freenode

← digests

Linux SCTP UAF and Apache Fory deserialization flaws

Security & Cryptography2026-08-08

A high-severity Linux kernel use-after-free in SCTP handling drew the bulk of attention, with container escape implications still under discussion. Several moderate Apache Fory issues and smaller utility and Perl module flaws rounded out the day's disclosures.

Linux SCTP ASCONF transport use-after-free

Public disclosure on oss-security detailed CVE-2026-64564, a use-after-free in the Linux kernel SCTP ASCONF transport path. The issue is rated CVSS 8.5 and can enable local privilege escalation together with container escape. Mitigation discussion among the four participants remains ongoing.

Apache Fory C++ polymorphic smart-pointer type confusion

Apache Fory published CVE-2026-71558 for a heap type confusion that arises during C++ polymorphic smart-pointer deserialization. The flaw may permit remote code execution when untrusted data is processed.

Buffer overflows in rpcinfo

Two buffer-overflow vulnerabilities, CVE-2026-16277 and CVE-2026-16461, were reported against rpcinfo. Fixes have already been noted for FreeBSD, Linux NFS, NetBSD, and illumos.

Apache Fory C++ struct deserializer out-of-bounds read

CVE-2026-71560 covers an out-of-bounds heap read in the Apache Fory C++ struct deserializer tagged-int fast-path. The moderate severity issue is fixed in version 1.5.0.

Perl Imager EXIF heap over-read

CVE-2026-19082 affects Imager versions from 0.45_02 before 1.034 for Perl. Zero-count ASCII EXIF entries can cause strlen() to over-read adjacent heap bytes inside copy_string_tags.

File::Rotate::Simple dangling symlink creation

CVE-2026-17435 reports that File::Rotate::Simple versions before 0.4.0 for Perl create the target of a dangling symlink when rotating files. The behavior can be abused in environments that allow untrusted symlink placement.

Apache Fory Go meta-string decoder panic

CVE-2026-71559 describes an uncaught panic in the Apache Fory Go meta-string decoder that can be triggered by untrusted metadata. The resulting remote denial of service is fixed in version 1.5.0.