THREAT OPS › Threat News
Threat Intelligence News
12306 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- [NVD] CVE-2024-9341 (MEDIUM 5.4) — A flaw was found in Go. When FIPS mode is enabled on a system, container runtimes may incorrectly handle certain file paths due to improper validation in the containers/common Go library. This flaw allows an attacker to exploit symbolic links and trick the system into mounting senvd · 2024-10-01
- VirusTotal AI-Generated Conversations: Threat Intel Made Easyvirustotal_blog · 2024-09-29
- CVE-2024-36435 Deep-Dive: The Year's Most Critical BMC Security Flawbinarly · 2024-09-26
- [NVD] CVE-2024-6594 (HIGH 7.5) — Improper Handling of Exceptional Conditions vulnerability in the WatchGuard Single Sign-On Client on Windows causes the client to crash while handling malformed commands. An attacker with network access to the client could create a denial of service condition for the Single Sign-nvd · 2024-09-25
- [NVD] CVE-2024-6593 (CRITICAL 9.1) — Incorrect Authorization vulnerability in WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows allows an attacker with network access to execute restricted management commands. An attacker that has already gained network access could exploit this vulnerability nvd · 2024-09-25
- [NVD] CVE-2024-6592 (CRITICAL 9.1) — An incorrect authorization vulnerability in the protocol communication between the WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows and the WatchGuard Single Sign-On Client on Windows and MacOS allows an attacker with network access to forge communications nvd · 2024-09-25
- [NVD] CVE-2024-45229 (MEDIUM 6.6) — The Versa Director offers REST APIs for orchestration and management. By design, certain APIs, such as the login screen, banner display, and device registration, do not require authentication. However, it was discovered that for Directors directly connected to the Internet, one onvd · 2024-09-20
- [NVD] CVE-2024-8883 (MEDIUM 6.1) — A misconfiguration flaw was found in Keycloak. This issue can allow an attacker to redirect users to an arbitrary URL if a 'Valid Redirect URI' is set to http://localhost or http://127.0.0.1, enabling sensitive information such as authorization codes to be exposed to the attackernvd · 2024-09-19
- [NVD] CVE-2024-8698 (HIGH 7.7) — A flaw exists in the SAML signature validation method within the Keycloak XMLSignatureUtil class. The method incorrectly determines whether a SAML signature is for the full document or only for specific assertions based on the position of the signature in the XML document, rathernvd · 2024-09-19
- Repeatable Failures: Test Keys Used to Sign Production Software…Again?binarly · 2024-09-19
- [NVD] CVE-2024-46754 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: bpf: Remove tst_run from lwt_seg6local_prog_ops. The syzbot reported that the lwt_seg6 related BPF ops can be invoked via bpf_test_run() without without entering input_action_end_bpf() first. Martin KaFai Lau nvd · 2024-09-18
- [NVD] CVE-2024-46741 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: Fix double free of 'buf' in error path smatch warning: drivers/misc/fastrpc.c:1926 fastrpc_req_mmap() error: double free of 'buf' In fastrpc_req_mmap() error path, the fastrpc buffer is freed innvd · 2024-09-18
- [NVD] CVE-2024-7387 (CRITICAL 9.1) — A flaw was found in openshift/builder. This vulnerability allows command injection via path traversal, where a malicious user can execute arbitrary commands on the OpenShift node running the builder container. When using the “Docker” strategy, executable files inside the privilegnvd · 2024-09-17
- [NVD] CVE-2024-45496 (CRITICAL 9.9) — A flaw was found in OpenShift. This issue occurs due to the misuse of elevated privileges in the OpenShift Container Platform's build process. During the build initialization step, the git-clone container is run with a privileged security context, allowing unrestricted access to nvd · 2024-09-17
- [NVD] CVE-2024-8775 (MEDIUM 5.5) — A flaw was found in Ansible, where sensitive information stored in Ansible Vault files can be exposed in plaintext during the execution of a playbook. This occurs when using tasks such as include_vars to load vaulted variables without setting the no_log: true parameter, resultingnvd · 2024-09-14
- [NVD] CVE-2024-7341 (HIGH 7.1) — A session fixation issue was discovered in the SAML adapters provided by Keycloak. The session ID and JSESSIONID cookie are not changed at login time, even when the turnOffChangeSessionIdOnLogin option is configured. This flaw allows an attacker who hijacks the current session benvd · 2024-09-09
- [NVD] CVE-2023-7279 (LOW 2.6) — A vulnerability has been found in Secure Systems Engineering Connaisseur up to 3.3.0 and classified as problematic. This vulnerability affects unknown code of the file connaisseur/res/targets_schema.json of the component Delegation Name Handler. The manipulation leads to inefficinvd · 2024-09-02
- [Breach] Burger King Russia — 3,155,792 accounts exposedhibp_breaches · 2024-08-25
- [NVD] CVE-2024-40766 (CRITICAL 9.8) — An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects SonicWall Firewall Gen 5 and Gen 6 devices, anvd · 2024-08-23
- [NVD] CVE-2024-45163 (CRITICAL 9.1) — The Mirai botnet through 2024-08-19 mishandles simultaneous TCP connections to the CNC (command and control) server. Unauthenticated sessions remain open, causing resource consumption. For example, an attacker can send a recognized username (such as root), or can send arbitrary dnvd · 2024-08-22
- [NVD] CVE-2024-7885 (HIGH 7.5) — A vulnerability was found in Undertow where the ProxyProtocolReadListener reuses the same StringBuilder instance across multiple requests. This issue occurs when the parseProxyProtocolV1 method processes multiple requests on the same HTTP connection. As a result, different requesnvd · 2024-08-21
- [NVD] CVE-2024-6508 (HIGH 8.0) — An insufficient entropy vulnerability was found in the Openshift Console. In the authorization code type and implicit grant type, the OAuth2 protocol is vulnerable to a Cross-Site Request Forgery (CSRF) attack if the state parameter is used inefficiently. This flaw allows loggingnvd · 2024-08-21
- [NVD] CVE-2024-42467 (CRITICAL 10.0) — openHAB, a provider of open-source home automation software, has add-ons including the visualization add-on CometVisu. In versions 3.4.0.M4 through 4.2.0,, the proxy endpoint of openHAB's CometVisu add-on can be accessed without authentication. This proxy-feature can be exploitednvd · 2024-08-12
- [NVD] CVE-2024-20479 (MEDIUM 4.8) — A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to conduct an XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based management innvd · 2024-08-07
- [NVD] CVE-2024-7523 (HIGH 8.1) — A select option could partially obscure security prompts. This could be used by a malicious site to trick a user into granting permissions. *This issue only affects Android versions of Firefox.* This vulnerability affects Firefox < 129.nvd · 2024-08-06
- [NVD] CVE-2024-41965 (MEDIUM 4.2) — Vim is an open source command line text editor. double-free in dialog_changed() in Vim < v9.1.0648. When abandoning a buffer, Vim may ask the user what to do with the modified buffer. If the user wants the changed buffer to be saved, Vim may create a new Untitled file, if the bufnvd · 2024-08-01
- [NVD] CVE-2024-42088 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: ASoC: mediatek: mt8195: Add platform entry for ETDM1_OUT_BE dai link Commit e70b8dd26711 ("ASoC: mediatek: mt8195: Remove afe-dai component and rework codec link") removed the codec entry for the ETDM1_OUT_BE dnvd · 2024-07-29
- [NVD] CVE-2024-41062 (HIGH 8.8) — In the Linux kernel, the following vulnerability has been resolved: bluetooth/l2cap: sync sock recv cb and release The problem occurs between the system call to close the sock and hci_rx_work, where the former releases the sock and the latter accesses it without lock protectionnvd · 2024-07-29
- PKfail: Untrusted Platform Keys Undermine Secure Boot on UEFI Ecosystembinarly · 2024-07-25
- [NVD] CVE-2022-48825 (MEDIUM 5.5) — In the Linux kernel, the following vulnerability has been resolved: scsi: qedf: Add stag_work to all the vports Call trace seen when creating NPIV ports, only 32 out of 64 show online. stag work was not initialized for vport, hence initialize the stag work. WARNING: CPU: 8 PIDnvd · 2024-07-16
- [NVD] CVE-2022-48823 (MEDIUM 5.5) — In the Linux kernel, the following vulnerability has been resolved: scsi: qedf: Fix refcount issue when LOGO is received during TMF Hung task call trace was seen during LOGO processing. [ 974.309060] [0000:00:00.0]:[qedf_eh_device_reset:868]: 1:0:2:0: LUN RESET Issued... [ 9nvd · 2024-07-16
- [NVD] CVE-2024-40973 (MEDIUM 5.5) — In the Linux kernel, the following vulnerability has been resolved: media: mtk-vcodec: potential null pointer deference in SCP The return value of devm_kzalloc() needs to be checked to avoid NULL pointer deference. This is similar to CVE-2022-3113.nvd · 2024-07-12
- [NVD] CVE-2024-5974 (HIGH 7.2) — A buffer overflow in WatchGuard Fireware OS could may allow an authenticated remote attacker with privileged management access to execute arbitrary code with system privileges on the firewall. This issue affects Fireware OS: from 11.9.6 through 12.10.3.nvd · 2024-07-09
- [NVD] CVE-2024-3653 (MEDIUM 5.3) — A vulnerability was found in Undertow. This issue requires enabling the learning-push handler in the server's config, which is disabled by default, leaving the maxAge config in the handler unconfigured. The default is -1, which makes the handler vulnerable. If someone overwrites nvd · 2024-07-08
- [NVD] CVE-2024-5971 (HIGH 7.5) — A vulnerability was found in Undertow, where the chunked response hangs after the body was flushed. The response headers and body were sent but the client would continue waiting as Undertow does not send the expected 0\r\n termination of the chunked response. This results in unconvd · 2024-07-08
- [NVD] CVE-2024-6409 (HIGH 7.0) — A race condition vulnerability was discovered in how signals are handled by OpenSSH's server (sshd). If a remote attacker does not authenticate within a set time period, then sshd's SIGALRM handler is called asynchronously. However, this signal handler calls various functions thanvd · 2024-07-08
- [NVD] CVE-2024-39478 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: crypto: starfive - Do not free stack buffer RSA text data uses variable length buffer allocated in software stack. Calling kfree on it causes undefined behaviour in subsequent operations.nvd · 2024-07-05
- [NVD] CVE-2024-6387 (HIGH 8.1) — A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time penvd · 2024-07-01
- [NVD] CVE-2024-5642 (MEDIUM 6.5) — CPython 3.9 and earlier doesn't disallow configuring an empty list ("[]") for SSLContext.set_npn_protocols() which is an invalid value for the underlying OpenSSL API. This results in a buffer over-read when NPN is used (see CVE-2024-5535 for OpenSSL). This vulnerability is of lownvd · 2024-06-27
- [NVD] CVE-2024-35768 (MEDIUM 5.9) — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Live Composer Team Page Builder: Live Composer live-composer-page-builder allows DOM-Based XSS.This issue affects Page Builder: Live Composer: from n/a through 2.1.22.nvd · 2024-06-21
- [NVD] CVE-2024-38620 (HIGH 8.8) — In the Linux kernel, the following vulnerability has been resolved: Bluetooth: HCI: Remove HCI_AMP support Since BT_HS has been remove HCI_AMP controllers no longer has any use so remove it along with the capability of creating AMP controllers. Since we no longer need to diffenvd · 2024-06-20
- [NVD] CVE-2021-47610 (MEDIUM 5.5) — In the Linux kernel, the following vulnerability has been resolved: drm/msm: Fix null ptr access msm_ioctl_gem_submit() Fix the below null pointer dereference in msm_ioctl_gem_submit(): 26545.260705: Call trace: 26545.263223: kref_put+0x1c/0x60 26545.266452: msm_iocnvd · 2024-06-19
- [NVD] CVE-2024-23692 (CRITICAL 9.8) — Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary commands on the affected system by sending a specially crafted HTTP request. As of thnvd · 2024-05-31
- [NVD] CVE-2024-24919 (HIGH 8.6) — Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerability is available.nvd · 2024-05-28
- [NVD] CVE-2023-7259 (LOW 2.4) — ** DISPUTED ** A vulnerability was found in zzdevelop lenosp up to 20230831. It has been classified as problematic. This affects an unknown part of the component Adduser Page. The manipulation of the argument username with the input <script>alert(1)</script> leads to cross site snvd · 2024-05-24
- [NVD] CVE-2021-47431 (MEDIUM 5.5) — In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix gart.bo pin_count leak gmc_v{9,10}_0_gart_disable() isn't called matched with correspoding gart_enbale function in SRIOV case. This will lead to gart.bo pin_count leak on driver unload.nvd · 2024-05-21
- [NVD] CVE-2021-47410 (MEDIUM 5.5) — In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: fix svm_migrate_fini warning Device manager releases device-specific resources when a driver disconnects from a device, devm_memunmap_pages and devm_release_mem_region calls in svm_migrate_fini are nvd · 2024-05-21
- [NVD] CVE-2021-47335 (MEDIUM 5.5) — In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid racing on fsync_entry_slab by multi filesystem instances As syzbot reported, there is an use-after-free issue during f2fs recovery: Use-after-free write at 0xffff88823bc16040 (in kfence-#10)nvd · 2024-05-21
- [NVD] CVE-2021-47253 (MEDIUM 5.5) — In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix potential memory leak in DMUB hw_init [Why] On resume we perform DMUB hw_init which allocates memory: dm_resume->dm_dmub_hw_init->dc_dmub_srv_create->kzalloc That results in memory leak in nvd · 2024-05-21
- [NVD] CVE-2024-35887 (HIGH 8.8) — In the Linux kernel, the following vulnerability has been resolved: ax25: fix use-after-free bugs caused by ax25_ds_del_timer When the ax25 device is detaching, the ax25_dev_device_down() calls ax25_ds_del_timer() to cleanup the slave_timer. When the timer handler is running, tnvd · 2024-05-19
- [NVD] CVE-2023-52676 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: bpf: Guard stack limits against 32bit overflow This patch promotes the arithmetic around checking stack bounds to be done in the 64-bit domain, instead of the current 32bit. The arithmetic implies adding togethnvd · 2024-05-17
- [NVD] CVE-2024-5042 (MEDIUM 6.6) — A flaw was found in the Submariner project. Due to unnecessary role-based access control permissions, a privileged attacker can run a malicious container on a node that may allow them to steal service account tokens and further compromise other nodes and potentially the entire clnvd · 2024-05-17
- [NVD] CVE-2024-3823 (LOW 2.4) — The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attacknvd · 2024-05-15
- [NVD] CVE-2024-3822 (MEDIUM 4.8) — The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as adminnvd · 2024-05-15
- [NVD] CVE-2024-3727 (HIGH 8.3) — A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks.nvd · 2024-05-14
- [NVD] CVE-2022-48670 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: peci: cpu: Fix use-after-free in adev_release() When auxiliary_device_add() returns an error, auxiliary_device_uninit() is called, which causes refcount for device to be decremented and .release callback will bnvd · 2024-05-03
- [NVD] CVE-2023-50224 (MEDIUM 6.5) — TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link TL-WR841N routers. Authentication is not required to exploit thinvd · 2024-05-03
- [NVD] CVE-2024-26305 (CRITICAL 9.8) — There is a buffer overflow vulnerability in the underlying Utility daemon that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of thisnvd · 2024-05-01
- [NVD] CVE-2024-27010 (MEDIUM 5.5) — In the Linux kernel, the following vulnerability has been resolved: net/sched: Fix mirred deadlock on device recursion When the mirred action is used on a classful egress qdisc and a packet is mirrored or redirected to self we hit a qdisc lock deadlock. See trace below. [.....nvd · 2024-05-01
- [NVD] CVE-2022-48650 (MEDIUM 4.7) — In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix memory leak in __qlt_24xx_handle_abts() Commit 8f394da36a36 ("scsi: qla2xxx: Drop TARGET_SCF_LOOKUP_LUN_FROM_TAG") made the __qlt_24xx_handle_abts() function return early if tcm_qla2xxx_find_nvd · 2024-04-28
- [NVD] CVE-2022-48633 (MEDIUM 5.5) — In the Linux kernel, the following vulnerability has been resolved: drm/gma500: Fix WARN_ON(lock->magic != lock) error psb_gem_unpin() calls dma_resv_lock() but the underlying ww_mutex gets destroyed by drm_gem_object_release() move the drm_gem_object_release() call in psb_gem_nvd · 2024-04-28
- [NVD] CVE-2024-33668 (CRITICAL 9.1) — An issue was discovered in Zammad before 6.3.0. The Zammad Upload Cache uses insecure, partially guessable FormIDs to identify content. An attacker could try to brute force them to upload malicious content to article drafts they have no access to.nvd · 2024-04-26
- [NVD] CVE-2024-1726 (MEDIUM 5.3) — A flaw was discovered in the RESTEasy Reactive implementation in Quarkus. Due to security checks for some JAX-RS endpoints being performed after serialization, more processing resources are consumed while the HTTP request is checked. In certain configurations, if an attacker has nvd · 2024-04-25
- [NVD] CVE-2023-6717 (MEDIUM 6.0) — A flaw was found in the SAML client registration in Keycloak that could allow an administrator to register malicious JavaScript URIs as Assertion Consumer Service POST Binding URLs (ACS), posing a Cross-Site Scripting (XSS) risk. This issue may allow a malicious admin in one realnvd · 2024-04-25
- [NVD] CVE-2024-22373 (HIGH 8.1) — An out-of-bounds write vulnerability exists in the JPEG2000Codec::DecodeByStreamsCommon functionality of Mathieu Malaterre Grassroot DICOM 3.0.23. A specially crafted DICOM file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerabinvd · 2024-04-25
- [NVD] CVE-2024-1249 (HIGH 7.4) — A flaw was found in Keycloak's OIDC component in the "checkLoginIframe," which allows unvalidated cross-origin messages. This flaw allows attackers to coordinate and send millions of requests in seconds using simple code, significantly impacting the application's availability witnvd · 2024-04-17
- [NVD] CVE-2024-1132 (HIGH 8.1) — A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. This issue could allow an attacker to construct a malicious request to bypass validation and access other URLs and sensitive information within the domain or conduct further attacks. Thnvd · 2024-04-17
- [NVD] CVE-2024-26882 (HIGH 7.3) — In the Linux kernel, the following vulnerability has been resolved: net: ip_tunnel: make sure to pull inner header in ip_tunnel_rcv() Apply the same fix than ones found in : 8d975c15c0cd ("ip6_tunnel: make sure to pull inner header in __ip6_tnl_rcv()") 1ca1ba465e55 ("geneve: mnvd · 2024-04-17
- [NVD] CVE-2024-28056 (CRITICAL 9.8) — Amazon AWS Amplify CLI before 12.10.1 incorrectly configures the role trust policy of IAM roles associated with Amplify projects. When the Authentication component is removed from an Amplify project, a Condition property is removed but "Effect":"Allow" remains present, and conseqnvd · 2024-04-15
- [NVD] CVE-2021-47210 (MEDIUM 5.5) — In the Linux kernel, the following vulnerability has been resolved: usb: typec: tipd: Remove WARN_ON in tps6598x_block_read Calling tps6598x_block_read with a higher than allowed len can be handled by just returning an error. There's no need to crash systems with panic-on-warn nvd · 2024-04-10
- [NVD] CVE-2024-2700 (HIGH 7.0) — A vulnerability was found in the quarkus-core component. Quarkus captures local environment variables from the Quarkus namespace during the application's build, therefore, running the resulting application inherits the values captured at build time. Some local environment variablnvd · 2024-04-04
- [NVD] CVE-2024-26804 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: net: ip_tunnel: prevent perpetual headroom growth syzkaller triggered following kasan splat: BUG: KASAN: use-after-free in __skb_flow_dissect+0x19d1/0x7a50 net/core/flow_dissector.c:1170 Read of size 1 at addr nvd · 2024-04-04
- [NVD] CVE-2024-26782 (CRITICAL 9.8) — In the Linux kernel, the following vulnerability has been resolved: mptcp: fix double-free on socket dismantle when MPTCP server accepts an incoming connection, it clones its listener socket. However, the pointer to 'inet_opt' for the new socket has the same value as the originnvd · 2024-04-04
- [NVD] CVE-2024-26779 (HIGH 8.8) — In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix race condition on enabling fast-xmit fast-xmit must only be enabled after the sta has been uploaded to the driver, otherwise it could end up passing the not-yet-uploaded sta via drv_tx callsnvd · 2024-04-03
- [NVD] CVE-2024-26773 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: ext4: avoid allocating blocks from corrupted group in ext4_mb_try_best_found() Determine if the group block bitmap is corrupted before using ac_b_ex in ext4_mb_try_best_found() to avoid allocating blocks from anvd · 2024-04-03
- [NVD] CVE-2024-26772 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: ext4: avoid allocating blocks from corrupted group in ext4_mb_find_by_goal() Places the logic for checking if the group's block bitmap is corrupt under the protection of the group lock to avoid allocating blocknvd · 2024-04-03
- [NVD] CVE-2024-26769 (HIGH 7.5) — In the Linux kernel, the following vulnerability has been resolved: nvmet-fc: avoid deadlock on delete association path When deleting an association the shutdown path is deadlocking because we try to flush the nvmet_wq nested. Avoid this by deadlock by deferring the put work innvd · 2024-04-03
- [NVD] CVE-2024-26768 (HIGH 7.2) — In the Linux kernel, the following vulnerability has been resolved: LoongArch: Change acpi_core_pic[NR_CPUS] to acpi_core_pic[MAX_CORE_PIC] With default config, the value of NR_CPUS is 64. When HW platform has more then 64 cpus, system will crash on these platforms. MAX_CORE_PInvd · 2024-04-03
- [NVD] CVE-2024-26766 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: IB/hfi1: Fix sdma.h tx->num_descs off-by-one error Unfortunately the commit `fd8958efe877` introduced another error causing the `descs` array to overflow. This reults in further crashes easily reproducible by `nvd · 2024-04-03
- [NVD] CVE-2024-26763 (HIGH 7.1) — In the Linux kernel, the following vulnerability has been resolved: dm-crypt: don't modify the data when using authenticated encryption It was said that authenticated encryption could produce invalid tag when the data that is being encrypted is modified [1]. So, fix this problenvd · 2024-04-03
- [NVD] CVE-2024-26762 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: cxl/pci: Skip to handle RAS errors if CXL.mem device is detached The PCI AER model is an awkward fit for CXL error handling. While the expectation is that a PCI device can escalate to link reset to recover fromnvd · 2024-04-03
- [NVD] CVE-2024-26760 (CRITICAL 9.8) — In the Linux kernel, the following vulnerability has been resolved: scsi: target: pscsi: Fix bio_put() for error case As of commit 066ff571011d ("block: turn bio_kmalloc into a simple kmalloc wrapper"), a bio allocated by bio_kmalloc() must be freed by bio_uninit() and kfree().nvd · 2024-04-03
- [NVD] CVE-2024-26759 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: mm/swap: fix race when skipping swapcache When skipping swapcache for SWP_SYNCHRONOUS_IO, if two or more threads swapin the same entry at the same time, they get different pages (A, B). Before one thread (T0) nvd · 2024-04-03
- [NVD] CVE-2024-26748 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: usb: cdns3: fix memory double free when handle zero packet 829 if (request->complete) { 830 spin_unlock(&priv_dev->lock); 831 usb_gadget_giveback_request(&priv_ep->endpoint, 832 nvd · 2024-04-03
- [NVD] CVE-2024-26739 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: net/sched: act_mirred: don't override retval if we already lost the skb If we're redirecting the skb, and haven't called tcf_mirred_forward(), yet, we need to tell the core to drop the skb by setting the retcodnvd · 2024-04-03
- [NVD] CVE-2024-26737 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: bpf: Fix racing between bpf_timer_cancel_and_free and bpf_timer_cancel The following race is possible between bpf_timer_cancel_and_free and bpf_timer_cancel. It will lead a UAF on the timer->timer. bpf_timer_cnvd · 2024-04-03
- [NVD] CVE-2024-26736 (HIGH 8.1) — In the Linux kernel, the following vulnerability has been resolved: afs: Increase buffer size in afs_update_volume_status() The max length of volume->vid value is 20 characters. So increase idbuf[] size up to 24 to avoid overflow. Found by Linux Verification Center (linuxtestinvd · 2024-04-03
- [NVD] CVE-2024-26734 (HIGH 7.0) — In the Linux kernel, the following vulnerability has been resolved: devlink: fix possible use-after-free and memory leaks in devlink_init() The pernet operations structure for the subsystem must be registered before registering the generic netlink family. Make an unregister innvd · 2024-04-03
- [NVD] CVE-2024-26730 (HIGH 7.3) — In the Linux kernel, the following vulnerability has been resolved: hwmon: (nct6775) Fix access to temperature configuration registers The number of temperature configuration registers does not always match the total number of temperature registers. This can result in access ernvd · 2024-04-03
- [NVD] CVE-2024-26728 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: fix null-pointer dereference on edid reading Use i2c adapter when there isn't aux_mode in dc_link to fix a null-pointer derefence that happens when running igt@kms_force_connector_basic in a synvd · 2024-04-03
- [NVD] CVE-2024-26718 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: dm-crypt, dm-verity: disable tasklets Tasklets have an inherent problem with memory corruption. The function tasklet_action_common calls tasklet_trylock, then it calls the tasklet callback and then it calls tasnvd · 2024-04-03
- [NVD] CVE-2024-26712 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: powerpc/kasan: Fix addr error caused by page alignment In kasan_init_region, when k_start is not page aligned, at the begin of for loop, k_cur = k_start & PAGE_MASK is less than k_start, and then `va = block + nvd · 2024-04-03
- [NVD] CVE-2024-26706 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: parisc: Fix random data corruption from exception handler The current exception handler implementation, which assists when accessing user space memory, may exhibit random data corruption if the compiler decidesnvd · 2024-04-03
- [NVD] CVE-2024-26704 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: ext4: fix double-free of blocks due to wrong extents moved_len In ext4_move_extents(), moved_len is only updated when all moves are successfully executed, and only discards orig_inode and donor_inode preallocatnvd · 2024-04-03
- [NVD] CVE-2024-26699 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix array-index-out-of-bounds in dcn35_clkmgr [Why] There is a potential memory access violation while iterating through array of dcn35 clks. [How] Limit iteration per array size.nvd · 2024-04-03
- [NVD] CVE-2024-26697 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix data corruption in dsync block recovery for small block sizes The helper function nilfs_recovery_copy_block() of nilfs_recovery_dsync_blocks(), which recovers data from logs created by data sync wrinvd · 2024-04-03
- [NVD] CVE-2024-26692 (HIGH 8.3) — In the Linux kernel, the following vulnerability has been resolved: smb: Fix regression in writes when non-standard maximum write size negotiated The conversion to netfs in the 6.3 kernel caused a regression when maximum write size is set by the server to an unexpected value whnvd · 2024-04-03
- [NVD] CVE-2024-26690 (HIGH 7.5) — In the Linux kernel, the following vulnerability has been resolved: net: stmmac: protect updates of 64-bit statistics counters As explained by a comment in <linux/u64_stats_sync.h>, write side of struct u64_stats_sync must ensure mutual exclusion, or one seqcount update could bnvd · 2024-04-03
- [NVD] CVE-2024-26689 (HIGH 8.8) — In the Linux kernel, the following vulnerability has been resolved: ceph: prevent use-after-free in encode_cap_msg() In fs/ceph/caps.c, in encode_cap_msg(), "use after free" error was caught by KASAN at this line - 'ceph_buffer_get(arg->xattr_buf);'. This implies before the refnvd · 2024-04-03
- [NVD] CVE-2024-1300 (MEDIUM 5.4) — A vulnerability in the Eclipse Vert.x toolkit causes a memory leak in TCP servers configured with TLS and SNI support. When processing an unknown SNI server name assigned the default certificate instead of a mapped certificate, the SSL context is erroneously cached in the server nvd · 2024-04-02