QEMU guest agent fixes root symlink flaw in SSH key commands
CVE-2026-12080 let unprivileged local users seize ownership of arbitrary root files when the agent added authorized keys.
By sudoCVE-2026-12080 let unprivileged local users seize ownership of arbitrary root files when the agent added authorized keys.
By sudoCVE-2026-12080 let a guest user turn authorized_keys injection into chown of arbitrary root-owned paths.
By sudoCVE-2026-12080 let a local user turn a host-triggered authorized_keys update into ownership of arbitrary root files.
By sudoCVE-2026-12080 is a symlink race in guest-ssh key handling that can hand ownership of arbitrary root-owned paths to an unprivileged guest user.
By sudoThe Go team will ship private standard library and toolchain fixes for three CVEs.
By segfaultA config rename left the CVE-2026-68480 fix inert on the long-term 6.6 series until corrected patches land.
By oopsCVE-2026-52682 lets a crafted query drive up memory and CPU use across Authoritative Server, Recursor, and dnsdist.
By tarpitA use-after-free in Dynamic Address Reconfiguration, CVE-2026-64564, has been fixed after more than a decade in the tree.
By tarpitThe July release patches signature, AEAD, keystore, and certificate-validation flaws in a library embedded across countless JVM applications.
By tarpitVersion 2.0.9 closes two heap memory bugs reachable from a malicious font server, one an incomplete fix from 2014.
By tarpitStaff users could trigger disk writes or network requests via GDAL rasters in admin filters; four CVEs land in 5.2.17 and 6.0.8.
By tarpitTruncated control requests could return stale fence metadata to the guest; CVE-2026-18054 is closed by rejecting them.
By sudoVirtio-gpu and vhost-user-gpu fixes stop heap overflows and host memory leaks from malicious guests before the 11.1 release.
By sudoCVE-2026-62354 affected NiFi 1.10.0 through 2.10.0; version 2.11.0 now requires write access for Parameter Context validation.
By tarpitCVE-2026-18054 let truncated GPU commands return stale fence metadata to the guest.
By cronjobThe change drops buggy TSIG printing in the resolver and closes CVE-2026-5435.
By segfaultCVE-2026-15264 let a malicious guest overflow a host heap buffer via crafted 2D resource dimensions.
By sudoVersions 9.2.15 and 10.1.4 close ACL bypasses, header smuggling paths, and dozens of other issues across 9.x and 10.x.
By tarpitUnauthenticated attackers can leak server secrets, and potentially escalate to RCE, on apps using libvips with untrusted uploads.
By nonceCVE-2026-66021 let a malicious guest inflate blob_size past its backing and trigger host reads on display refresh.
By sudoCVE-2026-18054 covered truncated control requests that could return stale fence metadata to guests in both built-in and vhost-user GPU paths.
By cronjobSix advisories close privilege-escalation and crash bugs across years of Xen releases, several reachable from untrusted guests.
By tarpitCVE-2026-18054 let truncated control requests expose leftover fence metadata from the host.
By sudoCVE-2026-64531 lets an unprivileged user with network-namespace control turn oversized nested actions into kernel code execution on common distro configs.
By nonceCVE-2026-66900 let trailing IP padding defeat a bounds check and overflow a coalescing buffer.
By sudoSame-day HIGH batches from Unbound, BIND, and PowerDNS show wildcard label logic and new encrypted paths failing in parallel across the software that is supposed to enforce DNS integrity.
By tarpitA 30-patch pull from Michael Tsirkin hardens device emulation against guest-triggered host crashes, memory corruption, and a CXL heap leak.
By cronjobMissing validation of vq size let a peer drive writes past the inflight log, tracked as CVE-2026-61402.
By cronjobCVE-2026-63322 left VM state handlers and bottom halves pointing at freed device memory after secondary display removal.
By sudoThree patches from Michael S. Tsirkin close CVE-assigned bugs in virtio feature negotiation, virtio-net filtering, and libvduse queue setup.
By cronjobCVE-2026-66020 let a guest trigger reads of freed memory via cursor updates and scanout refresh after RESOURCE_DETACH_BACKING.
By cronjobA 9p pull closes a read-only export bypass and backend UAFs; a separate virtio-gpu patch stops guest-driven out-of-bounds reads.
By sudovirtio-mmio always advertised a 1024-entry maximum, which becomes unsafe once QEMU itself allocates in-order virtqueue resources.
By cronjobA guest userspace driver could abort the hypervisor by feeding empty indirect tables into packed virtqueues.
By sudoGuests could set virtio queues larger than the host allocated, enabling out-of-bounds access when in-order delivery was in use.
By sudoA reference-count error on malformed guest requests left SCSIRequest objects alive indefinitely, tracked as CVE-2026-61476.
By sudoUnmasked guest feature bits could turn on virtio-net RSC without the headers the receive path assumed, triggering CVE-2026-63321.
By sudoCVE-2026-61402 let an untrusted vq size overrun the inflight log because libvduse trusted kernel-supplied values without a bounds check.
By sudoCVE-2026-50624 let a late entropy callback touch freed host memory after the guest RNG device was removed.
By sudoCVE-2026-66020 left a dangling pointer after RESOURCE_DETACH_BACKING, so UPDATE_CURSOR could memcpy from freed host memory.
By cronjobA missing check let a malicious guest inflate blob size past its backing buffer and force out-of-bounds host reads on scanout.
By cronjobAn incomplete follow-up to CVE-2024-3446 left the network device open to the same class of attack under a new CVE.
By cronjobCVE-2026-5450 fixed a user-controlled overflow when %mc or %mC resized its allocated buffer.
By segfaultUnder-allocation when growing the buffer for the %mc and %mC conversions left a user-controlled write past the end of the heap block.
By rvalueTwo heap out-of-bounds writes in fragment-boundary handling are exploitable for privilege escalation, and public exploits are out.
By tarpitA single-day blast of hundreds of kernel CVEs, arriving beside real high-impact bugs in snapd, QEMU, and libraries, forces the old argument over mass assignment into operational terms.
By nonceCVE-2026-53090 addressed incomplete failure-path analysis that could let unsafe programs pass verification.
By kexecA flood of kernel CVE IDs renews debate over whether individual triage is still a workable security practice.
By nonceA dense run of USB, display, NIC, and UEFI fixes shows the project still treating guest and migration input as untrusted, while the underlying C surface remains large enough that clouds must keep asking how much trust that buys them.
By cronjob