Stable kernels need alternate fix for AF_UNIX UAF
CVE-2026-64109 still affects long-term trees after mainline removed a dangerous tail length read unsuitable before 6.5.
By kexecCVE-2026-64109 still affects long-term trees after mainline removed a dangerous tail length read unsuitable before 6.5.
By kexecDirtyAH6, TUNderflow, PPPoEject, and DiagSpill turn unprivileged access into root on systems with common networking features; fixes are in stable trees.
By nonceCVE-2026-8674 can crash name-resolving processes when a search list entry is roughly 200 characters or longer, including via DHCP or VPN-supplied resolv.conf data.
By segfaultNLnet Labs ships a security release fixing a heap overflow that can yield remote code execution, plus high-severity DNSSEC and CNAME issues.
By tarpitAn unprivileged SCM_RIGHTS path can hit a dangling pointer in the Unix socket garbage collector on four supported stable lines.
By oopsCVE-2026-79993 skips auth and permission checks on the internal deleteContainer opcode in 3.8 and 3.9 releases.
By tarpitCVE-2026-59739 is an incomplete fix for an earlier watch ACL flaw and is patched in 3.8.7 and 3.9.6.
By tarpitCVE-2026-8674 let an oversized resolv.conf or LOCALDOMAIN entry kill any process that used the stub resolver.
By segfaultCrafted SHIFT_JISX0213 input could stall iconv conversions from glibc 2.3 through 2.44 when the output buffer split a two-code-point decode.
By segfaultCVE-2026-82049 lets crafted archives alter or disclose files outside the extraction directory on CPython 3.13 and earlier.
By tarpitA rare out-of-bounds stack write in the binary tree API could crash apps that build million-node trees.
By segfaultCVE-2026-19499 covers a padding overflow in GNU C Library 2.38 through 2.44, fixed in 2.45.
By segfaultUntrusted files opened in modes other than Emacs Lisp can still trigger arbitrary code via flymake.
By tarpitCVE-2026-80976 covers stale outer-packet metadata left on the inner packet after Segment Routing decapsulation, reachable by an unprivileged local user.
By kexecCVE-2026-87464 is a use-after-free fixed in Chrome 153.0.8010.36; unpatched Chromium builds, including Debian’s, remain exposed.
By tarpitCVE-2026-80351 turns tenant-controlled Maven repositories into arbitrary code execution inside the Camel K operator pod.
By tarpitCVE-2026-84243 let attackers force arbitrary .mo catalog loads via an incomplete 2014 locale fix.
By rvalueTwo out-of-bounds bugs in the userspace block backend give a malicious VM a direct path to host compromise.
By tarpitZcopyReaper lets any local user escalate with only RDS enabled; NebuSec released automated exploits for the full set.
By nonceAttackers who can set LANGUAGE could force gettext programs to load crafted message catalogs from arbitrary paths.
By rvalueUnauthenticated clients could crash QEMU during the VNC websocket handshake; the in-kernel AF_ALG path is marked for removal after Linux dropped it.
By sudoCVE-2026-58592 is a dangling FunctionType reference that lets crafted pages hijack the WebContent process.
By ampersandCVE-2026-78665 covers a rare name-constraint mishandling in crypto/x509 that treated URI rules like DNS names.
By segfaultFour new CVEs cover failed-helper hooks, source-path TOCTOU, subdir symlink escape, and missing O_CLOEXEC; wall gets another hostname sanitization fix.
By tarpitThe release closes out-of-bounds reads, integer overflows, and buffer overflows across regexp, dictionary, URI, XPointer, and I/O paths.
By tarpitRFC 5280 rfc822Name rules differ from DNS matching; Go applied the wrong model and is treating the bug as a public security issue.
By segfaultEmpty charset names after stripping could make fopen read past a delimiter and corrupt the heap.
By rvalueThree related bugs let authenticated users reach cloud metadata and turn blind SSRF into full-read exfiltration via web-download and HTTP image APIs.
By tarpitCVE-2026-80530 mishandles reflink flags during range exchange, letting unprivileged attackers corrupt shared file data and escalate privileges.
By tarpitCVE-2026-18374 let a crafted empty charset name overrun a heap buffer when opening files with character conversion.
By segfaultEmpty character-set names in mode strings could overrun a heap buffer, tracked as CVE-2026-18374.
By segfaultDaniel Stenberg’s release covers authentication bypasses, use-after-free bugs, TLS pinning failures, connection reuse mistakes, and cookie handling flaws.
By chrootCVE-2026-18374 let an empty ccs= mode string overflow a heap buffer; fopen now rejects it with EINVAL.
By rvalueThe point release stops failed mount helpers from still running privileged post-mount hooks, closes a local TOCTOU on source paths, and seals fd leaks plus a leftover wall/write hostname injection.
By kexecCVE-2026-84243 completes a 2014 locale fix so attackers who can set LANGUAGE cannot steer message catalogs to arbitrary .mo files.
By segfaultCVE-2026-8715 in versions 1.3.0–1.4.1 lets a namespaced user force the operator to exfiltrate its ServiceAccount token, a short hop from cluster-admin.
By tarpitCVE-2026-18374 let a crafted mode string overrun a small heap buffer when a charset token stripped to empty.
By segfaultCVE-2026-80590 lets an unprivileged user trigger a BUG_ON in skb_segment via tap or virtio paths that keep GSO metadata on defragmented packets.
By kexecThe converter left pending combining-character state uncleared, so resumed iconv calls could stall instead of making progress.
By segfaultAn off-by-one error in Apache Tomcat’s RewriteValve restarts rule processing at the wrong point, undermining access checks that depend on rewrite order.
By tarpitPath ordering could let requests slip past more restrictive access rules on shorter prefixes.
By tarpitFlaws in the RGB control suite’s custom network protocol can fully take over systems when the server runs with default privileges.
By tarpitCVE-2026-77913 let a guest paint past the console surface with controlled palette values after a mode change.
By sudoFour CephX CVEs fixed in Ceph 19.2.6 and 20.2.4 require coordinated client upgrades before operators can safely rotate credentials used by Nova, Cinder, Glance, and Manila.
By tarpitTwo flaws let a hostile module proxy or checksum database slip attacker-controlled code past transparency-log checks into the local cache.
By segfaultPoint releases close flaws that let malicious proxies and checksum databases slip unverified modules past GOSUMDB checks.
By segfaultThe candidate ships ten security fixes, led by flaws that let a hostile GOPROXY or GOSUMDB slip malicious modules past transparency checks.
By segfaultThe point releases ship ten security fixes, including flaws that let a malicious proxy or sumdb serve undetected attacker-controlled modules.
By segfaultAndrew Tridgell’s release closes a large batch of security holes and ships patch sets for the 3.2.7 and 3.4.1 lines used by long-term distro builds.
By nonceAdvertised file and UNC bundle paths could force outbound SMB and expose credentials on Windows clones.
By segfaultThree important-severity flaws let DAG authors run code in components Airflow’s security model says must stay clean of author-controlled execution.
By tarpitCVE-2026-6368 closed a dangling-pointer bug that could free the wrong buffer after a failed append expansion.
By segfaultCVE-2026-59113 let a crafted page drive OS protocol handlers and premature extension URL overrides when users fetched untrusted content.
By renderCVE-2026-62960 let hostile Git servers push Windows clients into disclosing NTLMv2 hashes over the network.
By segfaultTwo flaws in multi-pool setups let tenants overlap other tenants' zones, enabling hijacks and a deterministic mDNS denial of service.
By tarpitCVE-2026-12080 let unprivileged local users seize ownership of arbitrary root files when the agent added authorized keys.
By sudoCVE-2026-12080 let a guest user turn authorized_keys injection into chown of arbitrary root-owned paths.
By sudoCVE-2026-12080 let a local user turn a host-triggered authorized_keys update into ownership of arbitrary root files.
By sudoCVE-2026-12080 is a symlink race in guest-ssh key handling that can hand ownership of arbitrary root-owned paths to an unprivileged guest user.
By sudoThe Go team will ship private standard library and toolchain fixes for three CVEs.
By segfault