CVE-2026-76654 lets a privileged attacker steal or relay the kubelet account hash on Windows nodes.
By tarpit
CVE-2026-76183 lets attackers sidestep authentication rules on WebSocket endpoints across long-supported Tomcat lines.
By tarpit
CVE-2026-94422 let apps bypass D-Bus message filters and run code outside the sandbox.
By tarpit
oss-security carried a high-severity libexpat release, an OpenStack Amphora root RCE path, and two glibc dynamic-loader issues affecting AT_SECURE programs.
By tarpit
An AI-assisted lattice reduction forces HAWK out of the NIST signature round while quasipolynomial results leave Classic McEliece's proposed sizes without defenders.
By tarpit
The mail transfer agent closes four flaws dating to 2014, with no workaround short of upgrading.
By nonce
DirtyAH6, TUNderflow, PPPoEject, and DiagSpill turn unprivileged access into root on systems with common networking features; fixes are in stable trees.
By nonce
Researchers describe an unreported format-string bug in certificate import with debugging on, and urge tracking for an already-shipped RSASSA-PSS overflow.
By nonce
HAWK’s withdrawal after an AI-assisted lattice break and fresh holdout claims against Classic McEliece force a hard look at security margins while NIST timelines keep moving.
By nonce
CVE-2026-89775 leaves a freed host page writable to the guest when nested virtualization is enabled, enabling cloud breakout and local root on some setups.
By tarpit
NLnet Labs ships a security release fixing a heap overflow that can yield remote code execution, plus high-severity DNSSEC and CNAME issues.
By tarpit
Fixes span use-after-free bugs, DNSSEC validation errors, amplification paths, and unauthenticated crashes across recursive and authoritative roles.
By tarpit
CVE-2026-79993 skips auth and permission checks on the internal deleteContainer opcode in 3.8 and 3.9 releases.
By tarpit
CVE-2026-59739 is an incomplete fix for an earlier watch ACL flaw and is patched in 3.8.7 and 3.9.6.
By tarpit
CVE-2026-82049 lets crafted archives alter or disclose files outside the extraction directory on CPython 3.13 and earlier.
By tarpit
Untrusted files opened in modes other than Emacs Lisp can still trigger arbitrary code via flymake.
By tarpit
A local attacker who controls boot configuration can clear GRUB's file-verifier list and load unsigned modules while lockdown still reports enabled.
By tarpit
CVE-2026-87464 is a use-after-free fixed in Chrome 153.0.8010.36; unpatched Chromium builds, including Debian’s, remain exposed.
By tarpit
CVE-2026-80351 turns tenant-controlled Maven repositories into arbitrary code execution inside the Camel K operator pod.
By tarpit
Stable and legacy releases fix medium-impact defects, some decades old, reported by Qualys and OpenAI Security.
By nonce
The security release fixes multiple memory-safety flaws and requires relays to upgrade before authorities reject legacy descriptors.
By tarpit
Two out-of-bounds bugs in the userspace block backend give a malicious VM a direct path to host compromise.
By tarpit
ZcopyReaper lets any local user escalate with only RDS enabled; NebuSec released automated exploits for the full set.
By nonce
Four new CVEs cover failed-helper hooks, source-path TOCTOU, subdir symlink escape, and missing O_CLOEXEC; wall gets another hostname sanitization fix.
By tarpit
The release closes out-of-bounds reads, integer overflows, and buffer overflows across regexp, dictionary, URI, XPointer, and I/O paths.
By tarpit
Three related bugs let authenticated users reach cloud metadata and turn blind SSRF into full-read exfiltration via web-download and HTTP image APIs.
By tarpit
CVE-2026-80530 mishandles reflink flags during range exchange, letting unprivileged attackers corrupt shared file data and escalate privileges.
By tarpit
GNOME Remote Desktop and KDE krdp embeds are in scope when an administrator has enabled the service; client-only FreeRDP is not.
By tarpit
Integer overflows in ZFS, SquashFS, EXT4, and a shell move command can under-allocate heap buffers through U-Boot 2026.01-rc4.
By tarpit
CVE-2026-8715 in versions 1.3.0–1.4.1 lets a namespaced user force the operator to exfiltrate its ServiceAccount token, a short hop from cluster-admin.
By tarpit
The fix closes a setup-time traversal that could let a malicious app image plant files on the host via Flatpak and similar tools.
By nonce
Before 9.2.1013, huge terminal resize requests updated state but not clamped screen storage, so later output could write past the buffer.
By tarpit
An off-by-one error in Apache Tomcat’s RewriteValve restarts rule processing at the wrong point, undermining access checks that depend on rewrite order.
By tarpit
Path ordering could let requests slip past more restrictive access rules on shorter prefixes.
By tarpit
Flaws in the RGB control suite’s custom network protocol can fully take over systems when the server runs with default privileges.
By tarpit
Preliminary review of eprint 2026/1630 finds the claimed quasipolynomial approach above designed cost for every parameter set.
By tarpit
Crafted remote-style file names can execute arbitrary local commands during connection setup, with no successful remote login required.
By tarpit
Four CephX CVEs fixed in Ceph 19.2.6 and 20.2.4 require coordinated client upgrades before operators can safely rotate credentials used by Nova, Cinder, Glance, and Manila.
By tarpit
Opening a crafted file can run attacker code; upstream fixed it and Gentoo backported to 28.2.
By nonce