|
1171
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
perf: Make sure to use pmu_ctx->pmu for groups
Oliver reported that x86_pmu_del() ended up doing an out-of-bound memory access
wh…
|
CWE-125
Out-of-bounds Read
|
CVE-2026-31528
|
2026-04-29 03:00 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1172
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
cxl/region: Fix leakage in __construct_region()
Failing the first sysfs_update_group() needs to explicitly
kfree the resource as …
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2026-31529
|
2026-04-29 02:57 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1173
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
cxl/port: Fix use after free of parent_port in cxl_detach_ep()
cxl_detach_ep() is called during bottom-up removal when all CXL me…
|
CWE-416
Use After Free
|
CVE-2026-31530
|
2026-04-29 02:53 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1174
|
9.8 |
CRITICAL
Network
|
rust-openssl_project
|
rust-openssl
|
rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.24 to before 0.10.78, the FFI trampolines behind SslContextBuilder::set_psk_client_callback, set_psk_server_callbac…
|
CWE-126 CWE-130
Buffer Over-read Improper Handling of Length Parameter Inconsistency
|
CVE-2026-41898
|
2026-04-29 02:45 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1175
|
9.8 |
CRITICAL
Network
|
rust-openssl_project
|
rust-openssl
|
rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.39 to before 0.10.78, EVP_DigestFinal() always writes EVP_MD_CTX_size(ctx) to the out buffer. If out is smaller th…
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-41681
|
2026-04-29 02:44 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1176
|
9.8 |
CRITICAL
Network
|
rust-openssl_project
|
rust-openssl
|
rust-openssl provides OpenSSL bindings for the Rust programming language. From to before 0.10.78, aes::unwrap_key() contains an incorrect assertion: it checks that out.len() + 8 <= in_.len(), but t…
|
CWE-787
Out-of-bounds Write
|
CVE-2026-41678
|
2026-04-29 02:41 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1177
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
ipv4: nexthop: allocate skb dynamically in rtm_get_nexthop()
When querying a nexthop object via RTM_GETNEXTHOP, the kernel curren…
|
NVD-CWE-noinfo
|
CVE-2026-31531
|
2026-04-29 02:38 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1178
|
9.1 |
CRITICAL
Network
|
rust-openssl_project
|
rust-openssl
|
rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.0 to before 0.10.78, the *_from_pem_callback APIs did not validate the length returned by the user's callback. A pa…
|
CWE-125 CWE-1284
Out-of-bounds Read Improper Validation of Specified Quantity in Input
|
CVE-2026-41677
|
2026-04-29 02:34 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1179
|
9.8 |
CRITICAL
Network
|
rust-openssl_project
|
rust-openssl
|
rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.27 to before 0.10.78, Deriver::derive (and PkeyCtxRef::derive) sets len = buf.len() and passes it as the in/out len…
|
CWE-131 CWE-787
Incorrect Calculation of Buffer Size Out-of-bounds Write
|
CVE-2026-41676
|
2026-04-29 02:30 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1180
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: renesas_usb3: validate endpoint index in standard request handlers
The GET_STATUS and SET/CLEAR_FEATURE handlers ext…
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-31615
|
2026-04-29 02:29 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|