Количество 52 848
Количество 52 848
CVE-2026-64313
A flaw was found in the Linux kernel's Elliptic Curve Cryptography (ECC) component. An attacker on an adjacent network could exploit an error in the very long integer (vli) multiplication's carry flag calculation. This mathematical inaccuracy in cryptographic operations could lead to high impact on confidentiality, integrity, and availability.
CVE-2026-64312
A flaw was found in the Linux kernel's parallel cryptography (pcrypt) subsystem. When the system falls back to a non-parallel processing path, it fails to properly restore the original callback function and data. This oversight can lead to an asynchronous completion running an incorrect callback, potentially causing unexpected system behavior or resource management issues. This vulnerability could be exploited by a local attacker to disrupt system operations.
CVE-2026-64311
A flaw was found in the Linux kernel's `loongson-rng` random number generator. This component suffered from a use-after-free vulnerability, which could lead to system instability or denial of service. Additionally, the `loongson-rng` did not provide forward security, a crucial cryptographic property. Due to these security weaknesses and its limited utility, the `loongson-rng` driver has been removed from the kernel.
CVE-2026-64310
A flaw was found in the Linux kernel's crypto: ccp component. A local user, by triggering specific SEV (Secure Encrypted Virtualization) input/output control (ioctl) operations when SEV initialization fails and Kernel-based Virtual Machine (KVM) is actively running virtual machines, could cause the system to zero out a critical hardware register. This could lead to a general protection fault, resulting in a denial of service (DoS) by crashing the host system.
CVE-2026-64309
A flaw was found in the Linux kernel's `crypto: ccp` module. This vulnerability arises from improper initialization of Secure Nested Paging (SNP) when handling the `ioctl(SNP_COMMIT)` command. A local userspace process can exploit this by sending specific commands via `/dev/sev` ioctls. If Secure Encrypted Virtualization (SEV) initialization fails and Kernel-based Virtual Machine (KVM) is actively running virtual machines, this flaw could lead to a Denial of Service (DoS) by causing a host crash.
CVE-2026-64308
A flaw was found in the Linux kernel's crypto: ccp module, which handles AMD Secure Encrypted Virtualization (SEV) and Secure Nested Paging (SNP) features. A local user, by sending specific commands through the /dev/sev interface, could exploit improper initialization handling. If SEV initialization has failed and virtual machines are active, this could lead to a system crash, resulting in a Denial of Service (DoS).
CVE-2026-64307
A flaw was found in the Linux kernel's crypto:ccp module. A local attacker with access to a userspace process could exploit this vulnerability. If Secure Encrypted Virtualization (SEV) initialization fails while Kernel-based Virtual Machine (KVM) is running virtual machines, the attacker can trigger a specific code path through `/dev/sev` input/output controls (ioctls). This can cause a system crash, leading to a Denial of Service (DoS) for the host.
CVE-2026-64306
A flaw was found in the Linux kernel's Cryptographic API, specifically within the Counter Mode Deterministic Random Bit Generator (CTR_DRBG). The `drbg_ctr_generate()` function can incorrectly indicate a successful operation even when it has failed. This issue results in the output buffer remaining uninitialized, potentially leading to information disclosure or unpredictable system behavior when this uninitialized data is subsequently used.
CVE-2026-64305
A flaw was found in the Linux kernel's cryptographic acceleration (qat) component. This vulnerability occurs because certain functions iterate over a critical data structure without proper synchronization. If another operation modifies this structure concurrently, it can lead to data corruption or a use-after-free error. This could potentially allow an attacker to cause system instability, leading to a denial of service, or in some cases, execute unauthorized code.
CVE-2026-64304
A flaw was found in the Linux kernel's QAT (QuickAssist Technology) crypto module. This vulnerability occurs in the RSA key parser when handling CRT (Chinese Remainder Theorem) components. An underflow can happen during a memory copy operation if an RSA CRT component is larger than its allocated buffer, leading to memory corruption. This could potentially allow an attacker to cause system instability or execute arbitrary code.
CVE-2026-64303
A flaw was found in the Linux kernel's `fsl-lpspi` driver. This vulnerability occurs when the transmit (TX) Direct Memory Access (DMA) channel fails to prepare, but the receive (RX) DMA channel continues to operate. This can lead to memory corruption or a use-after-free condition, potentially allowing an attacker to compromise system integrity or execute unauthorized code.
CVE-2026-64302
A flaw was found in the Linux kernel. A local user could exploit an issue in the `pagetable_free()` function, which incorrectly handles `vmemmap` pages. This improper memory management leads to a memory leak, where only a portion of the allocated memory is freed. Consequently, this can result in a Denial of Service (DoS) due to resource exhaustion.
CVE-2026-64301
A flaw was found in the Linux kernel's regulator subsystem. An issue in the `scmi_regulator_probe()` function can lead to a reference count leak. This occurs when an error path is triggered during device node processing, causing a resource to not be properly released. Over time, this unreleased resource could potentially impact system stability or performance.
CVE-2026-64300
A flaw was found in the Linux kernel's `perf/aux` subsystem. A use-after-free (UAF) vulnerability exists in the `map_range()` function due to a race condition. This can occur when two performance events share a ring buffer, allowing a local attacker to map a memory page that has already been freed. Exploiting this flaw could lead to arbitrary code execution or privilege escalation.
CVE-2026-6429
When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, libcurl could leak the password used for the first host to the followed-to host under certain circumstances.
CVE-2026-64299
A flaw was found in the Linux kernel's tracing subsystem. This vulnerability allows a local attacker to trigger an out-of-bounds read by providing specially crafted input to glob matching functions. The issue arises because these functions did not correctly handle string event fields that were not properly terminated. Successful exploitation could lead to the disclosure of sensitive information or cause a system crash, resulting in a denial of service (DoS).
CVE-2026-64298
A flaw was found in the Linux kernel's NFSv4 implementation. A local user could exploit a vulnerability where opening a file with O_TRUNC (truncate) and O_RDONLY (read-only) flags would bypass the necessary write permission checks. This oversight allows an attacker to truncate a file without having explicit write access, leading to unauthorized data modification.
CVE-2026-64297
A flaw was found in the Linux kernel. An unchecked return value in the `module_extend_max_pages()` function within the module decompression logic can lead to a null pointer dereference. This vulnerability can be triggered if memory allocation fails during module loading, resulting in a kernel oops. This can allow a local attacker to cause a denial of service (DoS) by crashing the system.
CVE-2026-64296
A flaw was found in the Linux kernel's exFAT filesystem driver. A local attacker could create a specially crafted directory with malformed name fragments. When the kernel processes this directory, an out-of-bounds read and write can occur, potentially leading to a denial of service or system instability. This vulnerability arises from incorrect boundary checks during the processing of directory entries.
CVE-2026-64295
A flaw was found in the Linux kernel's memory management (mm) component, specifically within the `page_ext` iteration application programming interface (API). When memory is dynamically added to the system (a process known as 'hotplugging'), the API does not properly validate memory page frame numbers (PFNs). This oversight can lead to a null pointer dereference, potentially causing a system crash or denial of service (DoS) if an attacker can trigger memory hotplug operations.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-64313 A flaw was found in the Linux kernel's Elliptic Curve Cryptography (ECC) component. An attacker on an adjacent network could exploit an error in the very long integer (vli) multiplication's carry flag calculation. This mathematical inaccuracy in cryptographic operations could lead to high impact on confidentiality, integrity, and availability. | CVSS3: 5.5 | 0% Низкий | 8 дней назад | |
CVE-2026-64312 A flaw was found in the Linux kernel's parallel cryptography (pcrypt) subsystem. When the system falls back to a non-parallel processing path, it fails to properly restore the original callback function and data. This oversight can lead to an asynchronous completion running an incorrect callback, potentially causing unexpected system behavior or resource management issues. This vulnerability could be exploited by a local attacker to disrupt system operations. | CVSS3: 7 | 1% Низкий | 8 дней назад | |
CVE-2026-64311 A flaw was found in the Linux kernel's `loongson-rng` random number generator. This component suffered from a use-after-free vulnerability, which could lead to system instability or denial of service. Additionally, the `loongson-rng` did not provide forward security, a crucial cryptographic property. Due to these security weaknesses and its limited utility, the `loongson-rng` driver has been removed from the kernel. | 0% Низкий | 8 дней назад | ||
CVE-2026-64310 A flaw was found in the Linux kernel's crypto: ccp component. A local user, by triggering specific SEV (Secure Encrypted Virtualization) input/output control (ioctl) operations when SEV initialization fails and Kernel-based Virtual Machine (KVM) is actively running virtual machines, could cause the system to zero out a critical hardware register. This could lead to a general protection fault, resulting in a denial of service (DoS) by crashing the host system. | CVSS3: 5.5 | 0% Низкий | 8 дней назад | |
CVE-2026-64309 A flaw was found in the Linux kernel's `crypto: ccp` module. This vulnerability arises from improper initialization of Secure Nested Paging (SNP) when handling the `ioctl(SNP_COMMIT)` command. A local userspace process can exploit this by sending specific commands via `/dev/sev` ioctls. If Secure Encrypted Virtualization (SEV) initialization fails and Kernel-based Virtual Machine (KVM) is actively running virtual machines, this flaw could lead to a Denial of Service (DoS) by causing a host crash. | CVSS3: 5.5 | 0% Низкий | 8 дней назад | |
CVE-2026-64308 A flaw was found in the Linux kernel's crypto: ccp module, which handles AMD Secure Encrypted Virtualization (SEV) and Secure Nested Paging (SNP) features. A local user, by sending specific commands through the /dev/sev interface, could exploit improper initialization handling. If SEV initialization has failed and virtual machines are active, this could lead to a system crash, resulting in a Denial of Service (DoS). | CVSS3: 5.5 | 0% Низкий | 8 дней назад | |
CVE-2026-64307 A flaw was found in the Linux kernel's crypto:ccp module. A local attacker with access to a userspace process could exploit this vulnerability. If Secure Encrypted Virtualization (SEV) initialization fails while Kernel-based Virtual Machine (KVM) is running virtual machines, the attacker can trigger a specific code path through `/dev/sev` input/output controls (ioctls). This can cause a system crash, leading to a Denial of Service (DoS) for the host. | CVSS3: 5.5 | 0% Низкий | 8 дней назад | |
CVE-2026-64306 A flaw was found in the Linux kernel's Cryptographic API, specifically within the Counter Mode Deterministic Random Bit Generator (CTR_DRBG). The `drbg_ctr_generate()` function can incorrectly indicate a successful operation even when it has failed. This issue results in the output buffer remaining uninitialized, potentially leading to information disclosure or unpredictable system behavior when this uninitialized data is subsequently used. | CVSS3: 7 | 0% Низкий | 8 дней назад | |
CVE-2026-64305 A flaw was found in the Linux kernel's cryptographic acceleration (qat) component. This vulnerability occurs because certain functions iterate over a critical data structure without proper synchronization. If another operation modifies this structure concurrently, it can lead to data corruption or a use-after-free error. This could potentially allow an attacker to cause system instability, leading to a denial of service, or in some cases, execute unauthorized code. | CVSS3: 7 | 0% Низкий | 8 дней назад | |
CVE-2026-64304 A flaw was found in the Linux kernel's QAT (QuickAssist Technology) crypto module. This vulnerability occurs in the RSA key parser when handling CRT (Chinese Remainder Theorem) components. An underflow can happen during a memory copy operation if an RSA CRT component is larger than its allocated buffer, leading to memory corruption. This could potentially allow an attacker to cause system instability or execute arbitrary code. | CVSS3: 7 | 0% Низкий | 8 дней назад | |
CVE-2026-64303 A flaw was found in the Linux kernel's `fsl-lpspi` driver. This vulnerability occurs when the transmit (TX) Direct Memory Access (DMA) channel fails to prepare, but the receive (RX) DMA channel continues to operate. This can lead to memory corruption or a use-after-free condition, potentially allowing an attacker to compromise system integrity or execute unauthorized code. | CVSS3: 7 | 1% Низкий | 8 дней назад | |
CVE-2026-64302 A flaw was found in the Linux kernel. A local user could exploit an issue in the `pagetable_free()` function, which incorrectly handles `vmemmap` pages. This improper memory management leads to a memory leak, where only a portion of the allocated memory is freed. Consequently, this can result in a Denial of Service (DoS) due to resource exhaustion. | 0% Низкий | 8 дней назад | ||
CVE-2026-64301 A flaw was found in the Linux kernel's regulator subsystem. An issue in the `scmi_regulator_probe()` function can lead to a reference count leak. This occurs when an error path is triggered during device node processing, causing a resource to not be properly released. Over time, this unreleased resource could potentially impact system stability or performance. | CVSS3: 5.5 | 0% Низкий | 8 дней назад | |
CVE-2026-64300 A flaw was found in the Linux kernel's `perf/aux` subsystem. A use-after-free (UAF) vulnerability exists in the `map_range()` function due to a race condition. This can occur when two performance events share a ring buffer, allowing a local attacker to map a memory page that has already been freed. Exploiting this flaw could lead to arbitrary code execution or privilege escalation. | CVSS3: 7 | 0% Низкий | 8 дней назад | |
CVE-2026-6429 When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, libcurl could leak the password used for the first host to the followed-to host under certain circumstances. | CVSS3: 6.5 | 1% Низкий | 3 месяца назад | |
CVE-2026-64299 A flaw was found in the Linux kernel's tracing subsystem. This vulnerability allows a local attacker to trigger an out-of-bounds read by providing specially crafted input to glob matching functions. The issue arises because these functions did not correctly handle string event fields that were not properly terminated. Successful exploitation could lead to the disclosure of sensitive information or cause a system crash, resulting in a denial of service (DoS). | CVSS3: 5.5 | 0% Низкий | 8 дней назад | |
CVE-2026-64298 A flaw was found in the Linux kernel's NFSv4 implementation. A local user could exploit a vulnerability where opening a file with O_TRUNC (truncate) and O_RDONLY (read-only) flags would bypass the necessary write permission checks. This oversight allows an attacker to truncate a file without having explicit write access, leading to unauthorized data modification. | CVSS3: 7 | 0% Низкий | 8 дней назад | |
CVE-2026-64297 A flaw was found in the Linux kernel. An unchecked return value in the `module_extend_max_pages()` function within the module decompression logic can lead to a null pointer dereference. This vulnerability can be triggered if memory allocation fails during module loading, resulting in a kernel oops. This can allow a local attacker to cause a denial of service (DoS) by crashing the system. | CVSS3: 5.5 | 0% Низкий | 8 дней назад | |
CVE-2026-64296 A flaw was found in the Linux kernel's exFAT filesystem driver. A local attacker could create a specially crafted directory with malformed name fragments. When the kernel processes this directory, an out-of-bounds read and write can occur, potentially leading to a denial of service or system instability. This vulnerability arises from incorrect boundary checks during the processing of directory entries. | CVSS3: 7 | 0% Низкий | 8 дней назад | |
CVE-2026-64295 A flaw was found in the Linux kernel's memory management (mm) component, specifically within the `page_ext` iteration application programming interface (API). When memory is dynamically added to the system (a process known as 'hotplugging'), the API does not properly validate memory page frame numbers (PFNs). This oversight can lead to a null pointer dereference, potentially causing a system crash or denial of service (DoS) if an attacker can trigger memory hotplug operations. | CVSS3: 5.5 | 0% Низкий | 8 дней назад |
Уязвимостей на страницу