|
391
|
6.7 |
MEDIUM
Local
|
mediatek
|
mt6768_firmware mt6789_firmware mt6877_firmware mt6899_firmware mt6989_firmware mt6991_firmware mt6993_firmware mt8196_firmware mt8367_firmware mt8766_firmware mt8768_fi…
|
In geniezone, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privileg…
Update
|
CWE-125
Out-of-bounds Read
|
CVE-2026-20447
|
2026-05-7 21:43 |
2026-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
392
|
6.7 |
MEDIUM
Local
|
mediatek
|
mt6765_firmware mt6768_firmware mt6789_firmware mt6877_firmware mt6897_firmware mt6899_firmware mt6989_firmware mt6991_firmware mt6993_firmware mt8367_firmware mt8766_fi…
|
In geniezone, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege if a malicious actor has already obtained the System priv…
Update
|
CWE-280
Improper Handling of Insufficient Permissions or Privileges
|
CVE-2026-20448
|
2026-05-7 21:43 |
2026-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
393
|
6.5 |
MEDIUM
Adjacent
|
mediatek
|
mt6763_firmware mt6765_firmware mt6767_firmware mt6768_firmware mt6769_firmware mt6771_firmware mt6779_firmware mt6781_firmware mt6783_firmware mt6785_firmware mt6789_fi…
|
In Modem, there is a possible system crash due to a heap buffer overflow. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with n…
Update
|
CWE-120
Classic Buffer Overflow
|
CVE-2026-20449
|
2026-05-7 21:43 |
2026-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
394
|
6.5 |
MEDIUM
Adjacent
|
mediatek
|
mt2735_firmware mt2737_firmware mt6833_firmware mt6835_firmware mt6853_firmware mt6855_firmware mt6858_firmware mt6873_firmware mt6875_firmware mt6877_firmware mt6878_fi…
|
In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with…
Update
|
CWE-617
Reachable Assertion
|
CVE-2026-20450
|
2026-05-7 21:42 |
2026-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
395
|
6.7 |
MEDIUM
Local
|
mediatek
|
mt8115_firmware mt8186_firmware mt8188_firmware mt8196_firmware mt8365_firmware mt8367_firmware mt8370_firmware mt8371_firmware mt8390_firmware mt8391_firmware mt8395_fi…
|
In slbc, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interacti…
Update
|
CWE-843
Type Confusion
|
CVE-2026-20451
|
2026-05-7 21:42 |
2026-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
396
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
f2fs: fix UAF caused by decrementing sbi->nr_pages[] in f2fs_write_end_io()
The xfstests case "generic/107" and syzbot have both …
Update
|
CWE-416
Use After Free
|
CVE-2026-31715
|
2026-05-7 15:16 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
397
|
8.8 |
HIGH
Network
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
smb: client: validate the whole DACL before rewriting it in cifsacl
build_sec_desc() and id_mode_to_cifs_acl() derive a DACL poin…
Update
|
NVD-CWE-noinfo
|
CVE-2026-31709
|
2026-05-7 15:16 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
398
|
7.1 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
io_uring/net: fix slab-out-of-bounds read in io_bundle_nbufs()
sqe->len is __u32 but gets stored into sr->len which is int. When
…
Update
|
CWE-125
Out-of-bounds Read
|
CVE-2026-31774
|
2026-05-7 11:29 |
2026-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
399
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
ALSA: ctxfi: Don't enumerate SPDIF1 at DAIO initialization
The recent refactoring of xfi driver changed the assignment of
atc->da…
Update
|
NVD-CWE-noinfo
|
CVE-2026-31775
|
2026-05-7 11:28 |
2026-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
400
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
ALSA: ctxfi: Fix missing SPDIFI1 index handling
SPDIF1 DAIO type isn't properly handled in daio_device_index() for
hw20k2, and it…
Update
|
CWE-129
Improper Validation of Array Index
|
CVE-2026-31776
|
2026-05-7 11:27 |
2026-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|