Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 52 848

Количество 52 848

redhat логотип

CVE-2026-64294

8 дней назад

A flaw was found in the Linux kernel's memory management subsystem. This vulnerability arises from incorrect handling of file ownership checks within idmapped mounts, a feature that allows remapping user and group IDs. When certain memory operations are performed on files in an idmapped mount, the system may use an improper identifier mapping, causing ownership checks to fail unexpectedly. This could potentially lead to unintended information disclosure in specific, complex scenarios.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2026-64293

8 дней назад

A flaw was found in the Linux kernel's `iommufd` component. This vulnerability arises from an incorrect size calculation during a bound-check in the `iommufd_veventq_fops_read()` function. On 32-bit systems, this error can lead to an out-of-bounds write, allowing data to be copied past the intended user-supplied buffer. This memory corruption could potentially be exploited by a local attacker to cause a denial of service or escalate privileges.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2026-64292

8 дней назад

A flaw was found in the Linux kernel's iommufd component. A local user can exploit this vulnerability by allocating large `veventq` queues, which are processed inside a spinlock. This can lead to the exhaustion of atomic memory reserves, resulting in a Denial of Service (DoS) condition.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2026-64291

8 дней назад

A flaw was found in the Linux kernel's iommufd subsystem. A local user could exploit this vulnerability by allocating excessively large event queues, leading to the exhaustion of kernel memory. This can result in a Denial of Service (DoS) for the system.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2026-64290

8 дней назад

A flaw was found in the Linux kernel's `iommufd` component. When a `copy_to_user()` operation fails within the `iommufd_fault_fops_read()` function, the system enters an infinite loop. This continuous retry consumes 100% of the CPU and holds a mutex, which can lead to a denial of service (DoS) for affected systems.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2026-64289

8 дней назад

A flaw was found in the Linux kernel. In the `iommufd` component, the `iommufd_hwpt_invalidate()` function allows a local user to provide excessively large values for `entry_num` and `entry_len` during cache invalidation. This can lead to a Denial of Service (DoS) by causing the system to become unresponsive. Specifically, large `entry_len` values can trigger a soft-lockup watchdog due to extensive memory scanning, while large `entry_num` values can cause an uninterruptible loop, pinning the CPU.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2026-64288

8 дней назад

A flaw was found in the kernel's Kernel-based Virtual Machine (KVM) component for ARM64 architectures. A race condition can occur during the invalidation of the virtual Nested Translation Cache (VNCR pseudo-TLB) when a virtual CPU (vcpu) is being brought online or offline. This can lead to a null pointer dereference, which could cause the system to crash, resulting in a denial of service.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2026-64287

8 дней назад

A flaw was found in the Kernel-based Virtual Machine (KVM) component of the Linux kernel on ARM64 systems. A highly privileged local attacker could exploit a vulnerability where the system fails to properly restrict memory access during a specific virtual machine operation. This could allow the attacker to read or write to sensitive memory areas, potentially leading to privilege escalation, where they gain unauthorized higher access, or cause a system crash (denial of service).

CVSS3: 7
EPSS: Низкий
redhat логотип

CVE-2026-64286

8 дней назад

A flaw was found in the Linux kernel's Kernel-based Virtual Machine (KVM) for arm64 architecture. The `flush_hyp_vcpu()` function, responsible for copying the host virtual CPU (vCPU) context, does not properly clear a specific internal pointer (`__hyp_running_vcpu`). This oversight allows a host to provide a value that is then improperly accessed (dereferenced) at Exception Level 2 (EL2), potentially leading to arbitrary memory access within the hypervisor. This could allow a malicious host to compromise the integrity or availability of the hypervisor.

CVSS3: 7
EPSS: Низкий
redhat логотип

CVE-2026-64285

8 дней назад

A flaw was found in the Linux kernel's Kernel-based Virtual Machine (KVM) component, specifically within the Secure Nested Paging (SNP) guest functionality. When KVM populates a guest's CPUID (Central Processor Unit Identifier) data, it may attempt to write to a source memory page that is intended to be read-only. This incorrect memory pinning could lead to memory corruption, potentially allowing an attacker to overwrite sensitive data within the kernel.

EPSS: Низкий
redhat логотип

CVE-2026-64284

8 дней назад

A flaw was found in the Linux kernel's Kernel-based Virtual Machine (KVM) for x86 systems. This vulnerability occurs when KVM handles fastpath exits, where it may fail to execute vendor-specific cleanup operations before returning control to the virtual machine's userspace. Consequently, memory written by the virtual machine might not be correctly flagged as dirty, leading to the consumption of outdated data. A local attacker with access to a virtual machine could potentially exploit this to cause data integrity issues within the virtualized environment.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2026-64283

8 дней назад

A flaw was found in the Linux kernel's Kernel-based Virtual Machine (KVM) component. An integer overflow vulnerability exists in the `guest_memfd` functionality when binding memory slots. A malicious guest operating system could exploit this by providing crafted offset and size values, leading to incorrect memory access. This could result in memory corruption, potentially allowing the guest to escalate privileges, cause a denial of service, or compromise the host system.

CVSS3: 7
EPSS: Низкий
redhat логотип

CVE-2026-64282

8 дней назад

A flaw was found in the Linux kernel's KVM (Kernel-based Virtual Machine) for arm64 architectures. A race condition between the `kvm_translate_vncr()` function and an MMU (Memory Management Unit) notifier can lead to a Page Frame Number (PFN) leak. This occurs because an early return in `kvm_translate_vncr()` fails to release a reference on a faulted-in PFN, potentially leading to resource exhaustion or information disclosure.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2026-64281

8 дней назад

A flaw was found in the Linux kernel's svcrdma component. During transport teardown, threads waiting in `svc_rdma_sq_wait()` can hang indefinitely in an uninterruptible state. This occurs because these threads are not explicitly woken up when the transport closes, leading to them continuously holding references to `svc_xprt`. Consequently, this can block the `svc_rdma_free()` function, resulting in a denial of service (DoS) condition.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2026-64280

8 дней назад

A flaw was found in the Linux kernel's `dfl-afu` FPGA driver. A local user could exploit this vulnerability by providing an excessively large length value during Direct Memory Access (DMA) mapping operations. The system incorrectly truncates this value, leading to memory corruption. This could allow a local attacker to gain elevated privileges or execute arbitrary code on the system.

CVSS3: 7
EPSS: Низкий
redhat логотип

CVE-2026-64279

8 дней назад

A flaw was found in the Linux kernel, specifically within its I2C (Inter-Integrated Circuit) core component. This vulnerability involves a race condition that occurs when an I2C adapter is being removed from the system. During this process, it is possible for the system to attempt to access the adapter's memory after it has already been released. A local attacker could potentially exploit this issue, leading to system instability, unauthorized information access, or the execution of malicious code.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2026-64278

8 дней назад

A flaw was found in the Linux kernel's i2c: imx-lpi2c driver. During system suspend and resume operations, certain I2C client drivers may attempt to perform I2C transfers while the underlying hardware resources are temporarily unavailable. This can occur because the I2C adapter is not properly marked as suspended, allowing transfers to be initiated at an inappropriate time. The consequence of this vulnerability is a system hang, which can lead to a denial of service.

EPSS: Низкий
redhat логотип

CVE-2026-64277

8 дней назад

A flaw was found in the Linux kernel's `synaptics-rmi4` input driver. The `rmi_f3a_map_gpios()` function incorrectly allocates memory for the `gpio_key_map`, making it smaller than required. This allows a device reporting a specific `gpio_count` value to trigger an out-of-bounds read, leading to information disclosure by leaking adjacent slab memory to user space. Additionally, a local user with access to the `evdev` node can exploit this vulnerability to perform out-of-bounds writes with caller-controlled values, which may lead to further system compromise.

CVSS3: 7
EPSS: Низкий
redhat логотип

CVE-2026-64276

8 дней назад

A flaw was found in the Linux kernel's synaptics-rmi4 input driver. This vulnerability occurs because the driver incorrectly allocates memory for a keymap, leading to an out-of-bounds memory access. A local user with access to a specially crafted input device could exploit this to read or write to unauthorized memory regions. This could result in information disclosure or potentially allow for further system compromise.

CVSS3: 7
EPSS: Низкий
redhat логотип

CVE-2026-64275

8 дней назад

A flaw was found in the Linux kernel's Elan I2C touchpad driver. This vulnerability occurs when the driver receives invalid zero values for touchpad dimensions from device firmware or the device tree, or when a calculated width is too small. A local attacker with control over device input or a malicious device could exploit this to trigger a division-by-zero error, leading to a kernel panic and a denial of service.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2026-64294

A flaw was found in the Linux kernel's memory management subsystem. This vulnerability arises from incorrect handling of file ownership checks within idmapped mounts, a feature that allows remapping user and group IDs. When certain memory operations are performed on files in an idmapped mount, the system may use an improper identifier mapping, causing ownership checks to fail unexpectedly. This could potentially lead to unintended information disclosure in specific, complex scenarios.

CVSS3: 5.5
0%
Низкий
8 дней назад
redhat логотип
CVE-2026-64293

A flaw was found in the Linux kernel's `iommufd` component. This vulnerability arises from an incorrect size calculation during a bound-check in the `iommufd_veventq_fops_read()` function. On 32-bit systems, this error can lead to an out-of-bounds write, allowing data to be copied past the intended user-supplied buffer. This memory corruption could potentially be exploited by a local attacker to cause a denial of service or escalate privileges.

CVSS3: 5.5
0%
Низкий
8 дней назад
redhat логотип
CVE-2026-64292

A flaw was found in the Linux kernel's iommufd component. A local user can exploit this vulnerability by allocating large `veventq` queues, which are processed inside a spinlock. This can lead to the exhaustion of atomic memory reserves, resulting in a Denial of Service (DoS) condition.

CVSS3: 5.5
0%
Низкий
8 дней назад
redhat логотип
CVE-2026-64291

A flaw was found in the Linux kernel's iommufd subsystem. A local user could exploit this vulnerability by allocating excessively large event queues, leading to the exhaustion of kernel memory. This can result in a Denial of Service (DoS) for the system.

CVSS3: 5.5
0%
Низкий
8 дней назад
redhat логотип
CVE-2026-64290

A flaw was found in the Linux kernel's `iommufd` component. When a `copy_to_user()` operation fails within the `iommufd_fault_fops_read()` function, the system enters an infinite loop. This continuous retry consumes 100% of the CPU and holds a mutex, which can lead to a denial of service (DoS) for affected systems.

CVSS3: 5.5
0%
Низкий
8 дней назад
redhat логотип
CVE-2026-64289

A flaw was found in the Linux kernel. In the `iommufd` component, the `iommufd_hwpt_invalidate()` function allows a local user to provide excessively large values for `entry_num` and `entry_len` during cache invalidation. This can lead to a Denial of Service (DoS) by causing the system to become unresponsive. Specifically, large `entry_len` values can trigger a soft-lockup watchdog due to extensive memory scanning, while large `entry_num` values can cause an uninterruptible loop, pinning the CPU.

CVSS3: 5.5
0%
Низкий
8 дней назад
redhat логотип
CVE-2026-64288

A flaw was found in the kernel's Kernel-based Virtual Machine (KVM) component for ARM64 architectures. A race condition can occur during the invalidation of the virtual Nested Translation Cache (VNCR pseudo-TLB) when a virtual CPU (vcpu) is being brought online or offline. This can lead to a null pointer dereference, which could cause the system to crash, resulting in a denial of service.

CVSS3: 5.5
0%
Низкий
8 дней назад
redhat логотип
CVE-2026-64287

A flaw was found in the Kernel-based Virtual Machine (KVM) component of the Linux kernel on ARM64 systems. A highly privileged local attacker could exploit a vulnerability where the system fails to properly restrict memory access during a specific virtual machine operation. This could allow the attacker to read or write to sensitive memory areas, potentially leading to privilege escalation, where they gain unauthorized higher access, or cause a system crash (denial of service).

CVSS3: 7
0%
Низкий
8 дней назад
redhat логотип
CVE-2026-64286

A flaw was found in the Linux kernel's Kernel-based Virtual Machine (KVM) for arm64 architecture. The `flush_hyp_vcpu()` function, responsible for copying the host virtual CPU (vCPU) context, does not properly clear a specific internal pointer (`__hyp_running_vcpu`). This oversight allows a host to provide a value that is then improperly accessed (dereferenced) at Exception Level 2 (EL2), potentially leading to arbitrary memory access within the hypervisor. This could allow a malicious host to compromise the integrity or availability of the hypervisor.

CVSS3: 7
0%
Низкий
8 дней назад
redhat логотип
CVE-2026-64285

A flaw was found in the Linux kernel's Kernel-based Virtual Machine (KVM) component, specifically within the Secure Nested Paging (SNP) guest functionality. When KVM populates a guest's CPUID (Central Processor Unit Identifier) data, it may attempt to write to a source memory page that is intended to be read-only. This incorrect memory pinning could lead to memory corruption, potentially allowing an attacker to overwrite sensitive data within the kernel.

0%
Низкий
8 дней назад
redhat логотип
CVE-2026-64284

A flaw was found in the Linux kernel's Kernel-based Virtual Machine (KVM) for x86 systems. This vulnerability occurs when KVM handles fastpath exits, where it may fail to execute vendor-specific cleanup operations before returning control to the virtual machine's userspace. Consequently, memory written by the virtual machine might not be correctly flagged as dirty, leading to the consumption of outdated data. A local attacker with access to a virtual machine could potentially exploit this to cause data integrity issues within the virtualized environment.

CVSS3: 5.5
0%
Низкий
8 дней назад
redhat логотип
CVE-2026-64283

A flaw was found in the Linux kernel's Kernel-based Virtual Machine (KVM) component. An integer overflow vulnerability exists in the `guest_memfd` functionality when binding memory slots. A malicious guest operating system could exploit this by providing crafted offset and size values, leading to incorrect memory access. This could result in memory corruption, potentially allowing the guest to escalate privileges, cause a denial of service, or compromise the host system.

CVSS3: 7
0%
Низкий
8 дней назад
redhat логотип
CVE-2026-64282

A flaw was found in the Linux kernel's KVM (Kernel-based Virtual Machine) for arm64 architectures. A race condition between the `kvm_translate_vncr()` function and an MMU (Memory Management Unit) notifier can lead to a Page Frame Number (PFN) leak. This occurs because an early return in `kvm_translate_vncr()` fails to release a reference on a faulted-in PFN, potentially leading to resource exhaustion or information disclosure.

CVSS3: 5.5
0%
Низкий
8 дней назад
redhat логотип
CVE-2026-64281

A flaw was found in the Linux kernel's svcrdma component. During transport teardown, threads waiting in `svc_rdma_sq_wait()` can hang indefinitely in an uninterruptible state. This occurs because these threads are not explicitly woken up when the transport closes, leading to them continuously holding references to `svc_xprt`. Consequently, this can block the `svc_rdma_free()` function, resulting in a denial of service (DoS) condition.

CVSS3: 5.5
0%
Низкий
8 дней назад
redhat логотип
CVE-2026-64280

A flaw was found in the Linux kernel's `dfl-afu` FPGA driver. A local user could exploit this vulnerability by providing an excessively large length value during Direct Memory Access (DMA) mapping operations. The system incorrectly truncates this value, leading to memory corruption. This could allow a local attacker to gain elevated privileges or execute arbitrary code on the system.

CVSS3: 7
0%
Низкий
8 дней назад
redhat логотип
CVE-2026-64279

A flaw was found in the Linux kernel, specifically within its I2C (Inter-Integrated Circuit) core component. This vulnerability involves a race condition that occurs when an I2C adapter is being removed from the system. During this process, it is possible for the system to attempt to access the adapter's memory after it has already been released. A local attacker could potentially exploit this issue, leading to system instability, unauthorized information access, or the execution of malicious code.

CVSS3: 5.5
0%
Низкий
8 дней назад
redhat логотип
CVE-2026-64278

A flaw was found in the Linux kernel's i2c: imx-lpi2c driver. During system suspend and resume operations, certain I2C client drivers may attempt to perform I2C transfers while the underlying hardware resources are temporarily unavailable. This can occur because the I2C adapter is not properly marked as suspended, allowing transfers to be initiated at an inappropriate time. The consequence of this vulnerability is a system hang, which can lead to a denial of service.

0%
Низкий
8 дней назад
redhat логотип
CVE-2026-64277

A flaw was found in the Linux kernel's `synaptics-rmi4` input driver. The `rmi_f3a_map_gpios()` function incorrectly allocates memory for the `gpio_key_map`, making it smaller than required. This allows a device reporting a specific `gpio_count` value to trigger an out-of-bounds read, leading to information disclosure by leaking adjacent slab memory to user space. Additionally, a local user with access to the `evdev` node can exploit this vulnerability to perform out-of-bounds writes with caller-controlled values, which may lead to further system compromise.

CVSS3: 7
0%
Низкий
8 дней назад
redhat логотип
CVE-2026-64276

A flaw was found in the Linux kernel's synaptics-rmi4 input driver. This vulnerability occurs because the driver incorrectly allocates memory for a keymap, leading to an out-of-bounds memory access. A local user with access to a specially crafted input device could exploit this to read or write to unauthorized memory regions. This could result in information disclosure or potentially allow for further system compromise.

CVSS3: 7
0%
Низкий
8 дней назад
redhat логотип
CVE-2026-64275

A flaw was found in the Linux kernel's Elan I2C touchpad driver. This vulnerability occurs when the driver receives invalid zero values for touchpad dimensions from device firmware or the device tree, or when a calculated width is too small. A local attacker with control over device input or a malicious device could exploit this to trigger a division-by-zero error, leading to a kernel panic and a denial of service.

CVSS3: 5.5
0%
Низкий
8 дней назад

Уязвимостей на страницу