Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 52 848

Количество 52 848

redhat логотип

CVE-2026-64460

8 дней назад

A flaw was found in the Linux kernel's PCI/IOV subsystem. When a PCI device fails to respond during a power state transition, the kernel's Virtual Function (VF) Resizable Base Address Register (BAR) restoration process can attempt to access memory outside of its allocated bounds. This out-of-bounds memory access can lead to a system crash, resulting in a Denial of Service (DoS).

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2026-64459

8 дней назад

A flaw was found in the Linux kernel's TCP-AO (TCP Authentication Option) implementation. An unprivileged local user can exploit a use-after-free vulnerability in the `tcp_ao_destroy_sock()` function. By manipulating TCP sockets with TCP_MD5SIG and TCP_AO_ADD_KEY, an attacker can trigger a race condition during socket connection. This can lead to a system crash, resulting in a Denial of Service (DoS).

EPSS: Низкий
redhat логотип

CVE-2026-64458

8 дней назад

A flaw was found in the Linux kernel's Data Access MONitor (DAMON) subsystem. A local user with write permissions to the system file system (sysfs) can exploit this vulnerability by configuring extreme (zero or excessively high) monitoring intervals. This improper handling of interval values can lead to divide-by-zero errors or out-of-bounds array access, resulting in a kernel crash and a Denial of Service.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2026-64456

8 дней назад

A flaw was found in the Linux kernel's virtio-rng driver. A malicious or buggy virtualized hardware random number generator (virtio-rng) backend can report an overly large data length to the guest operating system. This unchecked length can lead to an out-of-bounds read, causing the driver to access memory beyond its intended buffer. This vulnerability can result in information disclosure, where sensitive guest-kernel heap data may be leaked to a malicious hypervisor or a compromised guest root user.

CVSS3: 7
EPSS: Низкий
redhat логотип

CVE-2026-64455

8 дней назад

A flaw was found in the Linux kernel's `chaoskey` driver. A local user could trigger a use-after-free vulnerability by closing the device file after the associated USB device has been unplugged. This could lead to a system crash due to memory corruption when a debugging statement attempts to access deallocated memory.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2026-64454

8 дней назад

A flaw was found in the Linux kernel's USB dwc3 driver. A local attacker could trigger a condition where a sleeping function is called from an invalid context during a USB gadget suspend operation. This can lead to system instability or a kernel panic, resulting in a Denial of Service (DoS).

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2026-64453

8 дней назад

A flaw was found in the Linux kernel's USB subsystem, specifically within the `usbio` module. This vulnerability, known as a use-after-free (UAF), occurs when the system attempts to access memory that has already been released during the disconnection of a USB device. A local attacker or a specially crafted malicious USB device could exploit this flaw. Successful exploitation could lead to a system crash (denial of service) or potentially allow for the execution of unauthorized code.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2026-64452

8 дней назад

A flaw was found in the Linux kernel's 6LoWPAN (IPv6 over Low-Power Wireless Personal Area Networks) component. A race condition in the `lowpan_nhc_do_uncompression` function can lead to a use-after-free vulnerability. This occurs when an NHC (Next Header Compression) descriptor is deallocated while another process attempts to access its name in an error handling path. This flaw could allow an attacker to cause a denial of service or potentially execute arbitrary code.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2026-64451

8 дней назад

A flaw was found in the Linux kernel's tracing subsystem. A local user, by manipulating function tracer options, can trigger a NULL pointer dereference in the func_set_flag() function. This vulnerability occurs when the active tracer is switched away from the function tracer while a process has an option file for it open, leading to a kernel crash and a denial of service.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2026-64449

8 дней назад

A flaw was found in the Linux kernel's vme_user module. This vulnerability allows a local user to cause a slab-out-of-bounds write or read due to improper validation of buffer sizes in the VME slave path. When a user-supplied VME window size exceeds the internal buffer, data can be copied beyond the allocated memory, leading to memory corruption. This can result in a system crash (denial of service) or potentially lead to further exploitation.

EPSS: Низкий
redhat логотип

CVE-2026-64448

8 дней назад

A flaw was found in the Linux kernel's Server Message Block (SMB) client. An attacker, by operating a malicious SMB server, could send specially crafted responses during the session negotiation phase. This could cause the client to read beyond the intended memory buffer, potentially leading to the disclosure of sensitive information from the kernel's memory.

CVSS3: 7
EPSS: Низкий
redhat логотип

CVE-2026-64447

8 дней назад

A flaw was found in the Linux kernel's `ipu7` media driver. This vulnerability involves incorrect memory management where memory can be freed multiple times and subsequently accessed after it has been freed, specifically during error handling paths in device initialization. A local attacker could potentially exploit this memory corruption to cause a system crash (denial of service) or, in more severe cases, execute arbitrary code with elevated privileges.

EPSS: Низкий
redhat логотип

CVE-2026-64445

8 дней назад

A flaw was found in the `rtl8723bs` Wi-Fi driver within the Linux kernel. During shared-key authentication, an attacker on an adjacent network could send a specially crafted frame. This could lead to an out-of-bounds read, potentially allowing for the disclosure of sensitive information or causing a denial of service (DoS).

EPSS: Низкий
redhat логотип

CVE-2026-64444

8 дней назад

A flaw was found in the Linux kernel's rtl8723bs Wi-Fi driver. A remote attacker, by operating a malicious Access Point (AP), could send a specially crafted association response frame. This could lead to an out-of-bounds read vulnerability, potentially causing information disclosure or system instability.

EPSS: Низкий
redhat логотип

CVE-2026-64443

8 дней назад

A flaw was found in the Linux kernel. A remote attacker could exploit an out-of-bounds read vulnerability in the `update_beacon_info()` function by sending a specially crafted wireless Beacon frame containing a malformed Information Element (IE). This could lead to the disclosure of sensitive information or cause a denial of-service (DoS) on the affected system.

EPSS: Низкий
redhat логотип

CVE-2026-64442

8 дней назад

A flaw was found in the Linux kernel's `rtl8723bs` Wi-Fi driver. Insufficient boundary checks in the information element (IE) parsing loops within the `issue_assocreq()` and `join_cmd_hdl()` functions allow a remote attacker to cause an out-of-bounds read. By sending specially crafted, truncated IE data from a malicious Wi-Fi Access Point, an attacker could trigger a system crash, leading to a denial of service.

EPSS: Низкий
redhat логотип

CVE-2026-64441

8 дней назад

A flaw was found in the Linux kernel's `rtl8723bs` Wi-Fi driver. This vulnerability involves out-of-bounds reads in several functions responsible for parsing information elements (IE) and attributes. Due to missing checks on the size of incoming data, these functions can read beyond the intended memory boundaries. This could allow an attacker to gain access to sensitive information from the system's memory.

EPSS: Низкий
redhat логотип

CVE-2026-64440

8 дней назад

A flaw was found in the Linux kernel's `rtl8723bs` Wi-Fi driver. A remote attacker, by operating a malicious Access Point (AP), can send a specially crafted 802.11 AssocResponse frame. This can trigger an out-of-bounds write vulnerability in the `HT_caps_handler()` function, leading to memory corruption. This memory corruption could allow an attacker to cause a denial of service or potentially execute arbitrary code.

EPSS: Низкий
redhat логотип

CVE-2026-64439

8 дней назад

A flaw was found in the Linux kernel's Kerberos 5 (krb5) cryptography module. This use-after-free vulnerability occurs when an asynchronous Authenticated Encryption with Associated Data (AEAD) instance is used. The system prematurely frees a memory buffer while a backend process still holds a pointer to it, leading to the process attempting to access the freed memory. This can result in a system crash, causing a Denial of Service (DoS).

CVSS3: 7
EPSS: Низкий
redhat логотип

CVE-2026-64437

8 дней назад

A flaw was found in the ksmbd component of the Linux kernel. This vulnerability allows an authenticated client using the Server Message Block (SMB) protocol to trigger a use-after-free error. By sending specific close and cancel requests, an attacker can cause the kernel to crash, leading to a denial of service for affected systems.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2026-64460

A flaw was found in the Linux kernel's PCI/IOV subsystem. When a PCI device fails to respond during a power state transition, the kernel's Virtual Function (VF) Resizable Base Address Register (BAR) restoration process can attempt to access memory outside of its allocated bounds. This out-of-bounds memory access can lead to a system crash, resulting in a Denial of Service (DoS).

CVSS3: 5.5
0%
Низкий
8 дней назад
redhat логотип
CVE-2026-64459

A flaw was found in the Linux kernel's TCP-AO (TCP Authentication Option) implementation. An unprivileged local user can exploit a use-after-free vulnerability in the `tcp_ao_destroy_sock()` function. By manipulating TCP sockets with TCP_MD5SIG and TCP_AO_ADD_KEY, an attacker can trigger a race condition during socket connection. This can lead to a system crash, resulting in a Denial of Service (DoS).

0%
Низкий
8 дней назад
redhat логотип
CVE-2026-64458

A flaw was found in the Linux kernel's Data Access MONitor (DAMON) subsystem. A local user with write permissions to the system file system (sysfs) can exploit this vulnerability by configuring extreme (zero or excessively high) monitoring intervals. This improper handling of interval values can lead to divide-by-zero errors or out-of-bounds array access, resulting in a kernel crash and a Denial of Service.

CVSS3: 5.5
0%
Низкий
8 дней назад
redhat логотип
CVE-2026-64456

A flaw was found in the Linux kernel's virtio-rng driver. A malicious or buggy virtualized hardware random number generator (virtio-rng) backend can report an overly large data length to the guest operating system. This unchecked length can lead to an out-of-bounds read, causing the driver to access memory beyond its intended buffer. This vulnerability can result in information disclosure, where sensitive guest-kernel heap data may be leaked to a malicious hypervisor or a compromised guest root user.

CVSS3: 7
0%
Низкий
8 дней назад
redhat логотип
CVE-2026-64455

A flaw was found in the Linux kernel's `chaoskey` driver. A local user could trigger a use-after-free vulnerability by closing the device file after the associated USB device has been unplugged. This could lead to a system crash due to memory corruption when a debugging statement attempts to access deallocated memory.

CVSS3: 5.5
0%
Низкий
8 дней назад
redhat логотип
CVE-2026-64454

A flaw was found in the Linux kernel's USB dwc3 driver. A local attacker could trigger a condition where a sleeping function is called from an invalid context during a USB gadget suspend operation. This can lead to system instability or a kernel panic, resulting in a Denial of Service (DoS).

CVSS3: 5.5
0%
Низкий
8 дней назад
redhat логотип
CVE-2026-64453

A flaw was found in the Linux kernel's USB subsystem, specifically within the `usbio` module. This vulnerability, known as a use-after-free (UAF), occurs when the system attempts to access memory that has already been released during the disconnection of a USB device. A local attacker or a specially crafted malicious USB device could exploit this flaw. Successful exploitation could lead to a system crash (denial of service) or potentially allow for the execution of unauthorized code.

CVSS3: 5.5
0%
Низкий
8 дней назад
redhat логотип
CVE-2026-64452

A flaw was found in the Linux kernel's 6LoWPAN (IPv6 over Low-Power Wireless Personal Area Networks) component. A race condition in the `lowpan_nhc_do_uncompression` function can lead to a use-after-free vulnerability. This occurs when an NHC (Next Header Compression) descriptor is deallocated while another process attempts to access its name in an error handling path. This flaw could allow an attacker to cause a denial of service or potentially execute arbitrary code.

CVSS3: 5.5
0%
Низкий
8 дней назад
redhat логотип
CVE-2026-64451

A flaw was found in the Linux kernel's tracing subsystem. A local user, by manipulating function tracer options, can trigger a NULL pointer dereference in the func_set_flag() function. This vulnerability occurs when the active tracer is switched away from the function tracer while a process has an option file for it open, leading to a kernel crash and a denial of service.

CVSS3: 5.5
0%
Низкий
8 дней назад
redhat логотип
CVE-2026-64449

A flaw was found in the Linux kernel's vme_user module. This vulnerability allows a local user to cause a slab-out-of-bounds write or read due to improper validation of buffer sizes in the VME slave path. When a user-supplied VME window size exceeds the internal buffer, data can be copied beyond the allocated memory, leading to memory corruption. This can result in a system crash (denial of service) or potentially lead to further exploitation.

0%
Низкий
8 дней назад
redhat логотип
CVE-2026-64448

A flaw was found in the Linux kernel's Server Message Block (SMB) client. An attacker, by operating a malicious SMB server, could send specially crafted responses during the session negotiation phase. This could cause the client to read beyond the intended memory buffer, potentially leading to the disclosure of sensitive information from the kernel's memory.

CVSS3: 7
0%
Низкий
8 дней назад
redhat логотип
CVE-2026-64447

A flaw was found in the Linux kernel's `ipu7` media driver. This vulnerability involves incorrect memory management where memory can be freed multiple times and subsequently accessed after it has been freed, specifically during error handling paths in device initialization. A local attacker could potentially exploit this memory corruption to cause a system crash (denial of service) or, in more severe cases, execute arbitrary code with elevated privileges.

0%
Низкий
8 дней назад
redhat логотип
CVE-2026-64445

A flaw was found in the `rtl8723bs` Wi-Fi driver within the Linux kernel. During shared-key authentication, an attacker on an adjacent network could send a specially crafted frame. This could lead to an out-of-bounds read, potentially allowing for the disclosure of sensitive information or causing a denial of service (DoS).

0%
Низкий
8 дней назад
redhat логотип
CVE-2026-64444

A flaw was found in the Linux kernel's rtl8723bs Wi-Fi driver. A remote attacker, by operating a malicious Access Point (AP), could send a specially crafted association response frame. This could lead to an out-of-bounds read vulnerability, potentially causing information disclosure or system instability.

0%
Низкий
8 дней назад
redhat логотип
CVE-2026-64443

A flaw was found in the Linux kernel. A remote attacker could exploit an out-of-bounds read vulnerability in the `update_beacon_info()` function by sending a specially crafted wireless Beacon frame containing a malformed Information Element (IE). This could lead to the disclosure of sensitive information or cause a denial of-service (DoS) on the affected system.

0%
Низкий
8 дней назад
redhat логотип
CVE-2026-64442

A flaw was found in the Linux kernel's `rtl8723bs` Wi-Fi driver. Insufficient boundary checks in the information element (IE) parsing loops within the `issue_assocreq()` and `join_cmd_hdl()` functions allow a remote attacker to cause an out-of-bounds read. By sending specially crafted, truncated IE data from a malicious Wi-Fi Access Point, an attacker could trigger a system crash, leading to a denial of service.

0%
Низкий
8 дней назад
redhat логотип
CVE-2026-64441

A flaw was found in the Linux kernel's `rtl8723bs` Wi-Fi driver. This vulnerability involves out-of-bounds reads in several functions responsible for parsing information elements (IE) and attributes. Due to missing checks on the size of incoming data, these functions can read beyond the intended memory boundaries. This could allow an attacker to gain access to sensitive information from the system's memory.

0%
Низкий
8 дней назад
redhat логотип
CVE-2026-64440

A flaw was found in the Linux kernel's `rtl8723bs` Wi-Fi driver. A remote attacker, by operating a malicious Access Point (AP), can send a specially crafted 802.11 AssocResponse frame. This can trigger an out-of-bounds write vulnerability in the `HT_caps_handler()` function, leading to memory corruption. This memory corruption could allow an attacker to cause a denial of service or potentially execute arbitrary code.

0%
Низкий
8 дней назад
redhat логотип
CVE-2026-64439

A flaw was found in the Linux kernel's Kerberos 5 (krb5) cryptography module. This use-after-free vulnerability occurs when an asynchronous Authenticated Encryption with Associated Data (AEAD) instance is used. The system prematurely frees a memory buffer while a backend process still holds a pointer to it, leading to the process attempting to access the freed memory. This can result in a system crash, causing a Denial of Service (DoS).

CVSS3: 7
0%
Низкий
8 дней назад
redhat логотип
CVE-2026-64437

A flaw was found in the ksmbd component of the Linux kernel. This vulnerability allows an authenticated client using the Server Message Block (SMB) protocol to trigger a use-after-free error. By sending specific close and cancel requests, an attacker can cause the kernel to crash, leading to a denial of service for affected systems.

0%
Низкий
8 дней назад

Уязвимостей на страницу