Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 52 848

Количество 52 848

redhat логотип

CVE-2026-64502

8 дней назад

A flaw was found in the Linux kernel's `ad_sigma_delta` driver. This vulnerability exists within the `clear_pending_event` function, affecting certain registerless devices or those with specific configurations. When specific conditions are met during device operation, an internal memory operation attempts to write beyond its intended buffer, leading to a heap overflow. This memory corruption could result in a system crash, causing a denial of service, or potentially lead to arbitrary code execution.

EPSS: Низкий
redhat логотип

CVE-2026-64501

8 дней назад

A flaw was found in the Linux kernel's `ad_sigma_delta` driver for analog-to-digital converters (ADCs). This vulnerability occurs when the Chip Select (CS) line, which controls communication with the ADC, remains asserted after a conversion or in an error state. This can prevent other devices on the Serial Peripheral Interface (SPI) bus from communicating, leading to a denial of service. Additionally, improper handling of the bus lock can allow concurrent access to the SPI bus, potentially causing system instability.

EPSS: Низкий
redhat логотип

CVE-2026-64499

8 дней назад

A flaw was found in the Linux kernel's `ti-ads1119` Analog-to-Digital Converter (ADC) driver. This vulnerability occurs during the buffer pre-enable process, where a Power Management (PM) reference is not properly released if an I2C communication error occurs. This oversight can lead to a resource leak, potentially causing the affected device to remain active indefinitely and consume system resources, which could result in a denial of service.

EPSS: Низкий
redhat логотип

CVE-2026-64498

8 дней назад

A flaw was found in the Linux kernel's Industrial I/O (IIO) subsystem, specifically within the hardware consumer buffer (hw-consumer). Due to an oversight in memory management, a dedicated memory region (scan_mask) was not properly released when its associated buffer was freed. A local attacker with low privileges could exploit this memory leak, potentially leading to system instability or a denial of service (DoS) by exhausting available memory resources.

EPSS: Низкий
redhat логотип

CVE-2026-64497

8 дней назад

A flaw was found in the Linux kernel's iio: chemical: scd30 driver, which manages a specific type of sensor. This vulnerability involves an error in how the driver processes numerical data, specifically a 'sign-extension bug' that can corrupt a part of a floating-point number called the exponent. This corruption could lead to the sensor providing inaccurate readings or cause the system to behave unexpectedly.

EPSS: Низкий
redhat логотип

CVE-2026-64496

8 дней назад

A flaw was found in the Linux kernel's Industrial I/O (IIO) event subsystem. A local user can exploit a race condition during the reset of the event FIFO (First-In, First-Out) buffer. This occurs when another thread accesses a newly allocated file descriptor before the FIFO reset is complete. This can lead to an out-of-bounds read, potentially disclosing sensitive kernel memory to the user.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2026-64495

8 дней назад

A flaw was found in the Linux kernel's `bmg160` gyroscope driver. An out-of-bounds read vulnerability exists when handling specific bandwidth or filter values provided by userspace through the `sysfs` interface. A local user can exploit this by supplying a malformed value, leading to a read past the end of an array. This can result in a denial of service.

EPSS: Низкий
redhat логотип

CVE-2026-64494

8 дней назад

A flaw was found in the Linux kernel's `gp2ap002` light sensor driver. When the driver attempts to read lux values and encounters an error, it fails to properly release a power management resource. This oversight leads to a permanent leak of the resource, which prevents the affected device from automatically entering a low-power state (autosuspending). The primary impact is increased power consumption for devices utilizing this driver.

EPSS: Низкий
redhat логотип

CVE-2026-64493

8 дней назад

A flaw was found in the Linux kernel's `mpl115` pressure sensor driver. When a read error occurs in the `mpl115_read_raw()` function, the driver fails to properly release a Power Management (PM) reference. This oversight leads to a continuous leak of PM references with each failed read. The accumulation of these unreleased references can prevent the affected device from entering an autosuspend state, potentially leading to increased power consumption or other resource management issues.

EPSS: Низкий
redhat логотип

CVE-2026-64492

8 дней назад

A flaw was found in the Linux kernel's `tmp006` temperature sensor driver. This vulnerability occurs because the driver incorrectly handles the registration and de-registration of a hardware trigger. When the module is unloaded, a pointer to freed memory remains active, creating a 'dangling pointer'. This can lead to system instability or potentially allow an attacker to cause a denial of service.

EPSS: Низкий
redhat логотип

CVE-2026-64491

8 дней назад

A flaw was found in the Linux kernel's ALSA (Advanced Linux Sound Architecture) usx2y us144mkii driver. This vulnerability, a Use-After-Free (UAF), occurs when a USB device is disconnected, leading to a race condition where the system attempts to access memory that has already been released. This could allow a local attacker to cause system instability, crash the system, or potentially execute malicious code.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2026-64490

8 дней назад

A flaw was found in the Linux kernel's ALSA virtio sound driver. A malicious or buggy virtio device can provide invalid control metadata, such as an unknown control type or an oversized value count. The driver's control handling trusts this unvalidated metadata, leading to out-of-bounds access when processing sound control information. This vulnerability could allow a malicious device to cause a denial of service or potentially other impacts on the system.

CVSS3: 7
EPSS: Низкий
redhat логотип

CVE-2026-64489

8 дней назад

A flaw was found in the ALSA (Advanced Linux Sound Architecture) ymfpci driver in the Linux kernel. This vulnerability occurs because the 'snd_ctl_new1()' function, which allocates memory, may return a null value if memory allocation fails. The driver then attempts to use this null value without proper checks, leading to a null pointer dereference. A local attacker could exploit this to cause a denial of service (DoS), resulting in a system crash.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2026-64488

8 дней назад

A flaw was found in the Linux kernel's Advanced Linux Sound Architecture (ALSA) 'aoa' component. This vulnerability arises when a specific function, `snd_ctl_new1()`, fails to allocate memory and returns an invalid pointer. The kernel then attempts to use this invalid pointer, which can cause the system to crash. This could allow a local attacker to trigger a Denial of Service (DoS) condition, making the system unavailable.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2026-64487

8 дней назад

A flaw was found in the Linux kernel's sound subsystem, specifically within the ALSA caiaq driver responsible for handling Traktor Kontrol S4 devices. A local attacker, by providing specially crafted input from a connected device, could exploit an out-of-bounds read vulnerability. This issue arises from incorrect handling of input stream lengths, leading to the system reading beyond its allocated memory buffer. Successful exploitation could result in the disclosure of sensitive information from kernel memory or cause a system crash, leading to a denial of service.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2026-64486

8 дней назад

A flaw was found in the Linux kernel's Advanced Linux Sound Architecture (ALSA) cmipci component. This vulnerability occurs because the `snd_cmipci_spdif_controls()` function fails to check the return value of `snd_ctl_new1()`, which can return a null pointer if memory allocation fails. A local attacker could exploit this to trigger a null pointer dereference, leading to a system crash and a denial of service (DoS).

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2026-64485

8 дней назад

A flaw was found in the Linux kernel's Advanced Linux Sound Architecture (ALSA) compress module. The `snd_compr_task_new()` function, responsible for creating driver tasks, does not properly handle errors during the validation of Direct Memory Access (DMA) buffers or file descriptor reservation. This oversight can lead to a resource leak, where driver resources allocated during task creation are not freed. Consequently, this could result in system instability or a Denial of Service (DoS) over time due to resource exhaustion.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2026-64484

8 дней назад

A flaw was found in the Linux kernel's ALSA (Advanced Linux Sound Architecture) es1938 sound driver. This vulnerability arises when a memory allocation failure causes the `snd_ctl_new1()` function to return a null value. The `snd_es1938_mixer()` function then attempts to use this null value without proper validation, leading to a null pointer dereference. This can result in a system crash, causing a Denial of Service (DoS) for affected systems.

EPSS: Низкий
redhat логотип

CVE-2026-64483

8 дней назад

A flaw was found in the Linux kernel's ALSA FireWire iSight driver. A malicious or faulty Apple iSight device connected via FireWire can send specially crafted audio packets. The driver incorrectly processes the sample count in these packets, leading to a buffer overflow where data can be written beyond the allocated memory region. This could result in memory corruption, potentially impacting system stability or leading to further exploitation.

CVSS3: 7
EPSS: Низкий
redhat логотип

CVE-2026-64482

8 дней назад

A flaw was found in the Linux kernel's Advanced Linux Sound Architecture (ALSA) Gravis Ultrasound (GUS) driver. When memory allocation fails, the `snd_ctl_new1()` function can return a null value. The `snd_gf1_pcm_volume_control()` function does not properly check for this null return, leading to a null pointer dereference. This vulnerability could allow a local attacker to cause a system crash, resulting in a denial of service.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2026-64502

A flaw was found in the Linux kernel's `ad_sigma_delta` driver. This vulnerability exists within the `clear_pending_event` function, affecting certain registerless devices or those with specific configurations. When specific conditions are met during device operation, an internal memory operation attempts to write beyond its intended buffer, leading to a heap overflow. This memory corruption could result in a system crash, causing a denial of service, or potentially lead to arbitrary code execution.

0%
Низкий
8 дней назад
redhat логотип
CVE-2026-64501

A flaw was found in the Linux kernel's `ad_sigma_delta` driver for analog-to-digital converters (ADCs). This vulnerability occurs when the Chip Select (CS) line, which controls communication with the ADC, remains asserted after a conversion or in an error state. This can prevent other devices on the Serial Peripheral Interface (SPI) bus from communicating, leading to a denial of service. Additionally, improper handling of the bus lock can allow concurrent access to the SPI bus, potentially causing system instability.

0%
Низкий
8 дней назад
redhat логотип
CVE-2026-64499

A flaw was found in the Linux kernel's `ti-ads1119` Analog-to-Digital Converter (ADC) driver. This vulnerability occurs during the buffer pre-enable process, where a Power Management (PM) reference is not properly released if an I2C communication error occurs. This oversight can lead to a resource leak, potentially causing the affected device to remain active indefinitely and consume system resources, which could result in a denial of service.

0%
Низкий
8 дней назад
redhat логотип
CVE-2026-64498

A flaw was found in the Linux kernel's Industrial I/O (IIO) subsystem, specifically within the hardware consumer buffer (hw-consumer). Due to an oversight in memory management, a dedicated memory region (scan_mask) was not properly released when its associated buffer was freed. A local attacker with low privileges could exploit this memory leak, potentially leading to system instability or a denial of service (DoS) by exhausting available memory resources.

0%
Низкий
8 дней назад
redhat логотип
CVE-2026-64497

A flaw was found in the Linux kernel's iio: chemical: scd30 driver, which manages a specific type of sensor. This vulnerability involves an error in how the driver processes numerical data, specifically a 'sign-extension bug' that can corrupt a part of a floating-point number called the exponent. This corruption could lead to the sensor providing inaccurate readings or cause the system to behave unexpectedly.

0%
Низкий
8 дней назад
redhat логотип
CVE-2026-64496

A flaw was found in the Linux kernel's Industrial I/O (IIO) event subsystem. A local user can exploit a race condition during the reset of the event FIFO (First-In, First-Out) buffer. This occurs when another thread accesses a newly allocated file descriptor before the FIFO reset is complete. This can lead to an out-of-bounds read, potentially disclosing sensitive kernel memory to the user.

CVSS3: 5.5
0%
Низкий
8 дней назад
redhat логотип
CVE-2026-64495

A flaw was found in the Linux kernel's `bmg160` gyroscope driver. An out-of-bounds read vulnerability exists when handling specific bandwidth or filter values provided by userspace through the `sysfs` interface. A local user can exploit this by supplying a malformed value, leading to a read past the end of an array. This can result in a denial of service.

0%
Низкий
8 дней назад
redhat логотип
CVE-2026-64494

A flaw was found in the Linux kernel's `gp2ap002` light sensor driver. When the driver attempts to read lux values and encounters an error, it fails to properly release a power management resource. This oversight leads to a permanent leak of the resource, which prevents the affected device from automatically entering a low-power state (autosuspending). The primary impact is increased power consumption for devices utilizing this driver.

0%
Низкий
8 дней назад
redhat логотип
CVE-2026-64493

A flaw was found in the Linux kernel's `mpl115` pressure sensor driver. When a read error occurs in the `mpl115_read_raw()` function, the driver fails to properly release a Power Management (PM) reference. This oversight leads to a continuous leak of PM references with each failed read. The accumulation of these unreleased references can prevent the affected device from entering an autosuspend state, potentially leading to increased power consumption or other resource management issues.

0%
Низкий
8 дней назад
redhat логотип
CVE-2026-64492

A flaw was found in the Linux kernel's `tmp006` temperature sensor driver. This vulnerability occurs because the driver incorrectly handles the registration and de-registration of a hardware trigger. When the module is unloaded, a pointer to freed memory remains active, creating a 'dangling pointer'. This can lead to system instability or potentially allow an attacker to cause a denial of service.

0%
Низкий
8 дней назад
redhat логотип
CVE-2026-64491

A flaw was found in the Linux kernel's ALSA (Advanced Linux Sound Architecture) usx2y us144mkii driver. This vulnerability, a Use-After-Free (UAF), occurs when a USB device is disconnected, leading to a race condition where the system attempts to access memory that has already been released. This could allow a local attacker to cause system instability, crash the system, or potentially execute malicious code.

CVSS3: 5.5
0%
Низкий
8 дней назад
redhat логотип
CVE-2026-64490

A flaw was found in the Linux kernel's ALSA virtio sound driver. A malicious or buggy virtio device can provide invalid control metadata, such as an unknown control type or an oversized value count. The driver's control handling trusts this unvalidated metadata, leading to out-of-bounds access when processing sound control information. This vulnerability could allow a malicious device to cause a denial of service or potentially other impacts on the system.

CVSS3: 7
0%
Низкий
8 дней назад
redhat логотип
CVE-2026-64489

A flaw was found in the ALSA (Advanced Linux Sound Architecture) ymfpci driver in the Linux kernel. This vulnerability occurs because the 'snd_ctl_new1()' function, which allocates memory, may return a null value if memory allocation fails. The driver then attempts to use this null value without proper checks, leading to a null pointer dereference. A local attacker could exploit this to cause a denial of service (DoS), resulting in a system crash.

CVSS3: 5.5
0%
Низкий
8 дней назад
redhat логотип
CVE-2026-64488

A flaw was found in the Linux kernel's Advanced Linux Sound Architecture (ALSA) 'aoa' component. This vulnerability arises when a specific function, `snd_ctl_new1()`, fails to allocate memory and returns an invalid pointer. The kernel then attempts to use this invalid pointer, which can cause the system to crash. This could allow a local attacker to trigger a Denial of Service (DoS) condition, making the system unavailable.

CVSS3: 5.5
0%
Низкий
8 дней назад
redhat логотип
CVE-2026-64487

A flaw was found in the Linux kernel's sound subsystem, specifically within the ALSA caiaq driver responsible for handling Traktor Kontrol S4 devices. A local attacker, by providing specially crafted input from a connected device, could exploit an out-of-bounds read vulnerability. This issue arises from incorrect handling of input stream lengths, leading to the system reading beyond its allocated memory buffer. Successful exploitation could result in the disclosure of sensitive information from kernel memory or cause a system crash, leading to a denial of service.

CVSS3: 5.5
0%
Низкий
8 дней назад
redhat логотип
CVE-2026-64486

A flaw was found in the Linux kernel's Advanced Linux Sound Architecture (ALSA) cmipci component. This vulnerability occurs because the `snd_cmipci_spdif_controls()` function fails to check the return value of `snd_ctl_new1()`, which can return a null pointer if memory allocation fails. A local attacker could exploit this to trigger a null pointer dereference, leading to a system crash and a denial of service (DoS).

CVSS3: 5.5
0%
Низкий
8 дней назад
redhat логотип
CVE-2026-64485

A flaw was found in the Linux kernel's Advanced Linux Sound Architecture (ALSA) compress module. The `snd_compr_task_new()` function, responsible for creating driver tasks, does not properly handle errors during the validation of Direct Memory Access (DMA) buffers or file descriptor reservation. This oversight can lead to a resource leak, where driver resources allocated during task creation are not freed. Consequently, this could result in system instability or a Denial of Service (DoS) over time due to resource exhaustion.

CVSS3: 5.5
0%
Низкий
8 дней назад
redhat логотип
CVE-2026-64484

A flaw was found in the Linux kernel's ALSA (Advanced Linux Sound Architecture) es1938 sound driver. This vulnerability arises when a memory allocation failure causes the `snd_ctl_new1()` function to return a null value. The `snd_es1938_mixer()` function then attempts to use this null value without proper validation, leading to a null pointer dereference. This can result in a system crash, causing a Denial of Service (DoS) for affected systems.

0%
Низкий
8 дней назад
redhat логотип
CVE-2026-64483

A flaw was found in the Linux kernel's ALSA FireWire iSight driver. A malicious or faulty Apple iSight device connected via FireWire can send specially crafted audio packets. The driver incorrectly processes the sample count in these packets, leading to a buffer overflow where data can be written beyond the allocated memory region. This could result in memory corruption, potentially impacting system stability or leading to further exploitation.

CVSS3: 7
0%
Низкий
8 дней назад
redhat логотип
CVE-2026-64482

A flaw was found in the Linux kernel's Advanced Linux Sound Architecture (ALSA) Gravis Ultrasound (GUS) driver. When memory allocation fails, the `snd_ctl_new1()` function can return a null value. The `snd_gf1_pcm_volume_control()` function does not properly check for this null return, leading to a null pointer dereference. This vulnerability could allow a local attacker to cause a system crash, resulting in a denial of service.

CVSS3: 5.5
0%
Низкий
8 дней назад

Уязвимостей на страницу