Security Advisories
Vulnerabilities discovered by Talence Security through original research and responsible disclosure.
CVSS 6.5
PipeWire RAOP RTSP Client NULL Pointer Dereference
TLSA-2026-0287
CVE-2026-14324
PipeWire
PipeWire ≤ 1.7.0
Apps
Summary
The PipeWire RAOP (AirPlay) RTSP client fails to validate the Content-Length header value, allowing a malicious server to trigger a NULL pointer dereference and crash the PipeWire daemon.
References
CVSS 7.5
PipeWire Pulse Server Unbounded alloca Stack Overflow
TLSA-2026-0288
CVE-2026-14330
PipeWire
PipeWire ≤ 1.7.0
Apps
Summary
The PipeWire PulseAudio-compatible server uses alloca() with an attacker-controlled size from incoming protocol messages without bounds checking, allowing a crafted message to cause a stack buffer overflow and crash the service.
References
CVSS 7.1
[Filesystem] Apple HFS+: Integer Overflow in Extended Attribute Handling
TLSA-2026-0289
CVE-2026-43764
Apple
Apple HFS+ (macOS Tahoe 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8)
Linux Kernel
Summary
An integer overflow in Apple HFS+ filesystem handling allows a crafted disk image to cause unexpected system termination. The integer overflow was addressed with improved input validation. Fixed in macOS Tahoe 26.6, macOS Sequoia 15.7.8, and macOS Sonoma 14.8.8.
References
CVSS 8.8
[Application] Apple MobileAccessoryUpdater: Buffer Overflow via Malicious Accessory
TLSA-2026-0290
CVE-2026-43807
Apple
Apple MobileAccessoryUpdater (macOS Sequoia 15.7.8, macOS Sonoma 14.8.8)
Apps
Summary
A buffer overflow in Apple MobileAccessoryUpdater allows a malicious accessory to cause unexpected app termination or potentially execute arbitrary code. The buffer overflow was addressed with improved bounds checking. Fixed in macOS Sequoia 15.7.8 and macOS Sonoma 14.8.8.
References
CVSS 5.5
[Linux Kernel] netfilter: x_tables Hook Ops NULL Pointer Dereference
TLSA-2026-0284
CVE-2026-64079
Linux
Linux Kernel netfilter x_tables
Linux Kernel
Summary
arp/ip(6)t_register_table() adds the table to the per-netns list before allocating the per-netns hook ops copy via kmemdup_array(). A concurrent pernet exit finds the table via xt_find_table() and passes the NULL ops pointer to nf_unregister_net_hooks(), causing a NULL dereference. Affected since 5.13, fixed in 7.0.11 and 7.1.
References
CVSS 5.5
[Linux Kernel] xfrm/iptfs: ABBA Deadlock in iptfs_destroy_state via hrtimer_cancel Under Spinlock
TLSA-2026-0285
CVE-2026-53197
Linux
Linux Kernel xfrm/iptfs
Linux Kernel
Summary
iptfs_destroy_state() calls hrtimer_cancel() while holding the xtsp->lock spinlock, but the hrtimer callback iptfs_delay_timer() also acquires xtsp->lock. If the timer is firing on another CPU, hrtimer_cancel() waits for the callback to complete while holding the lock the callback needs, creating an ABBA deadlock. Triggers under concurrent SA teardown and packet transmission.
References
- https://www.cve.org/CVERecord?id=CVE-2026-53197
- https://nvd.nist.gov/vuln/detail/CVE-2026-53197
- https://lore.kernel.org/all/?q=CVE-2026-53197
- https://git.kernel.org/stable/c/822b98d354e63e8249e85473c5f3c519f3c9cecc
- https://git.kernel.org/stable/c/a13ca53e47e500854a3b9ec18b5dc83acfec863e
- https://git.kernel.org/stable/c/c8a8a75b733467b00c08b91a38dbaf207a08ed6e
CVSS 5.3
[Application] Nessus: Second-Order SQL Injection via DNS PTR Hostname in Scan Plugin Queries
TLSA-2026-0278
CVE-2026-57587
Tenable
Nessus <= 10.12.0
Apps
Summary
The Nessus scanner daemon (nessusd) constructs SQL queries in the patches_summary.nbin NASL plugin using unsanitized hostname values via db_query() without parameterized binding. When reverse_lookup is enabled, an attacker controlling DNS PTR records for a scanned IP can inject SQL payloads that execute during scan processing, achieving second-order SQL injection and data exfiltration from the internal SQLite database (PASSWD, SETTINGS, PREFERENCES tables).
References
CVSS 3.3
[Application] Nessus: Second-Order SQL Injection via Imported .nessus File Hostname
TLSA-2026-0279
CVE-2026-57588
Tenable
Nessus <= 10.12.0
Apps
Summary
The Nessus scanner daemon (nessusd) stores hostnames from imported .nessus scan files via parameterized INSERT, but reads them back via snprintf string interpolation in the patches_summary.nbin NASL plugin without escaping. A crafted .nessus file with SQL injection payload in the ReportHost name field triggers second-order SQL injection when the imported results are processed, enabling data exfiltration from the internal SQLite database.
References
CVSS 7.5
[Library] libsoup: WebSocket permessage-deflate Decompression Bomb (DoS)
TLSA-2026-0280
CVE-2026-15709
GNOME
libsoup <= 3.7.0
Library
Summary
The WebSocket permessage-deflate extension does not limit the decompressed output size of incoming frames. A small compressed payload can expand to gigabytes, exhausting server memory and causing denial of service in any application using libsoup's WebSocket server (e.g. GNOME Online Accounts, Evolution, Flatpak).
References
CVSS 5.3
[Network] Samba: kpasswd 6-Byte Heap Out-of-Bounds Read in Packet Parser
TLSA-2026-0282
CVE-2026-58216
The Samba Team
Samba <= 4.24.4
Network
Summary
The kpasswd service reads 6 bytes from the KRB-PRIV packet header without checking that the received packet is at least 6 bytes long. A 0-5 byte UDP packet causes a heap out-of-bounds read, potentially crashing the KDC process and disrupting Kerberos authentication for the domain.
References
- https://www.cve.org/CVERecord?id=CVE-2026-58216
- https://nvd.nist.gov/vuln/detail/CVE-2026-58216
- https://bugzilla.samba.org/show_bug.cgi?id=16087
- https://access.redhat.com/security/cve/CVE-2026-58216
- https://bugzilla.redhat.com/show_bug.cgi?id=2502721
- https://www.samba.org/samba/security/CVE-2026-58216.html
CVSS 5.3
[Network] Samba: DNS TKEY Pre-Auth Flooding Denial of Service
TLSA-2026-0276
CVE-2026-58218
The Samba Team
Samba <= 4.24.3
Network
Summary
The internal DNS server stores GSSAPI TKEY session keys in a fixed 128-entry ring buffer with no rate limiting or authentication requirement. An unauthenticated attacker sends 128 TKEY requests to flush all legitimate GSS-TSIG session keys, breaking authenticated DNS updates for the entire AD domain. Each request also allocates a GENSEC/KRB5 context for resource exhaustion. Co-discovery with Tridge.
References
- https://www.cve.org/CVERecord?id=CVE-2026-58218
- https://nvd.nist.gov/vuln/detail/CVE-2026-58218
- https://bugzilla.samba.org/show_bug.cgi?id=16115
- https://access.redhat.com/security/cve/CVE-2026-58218
- https://bugzilla.redhat.com/show_bug.cgi?id=2502728
- https://www.samba.org/samba/security/CVE-2026-58218.html
CVSS 8.8
[Network] Samba: LDAP Compare Filter Injection and Trusted-Request ACL Bypass
TLSA-2026-0277
CVE-2026-58222
The Samba Team
Samba <= 4.24.3
Network
Summary
The LDAP CompareRequest handler constructs a search filter by interpolating the comparison value without escaping LDAP metacharacters, and evaluates the resulting LDB search without calling ldb_req_mark_untrusted() (unlike all other LDAP operations). Authenticated users can inject filter syntax and use the Compare true/false oracle to extract protected attributes including password hashes and LAPS passwords. Co-discovery with OpenAI.
References
- https://www.cve.org/CVERecord?id=CVE-2026-58222
- https://nvd.nist.gov/vuln/detail/CVE-2026-58222
- https://bugzilla.samba.org/show_bug.cgi?id=16148
- https://access.redhat.com/security/cve/CVE-2026-58222
- https://bugzilla.redhat.com/show_bug.cgi?id=2502722
- https://www.samba.org/samba/security/CVE-2026-58222.html
CVSS 8.8
[Browser] Apple libxslt: xsltAttribute Double-Free via Dictionary Pointer Aliasing
TLSA-2026-0231
CVE-2026-43706
Apple
Apple libxslt (Safari, macOS, iOS)
Browsers
Summary
The xsltAttribute() function in libxslt frees a dictionary string via xmlDictOwns() check, but the pointer can alias an earlier dictionary entry still referenced by the attribute node. Processing a crafted XSLT stylesheet triggers a double-free of the dictionary-allocated string, corrupting the heap. Solo discovery.
References
- https://www.cve.org/CVERecord?id=CVE-2026-43706
- https://nvd.nist.gov/vuln/detail/CVE-2026-43706
- https://support.apple.com/en-us/127685
- https://support.apple.com/en-us/127594
- https://support.apple.com/en-us/127595
- https://support.apple.com/en-us/128068
- https://support.apple.com/en-us/128069
- https://support.apple.com/en-us/128070
- https://support.apple.com/en-us/128071
- https://support.apple.com/en-us/128072
CVSS 8.3
[Browser] Apple libxslt: xsltParseTemplateContent Type Confusion / Attacker-Controlled Pointer Dereference
TLSA-2026-0232
CVE-2026-43703
Apple
Apple libxslt (Safari, macOS, iOS)
Browsers
Summary
The xsltParseTemplateContent() function in libxslt processes XSLT template nodes with incorrect type assumptions, allowing an attacker-controlled pointer dereference via a crafted XSLT stylesheet. This can lead to arbitrary code execution in the context of the rendering process. Solo discovery.
References
- https://www.cve.org/CVERecord?id=CVE-2026-43703
- https://nvd.nist.gov/vuln/detail/CVE-2026-43703
- https://support.apple.com/en-us/127685
- https://support.apple.com/en-us/127594
- https://support.apple.com/en-us/127595
- https://support.apple.com/en-us/128068
- https://support.apple.com/en-us/128069
- https://support.apple.com/en-us/128070
- https://support.apple.com/en-us/128071
- https://support.apple.com/en-us/128072
CVSS 6.5
[Browser] Apple WebKit: Path Handling Information Disclosure
TLSA-2026-0233
CVE-2026-43726
Apple
Apple WebKit (Safari)
Browsers
Summary
A path handling issue in WebKit allows web content to disclose sensitive information. Co-discovered with Nicolás Korbel, Kim Bui, and Mandeep Singh.
References
- https://www.cve.org/CVERecord?id=CVE-2026-43726
- https://nvd.nist.gov/vuln/detail/CVE-2026-43726
- https://support.apple.com/en-us/127685
- https://support.apple.com/en-us/127594
- https://support.apple.com/en-us/127595
- https://support.apple.com/en-us/128068
- https://support.apple.com/en-us/128069
- https://support.apple.com/en-us/128070
CVSS 8.8
[Browser] Apple WebKit: Wasm Table and Global Missing Transitive TypeDefinition Retention (Use-After-Free)
TLSA-2026-0234
CVE-2026-43712
Apple
Apple WebKit (Safari)
Browsers
Summary
WebKit's Wasm Table and Global implementations do not retain transitive TypeDefinition references, allowing a use-after-free when a TypeDefinition is garbage collected while still referenced through a table or global indirection. Co-discovered with Kwak Kiyong and Song Nuri.
References
- https://www.cve.org/CVERecord?id=CVE-2026-43712
- https://nvd.nist.gov/vuln/detail/CVE-2026-43712
- https://support.apple.com/en-us/127685
- https://support.apple.com/en-us/127594
- https://support.apple.com/en-us/127595
- https://support.apple.com/en-us/128068
- https://support.apple.com/en-us/128069
- https://support.apple.com/en-us/128070
CVSS 8.8
[Browser] Apple WebKit: Memory Handling Vulnerability
TLSA-2026-0235
CVE-2026-43663
Apple
Apple WebKit (Safari)
Browsers
Summary
A memory handling issue in WebKit allows processing maliciously crafted web content to lead to arbitrary code execution. Co-discovered with DEVCORE, Park, Burnett, and others.
References
- https://www.cve.org/CVERecord?id=CVE-2026-43663
- https://nvd.nist.gov/vuln/detail/CVE-2026-43663
- https://support.apple.com/en-us/127685
- https://support.apple.com/en-us/127594
- https://support.apple.com/en-us/127595
- https://support.apple.com/en-us/128068
- https://support.apple.com/en-us/128069
- https://support.apple.com/en-us/128070
CVSS 2.6
[Application] NanoMQ: Pre-Auth NULL Pointer Dereference in MQTT v5 CONNECT Will Properties
TLSA-2026-0275
CVE-2026-47275
EMQ Technologies
NanoMQ <= 0.24.11
Apps
Summary
The MQTT v5 CONNECT decoder accesses will_prop before validating it is non-NULL when processing Will Property fields. A CONNECT packet with Will Flag set but missing Will Properties causes a NULL dereference crash. Pre-auth (CONNECT is the first MQTT packet). Co-discovery with tteoks.
References
CVSS 6.2
[p11-kit] Stack Exhaustion via Unbounded Recursion in Nested Attribute Template Parsing
TLSA-2026-0236
CVE-2026-13757
p11-glue
p11-kit (<= 0.26.2)
Library
Summary
p11-kit's attribute template parser allows unbounded recursion when processing nested CKA_WRAP_TEMPLATE/CKA_UNWRAP_TEMPLATE attributes. A crafted PKCS#11 object with deeply nested templates causes stack exhaustion, crashing any application linked against p11-kit (e.g. GnuTLS, NSS, OpenSC). Confirmed real security issue by maintainer.
References
CVSS 7.5
[Application] GNU Wget: Heap Buffer Underread in clean_metalink_string() via All-Whitespace URL
TLSA-2026-0237
CVE-2026-58469
GNU Project
GNU Wget <= 1.25.0
Apps
Summary
The clean_metalink_string() function in Metalink URL parsing decrements a pointer past the start of the buffer when given an all-whitespace or trailing-whitespace URL. This causes a heap buffer underread that can crash wget or leak adjacent heap data. Fixed in commit 37a40fc with Reported-by credit. CVE pending via VulnCheck.
References
- https://www.cve.org/CVERecord?id=CVE-2026-58469
- https://nvd.nist.gov/vuln/detail/CVE-2026-58469
- https://git.savannah.gnu.org/cgit/wget.git/commit/?id=37a40fc
- https://gitlab.com/gnuwget/wget/-/commit/37a40fcb450153f69537c7cbc2a7a4fb0b6f7826
- https://www.vulncheck.com/advisories/gnu-wget-heap-buffer-underread-via-metalink-url-parsing
CVSS 5.3
[Application] GNU Wget: Signed Integer Overflow in parse_content_range() via Server-Controlled Header
TLSA-2026-0238
CVE-2026-58470
GNU Project
GNU Wget <= 1.25.0
Apps
Summary
The parse_content_range() function uses signed integer arithmetic to parse Content-Range header values from HTTP server responses. A malicious server can supply values that cause signed integer overflow, leading to undefined behavior and incorrect range calculations. Fixed in commit 43d3ba9 with Reported-by credit. CVE pending via VulnCheck.
References
- https://www.cve.org/CVERecord?id=CVE-2026-58470
- https://nvd.nist.gov/vuln/detail/CVE-2026-58470
- https://git.savannah.gnu.org/cgit/wget.git/commit/?id=43d3ba9
- https://gitlab.com/gnuwget/wget/-/commit/43d3ba9336bc94937e6fae2365c6ffd30c34ffcf
- https://www.vulncheck.com/advisories/gnu-wget-integer-overflow-via-content-range-header-parsing
CVSS 6.1
[Application] GNU Wget: Heap Buffer Overflow in convert_fname() iconv E2BIG Handler
TLSA-2026-0239
CVE-2026-58471
GNU Project
GNU Wget <= 1.25.0
Apps
Summary
The convert_fname() function in wget's filename conversion logic mishandles the iconv E2BIG error case, leading to a heap buffer overflow when processing filenames that require character set conversion. A malicious HTTP server can trigger this by serving responses with filenames that expand during iconv conversion. Co-discovery with Arkadi Vainbrand. Fixed in commit dd692d9c with Reported-by credit. CVE pending via VulnCheck.
References
- https://www.cve.org/CVERecord?id=CVE-2026-58471
- https://nvd.nist.gov/vuln/detail/CVE-2026-58471
- https://git.savannah.gnu.org/cgit/wget.git/commit/?id=dd692d9c
- https://gitlab.com/gnuwget/wget/-/commit/c2640fe5171c59f87c58dc9fcb195b2d18b010ee
- https://www.vulncheck.com/advisories/gnu-wget-heap-buffer-overflow-via-convert-fname-in-url-c
CVSS 5.9
[Application] GNU Wget: Integer Overflow in html_quote_string() Leading to Heap Buffer Overflow
TLSA-2026-0240
CVE-2026-58472
GNU Project
GNU Wget <= 1.25.0
Apps
Summary
The html_quote_string() function uses an integer size counter that can overflow when processing very long strings with many characters requiring HTML entity escaping. The overflowed size is used to allocate a heap buffer that is too small, and the subsequent copy loop writes past the buffer boundary. Triggered in recursive mode with --convert-links. CVE pending via VulnCheck.
References
CVSS 7.8
[Linux Kernel] nft_tunnel: Use-After-Free on Object Destroy via metadata_dst Refcount Bypass
TLSA-2026-0230
CVE-2026-53212
Linux
Linux Kernel (net/netfilter/nft_tunnel.c)
Linux Kernel
Summary
nft_tunnel_obj_destroy() calls metadata_dst_free() which directly kfree()s the metadata_dst, bypassing the dst_entry refcount mechanism. Packets that took a reference via dst_hold() in nft_tunnel_obj_eval() and are still queued (e.g. in a netem qdisc) are left with a dangling pointer. When these packets are eventually dequeued, dst_release() operates on freed memory, yielding a deterministic UAF-WRITE primitive in kmalloc-cg-256. Fully unprivileged via user namespace (unshare -Urn). Affects all kernels since v4.19 (2018). Working LPE exploit demonstrated on Ubuntu 24.04 and 26.04 with KASLR.
References
- https://git.kernel.org/stable/c/c32b26aaa2f9216520a38b3f4bfeec846eb3eb8a
- https://nvd.nist.gov/vuln/detail/CVE-2026-53212
- https://www.cve.org/CVERecord?id=CVE-2026-53212
- https://git.kernel.org/stable/c/349df61526d2e39decc685d246202e3e284cfe05
- https://git.kernel.org/stable/c/55b79b1ae42372012413ce0413181d26679b17ef
- https://git.kernel.org/stable/c/5e9ee18b27fde88cb6148202b33916c66693fe82
- https://git.kernel.org/stable/c/8767fe4079affa74314d7eb3220e700150289842
- https://git.kernel.org/stable/c/941d7394efda5e054e2d6f3e0dd0f6a9ba19aaa3
- https://git.kernel.org/stable/c/f9a0e4b61054cde89a2a77845293c726cc07cc43
- https://git.kernel.org/stable/c/fda6573a46ad24f35348e024905ee5bdf729797e
CVSS 6.5
[Library] libssh2: SFTP symlink_target Out-of-Bounds Read
TLSA-2025-0001
CVE-2025-15661
libssh2 project
libssh2 <= 1.11.1
Library
Summary
libssh2 through 1.11.1 has an out-of-bounds read in the SFTP READLINK/REALPATH response handler (sftp.c). The symlink_target buffer receives data without proper length validation, allowing a malicious SFTP server to trigger an OOB read. Independent co-discovery with Joshua Rogers. Fix: commit 2dae302/PR #1717. VulnCheck assigned CVE-2025-15661.
References
- https://www.cve.org/CVERecord?id=CVE-2025-15661
- https://nvd.nist.gov/vuln/detail/CVE-2025-15661
- https://github.com/libssh2/libssh2/pull/1717
- https://github.com/libssh2/libssh2/commit/2dae3024897e1898d389835151f4e9606227721d
- https://github.com/libssh2/libssh2/pull/1705
- https://www.vulncheck.com/advisories/libssh2-heap-buffer-over-read-via-sftp-symlink-in-sftp-c
CVSS 7.8
[Linux Kernel Driver] b43legacy: Out-of-Bounds Read (firmware key index)
TLSA-2026-0213
CVE-2026-46163
Broadcom
Linux Kernel b43legacy WiFi Driver
Drivers
Summary
The b43legacy RX handler uses a hardware-reported key index without bounds checking to look up entries in the key table array. Firmware-controlled values exceeding the array size cause out-of-bounds reads from adjacent kernel heap memory, potentially bypassing WPA decryption validation flags.
References
- https://www.cve.org/CVERecord?id=CVE-2026-46163
- https://nvd.nist.gov/vuln/detail/CVE-2026-46163
- https://lore.kernel.org/all/?q=CVE-2026-46163
- https://git.kernel.org/stable/c/1baaeb6adecb9691748c0253dab6ddd19a2b4e9e
- https://git.kernel.org/stable/c/4242db36de99de734cc1f60e5edd86cda7e598c6
- https://git.kernel.org/stable/c/6ee946077607d7783ae6709a899213fc4fe08f35
- https://git.kernel.org/stable/c/9d1bc155802943e92c57a5fb923d23edfbf0b525
- https://git.kernel.org/stable/c/a035766f970bde2d4298346a31a80685be5c0205
- https://git.kernel.org/stable/c/a92bd0503df2488f2cc040f329ebccff1c1934cb
- https://git.kernel.org/stable/c/df805c1d085b7a96077f0964185764c87060950d
- https://git.kernel.org/stable/c/fdd4e51979f42ca8b1ab7e6176b607e1caabf2a5
CVSS 8.1
[Proxy] HAProxy: Integer Overflow in FCGI Demux Record Length Field
TLSA-2026-0223
CVE-2026-55203
HAProxy Technologies
HAProxy <= 3.1.17
Network
Summary
HAProxy through 3.1.17 has an integer overflow in the FCGI demultiplexer. The ignore_record function accumulates record length via drl += drp using uint16_t arithmetic, which wraps at 65535+1=0. When this occurs, zero bytes are consumed and the remaining buffer data is parsed as new FCGI records, enabling cross-stream response poisoning from a crafted FCGI backend.
References
CVSS 7.5
[Proxy] HAProxy: NULL Pointer Dereference in hpack_dht_insert Function
TLSA-2026-0224
CVE-2026-55204
HAProxy Technologies
HAProxy <= 3.1.17
Network
Summary
HAProxy through 3.1.17 has a NULL pointer dereference in the HPACK dynamic header table. The hpack_dht_insert function at line 353 calls hpack_dht_defrag() for data-space defragmentation but does not check the return value for NULL. Two other call sites in the same function correctly check for NULL. Under memory pool exhaustion, this causes a worker process crash (denial of service).
References
CVSS 7.7
[Application] OpenCTI: Server-Side Request Forgery via CSV Ingestion Tester (Duplicate)
TLSA-2026-0211
CVE-2026-21887
OpenCTI Platform
OpenCTI 7.260529.0
Apps
Summary
The CSV ingestion tester endpoint does not validate target URLs against private IP ranges, allowing server-side request forgery with CSVMAPPERS capability. Co-discovery (duplicate).
References
CVSS 6.5
[Network] xrdp: Out-of-Bounds Read in Client Control PDU Processing
TLSA-2026-0215
CVE-2026-55645
neutrinoLabs
xrdp <= 0.10.6
Network
Summary
The xrdp_rdp_process_data_control function in xrdp reads from the network stream without validating that sufficient data remains for the control PDU fields. A malicious RDP client can send a truncated Client Request Control PDU that triggers out-of-bounds reads. Pre-authentication, within the MCS userData buffer. GHSA-3m4m-h22g-c7xx.
References
CVSS 5.3
[Network] xrdp: Out-of-Bounds Read in GCC Conference Create Request CS_SECURITY Processing
TLSA-2026-0216
CVE-2026-55639
neutrinoLabs
xrdp <= 0.10.6
Network
Summary
The xrdp_sec_process_mcs_data_CS_SECURITY function in xrdp reads security data fields from the GCC Conference Create Request without validating that the stream contains enough bytes. A malicious RDP client can send a truncated CS_SECURITY block that triggers out-of-bounds reads. Pre-authentication. GHSA-6g36-mxcf-r3gc.
References
CVSS 5.5
[Filesystem] nilfs-utils: Undefined Behavior and Out-of-Memory via Unvalidated s_log_block_size
TLSA-2026-0225
CVE-2026-55392
nilfs-dev
nilfs-utils <= 2.3.0
Linux Kernel
Summary
nilfs-utils through 2.3.0 does not validate the s_log_block_size field from NILFS2 filesystem superblocks. A crafted filesystem image with a large s_log_block_size value causes undefined behavior via excessive left-shift and subsequent out-of-memory conditions. Fix: PR #27 (commit 26efb5d).
References
CVSS 8.1
[Application] socat: Heap Buffer Overflow in SOCKS5 Reply Parser
TLSA-2026-0227
CVE-2026-56123
Gerhard Rieger
socat <= 1.8.1.1
Apps
Summary
The SOCKS5 reply parser in socat uses a signed char variable to store the address length byte from the SOCKS5 server response. When the server sends a value >= 128, the signed char becomes negative, bypassing the buffer size check. The negative value is then implicitly promoted to a large unsigned value in the subsequent recv() call, causing a heap buffer overflow. A malicious SOCKS5 proxy server can exploit this to crash the socat process or potentially achieve code execution. Fixed in socat 1.8.1.2.
References
CVSS 5.3
[Network] xrdp: FIPS Padding Underflow Pre-Auth Denial of Service
TLSA-2026-0195
CVE-2026-44978
neutrinoLabs
xrdp <= 0.10.6
Network
Summary
The FIPS security header parsing in xrdp_sec_recv_fastpath() and xrdp_sec_recv() reads a pad value from the client-supplied TS_FP_FIPS_INFO structure and subtracts it from the stream end pointer without validating that pad is within the valid range (0-7 for DES3-CBC). A pad value larger than the remaining data causes a pointer underflow, producing a negative length cast to size_t in the HMAC signature verification, triggering a massive heap out-of-bounds read and crash. Pre-auth, requires crypt_level=fips. Co-discovered with Tencent Xuanwu Lab.
References
CVSS 7.5
[Application] Evil-WinRM: Path Traversal in download_dir() Function
TLSA-2026-0220
CVE-2026-55201
Hackplayers
Evil-WinRM <= 3.9
Apps
Summary
Evil-WinRM through version 3.9 has a path traversal vulnerability in the download_dir() function. A malicious SMB server or compromised Windows host can serve file paths containing directory traversal sequences (../) that write files outside the intended download directory on the attacker's machine. Fix: PR #81.
References
- https://www.cve.org/CVERecord?id=CVE-2026-55201
- https://nvd.nist.gov/vuln/detail/CVE-2026-55201
- https://github.com/Hackplayers/evil-winrm/pull/81
- https://github.com/Hackplayers/evil-winrm/commit/6ecd570a298562dc72ad73978307eb34182f5850
- https://www.vulncheck.com/advisories/evil-winrm-path-traversal-in-download-dir-function
CVSS 7.5
[Network] xrdp: Pre-Auth Infinite Loop via totalLength=0 in RDP PDU Processing
TLSA-2026-0196
CVE-2026-54538
neutrinoLabs
xrdp <= 0.10.6
Network
Summary
The xrdp_rdp_recv() function processes RDP PDUs in a loop, advancing the stream position by totalLength bytes per iteration. When totalLength is 0, the stream position never advances and xrdp enters an infinite loop, consuming 100% CPU on that connection's forked process. Pre-auth, no credentials needed. GHSA-9j3q-9mvw-qv7j accepted.
References
CVSS 6.5
[Network] coturn: Arbitrary File Write via CLI psd Command
TLSA-2026-0167
CVE-2026-53449
coturn
coturn ≤ 4.12.0
Network
Summary
The psd (print sessions dump) CLI command in coturn takes a filename argument and directly passes it to fopen(cmd, "w") with no path validation. An authenticated admin with CLI access can overwrite arbitrary files writable by the coturn process. The file is truncated and overwritten with session dump data, whose content can be partially influenced by creating TURN allocations with crafted usernames. The CLI admin interface requires password authentication and binds to localhost by default.
References
- https://www.cve.org/CVERecord?id=CVE-2026-53449
- https://nvd.nist.gov/vuln/detail/CVE-2026-53449
- https://github.com/coturn/coturn/security/advisories/GHSA-jj76-vwjw-w34r
- https://github.com/coturn/coturn/commit/e72930f571beba3bc7a9f97661af2614aae92a55
- https://github.com/coturn/coturn/releases/tag/4.13.0
CVSS 9.8
[Linux Kernel] ksmbd: EA Alignment Out-of-Bounds Write in smb2_get_ea()
TLSA-2026-0178
CVE-2026-31705
Linux
Linux Kernel ksmbd (SMB3 Server)
Network
Summary
smb2_get_ea() in ksmbd computes extended attribute entry alignment using attacker-controlled ea_name_len and ea_value_len fields without overflow checking. A malicious SMB client can send crafted EA data causing an out-of-bounds write past the allocated response buffer. Remote, pre-auth on systems running ksmbd.
References
- https://www.cve.org/CVERecord?id=CVE-2026-31705
- https://nvd.nist.gov/vuln/detail/CVE-2026-31705
- https://lore.kernel.org/all/?q=CVE-2026-31705
- https://git.kernel.org/stable/c/30010c952077a1c89ecdd71fc4d574c75a8f5617
- https://git.kernel.org/stable/c/790304c02bf9bd7b8171feda4294d6e62d32ae8f
- https://git.kernel.org/stable/c/922d48fe8c19f388ffa2f709f33acaae4e408de2
- https://git.kernel.org/stable/c/98f3de6ef4efbd899348d333f0902dc4ff14380c
- https://git.kernel.org/stable/c/ddbbc8b2a09dd2cfed90871313e3691ae1db08a2
- https://git.kernel.org/stable/c/ffbce350c6fd1e99116ea57383b9031717e36d3b
CVSS 5.5
[Linux Kernel] ksmbd: DACL Size u16 Integer Overflow
TLSA-2026-0179
CVE-2026-31704
Linux
Linux Kernel ksmbd (SMB3 Server)
Network
Summary
The DACL parsing code in ksmbd uses a u16 variable for tracking accumulated ACE sizes. When processing a DACL with many ACEs, the size counter overflows u16, causing the parser to accept malformed ACLs and write past the validated boundary. Remote, pre-auth on systems running ksmbd.
References
- https://www.cve.org/CVERecord?id=CVE-2026-31704
- https://nvd.nist.gov/vuln/detail/CVE-2026-31704
- https://lore.kernel.org/all/?q=CVE-2026-31704
- https://git.kernel.org/stable/c/299f962c0b02d048fb45d248b4da493d03f3175d
- https://git.kernel.org/stable/c/41e53a773db6342ac9a689ee5ba635c31744c9f0
- https://git.kernel.org/stable/c/5e7b8f3c539d69b2ed5f2408e2f75e68ce7eef43
- https://git.kernel.org/stable/c/8d5729350b236896f51379588d9a690b7fafb8db
- https://git.kernel.org/stable/c/e1955a94b6f17f4b058afa955a6f187eb3ed7615
- https://git.kernel.org/stable/c/ef7902be3f215b6bf7babe4dc9dd9a7d57dad7a7
CVSS 5.5
[Linux Kernel] Ubuntu AppArmor: Memory Leak via Inverted NULL Check in Large Response Path (apparmorfs.c)
TLSA-2026-0138
CVE-2026-47326
Canonical
Ubuntu Linux Kernel (AppArmor SAUCE, security/apparmor/apparmorfs.c)
Linux Kernel
Summary
In notify_user_response(), the check 'if (big_resp)' is inverted -- should be 'if (!big_resp)'. On successful aa_get_buffer() allocation, the function returns -ENOMEM and leaks the buffer. On failure, big_resp is NULL and execution continues with a NULL dereference. Additionally, the stack variable &uresp is always passed to the handler instead of big_resp, so the entire large-response code path is non-functional. An unprivileged local user can trigger the memory leak, leading to resource exhaustion. Affects Ubuntu 24.04 (6.8), 24.10 (6.17), 25.04 (7.0). Fixed in USN-8370-1 / USN-8373-1.
References
CVSS 3.3
[Linux Kernel] Ubuntu AppArmor: NULL Deref via Wrong Variable in kstrdup Check (notify.c)
TLSA-2026-0139
CVE-2026-47327
Canonical
Ubuntu Linux Kernel (AppArmor SAUCE, security/apparmor/notify.c)
Linux Kernel
Summary
After kstrdup() allocates glob, the code checks 'if (!name)' instead of 'if (!glob)'. Since name is never NULL at that point, a kstrdup failure stores glob=NULL as clone->data.name, leading to a NULL pointer dereference on subsequent access. An unprivileged local user can trigger this to cause a kernel oops. Affects Ubuntu 24.04 (6.8), 24.10 (6.17), 25.04 (7.0). Fixed in USN-8370-1 / USN-8373-1.
References
CVSS 6.1
[Linux Kernel] Ubuntu AppArmor: kfree(stack pointer) in TAILGLOB Path → Slab Corruption (notify.c)
TLSA-2026-0140
CVE-2026-47328
Canonical
Ubuntu Linux Kernel (AppArmor SAUCE, security/apparmor/notify.c)
Linux Kernel
Summary
In the TAILGLOB notification response path, kfree(name) is called on a pointer into the stack-allocated uresp union instead of the kstrdup'd glob pointer. This attempts to free a non-kmalloc'd address, corrupting slab metadata. Meanwhile the actual heap allocation (glob) is leaked. An unprivileged local user can trigger this to corrupt kernel memory. Affects Ubuntu 24.04 (6.8), 24.10 (6.17), 25.04 (7.0). Fixed in USN-8370-1 / USN-8373-1.
References
CVSS 3.3
[Linux Kernel] Ubuntu AppArmor: Validation Bypass via -errno Returned as bool (notify.c)
TLSA-2026-0141
CVE-2026-47329
Canonical
Ubuntu Linux Kernel (AppArmor SAUCE, security/apparmor/notify.c)
Linux Kernel
Summary
The response_is_valid_name() function returns -EMSGSIZE or -EINVAL on validation failures instead of false. Since the return type is bool, (bool)(-EINVAL) = true, so every validation check passes. This allows notification responses with invalid sizes, out-of-bounds offsets, or incorrect flags to be accepted and processed as if well-formed. An unprivileged local user can send crafted responses to bypass all name validation. Affects Ubuntu 24.04 (6.8), 24.10 (6.17), 25.04 (7.0). Fixed in USN-8370-1 / USN-8373-1.
References
CVSS 3.3
[Linux Kernel] Ubuntu AppArmor: Uninitialized Variable in Notification Response Caching (notify.c)
TLSA-2026-0142
CVE-2026-47330
Canonical
Ubuntu Linux Kernel (AppArmor SAUCE, security/apparmor/notify.c)
Linux Kernel
Summary
In knotif_update_from_uresp_perm(), the variable 'flags' is declared but not initialized in the else branch when uresp is NULL. The subsequent check 'if (!(flags & URESPONSE_NO_CACHE))' reads an uninitialized stack value, causing nondeterministic notification response caching behavior. An unprivileged local user can trigger incorrect caching of AppArmor notification responses. Affects Ubuntu 24.04 (6.8), 24.10 (6.17), 25.04 (7.0). Fixed in USN-8370-1 / USN-8373-1.
References
CVSS 7.8
[Linux Kernel] Ubuntu AppArmor: Unlocked list_add_tail Race → UAF in Notification Rules (notify.c)
TLSA-2026-0143
CVE-2026-47331
Canonical
Ubuntu Linux Kernel (AppArmor SAUCE, security/apparmor/notify.c)
Linux Kernel
Summary
The knotif_update_from_uresp_name() function modifies the profile->rules linked list via list_add_tail_entry() without holding any lock. This list is concurrently walked during file access mediation (aa_file_perm path). The source code contains a TODO comment acknowledging the missing lock. Concurrent modification and traversal causes list corruption, which can lead to use-after-free when a corrupted list entry is freed while another thread holds a stale pointer. An unprivileged local user can trigger the race condition to cause memory corruption and, theoretically, arbitrary code execution (local privilege escalation). Affects Ubuntu 24.04 (6.8) only. Rated HIGH by Canonical. Fixed in USN-8373-1 (6.8.0-124.124).
References
CVSS 5.5
[Linux Kernel] Ubuntu AppArmor: Heap OOB Read via sizeof(pointer) Filter Size Mismatch (apparmorfs.c)
TLSA-2026-0144
CVE-2026-47332
Canonical
Ubuntu Linux Kernel (AppArmor SAUCE, security/apparmor/apparmorfs.c)
Linux Kernel
Summary
sizeof(unotif) evaluates to 8 bytes (pointer size on x86_64) instead of sizeof(*unotif) (the actual struct size). This allows kzalloc(size) to be called with a size between 8 and the struct size, and subsequent access to struct fields beyond the allocation causes a slab-out-of-bounds read. KASAN confirmed: 2-minute fuzzer reproduces reliably. Information disclosure from adjacent slab objects. An unprivileged local user can trigger this via the notification interface. Affects Ubuntu 24.04 (6.8), 24.10 (6.17), 25.04 (7.0). Fixed in USN-8370-1 / USN-8373-1.
References
CVSS 7.8
[Linux Kernel] Ubuntu AppArmor: Heap Buffer Over-Read in DFA Unpack → Security Bypass (apparmorfs.c)
TLSA-2026-0145
CVE-2026-47333
Canonical
Ubuntu Linux Kernel (AppArmor SAUCE, security/apparmor/apparmorfs.c)
Linux Kernel
Summary
The DFA unpack length calculation 'size - ((void *)unotif - pos)' expands to 'size + filter' instead of 'size - filter', giving the DFA parser access to up to 2*filter bytes past the buffer end. Invalid data from adjacent slab objects is fed into the AppArmor DFA policy engine, which can result in incorrect access control decisions. An unprivileged local user can exploit this to bypass AppArmor security policies. Rated HIGH by Canonical: 'can allow a local user to bypass security measures'. Affects Ubuntu 24.04 (6.8), 24.10 (6.17), 25.04 (7.0). Fixed in USN-8370-1 / USN-8373-1.
References
CVSS 5.5
[Linux Kernel] Ubuntu AppArmor: GFP_KERNEL Allocation Under Spinlock → Deadlock (notify.c)
TLSA-2026-0146
CVE-2026-47334
Canonical
Ubuntu Linux Kernel (AppArmor SAUCE, security/apparmor/notify.c)
Linux Kernel
Summary
knotif_update_from_uresp_name() is called under listener->lock (spinlock) but performs sleeping operations: kzalloc(GFP_KERNEL), kstrdup(GFP_KERNEL), and aa_lookup_profile() (may acquire mutex). This triggers 'BUG: scheduling while atomic' on debug kernels and causes deadlocks on production kernels. An unprivileged local user can trigger kernel panic or deadlock. Affects Ubuntu 24.04 (6.8), 24.10 (6.17), 25.04 (7.0). Fixed in USN-8370-1 / USN-8373-1.
References
CVSS 5.5
[Linux Kernel] Ubuntu AppArmor: Missing NULL Check in aa_new_ruleset → Kernel Panic (notify.c)
TLSA-2026-0147
CVE-2026-47335
Canonical
Ubuntu Linux Kernel (AppArmor SAUCE, security/apparmor/notify.c)
Linux Kernel
Summary
aa_new_ruleset() calls INIT_LIST_HEAD(&rules->list) without checking the kzalloc() return value. On memory allocation failure (especially likely under GFP_KERNEL-under-spinlock from CVE-2026-47334), this dereferences NULL and causes a kernel panic. Chains with CVE-2026-47334 (sleep under spinlock forces GFP_ATOMIC behavior, increasing OOM probability). An unprivileged local user can trigger this to cause a kernel panic. Affects Ubuntu 24.04 (6.8) only. Fixed in USN-8373-1.
References
CVSS 3.3
[Linux Kernel] Ubuntu AppArmor: Uninitialized Variable in Sockopt Level (af_inet.c)
TLSA-2026-0148
CVE-2026-47336
Canonical
Ubuntu Linux Kernel (AppArmor SAUCE, security/apparmor/af_inet.c)
Linux Kernel
Summary
In profile_opt_perm(), the variable declaration '__be16 l = htons(l)' reads l before initialization. The intention was htons(level) using the function parameter. Instead, l reads garbage from the stack and uses it for the DFA permission lookup, making all fine-grained sockopt mediation non-functional on Ubuntu 24.04. Policies restricting specific sockopt levels neither correctly allow nor correctly deny. An unprivileged local user can influence fine-grained network socket mediation. Affects Ubuntu 24.04 (6.8) only. Fixed in USN-8373-1.
References
CVSS 3.3
[Linux Kernel] Ubuntu AppArmor: NULL Deref in bind_map_addr (af_inet.c)
TLSA-2026-0149
CVE-2026-47337
Canonical
Ubuntu Linux Kernel (AppArmor SAUCE, security/apparmor/af_inet.c)
Linux Kernel
Summary
In bind_map_addr(), addr4 is initialized to NULL. When sa_family is AF_UNSPEC and sk_family is PF_INET, the code reads addr4->sin_addr.s_addr while addr4 is still NULL (the assignment happens after the fallthrough to case AF_INET). This dereferences address 0x4, causing a kernel oops. Triggered when any AppArmor-confined application (snap, Docker, LXD) calls bind() with AF_UNSPEC on an IPv4 socket. Co-discovered independently by Trevor Lawrence. Affects Ubuntu 24.04 (6.8), 24.10 (6.17), 25.04 (7.0). Fixed in USN-8370-1 / USN-8373-1.
References
CVSS 5.3
[Network] xrdp: Multiple Out-of-Bounds Reads in Capability Set Processors
TLSA-2026-0197
CVE-2026-55238
neutrinoLabs
xrdp <= 0.10.6
Network
Summary
Multiple capability set processing functions in xrdp read from the network stream without validating that sufficient data remains. The S_CHECK_REM macro is a no-op in production builds (only active with --enable-devel-streamcheck). When a malicious RDP client sends capability sets with lengthCapability=4 (header only, zero data bytes), handlers read 2-8 bytes past the declared boundary. Pre-auth, within the 16KB MCS userData buffer. GHSA-mwrh-rwqc-xwhx accepted.
References
CVSS 7.2
[Network] coturn: SQL Injection in HTTPS Admin Panel Delete Operations
TLSA-2026-0150
CVE-2026-53448
coturn
coturn <= 4.11.0
Network
Summary
The coturn HTTPS admin panel passes HTTP query parameters directly into SQL queries via snprintf string interpolation without any sanitization. The is_secure_string() filter that protects the STUN protocol path is not applied to the admin panel's delete-user, delete-secret, and delete-IP operations. Three injection vectors exist in turn_admin_server.c, each flowing through dbd_pgsql.c snprintf patterns into PQexec() which supports stacked queries. An authenticated admin can inject arbitrary SQL, gaining full database control and potentially OS-level access via PostgreSQL's COPY TO PROGRAM. The --web-admin flag must be enabled (disabled by default).
References
- https://www.cve.org/CVERecord?id=CVE-2026-53448
- https://nvd.nist.gov/vuln/detail/CVE-2026-53448
- https://github.com/coturn/coturn/security/advisories/GHSA-v8hj-2xx7-xmp5
- https://github.com/coturn/coturn/commit/b84dbab1d1aa6e2bf0211a1cdbb250d6de2a0d09
- https://github.com/coturn/coturn/pull/1924
- https://github.com/coturn/coturn/releases/tag/4.12.0
CVSS 8.8
[Network] radvd: Stack Buffer Overflow in radvdump Route Information Option Parser
TLSA-2026-0151
CVE-2026-48715
radvd project
radvd <= 2.20
Network
Summary
The radvdump utility shipped with radvd contains a stack buffer overflow in the Route Information option parser. When processing a crafted ICMPv6 Router Advertisement, print_ff() copies up to 2032 bytes from attacker-controlled packet data into a 16-byte struct in6_addr on the stack via memcpy with rinfo->nd_opt_ri_len as the size control, overflowing by up to 2016 bytes. Pre-authentication, network-adjacent attack vector (Layer 2). The nd_opt_ri_len field is an 8-bit value from the wire packet, and when greater than 1, the copy size is (nd_opt_ri_len - 1) * 8 bytes with no upper bound check.
References
CVSS 7.5
[Application] Terrascan <= 1.18.3: Unauthenticated SSRF via Webhook URL
TLSA-2026-0135
CVE-2026-47356
Tenable
Terrascan <= 1.18.3
Apps
Summary
The Terrascan server mode scan endpoints accept a webhook_url parameter (form field on file/scan, JSON field on remote/dir/scan, query param on k8s webhook validate). The user-controlled URL flows to executor.go -> webhook.Webhook{URL} -> SendPOSTRequest() which makes an HTTP POST with scan results to the attacker-specified URL. The HTTP client retries 10 times and follows redirects. No URL validation is performed anywhere in the code path. Product archived August 2023.
References
CVSS 7.5
[Application] Terrascan <= 1.18.3: Unauthenticated SSRF via Remote Repository URL
TLSA-2026-0136
CVE-2026-47357
Tenable
Terrascan <= 1.18.3
Apps
Summary
The remote/dir/scan endpoint accepts a remote_url JSON field passed to hashicorp/go-getter v1.7.5 DownloadWithType() with http remote type. go-getter HttpGetter fetches the URL and supports X-Terraform-Get redirect headers that can chain to file:// URLs via the registered FileGetter. The Netrc option is enabled, which can leak credentials. No URL validation or scheme restrictions are applied. Product archived August 2023.
References
CVSS 7.5
[Application] Terrascan <= 1.18.3: Unauthenticated SSRF via IaC Template URL Resolution
TLSA-2026-0137
CVE-2026-47358
Tenable
Terrascan <= 1.18.3
Apps
Summary
ARM template templateLink.uri and parametersLink.uri fields, as well as CloudFormation AWS::CloudFormation::Stack TemplateURL fields, are fetched via go-getter with all detectors enabled including FileDetector, allowing direct file:// URL access. Both are triggered by uploading crafted IaC files to the unauthenticated file scan endpoint. Product archived August 2023.
References
CVSS 5.5
[Application] libheif <= 1.21.2: Infinite Loop DoS in stts Sample Duration Lookup
TLSA-2026-0130
CVE-2026-32739
struktur AG
libheif <= 1.21.2
Apps
Summary
Box_stts::get_sample_duration() and Box_ctts::get_sample_offset() in seq_boxes.cc contain while loops that never increment the index variable. A crafted HEIF/AVIF sequence file with a stts entry where sample_count is 0 triggers an infinite loop in init_sample_timing_table(), causing 100% CPU denial of service on any application using libheif for sequence decoding. The consistency check passes because 0 + N = N. Fixed on master (723b58d6) but not in v1.21.2 (latest release at time of discovery).
References
CVSS 8.8
[Application] THC-Hydra: Stack Buffer Overflow via Malicious Server NTLM Challenge (7 Modules)
TLSA-2026-0226
CVE-2026-56766
THC / Van Hauser
THC-Hydra ≤ 9.7
Apps
Summary
Seven Hydra protocol modules (SMTP, POP3, IMAP, NNTP, HTTP, HTTP-Proxy, HTTP-Proxy-Urlenum) build an NTLM Type-3 response from a server-supplied Type-2 challenge, base64-encode it into a 4096-byte intermediate buffer, then copy it into a 500-byte stack buffer via sprintf without a length check. A malicious server sending a crafted NTLM Type-2 challenge with a long domain string (up to 127 Unicode characters after truncation in ntlm.c) causes the base64-encoded response to exceed 500 bytes, overflowing the stack buffer by 18 to 330 bytes with partially attacker-controlled data. On default builds with FORTIFY_SOURCE, the process is terminated; on builds without stack protector, this enables code execution on the pentester's machine. Fix: commit 9cc84c20e7 (2026-05-19).
References
CVSS 8.8
[Browser] Apple WebKit/JSC: Use-After-Free in DFG JIT via Wasm Resizable Buffer Grow
TLSA-2026-0123
CVE-2026-28902
Apple
Safari, iOS, iPadOS, macOS, tvOS, watchOS, visionOS
Browsers
Summary
Use-after-free in JavaScriptCore's DFG/FTL JIT compiler. The GetIndexedPropertyStorage constant folding phase bakes a raw storage pointer (view->vector()) as a ConstantStoragePointer for TypedArray views on WebAssembly resizable buffers. The associated watchpoint only fires on buffer detach, not on resizable buffer grow. When memory.grow() reallocates the backing store in BoundsChecking mode, JIT-compiled code continues reading and writing through the stale pointer to freed memory. Exploitation yields a heap read/write primitive from web content without flags or user interaction beyond navigation. No cage in JSC means the primitive leads directly to renderer code execution. Patched in iOS 26.5, iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, watchOS 26.5, visionOS 26.5 (May 11, 2026). WebKit Bugzilla 310207.
References
CVSS 7.0
[Kernel] XNU: Non-atomic Task Token Mutation Race Condition (CVE-2025-24118 Variant)
TLSA-2026-0118
CVE-2026-28986
Apple
macOS Tahoe 26.5 (XNU xnu-12377.81.4)
Linux Kernel
Summary
task_set_tokens() writes 40-byte task_token_ro_data via non-atomic memcpy into a read-only zone. Concurrent lock-free readers (ipc_kmsg.c, task_is_privileged) observe torn/inconsistent identity data. CVE-2025-24118 fix addressed p_ucred but missed task_tokens. Affects all architectures (x86_64, ARM64 SPTM, ARM64 PPL). An app may be able to cause unexpected system termination. Co-discovered.
References
CVSS 6.5
[Network] lldpd: Heap OOB Read in VLAN Decapsulation
TLSA-2026-0121
CVE-2026-46433
lldpd
lldpd 1.0.21
Network
Summary
Heap out-of-bounds read (4 bytes) in VLAN decapsulation memmove in lldpd.c. When a received frame size equals the MTU allocation, the memmove length argument is 4 bytes too large, reading past the heap buffer. Pre-authentication, Layer 2 adjacent attack vector. Fix merged.
References
CVSS 7.1
[Network] Netatalk: Spotlight RPC Systemic Heap OOB Read (sl_unpack)
TLSA-2026-0100
CVE-2026-44066
Netatalk Project
Netatalk (through commit 433c9ec)
Network
Summary
sl_unpack() discards the buffer length parameter (ibuflen), leaving all sl_unpack_* functions to use attacker-controlled count and offset values without bounds checking. The toc_entries field is computed but never validated (dead code), and toc_index values are unbounded. An authenticated AFP user with Spotlight access can trigger reads up to 64KB past the server_quantum allocation. Co-discovered (our report selected as primary). GHSA-wq5m-vg8f-w65f.
References
CVSS 8.1
[Network] Netatalk: Arbitrary Symlink Creation via AFP SetFilParams FinderInfo
TLSA-2026-0103
CVE-2026-44051
Netatalk Project
Netatalk (through commit 433c9ec)
Network
Summary
afp_setfilparams reads file contents as a symlink target when FinderInfo matches the 'slnkrhap' magic without validating the target path. No absolute path check, no directory traversal check, and no volume boundary check are performed. An authenticated user can create symlinks pointing anywhere on the filesystem, enabling cross-protocol exploitation via Samba, NFS, or backup daemons that follow symlinks. Co-discovered (our report selected as primary). CVSS raised to 8.1 by maintainer. GHSA-fxgp-28q4-5cwx.
References
CVSS 6.3
[Web CMS] Concrete CMS: Unauthenticated Express Entry Detail IDOR
TLSA-2026-0104
CVE-2026-7881
Portland Labs
Concrete CMS <=9.5.0
Web
Summary
The Express Entry Detail block's action_view_express_entity() method allows any unauthenticated visitor to access arbitrary Express entries by enumerating auto-increment integer IDs in the URL. The method fetches entries directly by ID without performing any permission check, bypassing the canViewExpressEntry() authorization enforced everywhere else. Express entries commonly contain form submissions (contact forms, support requests, surveys), making this a direct path to PII disclosure. Fixed in 9.5.1.
References
CVSS 6.3
[Web CMS] Concrete CMS: Unauthenticated Conversation message_detail IDOR
TLSA-2026-0105
CVE-2026-8237
Portland Labs
Concrete CMS <=9.5.0
Web
Summary
The message_detail conversation frontend endpoint allows unauthenticated users to read any conversation message by providing sequential integer message IDs. The endpoint does not verify that the requesting user has permission to view the conversation or its messages. Fixed in 9.5.1. Independent co-discovery.
References
CVSS 6.3
[Web CMS] Concrete CMS: Unauthenticated Conversation message_page IDOR
TLSA-2026-0106
CVE-2026-8238
Portland Labs
Concrete CMS <=9.5.0
Web
Summary
The message_page conversation frontend endpoint allows unauthenticated users to enumerate conversation messages by providing sequential integer conversation IDs. The endpoint does not verify that the requesting user has permission to view the conversation or its messages. Fixed in 9.5.1.
References
CVSS 6.3
[Web CMS] Concrete CMS: Unauthenticated Conversation get_rating IDOR
TLSA-2026-0107
CVE-2026-8239
Portland Labs
Concrete CMS <=9.5.0
Web
Summary
The get_rating conversation frontend endpoint allows unauthenticated users to retrieve conversation message ratings by providing sequential integer message IDs. The endpoint does not verify that the requesting user has permission to view the conversation or its messages. Fixed in 9.5.1.
References
CVSS 2.3
[Web CMS] Concrete CMS: Conversation File Attachment IDOR
TLSA-2026-0108
CVE-2026-7886
Portland Labs
Concrete CMS <=9.5.0
Web
Summary
The AddMessage and UpdateMessage conversation controllers accept user-supplied file attachment IDs and load files directly via EntityManager::find() without checking per-file permissions (canViewFile). A user who can post in any conversation can reference any file in the CMS file manager by its sequential ID, bypassing the file permission system. Fixed in 9.5.1.
References
CVSS 2.3
[Web CMS] Concrete CMS: Conversation DeleteFile Inverted CSRF Token Check
TLSA-2026-0109
CVE-2026-7882
Portland Labs
Concrete CMS <=9.5.0
Web
Summary
The conversation DeleteFile controller has an inverted CSRF token validation condition. The code throws an error when the token IS valid and proceeds with file deletion when the token is invalid or missing, effectively disabling CSRF protection for the file deletion endpoint. Fixed in 9.5.1.
References
CVSS 5.3
[Web Framework] GoFiber: Username Enumeration via Timing Oracle in BasicAuth
TLSA-2026-0091
CVE-2026-44332
GoFiber
GoFiber ≤3.2.0
Web
Summary
The default Authorizer function in GoFiber's BasicAuth middleware uses short-circuit evaluation that skips password hash comparison for non-existent usernames. With bcrypt-hashed passwords, the timing difference between a valid and invalid username is approximately 1,000,000:1 (~100ms vs ~100ns), enabling reliable remote username enumeration. GHSA-g5vh-55hw-rxm8.
References
- https://www.cve.org/CVERecord?id=CVE-2026-44332
- https://nvd.nist.gov/vuln/detail/CVE-2026-44332
- https://github.com/gofiber/fiber/commit/c7ac00edd19f9669b1aebbec6e229658baaa059e
- https://github.com/gofiber/fiber/pull/4245
- https://github.com/gofiber/fiber/releases/tag/v3.3.0
- https://github.com/gofiber/fiber/security/advisories/GHSA-g5vh-55hw-rxm8
CVSS 5.3
[Web Framework] GoFiber: X-Real-IP Spoofing via Header.Add() in BalancerForward
TLSA-2026-0093
CVE-2026-45045
GoFiber
GoFiber ≤3.2.0
Web
Summary
The BalancerForward proxy helper in GoFiber uses Header.Add() instead of Header.Set() when injecting the X-Real-IP header. This appends the real client IP as a second header value rather than replacing any attacker-supplied value. Upstream servers that read the first X-Real-IP header use the attacker's spoofed IP for logging, rate limiting, and access control. GHSA-gcfq-8gqf-4876.
References
- https://www.cve.org/CVERecord?id=CVE-2026-45045
- https://nvd.nist.gov/vuln/detail/CVE-2026-45045
- https://github.com/gofiber/fiber/commit/1403cc8292da3220e9316960b4030cc722a0f396
- https://github.com/gofiber/fiber/commit/33c9501288ab47a429c8b5e701493f0c3c0af37d
- https://github.com/gofiber/fiber/pull/4260
- https://github.com/gofiber/fiber/pull/4495
- https://github.com/gofiber/fiber/releases/tag/v2.52.14
- https://github.com/gofiber/fiber/releases/tag/v3.3.0
- https://github.com/gofiber/fiber/security/advisories/GHSA-gcfq-8gqf-4876
CVSS 8.8
[Network] Netatalk: SQL Injection in MySQL CNID Backend via AFP Filenames
TLSA-2026-0097
CVE-2026-44047
Netatalk Project
Netatalk (through commit 433c9ec)
Network
Summary
The MySQL CNID backend constructs SQL queries via asprintf() string interpolation of AFP filenames without escaping. Three functions (cnid_mysql_add, cnid_mysql_get, cnid_mysql_find) pass user-controlled filenames directly into SQL strings, enabling full SQL injection for any authenticated AFP user. The entire module contains only one mysql_real_escape_string() call, and it is for a binary stamp blob, not for filenames. Co-discovered. GHSA-627q-6pww-j6x4.
References
CVSS 7.5
[Network] Netatalk: Integer Underflow in dsi_writeinit Datasize Calculation
TLSA-2026-0099
CVE-2026-44060
Netatalk Project
Netatalk (through commit 433c9ec)
Network
Summary
dsi_writeinit() computes the data payload size as ntohl(dsi_len) - dsi_doff using unsigned 32-bit arithmetic with no validation that dsi_len >= dsi_doff. When dsi_doff exceeds dsi_len, the subtraction wraps to near UINT32_MAX (~4GB), causing dsi_writeflush() to enter an infinite socket read loop (pre-auth DoS via desync chain) or ad_recvfile to splice ~4GB to disk (post-auth disk fill). Co-discovered (our report selected as primary). GHSA-p8cw-m237-6w2c.
References
CVSS 9.1
[Proxy] Tinyproxy: HTTP Request Smuggling via CL/TE Desynchronization
TLSA-2026-0221
CVE-2026-54387
Tinyproxy project
Tinyproxy <= 1.11.3
Network
Summary
Tinyproxy through 1.11.2 is vulnerable to HTTP request smuggling via Content-Length / Transfer-Encoding desynchronization. When both headers are present in a request, Tinyproxy processes one while forwarding both to the backend, allowing an attacker to smuggle requests. Fix: PR #610 (commit ff45d3b).
References
- https://www.cve.org/CVERecord?id=CVE-2026-54387
- https://nvd.nist.gov/vuln/detail/CVE-2026-54387
- https://github.com/tinyproxy/tinyproxy/pull/610
- https://github.com/tinyproxy/tinyproxy/commit/ff45d3bf0e61d0f8ed97ab379d3047f04eb67521
- https://github.com/tinyproxy/tinyproxy/issues/609
- https://www.vulncheck.com/advisories/tinyproxy-http-request-smuggling-via-cl-te-desynchronization
CVSS 9.1
[Proxy] Tinyproxy: HTTP Request Smuggling via Duplicate Content-Length Headers
TLSA-2026-0222
CVE-2026-54388
Tinyproxy project
Tinyproxy <= 1.11.3
Network
Summary
Tinyproxy through 1.11.2 accepts HTTP requests with duplicate Content-Length headers containing different values. It uses one value for its own processing while forwarding both to the backend server, enabling HTTP request smuggling. Fix: PR #610 (commit 6ed6fc9).
References
- https://www.cve.org/CVERecord?id=CVE-2026-54388
- https://nvd.nist.gov/vuln/detail/CVE-2026-54388
- https://github.com/tinyproxy/tinyproxy/pull/610
- https://github.com/tinyproxy/tinyproxy/commit/364cdb67e0ea00a8e4a7037e2693e0711e816adb
- https://github.com/tinyproxy/tinyproxy/issues/609
- https://www.vulncheck.com/advisories/tinyproxy-http-request-smuggling-via-duplicate-content-length-headers
CVSS 7.2
MantisBT 2.29.0: Private Bugnote Attachment Content Leak via REST API
TLSA-2026-0084
CVE-2026-42071
MantisBT
MantisBT ≤ 2.28.1
Web
Summary
A missing authorization check in MantisBT's file visibility function allows any authenticated user (REPORTER+) to view attachments on private bugnotes they should not be able to access, via the REST API endpoint GET /api/rest/issues/{id}/files. The function file_can_view_bugnote_attachments() does not pass the bugnote ID to file_can_view_or_download(), skipping the private bugnote visibility check entirely. The download path is correctly protected, but the view/content path is not.
References
CVSS 5.3
MantisBT 2.29.0: Bugnote Edit Authorization Bypass via Issue Update API
TLSA-2026-0085
CVE-2026-42070
MantisBT
MantisBT ≤ 2.28.1
Web
Summary
The mc_issue_update() function in MantisBT allows users with UPDATER (level 40) access to edit, change view state, and modify time tracking on bugnotes belonging to other users, bypassing the DEVELOPER (level 55) threshold required by the dedicated mc_issue_note_update() function. The issue update endpoint checks only update_bug_threshold before processing note modifications, with no per-note authorization check. This affects both the SOAP and REST API endpoints.
References
CVSS 5.4
MantisBT 2.29.0: Stored XSS via Textarea Custom Field (CSP-Mitigated)
TLSA-2026-0086
CVE-2026-39960
MantisBT
MantisBT ≤ 2.28.1
Web
Summary
MantisBT's textarea custom field input function echoes user-supplied values without HTML encoding, allowing a textarea breakout and arbitrary HTML injection. The function cfdef_input_textarea() outputs the raw custom field value into a textarea element without htmlspecialchars(). Every other textarea in MantisBT uses string_textarea() for encoding, making this the sole omission. Default CSP blocks JavaScript execution, but CSS injection and HTML phishing remain exploitable.
References
CVSS 8.1
[Web Server] Apache httpd: AJP Response Heap Buffer Overflow (4-byte write)
TLSA-2026-0074
CVE-2026-28780
Apache Software Foundation
Apache httpd <= 2.4.66
Apps
Summary
The AJP message header validation in ajp_msg_check_header() uses an incorrect boundary check (> instead of >=), allowing a malicious or compromised AJP backend to send a response whose body length equals max_size. Since the 4-byte AJP header is already stored at the start of the buffer, the body write overflows the heap-allocated buffer by exactly 4 bytes with attacker-controlled content. The AJP secret directive does not protect against this because it only authenticates requests from Apache to the backend, not responses. Co-discovered independently, CVE-2026-28780 assigned by Apache Security Team.
References
CVSS 5.9
[VPN] OpenVPN: NTLM Proxy Authentication Stack Buffer Overflow (1-byte OOB write)
TLSA-2026-0075
CVE-2026-11771
OpenVPN
OpenVPN <= 2.7.1
Network
Summary
The NTLM proxy authentication handler contains a stack-based off-by-one buffer overflow when processing proxy challenge responses. A malicious proxy server can trigger a 1-byte out-of-bounds write on the stack. NTLM authentication has been removed from the post-2.7 codebase. Fix confirmed by vendor, credit as Reported-by: Tristan Madani (@TristanInSec).
References
- https://www.cve.org/CVERecord?id=CVE-2026-11771
- https://nvd.nist.gov/vuln/detail/CVE-2026-11771
- https://community.openvpn.net/ReleaseHistory#openvpn-2621-released-1-july-2026
- https://community.openvpn.net/ReleaseHistory#openvpn-275-released-1-july-2026
- https://community.openvpn.net/Security%20Announcements/CVE-2026-11771
CVSS 8.1
[Library] Ruby ERB: Deserialization Guard Bypass via def_module/def_method/def_class
TLSA-2026-0011
CVE-2026-41316
Ruby
Ruby ERB <= 6.0.3
Apps
Summary
ERB's deserialization guard (@_init check) only protects ERB#result and ERB#run, but three other methods (def_method, def_module, def_class) evaluate @src via module_eval without the guard. An attacker crafts a malicious ERB object with @src beginning with 'end' to break out of the wrapping method definition, then calls def_module() (zero-argument, ideal gadget) to achieve immediate code execution during module evaluation. Combined with ActiveSupport::Deprecation::DeprecatedInstanceVariableProxy, this creates a complete RCE chain triggered by Marshal.load on untrusted data, affecting Rails applications and any Ruby tool deserializing untrusted objects.
References
- https://www.cve.org/CVERecord?id=CVE-2026-41316
- https://nvd.nist.gov/vuln/detail/CVE-2026-41316
- https://github.com/ruby/erb/security/advisories/GHSA-q339-8rmv-2mhv
- https://access.redhat.com/errata/RHSA-2026:18030
- https://access.redhat.com/errata/RHSA-2026:18039
- https://access.redhat.com/errata/RHSA-2026:18065
- https://access.redhat.com/errata/RHSA-2026:20596
- https://access.redhat.com/errata/RHSA-2026:20606
- https://access.redhat.com/errata/RHSA-2026:20614
- https://access.redhat.com/errata/RHSA-2026:20670
- https://access.redhat.com/errata/RHSA-2026:26312
- https://access.redhat.com/errata/RHSA-2026:26655
- https://access.redhat.com/errata/RHSA-2026:33462
- https://access.redhat.com/errata/RHSA-2026:33478
- https://access.redhat.com/errata/RHSA-2026:35834
- https://access.redhat.com/errata/RHSA-2026:37238
- https://access.redhat.com/security/cve/CVE-2026-41316
- https://bugzilla.redhat.com/show_bug.cgi?id=2461369
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41316.json
CVSS 9.8
[Application] xrdp: Heap Out-of-Bounds Write via SetColourMapEntries in VNC Backend
TLSA-2026-0012
CVE-2026-41252
neutrinolabs
xrdp ≤ 0.10.6
Apps
Summary
The lib_palette_update() function in xrdp's VNC backend processes RFB SetColourMapEntries messages without validating the first_color field against the palette[256] array bounds. A malicious VNC server can send first_color values up to 65535, causing attacker-controlled 24-bit values to be written at offsets up to 262,140 bytes past the palette array in the heap-allocated vnc struct. This overwrites adjacent struct fields including the trans pointer (which contains function pointers), providing a direct path to remote code execution. Co-discovered with Tencent Xuanwu Lab.
References
CVSS 9.1
[Application] xrdp: Integer Overflow in Framebuffer Update Leads to Heap OOB Read
TLSA-2026-0013
CVE-2026-41521
neutrinolabs
xrdp ≤ 0.10.6
Apps
Summary
The lib_framebuffer_update() function computes pixel buffer size as cx * cy * bytes_per_pixel using signed 32-bit integer arithmetic. Since cx and cy are 16-bit values from the VNC server, the multiplication can overflow, producing a small positive value that causes an undersized heap allocation. The buffer is then passed to server_paint_rect with the original dimensions, causing xrdp_painter_copy to read up to 786 KB of heap memory past the allocated buffer. The leaked data is encoded and sent back to the attacker's RDP client, enabling ASLR bypass and credential theft. Co-discovered with Tencent Xuanwu Lab.
References
CVSS 5.3
[Browser] Mozilla Firefox: Use-After-Free via Missing MozPromise Request Tracking in WebCodecs ImageDecoder
TLSA-2026-0052
CVE-2026-8968
Mozilla
Mozilla Firefox
Browsers
Summary
The WebCodecs ImageDecoder implementation creates MozPromise callback chains for metadata decode, frame count, and frame decode operations without calling Track() to store request handles. Unlike the sibling DecoderTemplate used by VideoDecoder, AudioDecoder, VideoEncoder, and AudioEncoder, ImageDecoder lacks request tracking entirely. After the Cycle Collector UNLINKs the decoder, mCompletePromise is set to nullptr, but Destroy() does not set mClosed or mComplete to true. The orphaned callback fires, enters OnMetadataFailed which sees mClosed == false, calls Close() which sees mComplete == false, and dereferences the null mCompletePromise pointer. The developer confirmed additional lifetime problems in Reset() and ProcessControlMessageQueue(). Affects Firefox 149 and 150. Fixed in Firefox 151, with uplift tracking for Firefox 150 and ESR 140.
References
- https://www.cve.org/CVERecord?id=CVE-2026-8968
- https://nvd.nist.gov/vuln/detail/CVE-2026-8968
- https://www.mozilla.org/en-US/security/advisories/mfsa2026-46/
- https://bugzilla.mozilla.org/show_bug.cgi?id=2030467
- https://github.com/mozilla-firefox/firefox/commit/ae1b6eb6cfbc
- https://hg.mozilla.org/integration/autoland/rev/56c8a61dcbb1
CVSS 8.2
[Web Application] OPNsense: LDAP Injection in Authentication
TLSA-2026-0008
CVE-2026-34578
OPNsense
OPNsense < 26.1.6
Web
Summary
The OPNsense authentication system passes login usernames directly into LDAP search filters via string interpolation without calling ldap_escape(). An unauthenticated attacker can inject LDAP filter metacharacters through the login form, Captive Portal (CORS: *), or OpenVPN authentication to enumerate directory users and probe attributes. Additionally, the LDAP authenticator overrides Base::authenticate() to bypass the 2-second constant-time timing normalization, creating a reliable timing side-channel for user enumeration. Independently discovered; CVE-2026-34578 was assigned to Matt Andreko who reported the same vulnerability a few days earlier.
References
CVSS 6.5
[Library] libssh2: Pre-Authentication Denial of Service via SSH_MSG_EXT_INFO Handler
TLSA-2026-0218
CVE-2026-55199
libssh2 project
libssh2 <= 1.11.1
Library
Summary
The SSH_MSG_EXT_INFO handler in libssh2 through 1.11.1 does not validate return values from _libssh2_get_string() when parsing extension info messages. A malicious SSH server can send a crafted EXT_INFO message that causes CPU exhaustion or denial of service during the pre-authentication phase. Fix: PR #1864.
References
- https://www.cve.org/CVERecord?id=CVE-2026-55199
- https://nvd.nist.gov/vuln/detail/CVE-2026-55199
- https://github.com/libssh2/libssh2/pull/1864
- https://github.com/libssh2/libssh2/commit/17626857d20b3c9a1addfa45979dadcee1cd84a4
- https://www.vulncheck.com/advisories/libssh2-pre-authentication-dos-via-ssh-msg-ext-info-handler
CVSS 8.1
[Library] libssh2: Integer Overflow in chacha20-poly1305 Leads to Heap Buffer Overflow
TLSA-2026-0219
CVE-2026-55200
libssh2 project
libssh2 <= 1.11.1
Library
Summary
libssh2 through 1.11.1 has an integer overflow in the chacha20-poly1305 transport handler (transport.c) when processing packet_length on 32-bit platforms. An unchecked packet_length value leads to a heap buffer overflow during decryption. A malicious SSH server or MITM attacker can trigger this to achieve remote code execution.
References
- https://www.cve.org/CVERecord?id=CVE-2026-55200
- https://nvd.nist.gov/vuln/detail/CVE-2026-55200
- https://github.com/advisories/GHSA-r8mh-x5qv-7gg2
- https://github.com/libssh2/libssh2/commit/97acf3dfda80c91c3a8c9f2372546301d4a1a7a8
- https://github.com/libssh2/libssh2/pull/2052
- https://www.vulncheck.com/advisories/libssh2-out-of-bounds-write-via-unchecked-packet-length-in-transport-c
- https://web.archive.org/web/20260623211210/https://github.com/bikini/exploitarium/tree/main/libssh2-cve-2026-55200-poc
CVSS 6.2
[Library] Go x/image/webp: 32-bit Canvas Overflow Yields Corrupt Image That Panics on Access
TLSA-2026-0006
CVE-2026-33813
Go (golang.org/x/image)
Go x/image/webp
Apps
Summary
On 32-bit platforms, decoding a WebP image whose VP8X header declares a canvas size (width × height) that overflows int32 returns a corrupt Image whose subsequent access panics the program. RFC 9649 §2.7 caps canvas size at 2^32 − 1 pixels, but the decoder neither rejects oversized canvases nor avoids constructing a malformed image, exposing any 32-bit Go service that decodes untrusted WebP input to a remote denial of service. Designated PUBLIC track by the Go security team.
References
CVSS 7.8
[Linux Kernel Driver] b43: Out-of-Bounds Read (1B, DECRYPTED bypass)
TLSA-2026-0029
CVE-2026-46122
Broadcom
Linux Kernel b43 WiFi Driver
Drivers
Summary
The b43 RX handler uses a hardware-reported key index (up to 67) to look up entries in a 58-element array. B43_WARN_ON triggers but does not return, causing a 1-byte out-of-bounds read. The read value can set RX_FLAG_DECRYPTED, bypassing WPA decryption validation for received frames.
References
- https://www.cve.org/CVERecord?id=CVE-2026-46122
- https://nvd.nist.gov/vuln/detail/CVE-2026-46122
- https://lore.kernel.org/all/?q=CVE-2026-46122
- https://git.kernel.org/stable/c/135cb49c9a42a02cceeac7b49ec03e267f7ed6d6
- https://git.kernel.org/stable/c/1e9e55cf66f0fa4799f4d86ef3aaba8e606b5c14
- https://git.kernel.org/stable/c/1f4f78bf8549e6ac4f04fba4176854f3a6e0c332
- https://git.kernel.org/stable/c/219ba67e69e49681e48c822d6eaafb5def032f34
- https://git.kernel.org/stable/c/3157ad40b084a8f3932da2641749ab45e99b933e
- https://git.kernel.org/stable/c/765709720e6af9a178abc40244a8d1aa39ac4e71
- https://git.kernel.org/stable/c/c3d7b90dc95020cd9282c4630e402fe224f7644e
- https://git.kernel.org/stable/c/d7029879bafdac2006c67553807d122283dc6cbf
CVSS 7.1
[Linux Kernel Driver] btmtk: Out-of-Bounds Read (WMT struct cast, init-time)
TLSA-2026-0031
CVE-2026-46140
MediaTek
Linux Kernel btmtk Bluetooth Driver
Drivers
Summary
The btmtk WMT event handler casts the event SKB data to progressively larger structs (7, 9, and 18 bytes) without checking that the SKB contains enough data for each cast. Short firmware responses during initialization cause reads from SKB tailroom past the actual data.
References
- https://www.cve.org/CVERecord?id=CVE-2026-46140
- https://nvd.nist.gov/vuln/detail/CVE-2026-46140
- https://lore.kernel.org/all/?q=CVE-2026-46140
- https://git.kernel.org/stable/c/36c85f7029484d5ede769f8873d16e9c8e35533c
- https://git.kernel.org/stable/c/624fb79dadc1b65757986a9d0fdde5c0cf3fe179
- https://git.kernel.org/stable/c/634a4408c0615c523cf7531790f4f14a422b9206
- https://git.kernel.org/stable/c/70d37a8b9229e394cc17ddad47e90b81d80fcd09
- https://git.kernel.org/stable/c/c411cf1bfde951cfa821809cf4020ba177f76e0c
CVSS 9.3
[Web Application] Hoppscotch: Stored XSS via Mock Server on Backend Origin
TLSA-2026-0007
CVE-2026-34932
Hoppscotch
Hoppscotch Backend ≤2026.2.1
Web
Summary
An authenticated user can create a public mock server whose response headers and body are fully user-controlled. By setting Content-Type: text/html and a JavaScript payload in the response body, the attacker achieves stored XSS on the backend origin. Since mock URLs share the same origin as the API and authentication cookies are httpOnly/sameSite:lax, the XSS executes with the victim's session context — enabling account takeover, admin escalation, and full data exfiltration via authenticated GraphQL calls. Co-discovered.
References
CVSS 6.5
[Web Application] Cacti: Arbitrary File Read via Path Traversal in Report format_file
TLSA-2026-0001
CVE-2026-40084
The Cacti Group
Cacti ≤1.2.30
Web
Summary
The reports_form_save() function accepts the format_file parameter via get_nfilter_request_var() (zero filtering) and stores it directly in the database. When the report is generated, reports_load_format_file() concatenates this value into a file path without path traversal validation. An authenticated user with Reports permission (realm 21) can read arbitrary server files including include/config.php (database credentials) by supplying a traversal payload such as ../include/config.php.
References
CVSS 6.5
[Web Application] Plane: IDOR in Cross-Project Issue Date Modification via Bulk Update
TLSA-2026-0009
CVE-2026-39374
Plane / makeplane.com
Plane ≤0.24.0
Web
Summary
The IssueBulkUpdateDateEndpoint allows a project member (ADMIN or MEMBER) to modify the start_date and target_date of any issue across the entire Plane instance, regardless of workspace or project membership. The endpoint fetches issues by ID with Issue.objects.filter(id__in=issue_ids) without filtering by workspace or project, breaking tenant isolation in multi-workspace deployments.
References
CVSS 6.5
[Web Application] Plane: ORM Field Reference Injection via Saved Analytics segment Parameter
TLSA-2026-0010
CVE-2026-40102
Plane / makeplane.com
Plane ≤0.24.0
Web
Summary
The SavedAnalyticEndpoint passes the user-controlled segment query parameter directly to Django's F() expression without validation, unlike the regular AnalyticsEndpoint which validates against an allowlist. An authenticated workspace member can extract values from any related database field — including workspace__owner__password (bcrypt hashes), API tokens, and email addresses — by abusing Django's field reference resolution in annotated queries.
References
CVSS 5.5
[Linux Kernel] xattr: File Reference Leak in fremovexattr()
TLSA-2024-0001
CVE-2024-14027
Linux
Linux Kernel (fs/xattr.c)
Linux Kernel
Summary
The fremovexattr() syscall calls fdget() to acquire a file reference but returns early without calling fdput() when strncpy_from_user() fails on the name argument. In multi-threaded processes where fdget() takes the slow path, this permanently leaks one file reference per call, pinning the struct file and associated kernel objects in memory. An unprivileged local user can exploit this to cause kernel memory exhaustion. The issue was inadvertently fixed by commit a71874379ec8 (xattr: switch to CLASS(fd)).
References
- https://www.cve.org/CVERecord?id=CVE-2024-14027
- https://nvd.nist.gov/vuln/detail/CVE-2024-14027
- https://lore.kernel.org/all/?q=CVE-2024-14027
- https://git.kernel.org/stable/c/9a3a2ae5efbbcaed37551218abed94e23c537157
- https://git.kernel.org/stable/c/a71874379ec8c6e788a61d71b3ad014a8d9a5c08
- https://git.kernel.org/stable/c/d151b94967c8247005435b63fc60f8f4baa320da
CVSS 7.1
[Linux Kernel] n_tty: Use-After-Free in n_tty_receive_buf_common
TLSA-2020-0001
CVE-2020-8648
Linux
Linux Kernel through 5.5.2 (drivers/tty/n_tty.c)
Linux Kernel
Summary
A use-after-free vulnerability in the n_tty_receive_buf_common function in drivers/tty/n_tty.c in the Linux kernel through 5.5.2.
References
- https://www.cve.org/CVERecord?id=CVE-2020-8648
- https://nvd.nist.gov/vuln/detail/CVE-2020-8648
- https://lore.kernel.org/all/?q=CVE-2020-8648
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00021.html
- https://bugzilla.kernel.org/show_bug.cgi?id=206361
- https://lists.debian.org/debian-lts-announce/2020/06/msg00011.html
- https://lists.debian.org/debian-lts-announce/2020/06/msg00012.html
- https://lists.debian.org/debian-lts-announce/2020/06/msg00013.html
- https://security.netapp.com/advisory/ntap-20200924-0004/
- https://usn.ubuntu.com/4342-1/
- https://usn.ubuntu.com/4344-1/
- https://usn.ubuntu.com/4345-1/
- https://usn.ubuntu.com/4346-1/
- https://www.debian.org/security/2020/dsa-4698
CVSS 6.1
[Linux Kernel] vt: Use-After-Free in vc_do_resize
TLSA-2020-0002
CVE-2020-8647
Linux
Linux Kernel through 5.5.2 (drivers/tty/vt/vt.c)
Linux Kernel
Summary
A use-after-free vulnerability in the vc_do_resize function in drivers/tty/vt/vt.c in the Linux kernel through 5.5.2.
References
- https://www.cve.org/CVERecord?id=CVE-2020-8647
- https://nvd.nist.gov/vuln/detail/CVE-2020-8647
- https://lore.kernel.org/all/?q=CVE-2020-8647
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00039.html
- https://bugzilla.kernel.org/show_bug.cgi?id=206359
- https://lists.debian.org/debian-lts-announce/2020/06/msg00011.html
- https://lists.debian.org/debian-lts-announce/2020/06/msg00012.html
- https://lists.debian.org/debian-lts-announce/2020/06/msg00013.html
- https://www.debian.org/security/2020/dsa-4698
CVSS 5.9
[Linux Kernel] vgacon: Use-After-Free in vgacon_invert_region
TLSA-2020-0003
CVE-2020-8649
Linux
Linux Kernel through 5.5.2 (drivers/video/console/vgacon.c)
Linux Kernel
Summary
A use-after-free vulnerability in the vgacon_invert_region function in drivers/video/console/vgacon.c in the Linux kernel through 5.5.2.
References
- https://www.cve.org/CVERecord?id=CVE-2020-8649
- https://nvd.nist.gov/vuln/detail/CVE-2020-8649
- https://lore.kernel.org/all/?q=CVE-2020-8649
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00039.html
- https://bugzilla.kernel.org/show_bug.cgi?id=206357
- https://lists.debian.org/debian-lts-announce/2020/06/msg00011.html
- https://lists.debian.org/debian-lts-announce/2020/06/msg00012.html
- https://lists.debian.org/debian-lts-announce/2020/06/msg00013.html
- https://www.debian.org/security/2020/dsa-4698
CVSS 7.8
[Linux Kernel] ALSA timer: Use-After-Free in snd_timer_open
TLSA-2019-0002
CVE-2019-19807
Linux
Linux Kernel before 5.3.11 (sound/core/timer.c)
Linux Kernel
Summary
In the Linux kernel before 5.3.11, sound/core/timer.c has a use-after-free caused by erroneous code refactoring, aka CID-e7af6307a8a5. This is related to snd_timer_open and snd_timer_close_locked. The timeri variable was originally intended to be for a newly created timer instance, but was used for a different purpose after refactoring.
References
CVSS 8.2
[Linux Kernel] debugfs: Use-After-Free in debugfs_remove
TLSA-2019-0001
CVE-2019-19770
Linux
Linux Kernel 4.19.83 (fs/debugfs/inode.c)
Linux Kernel
Summary
A use-after-free in the debugfs_remove function in fs/debugfs/inode.c in the Linux kernel 4.19.83, used to remove a file or directory in debugfs that was previously created with a call to another debugfs function such as debugfs_create_file.
References
- https://www.cve.org/CVERecord?id=CVE-2019-19770
- https://nvd.nist.gov/vuln/detail/CVE-2019-19770
- https://lore.kernel.org/all/?q=CVE-2019-19770
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00035.html
- https://bugzilla.kernel.org/show_bug.cgi?id=205713
- https://lists.debian.org/debian-lts-announce/2020/12/msg00015.html
- https://lore.kernel.org/linux-block/20200402000002.7442-1-mcgrof%40kernel.org/
- https://security.netapp.com/advisory/ntap-20200103-0001/
CVSS 7.5
[Linux Kernel] blktrace: Use-After-Free in __blk_add_trace
TLSA-2019-0004
CVE-2019-19768
Linux
Linux Kernel 5.4.x (kernel/trace/blktrace.c)
Linux Kernel
Summary
In the Linux kernel 5.4.x, there is a use-after-free in the __blk_add_trace function in kernel/trace/blktrace.c, which is used to fill out a blk_io_trace structure and place it in a per-cpu sub-buffer.
References
- https://www.cve.org/CVERecord?id=CVE-2019-19768
- https://nvd.nist.gov/vuln/detail/CVE-2019-19768
- https://ubuntu.com/security/notices/USN-4344-1
- https://ubuntu.com/security/notices/USN-4345-1
- https://lists.debian.org/debian-security-announce/2020/msg00102.html
- https://lists.debian.org/debian-lts-announce/2020/06/msg00011.html
- https://lore.kernel.org/all/?q=CVE-2019-19768
CVSS 6.7
[Linux Kernel] perf: Use-After-Free in perf_trace_lock_acquire
TLSA-2019-0005
CVE-2019-19769
Linux
Linux Kernel 5.3.10 (include/trace/events/lock.h)
Linux Kernel
Summary
In the Linux kernel 5.3.10, there is a use-after-free in the perf_trace_lock_acquire function, related to include/trace/events/lock.h.
References
CVSS 5.5
[Linux Kernel] ext4: Use-After-Free in ext4_expand_extra_isize
TLSA-2019-0006
CVE-2019-19767
Linux
Linux Kernel before 5.4.2 (fs/ext4)
Linux Kernel
Summary
The Linux kernel before 5.4.2 mishandles ext4_expand_extra_isize, as demonstrated by use-after-free errors in ext4_expand_extra_isize and ext4_xattr_set_entry, related to fs/ext4/inode.c and fs/ext4/super.c, aka CID-4ea99936a163.
References
- https://www.cve.org/CVERecord?id=CVE-2019-19767
- https://nvd.nist.gov/vuln/detail/CVE-2019-19767
- https://lore.kernel.org/all/?q=CVE-2019-19767
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00021.html
- https://bugzilla.kernel.org/show_bug.cgi?id=205609
- https://bugzilla.kernel.org/show_bug.cgi?id=205707
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.2
- https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=4ea99936a1630f51fc3a2d61a58ec4a1c4b7d55a
- https://github.com/torvalds/linux/commit/4ea99936a1630f51fc3a2d61a58ec4a1c4b7d55a
- https://lists.debian.org/debian-lts-announce/2020/01/msg00013.html
- https://lists.debian.org/debian-lts-announce/2020/03/msg00001.html
- https://security.netapp.com/advisory/ntap-20200103-0001/
- https://usn.ubuntu.com/4258-1/
- https://usn.ubuntu.com/4284-1/
- https://usn.ubuntu.com/4287-1/
- https://usn.ubuntu.com/4287-2/
CVSS 7.5
[Network] tcpdump: Heap Buffer Over-Read in Rx Parser rx_cache_find / rx_cache_insert
TLSA-2018-0001
CVE-2018-14466
The Tcpdump Group
tcpdump < 4.9.3 (print-rx.c)
Network
Summary
The Rx parser in tcpdump before 4.9.3 has a buffer over-read in print-rx.c:rx_cache_find() and rx_cache_insert(). A crafted packet can trigger an out-of-bounds read, potentially leaking process memory or crashing the application. Independently co-discovered and reported before public disclosure.
References
- https://www.cve.org/CVERecord?id=CVE-2018-14466
- https://nvd.nist.gov/vuln/detail/CVE-2018-14466
- https://www.tcpdump.org/public-cve-list.txt
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00050.html
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00053.html
- http://seclists.org/fulldisclosure/2019/Dec/26
- https://github.com/the-tcpdump-group/tcpdump/blob/tcpdump-4.9/CHANGES
- https://github.com/the-tcpdump-group/tcpdump/commit/c24922e692a52121e853a84ead6b9337f4c08a94
- https://lists.debian.org/debian-lts-announce/2019/10/msg00015.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/62XY42U6HY3H2APR5EHNWCZ7SAQNMMJN/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FNYXF3IY2X65IOD422SA6EQUULSGW7FN/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R2UDPOSGVJQIYC33SQBXMDXHH4QDSDMU/
- https://seclists.org/bugtraq/2019/Dec/23
- https://seclists.org/bugtraq/2019/Oct/28
- https://security.netapp.com/advisory/ntap-20200120-0001/
- https://support.apple.com/kb/HT210788
- https://usn.ubuntu.com/4252-1/
- https://usn.ubuntu.com/4252-2/
- https://www.debian.org/security/2019/dsa-4547
CVSS 7.5
[Network] tcpdump: Heap Buffer Over-Read in Babel Parser babel_print_v2
TLSA-2018-0002
CVE-2018-14470
The Tcpdump Group
tcpdump < 4.9.3 (print-babel.c)
Network
Summary
The Babel parser in tcpdump before 4.9.3 has a buffer over-read in print-babel.c:babel_print_v2(). A crafted Babel routing protocol packet can trigger an out-of-bounds heap read, potentially leaking process memory or causing a denial of service. Independently co-discovered and reported before public disclosure.
References
- https://www.cve.org/CVERecord?id=CVE-2018-14470
- https://nvd.nist.gov/vuln/detail/CVE-2018-14470
- https://www.tcpdump.org/public-cve-list.txt
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00050.html
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00053.html
- http://seclists.org/fulldisclosure/2019/Dec/26
- https://github.com/the-tcpdump-group/tcpdump/blob/tcpdump-4.9/CHANGES
- https://github.com/the-tcpdump-group/tcpdump/commit/12f66f69f7bf1ec1266ddbee90a7616cbf33696b
- https://lists.debian.org/debian-lts-announce/2019/10/msg00015.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/62XY42U6HY3H2APR5EHNWCZ7SAQNMMJN/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FNYXF3IY2X65IOD422SA6EQUULSGW7FN/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R2UDPOSGVJQIYC33SQBXMDXHH4QDSDMU/
- https://seclists.org/bugtraq/2019/Dec/23
- https://seclists.org/bugtraq/2019/Oct/28
- https://security.netapp.com/advisory/ntap-20200120-0001/
- https://support.apple.com/kb/HT210788
- https://usn.ubuntu.com/4252-1/
- https://usn.ubuntu.com/4252-2/
- https://www.debian.org/security/2019/dsa-4547
CVSS 8.8
[WordPress] Google Doc Embedder: CSRF on Profile Settings
TLSA-2016-0001
CVE-2016-10882
Developer / WordPress.org
WordPress Google Doc Embedder ≤2.6.1
Web
Summary
The Google Doc Embedder plugin (90,000+ active installs) lacks CSRF protection on its profile settings forms (options-general.php?page=gde-settings). An attacker can forge requests that create, edit, or delete embed profiles — including changing the file base URL, viewer permissions, and profile metadata — when an authenticated admin visits a malicious page. The CSRF can be chained with the plugin's stored XSS in the description field to plant persistent payloads.
References
CVSS 6.1
[WordPress] Google Doc Embedder: Authenticated Stored XSS in Profile Description
TLSA-2016-0002
CVE-2016-10881
Developer / WordPress.org
WordPress Google Doc Embedder ≤2.6.1
Web
Summary
The Google Doc Embedder plugin (90,000+ active installs) renders the profile description field without sanitization in tab-profiles.php (the value is passed through _e() rather than esc_html()). An authenticated user with access to the plugin's settings can store a payload that executes whenever any admin views the embed profiles list.
References
108 Advisories Published