|
1131
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
netfilter: xt_CT: drop pending enqueued packets on template removal
Templates refer to objects that can go away while packets are…
|
NVD-CWE-noinfo
|
CVE-2026-23391
|
2026-04-25 03:38 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1132
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta:
netfilter: xt_CT: descartar paquetes pendientes encolados al eliminar la plantilla
Las plantillas se refieren a objetos que pued…
|
NVD-CWE-noinfo
|
CVE-2026-23391
|
2026-04-25 03:38 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1133
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
tracing/dma: Cap dma_map_sg tracepoint arrays to prevent buffer overflow
The dma_map_sg tracepoint can trigger a perf buffer over…
|
CWE-787
Out-of-bounds Write
|
CVE-2026-23390
|
2026-04-25 03:32 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1134
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta:
tracing/dma: Limitar los arrays del tracepoint dma_map_sg para prevenir el desbordamiento de búfer
El tracepoint dma_map_sg pued…
|
CWE-787
Out-of-bounds Write
|
CVE-2026-23390
|
2026-04-25 03:32 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1135
|
9.1 |
CRITICAL
Network
|
openssl
|
openssl
|
Issue summary: Applications using AES-CFB128 encryption or decryption on
systems with AVX-512 and VAES support can trigger an out-of-bounds read
of up to 15 bytes when processing partial cipher block…
|
CWE-125
Out-of-bounds Read
|
CVE-2026-28386
|
2026-04-25 03:28 |
2026-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1136
|
7.5 |
HIGH
Network
|
apache
|
log4j
|
Apache Log4j's JsonTemplateLayout https://logging.apache.org/log4j/2.x/manual/json-template-layout.html , in versions up to and including 2.25.3, produces invalid JSON output when log events contain…
|
CWE-116
Improper Encoding or Escaping of Output
|
CVE-2026-34481
|
2026-04-25 03:24 |
2026-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1137
|
7.5 |
HIGH
Network
|
apache
|
log4j
|
Apache Log4j Core's XmlLayout https://logging.apache.org/log4j/2.x/manual/layouts.html#XmlLayout , in versions up to and including 2.25.3, fails to sanitize characters forbidden by the XML 1.0 spec…
|
CWE-116
Improper Encoding or Escaping of Output
|
CVE-2026-34480
|
2026-04-25 03:21 |
2026-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1138
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
can: bcm: fix locking for bcm_op runtime updates
Commit c2aba69d0c36 ("can: bcm: add locking for bcm_op runtime updates")
added a…
|
CWE-667
Improper Locking
|
CVE-2026-23362
|
2026-04-25 03:21 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1139
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta:
can: bcm: corregir el bloqueo para las actualizaciones en tiempo de ejecución de bcm_op
El commit c2aba69d0c36 ('can: bcm: añadi…
|
CWE-667
Improper Locking
|
CVE-2026-23362
|
2026-04-25 03:21 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1140
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
crypto: ccp - Fix use-after-free on error path
In the error path of sev_tsm_init_locked(), the code dereferences 't'
after it has…
|
CWE-416
Use After Free
|
CVE-2026-23344
|
2026-04-25 03:17 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|