Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 98

Количество 98

fstec логотип

BDU:2026-07254

3 месяца назад

Уязвимость компонента crypto-x509 языка программирования Go, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20260507-73-0012

около 2 месяцев назад

Уязвимость golang

CVSS3: 7.5
EPSS: Низкий
rocky логотип

RLSA-2026:29702

2 дня назад

Important: runc security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-29702

4 дня назад

ELSA-2026-29702: runc security update (IMPORTANT)

EPSS: Низкий
ubuntu логотип

CVE-2026-32282

3 месяца назад

On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the symlink, even when the target lies outside the root. The Linux fchmodat syscall silently ignores the AT_SYMLINK_NOFOLLOW flag, which Root.Chmod uses to avoid symlink traversal. Root.Chmod checks its target before acting and returns an error if the target is a symlink lying outside the root, so the impact is limited to cases where the target is replaced with a symlink between the check and operation.

CVSS3: 6.4
EPSS: Низкий
redhat логотип

CVE-2026-32282

3 месяца назад

On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the symlink, even when the target lies outside the root. The Linux fchmodat syscall silently ignores the AT_SYMLINK_NOFOLLOW flag, which Root.Chmod uses to avoid symlink traversal. Root.Chmod checks its target before acting and returns an error if the target is a symlink lying outside the root, so the impact is limited to cases where the target is replaced with a symlink between the check and operation.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-32282

3 месяца назад

On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the symlink, even when the target lies outside the root. The Linux fchmodat syscall silently ignores the AT_SYMLINK_NOFOLLOW flag, which Root.Chmod uses to avoid symlink traversal. Root.Chmod checks its target before acting and returns an error if the target is a symlink lying outside the root, so the impact is limited to cases where the target is replaced with a symlink between the check and operation.

CVSS3: 6.4
EPSS: Низкий
msrc логотип

CVE-2026-32282

26 дней назад

TOCTOU permits root escape on Linux via Root.Chmod in os in internal/syscall/unix

EPSS: Низкий
debian логотип

CVE-2026-32282

3 месяца назад

On Linux, if the target of Root.Chmod is replaced with a symlink while ...

CVSS3: 6.4
EPSS: Низкий
rocky логотип

RLSA-2026:23228

23 дня назад

Important: image-builder security update

EPSS: Низкий
rocky логотип

RLSA-2026:22937

23 дня назад

Important: image-builder security update

EPSS: Низкий
rocky логотип

RLSA-2026:22714

17 дней назад

Important: osbuild-composer security update

EPSS: Низкий
rocky логотип

RLSA-2026:22450

23 дня назад

Important: osbuild-composer security update

EPSS: Низкий
rocky логотип

RLSA-2026:25999

10 дней назад

Moderate: yggdrasil-worker-package-manager security update

EPSS: Низкий
github логотип

GHSA-xj38-jxc5-rppx

3 месяца назад

On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the symlink, even when the target lies outside the root. The Linux fchmodat syscall silently ignores the AT_SYMLINK_NOFOLLOW flag, which Root.Chmod uses to avoid symlink traversal. Root.Chmod checks its target before acting and returns an error if the target is a symlink lying outside the root, so the impact is limited to cases where the target is replaced with a symlink between the check and operation.

CVSS3: 6.4
EPSS: Низкий
fstec логотип

BDU:2026-07252

3 месяца назад

Уязвимость языка программирования Go, связанная с неверным определением ссылки перед доступом к файлу, позволяющая нарушителю повысить свои привилегии

CVSS3: 6.4
EPSS: Низкий
ubuntu логотип

CVE-2026-33810

3 месяца назад

When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constraint. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.

CVSS3: 8.2
EPSS: Низкий
redhat логотип

CVE-2026-33810

3 месяца назад

When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constraint. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-33810

3 месяца назад

When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constraint. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.

CVSS3: 8.2
EPSS: Низкий
msrc логотип

CVE-2026-33810

3 месяца назад

Case-sensitive excludedSubtrees name constraints cause Auth Bypass in crypto/x509

CVSS3: 5.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2026-07254

Уязвимость компонента crypto-x509 языка программирования Go, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
0%
Низкий
3 месяца назад
redos логотип
ROS-20260507-73-0012

Уязвимость golang

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
rocky логотип
RLSA-2026:29702

Important: runc security update

2 дня назад
oracle-oval логотип
ELSA-2026-29702

ELSA-2026-29702: runc security update (IMPORTANT)

4 дня назад
ubuntu логотип
CVE-2026-32282

On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the symlink, even when the target lies outside the root. The Linux fchmodat syscall silently ignores the AT_SYMLINK_NOFOLLOW flag, which Root.Chmod uses to avoid symlink traversal. Root.Chmod checks its target before acting and returns an error if the target is a symlink lying outside the root, so the impact is limited to cases where the target is replaced with a symlink between the check and operation.

CVSS3: 6.4
0%
Низкий
3 месяца назад
redhat логотип
CVE-2026-32282

On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the symlink, even when the target lies outside the root. The Linux fchmodat syscall silently ignores the AT_SYMLINK_NOFOLLOW flag, which Root.Chmod uses to avoid symlink traversal. Root.Chmod checks its target before acting and returns an error if the target is a symlink lying outside the root, so the impact is limited to cases where the target is replaced with a symlink between the check and operation.

CVSS3: 7.8
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-32282

On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the symlink, even when the target lies outside the root. The Linux fchmodat syscall silently ignores the AT_SYMLINK_NOFOLLOW flag, which Root.Chmod uses to avoid symlink traversal. Root.Chmod checks its target before acting and returns an error if the target is a symlink lying outside the root, so the impact is limited to cases where the target is replaced with a symlink between the check and operation.

CVSS3: 6.4
0%
Низкий
3 месяца назад
msrc логотип
CVE-2026-32282

TOCTOU permits root escape on Linux via Root.Chmod in os in internal/syscall/unix

0%
Низкий
26 дней назад
debian логотип
CVE-2026-32282

On Linux, if the target of Root.Chmod is replaced with a symlink while ...

CVSS3: 6.4
0%
Низкий
3 месяца назад
rocky логотип
RLSA-2026:23228

Important: image-builder security update

23 дня назад
rocky логотип
RLSA-2026:22937

Important: image-builder security update

23 дня назад
rocky логотип
RLSA-2026:22714

Important: osbuild-composer security update

17 дней назад
rocky логотип
RLSA-2026:22450

Important: osbuild-composer security update

23 дня назад
rocky логотип
RLSA-2026:25999

Moderate: yggdrasil-worker-package-manager security update

0%
Низкий
10 дней назад
github логотип
GHSA-xj38-jxc5-rppx

On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the symlink, even when the target lies outside the root. The Linux fchmodat syscall silently ignores the AT_SYMLINK_NOFOLLOW flag, which Root.Chmod uses to avoid symlink traversal. Root.Chmod checks its target before acting and returns an error if the target is a symlink lying outside the root, so the impact is limited to cases where the target is replaced with a symlink between the check and operation.

CVSS3: 6.4
0%
Низкий
3 месяца назад
fstec логотип
BDU:2026-07252

Уязвимость языка программирования Go, связанная с неверным определением ссылки перед доступом к файлу, позволяющая нарушителю повысить свои привилегии

CVSS3: 6.4
0%
Низкий
3 месяца назад
ubuntu логотип
CVE-2026-33810

When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constraint. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.

CVSS3: 8.2
0%
Низкий
3 месяца назад
redhat логотип
CVE-2026-33810

When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constraint. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.

CVSS3: 8.8
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-33810

When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constraint. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.

CVSS3: 8.2
0%
Низкий
3 месяца назад
msrc логотип
CVE-2026-33810

Case-sensitive excludedSubtrees name constraints cause Auth Bypass in crypto/x509

CVSS3: 5.9
0%
Низкий
3 месяца назад

Уязвимостей на страницу