Four U-Boot filesystem overflows risk pre-boot code execution
Integer overflows in ZFS, SquashFS, EXT4, and a shell move command can under-allocate heap buffers through U-Boot 2026.01-rc4.
By tarpitInteger overflows in ZFS, SquashFS, EXT4, and a shell move command can under-allocate heap buffers through U-Boot 2026.01-rc4.
By tarpitCVE-2026-8715 in versions 1.3.0–1.4.1 lets a namespaced user force the operator to exfiltrate its ServiceAccount token, a short hop from cluster-admin.
By tarpitThe fix closes a setup-time traversal that could let a malicious app image plant files on the host via Flatpak and similar tools.
By nonceBefore 9.2.1013, huge terminal resize requests updated state but not clamped screen storage, so later output could write past the buffer.
By tarpitAn off-by-one error in Apache Tomcat’s RewriteValve restarts rule processing at the wrong point, undermining access checks that depend on rewrite order.
By tarpitPath ordering could let requests slip past more restrictive access rules on shorter prefixes.
By tarpitFlaws in the RGB control suite’s custom network protocol can fully take over systems when the server runs with default privileges.
By tarpitPreliminary review of eprint 2026/1630 finds the claimed quasipolynomial approach above designed cost for every parameter set.
By tarpitCrafted remote-style file names can execute arbitrary local commands during connection setup, with no successful remote login required.
By tarpitFour CephX CVEs fixed in Ceph 19.2.6 and 20.2.4 require coordinated client upgrades before operators can safely rotate credentials used by Nova, Cinder, Glance, and Manila.
By tarpitOpening a crafted file can run attacker code; upstream fixed it and Gentoo backported to 28.2.
By nonceTentacle 20.2.4 and Squid 19.2.6 fix a high-severity AES-CBC flaw in CephX and an authorization bug that could expose LUKS passphrases and cephadm SSH keys.
By tarpitResearcher Erica Windisch publicized flaws she says let unprivileged users manipulate pools and break out of user namespaces, after notifying CERT.
By tarpitIETF makes hybrid ML-KEM key agreement a Proposed Standard just as an AI-found attack kills HAWK and pure-ML-KEM last call draws public process and security objections.
By nonceAndrew Tridgell’s release closes a large batch of security holes and ships patch sets for the 3.2.7 and 3.4.1 lines used by long-term distro builds.
By nonceThree important-severity flaws let DAG authors run code in components Airflow’s security model says must stay clean of author-controlled execution.
By tarpitThe stable update closes symlink and path-traversal flaws that broke app isolation, with CVE IDs still pending.
By tarpitTwo flaws in multi-pool setups let tenants overlap other tenants' zones, enabling hijacks and a deterministic mDNS denial of service.
By tarpitAn AI-found key-recovery attack forced HAWK out of NIST's signature on-ramp just as the IETF SSH working group split over pure and hybrid ML-DSA drafts, exposing both technical fragility and process strain under compressed post-quantum timelines.
By nonceCVE-2026-64561 corrupts host shadow pages from untrusted guests when nested virtualization is exposed, especially on multi-tenant clouds.
By tarpitCVE-2026-52682 lets a crafted query drive up memory and CPU use across Authoritative Server, Recursor, and dnsdist.
By tarpitA use-after-free in Dynamic Address Reconfiguration, CVE-2026-64564, has been fixed after more than a decade in the tree.
By tarpitThe July release patches signature, AEAD, keystore, and certificate-validation flaws in a library embedded across countless JVM applications.
By tarpitVersion 2.0.9 closes two heap memory bugs reachable from a malicious font server, one an incomplete fix from 2014.
By tarpitAn Anthropic lattice break that halved HAWK’s dimension, and an IETF call for ML-DSA drafts that immediately invoked machine-assisted attacks, have turned AI from a future worry into a live input on which post-quantum algorithms survive standardization.
By tarpitStaff users could trigger disk writes or network requests via GDAL rasters in admin filters; four CVEs land in 5.2.17 and 6.0.8.
By tarpitCVE-2026-62354 affected NiFi 1.10.0 through 2.10.0; version 2.11.0 now requires write access for Parameter Context validation.
By tarpitThe agency plans a single private-key format for the upcoming HQC-KEM standard, departing from the dual formats allowed in ML-KEM.
By tarpitA nested inductive projection flaw accepted axiom-free proofs of 0 = 1 until a late July nightly fix.
By tarpitLongtime security coordinator Michael Catanzaro will step down in November and is seeking a successor.
By tarpitFour branches ship fixes for PostgreSQL injection, Phar crashes, libgd, and a BCMath flaw limited to newer lines.
By tarpitMemory-safety and logic bugs remain unfixed in a widely vendored C JSON parser after years of stalled maintenance.
By tarpitVersions 9.2.15 and 10.1.4 close ACL bypasses, header smuggling paths, and dozens of other issues across 9.x and 10.x.
By tarpitUnauthenticated attackers can leak server secrets, and potentially escalate to RCE, on apps using libvips with untrusted uploads.
By nonceThe SSHM chairs met an unanswered objection to solo post-quantum signatures with moderation threats instead of discussion. D. J. Bernstein's RFC 2026 complaint reads IETF's own rules back to them: address objections and measure consensus, do not gavel them away. The call for adoption closes 17 August.
By staffAnthropic says its Claude Mythos Preview model found the key-recovery attack largely on its own, in about 60 hours for roughly $100,000 in compute. Steve Weis posted it to pqc-forum, Daniel Apon confirmed the math independently, and the HAWK team helped verify it. HAWK is a NIST candidate, not deployed, so no software has to change.
By nonceSix advisories close privilege-escalation and crash bugs across years of Xen releases, several reachable from untrusted guests.
By tarpitCVE-2026-64531 lets an unprivileged user with network-namespace control turn oversized nested actions into kernel code execution on common distro configs.
By nonceSame-day HIGH batches from Unbound, BIND, and PowerDNS show wildcard label logic and new encrypted paths failing in parallel across the software that is supposed to enforce DNS integrity.
By tarpitUnsanitized ntp_server values let project managers run arbitrary commands during ramdisk startup.
By tarpit