GHSA] GHSA-8wqc-v2q8-vff2 (medium) — @Mockoon/commons-server: Path traversal in templated `filePath` lets a request escape the served directory (prefix-only base check)github_advisories · 2026-09-11
- [qilin] Imperial Healthcare Solutions posted to leak siteransomware_live · 2026-09-11
- [GHSA] GHSA-65h7-9wrw-629c (high) — FrontMCP and mcp-from-openapi have bypass of OpenAPI external $ref SSRF fixgithub_advisories · 2026-09-11
- [GHSA] GHSA-h8m9-jgf8-vwvp (critical) — Prowler: SAML Domain Claiming Enables Cross-Tenant Account Takeovergithub_advisories · 2026-09-11
- [GHSA] GHSA-v77h-2w3m-94hx (medium) — ZITADEL: Missing Token Expiration (`exp`) Validation in JWT IdP Providergithub_advisories · 2026-09-11
- [GHSA] GHSA-2cg9-97gq-9mqp (high) — Shopper: Missing authorization on product removal actions in CollectionProducts componentgithub_advisories · 2026-09-11
- [GHSA] GHSA-99h5-jhh7-v3r3 (medium) — Shopper: Media sub-form store() still lacks authorization (Incomplete fix for GHSA-h4mp-g9c6-xwph)github_advisories · 2026-09-11
- [GHSA] GHSA-g3f9-g5vj-p62f (high) — Shopper: Unauthorized inventory stock manipulation via unlocked variant property in VariantStock componentgithub_advisories · 2026-09-11
- [GHSA] GHSA-j328-xmgp-j4q3 (high) — Shopper: privilege escalation via improper Livewire admin component authorizationgithub_advisories · 2026-09-11
- [GHSA] GHSA-f7h9-qv4x-9x57 (medium) — Shopping privilege escalation through missing authorization in Settings componentsgithub_advisories · 2026-09-11
- [GHSA] GHSA-5vf4-452p-jjhf (medium) — Shopper: Negative discount values accepted and propagated through order calculation pipelinegithub_advisories · 2026-09-11
- Friday Squid Blogging: Rotting Squid on a Beached California Boatschneier · 2026-09-11
- [GHSA] GHSA-243p-f3cv-c5wh (high) — Shopper: Authorization bypass in Filament bulk actions allows browse-only staff to mass-delete attributes/tags and mass-toggle visibility of brands/categories/suppliersgithub_advisories · 2026-09-11
- [GHSA] GHSA-vjfw-cpmh-xwv3 (high) — Central Dogma: SSH host-key verification permanently disabled in Git mirror (SshGitMirror)github_advisories · 2026-09-11
- [GHSA] GHSA-2j95-gqxf-v3vg (critical) — Central Dogma: Hard-coded ZooKeeper replication secret 'ch4n63m3' with silent fallback enables cluster takeovergithub_advisories · 2026-09-11
- [GHSA] GHSA-98q5-5qh2-7w75 (medium) — Central Dogma: LDAP injection in SearchFirstActiveDirectoryRealm enables authentication confusion and audit log evasiongithub_advisories · 2026-09-11
- GitLab security advisory (AV26-917)cccs_ca · 2026-09-11
- [GHSA] GHSA-rqfv-2mw9-78g2 (critical) — MySQL MCP Server: Missing Origin/Host Validation in SSE Transport Enables Unauthenticated SQL Execution (DNS Rebinding / Direct Exposure)github_advisories · 2026-09-11
- [NVD] CVE-2026-89469 (HIGH 8.4) — In the Linux kernel, the following vulnerability has been resolved: power: supply: lp8727: fix use-after-free in lp8727_release_irq() lp8727_isr_func(), the threaded IRQ handler, is the only caller that arms pchg->work via schedule_delayed_work(). lp8727_release_irq() currentlnvd · 2026-09-11
- [NVD] CVE-2026-89466 (HIGH 7.7) — In the Linux kernel, the following vulnerability has been resolved: power: supply: qcom_battmgr: terminate the strings from firmware The qcom_battmgr_sc8280xp_strcpy() takes a Pascal-style string when the firmware sends one. Otherwise it copies all BATTMGR_STRING_LEN bytes and nvd · 2026-09-11
- [NVD] CVE-2026-89465 (HIGH 8.4) — In the Linux kernel, the following vulnerability has been resolved: power: supply: rt9455: quiesce delayed work before teardown The threaded IRQ handler can queue pwr_rdy_work, max_charging_time_work and batt_presence_work. pwr_rdy_work and batt_presence_work can also queue manvd · 2026-09-11
- [NVD] CVE-2026-89459 (HIGH 7.0) — In the Linux kernel, the following vulnerability has been resolved: s390/percpu: Fix MVIY_PERCPU() with older binutils Commit a737737cdb9c ("s390/percpu: Infrastructure for more efficient this_cpu operations") introduced MVIY_PERCPU(), which stringifies arguments that are alreanvd · 2026-09-11
- [NVD] CVE-2026-89456 (HIGH 7.0) — In the Linux kernel, the following vulnerability has been resolved: s390/dasd: Propagate partial completion length across ERP recovery dasd_default_erp_postaction() copies the timing and device state from the finished ERP request back to the original request but drops proc_bytenvd · 2026-09-11
- [NVD] CVE-2026-89452 (HIGH 8.4) — In the Linux kernel, the following vulnerability has been resolved: iommu/msm: Unwind probe state on registration failure msm_iommu_probe() adds its devm-managed IOMMU object to qcom_iommu_devices before adding the IOMMU sysfs device and registering it with the IOMMU core. If nvd · 2026-09-11
- [NVD] CVE-2026-89450 (HIGH 8.8) — In the Linux kernel, the following vulnerability has been resolved: iommu/tegra241-cmdqv: Reject a vSID wider than the SID_MATCH field tegra241_vintf_init_vsid() programs the guest-provided vSID into SID_MATCH, whose VIRT_SID field spans bits [20:1] with bit 0 as the match-enabnvd · 2026-09-11
- [NVD] CVE-2026-89448 (CRITICAL 9.3) — In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Force requesting ACS when tboot is enabled Currently the conditions of requesting ACS in detect_intel_iommu() don't include tboot, leading to a possible misconfiguration with ACS disabled (e.g. due nvd · 2026-09-11
- [NVD] CVE-2026-89445 (HIGH 8.8) — In the Linux kernel, the following vulnerability has been resolved: iommufd: Fix UAF in selftest IOPF reporting IOMMUFD selftest TRIGGER_IOPF borrows an attach handle from group->pasid_array without synchronizing against PASID detach, then a concurrent iommu_report_device_faultnvd · 2026-09-11
- [NVD] CVE-2026-89443 (HIGH 7.1) — In the Linux kernel, the following vulnerability has been resolved: platform/x86: ISST: Validate level in perf mask ioctls isst_if_get_perf_level_mask() and isst_if_get_base_freq_mask() use the user-provided level as an index into perf_levels[] via _read_pp_level_info() and _renvd · 2026-09-11
- [NVD] CVE-2026-89442 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: platform/x86: ISST: Validate socket ID in clos_assoc ioctl isst_if_clos_assoc() validates the user-supplied socket_id with 'socket_id > topology_max_packages()', but isst_common.sst_inst[] is allocated with topnvd · 2026-09-11
- [NVD] CVE-2026-89441 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: mmc: via-sdmmc: cancel card-detect work on remove Disabling the device interrupt and freeing the IRQ prevents new card-detect work from being queued, but carddet_work already queued by the handler can still runnvd · 2026-09-11
- [NVD] CVE-2026-89440 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: mmc: via-sdmmc: stop card-detect handling on probe failure request_irq() registers the SD card-detect interrupt and the probe enables it before mmc_add_host() runs. If mmc_add_host() fails, the error path only nvd · 2026-09-11
- [NVD] CVE-2026-89436 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: platform/x86: panasonic-laptop: Fix sentinel write past pcc->sinf[] acpi_pcc_retrieve_biosdata() rejects SINF packages only when pcc->num_sifr is strictly less than hkey->package.count, then unconditionally wrinvd · 2026-09-11
- Re: pcre2 version 10.48 released with security fixesoss_sec · 2026-09-11
- [NVD] CVE-2026-81017 (HIGH 8.4) — In the Linux kernel, the following vulnerability has been resolved: platform/chrome: sensorhub: Bound the EC-reported sensor number Each EC FIFO event carries an 8-bit sensor number (in->sensor_num). cros_ec_sensorhub_ring_handler() validates the FIFO event count, the per-read nvd · 2026-09-11
- [NVD] CVE-2026-81016 (HIGH 7.7) — In the Linux kernel, the following vulnerability has been resolved: platform/x86/amd/pmc: Propagate SMU errors and validate S2D address amd_stb_s2d_init() discards the return value of several S2D SMU commands. When the SMU refuses a command (e.g. "SMU cmd failed. err: 0xff") thnvd · 2026-09-11
- [NVD] CVE-2026-81015 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: platform/x86/amd/pmc: Fix LPS0 and debugfs leaks when STB init fails amd_pmc_probe() registers the LPS0 s2idle handler with acpi_register_lps0_dev() and creates the driver's debugfs directory before calling amdnvd · 2026-09-11
- [NVD] CVE-2026-81012 (HIGH 8.4) — In the Linux kernel, the following vulnerability has been resolved: platform/x86: hp-bioscfg: fix off-by-one write in hp_get_string_from_buffer() hp_get_string_from_buffer() clamps the converted string length against the destination buffer size with "size > dst_size", so when tnvd · 2026-09-11
- [NVD] CVE-2026-81011 (HIGH 7.1) — In the Linux kernel, the following vulnerability has been resolved: platform/x86: hp-bioscfg: pass validated element count to package parsers The per-type package parsers are handed the wrong element count. hp_init_bios_package_attribute() validates obj->package.count and thennvd · 2026-09-11
- [NVD] CVE-2026-81010 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: io_uring/waitid: honor task_work cancellation io_waitid_cb() may run through the fallback task_work path when task_work_add() can no longer queue work to the originating task. The fallback runs from a kworker anvd · 2026-09-11
- [NVD] CVE-2026-81008 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: interconnect: Fix use after free in icc_get() and of_icc_get_by_index() In of_icc_get_by_index() and icc_get(), if the dynamic allocation for path->name fails via kasprintf(), the error handling path directly cnvd · 2026-09-11
- [NVD] CVE-2026-81007 (HIGH 7.1) — In the Linux kernel, the following vulnerability has been resolved: ipmi: ipmb: validate write message length ipmb_write() read message fields before validating the length byte. A zero or short write can read uninitialized stack bytes. A length smaller than the SMBus header unvd · 2026-09-11
- [NVD] CVE-2026-81006 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: ipmi: Remove all sysfs files on registration failure ipmi_add_smi() creates the nr_users and nr_msgs files before trying to create the maintenance_mode file. If that last creation fails, the error path removes nvd · 2026-09-11
- [NVD] CVE-2026-81004 (HIGH 8.4) — In the Linux kernel, the following vulnerability has been resolved: ipmi:msghandler: Cancel work cleanly on an error If an error occurs during startup of an IPMI interface, it may have scheduled work to run. The work needs to be canceled before the interface can be freed.nvd · 2026-09-11
- [NVD] CVE-2026-81003 (HIGH 8.1) — In the Linux kernel, the following vulnerability has been resolved: net/iucv: filter frames in afiucv_hs_rcv() by ingress device afiucv_hs_rcv() selects a socket from iucv_sk_list by matching four 8-byte name fields in the transport header alone. No check is made against the nenvd · 2026-09-11
- [NVD] CVE-2026-81002 (CRITICAL 9.8) — In the Linux kernel, the following vulnerability has been resolved: xdp: fix zero-copy frame layout xdp_convert_zc_to_xdp_frame() clones an XSK packet into an order-0 page and advertises PAGE_SIZE as its frame size. It allows the copied frame to occupy the page tail needed by nvd · 2026-09-11
- [NVD] CVE-2026-81001 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: slip: fix use-after-free in sl_sync() slip_devs[] stores bare net_device pointers and takes no reference on them. sl_sync() and sl_alloc() walk that table from slip_open() under rtnl_lock(), while an entry is nvd · 2026-09-11
- [NVD] CVE-2026-81000 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: net: tun: bound receive headroom tun_get_user() uses tun->align both as skb headroom and when choosing how much packet data to keep linear. OVS can propagate an oversized headroom request from another port to Tnvd · 2026-09-11
- [NVD] CVE-2026-80998 (HIGH 7.5) — In the Linux kernel, the following vulnerability has been resolved: net: bnxt: ring the doorbell when SW USO exits early When a burst of packets is handed down to the driver, the driver defers the doorbell to the end by setting txr->kick_pending = 1. The normal TX path handles nvd · 2026-09-11
- [NVD] CVE-2026-80997 (HIGH 7.5) — In the Linux kernel, the following vulnerability has been resolved: net: ipa: fix stalled modem TX queue after runtime resume ipa_start_xmit() unconditionally stops the TX queue before calling pm_runtime_get(), relying on the wake scheduled by runtime resume (ipa_modem_wake_quenvd · 2026-09-11
- [NVD] CVE-2026-80995 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: net: mctp: hold a reference to the route device in mctp_route_lookup() mctp_route_lookup() uses rt->dev without holding a reference on it. mctp_route_lookup_single() returns the route under RCU only, so the rounvd · 2026-09-11
- [NVD] CVE-2026-80994 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: fix flow mask use-after-free on flow deletion The commit in the Fixes tag below made so flow->mask free is scheduled via RCU right after it is removed from the flow table. The pointer stays invd · 2026-09-11
- [NVD] CVE-2026-80992 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: net: ravb: avoid dereferencing an invalid PTP clock The PTP clock is unavailable before the first open, so querying its index can dereference a NULL pointer. Registration failures can also leave an error pointenvd · 2026-09-11
- [NVD] CVE-2026-80991 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: net: ravb: serialize PTP clock teardown ravb_ptp_interrupt() can race with ravb_ptp_stop() and pass the clock to ptp_clock_event() while ptp_clock_unregister() is freeing it. This can lead to a use-after-free. nvd · 2026-09-11
- [NVD] CVE-2026-80989 (HIGH 8.8) — In the Linux kernel, the following vulnerability has been resolved: net: thunderbolt: Mark the connection down when bringing it up fails Every failure path in tbnet_connected_work() undoes its own work and returns without clearing login_sent, so the connection still looks estabnvd · 2026-09-11
- [NVD] CVE-2026-80987 (HIGH 7.5) — In the Linux kernel, the following vulnerability has been resolved: NTB: ntb_transport: Reject oversized TX buffers ntb_process_tx() handles an oversized buffer by calling tx_handler() with a NULL data pointer and returning success. ntb_netdev therefore neither frees the skb innvd · 2026-09-11
- [NVD] CVE-2026-80986 (CRITICAL 9.8) — In the Linux kernel, the following vulnerability has been resolved: net/smc: bound the peer rkey counts in SMC-Rv2 LLC messages On a link whose device has max_recv_sge == 1 there is no shared v2 receive buffer, and smc_llc_save_add_link_rkeys() takes the v2 extension from 44 bynvd · 2026-09-11
- [NVD] CVE-2026-80985 (HIGH 8.2) — In the Linux kernel, the following vulnerability has been resolved: net/smc: carry oversized SMC-Rv2 LLC messages in the queue entry smc_llc_rmt_delete_rkey() and smc_llc_save_add_link_rkeys() read the part of a v2 message that does not fit into the 44-byte union smc_llc_msg, anvd · 2026-09-11
- [NVD] CVE-2026-80982 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: net/smc: fix use-after-free in smc_rx_pipe_buf_release() smc_rx_splice() hands RMB pages to a pipe and takes a socket reference per entry so the smc_sock stays alive until the reader finishes. The connection donvd · 2026-09-11
- [NVD] CVE-2026-80981 (CRITICAL 9.8) — In the Linux kernel, the following vulnerability has been resolved: net/smc: fix use-after-free of the LLC qentry in smc_llc_srv_add_link() smc_llc_srv_add_link() keeps add_llc pointing into the queue entry: add_llc = &qentry->msg.add_link; smc_llc.c:1482 ... smc_llc_snvd · 2026-09-11
- [NVD] CVE-2026-80980 (CRITICAL 9.8) — In the Linux kernel, the following vulnerability has been resolved: net/smc: stop killed, freed and out_of_sync sharing a byte The three connection state flags are single-bit bitfields, so they occupy one byte of struct smc_connection and every store to one is a read-modify-wrinvd · 2026-09-11
- [NVD] CVE-2026-80979 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: net/smc: unregister the connection before draining the rx tasklet smc_conn_free() calls smc_ism_unset_conn() only while the link group is still on its device list, and never sets conn->killed. smc_lgr_terminatenvd · 2026-09-11
- [NVD] CVE-2026-80978 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: net: cap advertised IP tunnel headroom IP tunnel devices derive their advertised needed_headroom from lower output devices. A stack of user-created devices can make the derived value larger than the 16-bit skb nvd · 2026-09-11
- [NVD] CVE-2026-80977 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: net: skbuff: don't touch shared zerocopy state in skb_tx_error() skb_tx_error() completes the zerocopy uarg and clears SKBFL_ALL_ZEROCOPY, and skb_zcopy_downgrade_managed() clears SKBFL_MANAGED_FRAG_REFS. Both nvd · 2026-09-11