By vendor
Linux vulnerabilities
Known CVEs affecting Linux products, prioritized by severity, with SEC.co remediation and detection guidance.
1178 published vulnerabilities · page 2 of 12
- CVE-2026-11683HIGH 8.8
Google Chrome contains a use-after-free vulnerability in its WebCodecs component that allows remote attackers to execute arbitrary code within the browser sandbox. An attacker would need to trick a user into visiting a specially crafted webpage to trigger the flaw. Once exploited, the attacker gains code execution privileges within Chrome's sandbox environment, which limits but does not eliminate the potential for system compromise depending on sandbox escape possibilities.
- CVE-2026-11688HIGH 8.8
Google Chrome versions prior to 149.0.7827.103 contain a flaw in how the browser handles SVG (Scalable Vector Graphics) content. An attacker can craft a malicious HTML page that, when visited by a user, executes arbitrary code within Chrome's sandbox environment. While the sandbox is designed to limit damage, this vulnerability allows an attacker to breach that boundary, potentially compromising user data and system integrity.
- CVE-2026-12439HIGH 8.8
Google Chrome contains a use-after-free vulnerability in its Digital Credentials component that could allow an attacker to corrupt heap memory and potentially execute arbitrary code. The flaw requires user interaction—specifically, visiting a specially crafted webpage—but poses a critical risk because it affects a widely deployed browser across multiple operating systems. Users running Chrome versions prior to 149.0.7827.155 are at risk.
- CVE-2026-12441HIGH 8.8
A use-after-free vulnerability exists in Google Chrome's file input handling on Linux systems. An attacker can craft a malicious HTML page that, when visited by a user, exploits this memory safety flaw to corrupt the browser's heap and potentially execute arbitrary code. The vulnerability affects Chrome versions prior to 149.0.7827.155 and requires user interaction (clicking or interacting with the page).
- CVE-2026-12443HIGH 8.8
A use-after-free vulnerability in Google Chrome's Web Authentication subsystem allows attackers to execute arbitrary code by tricking users into visiting a malicious website. The flaw affects Chrome versions before 149.0.7827.155 across Windows, macOS, and Linux. An attacker would need to craft a deceptive HTML page and convince a user to visit it; successful exploitation grants the attacker the same privileges as the compromised browser process.
- CVE-2026-12447HIGH 8.8
A vulnerability in Google Chrome's WebRTC component allows attackers to crash the browser or run malicious code within Chrome's sandbox protection by tricking users into visiting a specially crafted website. The attack requires user interaction—specifically, a user must open or be redirected to the malicious page—but no special privileges are needed on the target system. While the code execution is limited to the Chrome sandbox environment, successful exploitation could still enable data theft or further system compromise.
- CVE-2026-13027HIGH 8.8
A use-after-free vulnerability in Google Chrome's FileSystem component allows attackers to corrupt memory and potentially execute arbitrary code when a user visits a malicious website. The flaw affects Chrome versions before 149.0.7827.197 across Windows, macOS, and Linux systems. Exploitation requires user interaction—specifically visiting a crafted HTML page—but once triggered, the vulnerability can lead to complete system compromise.
- CVE-2026-13031HIGH 8.8
A use-after-free memory vulnerability exists in Chrome's Blink rendering engine that could allow an attacker to run malicious code within Chrome's sandbox by tricking a user into visiting a specially crafted website. The flaw affects Chrome versions before 149.0.7827.197 and impacts users across Windows, macOS, and Linux systems.
- CVE-2026-13033HIGH 8.8
A memory safety vulnerability in Google Chrome's interest groups feature allows attackers to read and write data outside intended memory boundaries. An attacker can craft a malicious HTML page that, when visited by a user, triggers the flaw to execute arbitrary code on the victim's machine. The vulnerability affects Chrome versions before 149.0.7827.197 and is classified as critical by Chrome's security team.
- CVE-2026-13036HIGH 8.8
A use-after-free memory vulnerability exists in Google Chrome's Blink rendering engine that allows remote attackers to execute arbitrary code within the browser's sandbox. The flaw requires user interaction—specifically opening a malicious HTML page—but poses a direct threat to confidentiality, integrity, and availability once triggered. Attackers can escape the sandbox's execution context and potentially gain control over the affected system.
- CVE-2026-13777HIGH 8.8
Google Chrome on iOS contains a vulnerability that allows attackers to trigger heap memory corruption by tricking users into visiting a malicious webpage. The flaw stems from Chrome's iOSWeb component failing to properly validate user-supplied input before processing it. An attacker would need to craft a specially designed HTML page and convince a user to visit it; the user's device would then be at risk of compromise. Chrome versions before 150.0.7871.47 are vulnerable on iOS.
- CVE-2026-13783HIGH 8.8
A use-after-free memory vulnerability exists in Google Chrome's Views component that could allow an attacker to corrupt the heap memory of an affected system. The vulnerability requires a user to visit a malicious website and perform specific UI interactions, such as clicking or gesturing within the page. If exploited successfully, an attacker could read sensitive data, modify system behavior, or crash the application. This is a memory safety issue—a category of bugs that remains a persistent challenge in browser security.
- CVE-2026-13784HIGH 8.8
A use-after-free vulnerability exists in Google Chrome's Views component that could allow an attacker to corrupt browser memory. The flaw requires user interaction—specifically, the victim must perform certain UI gestures (like clicking, dragging, or other interface actions) while visiting a malicious webpage. If successfully exploited, this could lead to a complete compromise of the user's browser, potentially affecting data confidentiality, integrity, and availability. Chrome versions prior to 150.0.7871.47 are affected.
- CVE-2026-13811HIGH 8.8
Google Chrome versions before 150.0.7871.47 contain a use-after-free vulnerability in the Input Method Editor (IME) component that can be exploited when a user visits a malicious webpage. An attacker could leverage this flaw to execute arbitrary code within Chrome's sandbox environment, potentially leading to system compromise. The vulnerability requires user interaction (visiting a crafted page) but does not require elevated privileges to trigger.
- CVE-2026-13821HIGH 8.8
A use-after-free memory bug in Google Chrome's Canvas rendering engine allows attackers to run malicious code within the browser's sandbox by tricking users into visiting a specially crafted webpage. No special privileges are required—any user viewing a malicious site can be compromised. The vulnerability affects Chrome versions before 150.0.7871.47 across Windows, macOS, and Linux systems.
- CVE-2026-13825HIGH 8.8
Google Chrome contains a flaw where certain memory in the browser's graphics component (Dawn) is not properly initialized before use. An attacker who crafts a malicious HTML page can trigger this condition and potentially corrupt the heap memory that Chrome relies on, leading to crashes or, in the worst case, arbitrary code execution. The vulnerability requires user interaction—the victim must visit the malicious page—but once they do, the attack executes with no additional privileges needed.
- CVE-2026-13830HIGH 8.8
A use-after-free vulnerability in Google Chrome's Chromoting feature on Linux allows an attacker on the same network to remotely execute arbitrary code without user interaction. An attacker would need to send malicious network traffic to trigger the flaw, which resides in memory management of the Chromoting subsystem. This is a particularly dangerous class of vulnerability because it gives an attacker direct code execution capability on an affected system.
- CVE-2026-13845HIGH 8.8
Google Chrome versions prior to 150.0.7871.47 contain a use-after-free vulnerability in the DOM (Document Object Model) that could allow an attacker to run arbitrary code within the browser's sandbox by tricking a user into visiting a specially crafted webpage. This is a memory safety issue where Chrome continues to reference DOM objects after they have been freed, creating a window for code execution. The vulnerability requires user interaction—specifically visiting a malicious site—but carries high risk once triggered.
- CVE-2026-13848HIGH 8.8
A use-after-free memory flaw in Google Chrome's form handling allows attackers to run malicious code within the browser's sandbox by tricking users into visiting a specially crafted website. The vulnerability affects Chrome versions prior to 150.0.7871.47 across Windows, macOS, and Linux. While the code executes in a sandbox—which limits what an attacker can directly access on the system—the sandbox itself isn't impenetrable, and successful exploitation could lead to full browser compromise or escalation of privileges.
- CVE-2026-13888HIGH 8.8
A use-after-free memory vulnerability exists in Google Chrome's extension handling system. When a user visits a malicious webpage, an attacker can exploit this flaw to run arbitrary code within Chrome's sandboxed extension environment. The vulnerability requires user interaction (visiting a crafted webpage) but carries significant risk because it bypasses Chrome's sandbox protections, which are designed to contain extension-level exploits. All recent versions of Chrome before 150.0.7871.47 are affected across Windows, macOS, and Linux platforms.
- CVE-2026-14024HIGH 8.8
A use-after-free flaw in Chrome's Ozone display server component on Linux allows attackers to corrupt memory and potentially execute code if a user is tricked into performing specific UI interactions on a malicious webpage. The vulnerability affects Chrome versions before 150.0.7871.47 and requires user interaction to exploit, but once triggered can lead to full system compromise.
- CVE-2026-14091HIGH 8.8
A use-after-free memory vulnerability exists in Chrome's DevTools (developer tools) that allows an attacker to execute arbitrary code within the browser's sandbox through a malicious HTML page. The vulnerability affects Chrome versions prior to 150.0.7871.47 and requires user interaction—the victim must view the crafted HTML in their browser. While Chromium rates this as low severity internally, the CVSS 3.1 assessment reflects high risk due to the combination of network delivery, lack of authentication, and potential for complete system compromise.
- CVE-2026-14107HIGH 8.8
A use-after-free vulnerability exists in Google Chrome's scheduling system that allows attackers to execute code within the Chrome sandbox by tricking users into visiting a malicious webpage. The vulnerability affects Chrome versions prior to 150.0.7871.47. While the Chromium project classified this as low severity, the CVSS score of 8.8 reflects the high-impact nature of the issue due to the combination of network accessibility, low complexity, and the requirement for user interaction.
- CVE-2026-14108HIGH 8.8
A use-after-free vulnerability in PDFium, the PDF rendering engine embedded in Google Chrome, allows attackers to execute arbitrary code within Chrome's sandboxed environment by crafting a malicious PDF file. The vulnerability requires user interaction—a victim must open the malicious PDF—but once triggered, it can bypass Chrome's sandbox protections. This affects Chrome versions prior to 150.0.7871.47 across Windows, macOS, and Linux systems.
- CVE-2026-14149HIGH 8.8
A use-after-free vulnerability exists in Google Chrome's audio processing component on Linux systems. An attacker can craft a malicious HTML page that, when visited by a user, exploits this memory safety flaw to execute arbitrary code on the victim's machine. The vulnerability requires user interaction (visiting a webpage) but needs no special privileges to trigger. Chrome versions before 150.0.7871.47 on Linux are affected.
- CVE-2026-46113HIGH 8.8
A use-after-free vulnerability exists in the Linux kernel's KVM (Kernel Virtual Machine) shadow page table management. The issue arises when guest page tables are modified between VM entries, causing KVM to track memory references incorrectly. This can lead to the kernel accessing freed memory structures, potentially allowing a local attacker with guest access to crash the system or execute code with elevated privileges. The vulnerability requires local access and affects systems running KVM with shadow paging enabled.
- CVE-2026-46125HIGH 8.8
CVE-2026-46125 is a memory safety bug in Linux kernel WiFi driver code that can cause system crashes or privilege escalation. When the kernel attempts to establish a multi-link WiFi connection and that setup fails, the code incorrectly retains station references that should have been cleaned up. This leaves dangling pointers in memory that can be exploited or cause the system to crash when the kernel debugfs interface tries to access them later. The vulnerability requires local network access and affects systems with WiFi enabled.
- CVE-2026-46152HIGH 8.8
A vulnerability in the Linux kernel's WiFi driver (mac80211) allows concurrent network packet processing threads to interfere with each other. The issue stems from a shared variable that should have been unique to each processing thread. When multiple packets arrive simultaneously, one thread's processing result can be overwritten by another, causing packets to be misrouted or incorrectly marked as already processed. This can lead to dropped packets, incorrect packet handling, or exposure of network data.
- CVE-2026-46166HIGH 8.8
A memory safety flaw exists in the Linux kernel's Wi-Fi driver subsystem (mac80211). When the kernel performs radar detection checks on wireless channels, it can inadvertently access memory that has already been freed, potentially causing a system crash or enabling privilege escalation. The issue stems from unsafe iteration over a list of wireless channel contexts that can be modified during the operation.
- CVE-2026-46174HIGH 8.8
CVE-2026-46174 is a high-severity vulnerability in the Linux kernel that affects AMD Zen2 processors. The issue involves improper isolation of shared resources within the processor's op cache, which can allow instructions to become corrupted when resources are improperly shared between processes or virtual machines. An attacker with local access could potentially exploit this to gain unauthorized access, modify data, or disrupt system availability. This is a privilege escalation and isolation bypass issue that requires local code execution capability to trigger.
- CVE-2026-46198HIGH 8.8
A flaw in the Linux kernel's batman-adv (Better Approach To Mobile Ad-hoc Networking) module allows an attacker on the network to trigger an integer overflow that leads to reading memory beyond intended bounds. The vulnerability stems from a type mismatch: a size validation uses a larger integer type (int) while the actual buffer position is stored in a smaller signed type (s16), creating a window where the validation passes but the buffer position can still exceed safe limits. An attacker with network access could exploit this to read sensitive kernel memory.
- CVE-2026-46212HIGH 8.8
A use-after-free vulnerability exists in the Linux kernel's batman-adv module, specifically in the B.A.T.M.A.N. advanced mesh networking layer. When removing backbone claims from a network topology, the code attempts to free a claim object before it has finished using it, creating a window where the freed memory could be accessed or overwritten. This can lead to system crashes, data corruption, or privilege escalation in mesh-networked Linux systems running the affected code.
- CVE-2026-46238HIGH 8.8
A memory management flaw in the Linux kernel's B.A.T.M.A.N. (Better Approach To Mobile Ad-hoc Networking) advanced routing implementation allows an attacker on the local network to crash the system or potentially execute code with high privileges. The vulnerability stems from the protocol caching a pointer to routing data that can become invalid after the system cleans up stale entries, leading to use-after-free conditions when that stale pointer is later accessed.
- CVE-2026-46264HIGH 8.8
A flaw in the Linux kernel's display driver (xe) for Intel GPUs causes a crash during system initialization. When the driver sets up user-facing controls (sysfs), a cleanup routine may run on an uninitialized object, leading to memory corruption and system instability. This occurs specifically in SR-IOV (virtualization) configurations where one GPU is shared among multiple virtual machines. The issue affects driver initialization sequences and can trigger kernel warnings and potential use-after-free conditions.
- CVE-2026-46317HIGH 8.8
A race condition in the Linux kernel's KVM (virtualization) subsystem on ARM64 systems allows a local, unprivileged user to cause a use-after-free memory error. The vulnerability exists in how the kernel manages nested virtual machine memory structures during reallocation. When the kernel reallocates its internal data structure for nested virtual machines, it frees the old memory while another part of the kernel may still be trying to access it, leading to a crash or potential privilege escalation. This requires local access and affects systems running vulnerable kernel versions with KVM nested virtualization enabled.
- CVE-2026-52911HIGH 8.8
A flaw in the Linux kernel's ksmbd SMB server implementation allows an authenticated attacker to bypass session isolation controls. When a client initiates a session binding operation, a flag remains set on the connection, causing the session lookup mechanism to return sessions that should not be accessible to that connection. An attacker with valid credentials could leverage this to access or manipulate sessions they should not be authorized to reach, potentially gaining unauthorized access to shared resources or escalating privileges within the SMB session context.
- CVE-2026-52918HIGH 8.8
A synchronization bug in the Linux kernel's Bluetooth subsystem allows a race condition between socket polling and socket cleanup. When the kernel checks for incoming Bluetooth connections, it walks through a queue of pending connections without proper locking. Meanwhile, a child socket being destroyed can unlink itself from that same queue and release its reference count. If these operations happen simultaneously, the kernel can use freed memory, leading to potential system instability or worse. This is a long-standing flaw that traces back to the original Bluetooth implementation in the kernel.
- CVE-2026-52934HIGH 8.8
A memory corruption vulnerability exists in the Linux kernel's B.A.T.M.A.N. (Better Approach To Mobile Ad-hoc Networking) advanced routing protocol implementation. When the kernel builds network packets containing TVLV (Type–Length–Value) container data, it calculates the required buffer size using a 16-bit counter that can overflow. If enough TVLV containers are registered, the size calculation wraps around to a small number, causing the kernel to allocate insufficient memory. The code then writes the actual packet data beyond the buffer boundary, corrupting kernel memory. An attacker on the local network can trigger this by crafting packets or registering malicious TVLV containers, potentially gaining kernel-level privileges.
- CVE-2026-52952HIGH 8.8
A flaw in the Linux kernel's IOMMU (Input/Output Memory Management Unit) subsystem can cause a use-after-free condition when multiple devices in the same group undergo concurrent domain attachment operations during device recovery. The vulnerability arises from overly strict rejection of domain attachments while a device is resetting, which prevents necessary cleanup operations from completing and leaves dangling pointers to freed memory. A local attacker with sufficient privileges can exploit this to cause a kernel crash or potentially execute arbitrary code.
- CVE-2026-52968HIGH 8.8
A memory access error in the Linux kernel's KVM hypervisor implementation for IBM System z (s390) PCI device handling allows a local privileged user to read or modify kernel memory outside intended boundaries. The bug stems from incorrect pointer arithmetic that scales offsets twice when accessing internal device management tables, causing the kernel to read from or write to the wrong memory location when handling PCI device interrupts. This can crash the system or potentially allow privilege escalation on affected virtualization hosts.
- CVE-2026-53053HIGH 8.8
A flaw in AMD IOMMU (Input/Output Memory Management Unit) support within the Linux kernel can cause incorrect device isolation when handling PCI device aliases. The vulnerability stems from clone_alias() receiving the wrong device identifier, leading to stale or incorrect memory translation entries being copied to aliased devices. This breaks the isolation guarantees that IOMMUs provide, potentially allowing one device to access memory intended for another. The issue is present in how the kernel decides which device information to use when setting up DMA aliases across PCIe topologies.
- CVE-2026-53057HIGH 8.8
A vulnerability in the Linux kernel's RISC-V IOMMU driver could allow a local attacker with basic user privileges to gain elevated access and affect system stability. The issue stems from missing cache invalidation operations after updating device and page directory table entries. When these tables are modified without proper invalidation, stale cached data can remain in the IOMMU's TLB and context cache, potentially allowing an attacker to bypass memory protections or cause system instability. This is a local attack vector requiring an account on the affected system, but the potential impact is significant because it can affect the confidentiality, integrity, and availability of data.
- CVE-2026-53071HIGH 8.8
A vulnerability in the Linux kernel's Bluetooth L2CAP protocol implementation allows a malicious Bluetooth device to cause memory corruption and system instability. When a remote device sends a specially crafted L2CAP reconfiguration response, the kernel fails to properly protect a critical data structure (the channel list) from concurrent access. This can lead to a system crash, information disclosure, or potential privilege escalation. The flaw stems from a missing lock that should prevent simultaneous modifications and reads of the channel list, a synchronization pattern that was properly implemented in similar code paths but overlooked in this particular handler.
- CVE-2026-53072HIGH 8.8
A locking bug in the Linux kernel's Bluetooth subsystem can lead to a use-after-free (UAF) vulnerability when handling incoming connection requests under specific conditions. When the kernel's Bluetooth protocol layer defers connection setup (a mechanism used by SCO and ISO protocols), a critical lock is not held during a function call that expects it, allowing concurrent code to delete connection objects while another code path is still using them. This can crash the system or potentially be exploited to gain elevated privileges on vulnerable systems.
- CVE-2026-53075HIGH 8.8
A flaw in the Linux kernel's PPP (Point-to-Point Protocol) driver allows a local user without administrative privileges to perform privileged operations on network interfaces. The vulnerability exploits a gap in permission checking: while opening /dev/ppp is restricted to privileged users in one context, certain administrative commands can be issued against a different, inherited network namespace where the attacker has gained limited privileges. An attacker can create an isolated user namespace, become an administrator within that isolated space only, and then use that position to manipulate PPP network configuration in the main system namespace. The kernel now requires stricter permission validation to close this loophole.
- CVE-2026-53159HIGH 8.8
A flaw exists in the Linux kernel's fastrpc driver that can corrupt memory addresses used for direct memory access (DMA) operations. When user-level code passes a pointer to the fastrpc subsystem, the kernel incorrectly calculates the corresponding DMA address if that pointer falls into a gap between memory regions. This miscalculation allows a local attacker to corrupt data sent to a specialized digital signal processor (DSP), potentially leading to privilege escalation or system compromise. The fix involves replacing an unsafe kernel function with a safer alternative that properly validates memory regions.
- CVE-2026-53170HIGH 8.8
CVE-2026-53170 is a privilege escalation vulnerability in the Linux kernel's Arm Ethos-U NPU (neural processing unit) driver. A local attacker with basic user privileges can trigger unsafe DMA (direct memory access) operations by submitting incomplete hardware commands, allowing the NPU to read or write arbitrary physical memory locations. The flaw stems from an initialization check that fails when arithmetic overflow wraps a sentinel value, bypassing memory bounds validation.
- CVE-2026-53171HIGH 8.8
A Linux kernel vulnerability in the Arm Ethos-U NPU driver's DMA length calculation function allows arithmetic wraparound to corrupt internal memory region size tracking. This corruption bypasses security checks that prevent invalid memory access, potentially enabling privilege escalation or system compromise on systems running vulnerable kernel versions with the Ethos-U accelerator driver loaded.
- CVE-2026-53188HIGH 8.8
A vulnerability in the Linux kernel's RDMA core subsystem fails to properly validate device file operations when handling user capability requests. An attacker with local access could exploit character device aliasing—where a block device shares the same device number (dev_t) as a character device—to impersonate a legitimate RDMA user capability device and gain unauthorized access to privileged functions. The fix adds explicit validation of file operation pointers to ensure only authentic RDMA character devices are accepted.
- CVE-2026-53198HIGH 8.8
A memory safety bug in the Linux kernel's ksmbd (kernel SMB daemon) file-locking code can be exploited to crash the system or potentially execute code. The vulnerability occurs when a network-connected attacker sends two specially-crafted SMB2 cancellation commands targeting the same lock request in rapid succession. This causes the kernel to access memory that has already been freed, leading to memory corruption. An attacker must be authenticated to the SMB service to exploit this issue.
- CVE-2026-53200HIGH 8.8
A bug in the Linux kernel's KVM (Kernel Virtual Machine) hypervisor for ARM64 systems with nested virtualization support incorrectly grants execute permissions to memory regions that should be non-executable. The flaw stems from a misuse of a bitfield operation that was supposed to clear execute permissions but instead does the opposite. This affects systems running KVM nested virtualization on ARM64 processors without the XNX (Execute-Never eXtended) feature. An attacker with local access and the ability to create or manage virtual machines could exploit this to execute code in memory regions marked as non-executable, potentially breaking security boundaries between the hypervisor and guest virtual machines.
- CVE-2026-53232HIGH 8.8
A resource cleanup bug in the Linux kernel's network PHY (physical layer) driver code can leave orphaned data structures in memory when the driver fails to initialize properly. Specifically, when an SFP (Small Form-factor Pluggable) module initialization encounters an error, the kernel fails to properly discard the upstream connection pointer, creating a dangling reference. This orphaned pointer can be mistakenly used in subsequent SFP-related events, potentially leading to memory corruption or unexpected behavior. The issue affects systems using network drivers that rely on the kernel's phylib SFP support, particularly those with hot-swappable fiber optic transceivers.
- CVE-2026-53240HIGH 8.8
A use-after-free vulnerability exists in the Linux kernel's IPsec Tunnel Traffic Flow Security (IPTFs) reassembly logic. When handling fragmented packets, the code temporarily releases a lock and then checks whether a packet buffer is still owned by the reassembly state. Between the lock release and that check, another CPU or timer can complete reassembly and free the buffer, but the original code doesn't know this has happened. It then attempts to operate on the freed memory, causing a crash or potential code execution. The flaw requires an authenticated attacker to send specially crafted fragmented packets to a system with IPTFs enabled.
- CVE-2026-53248HIGH 8.8
A use-after-free vulnerability exists in the Linux kernel's airoha network driver. When the driver tears down metadata destinations during cleanup, it frees memory immediately without waiting for all in-flight network packets to finish processing. If a packet is still referencing that freed memory, an attacker can trigger a crash or potentially execute code. The fix ensures proper memory synchronization by using the kernel's refcount and RCU (Read-Copy-Update) mechanism to defer memory deallocation until all active references are complete.
- CVE-2026-53266HIGH 8.8
A vulnerability exists in the Linux kernel's network filtering bridge module where the SNAT (Source Network Address Translation) target fails to properly protect memory when rewriting ARP (Address Resolution Protocol) sender hardware addresses. The issue occurs when packet data is stored in non-contiguous memory fragments—particularly those backed by memory-mapped file pages. An attacker with local access could exploit this to write arbitrary data into kernel memory, potentially leading to privilege escalation or system compromise.
- CVE-2026-53275HIGH 8.8
A memory safety flaw exists in how the Linux kernel processes IPv6 Multicast Listener Discovery (MLD) queries. When the kernel receives an MLD query packet, it saves a pointer to the multicast group address early in processing. However, later in the same function, the kernel may reallocate the packet buffer to add more data. After this reallocation, the saved pointer becomes invalid—it points to freed memory. If the code then tries to read from this invalid pointer, the kernel crashes or behaves unpredictably. An attacker on the same local network can send a specially crafted MLD query to trigger this condition, potentially causing a denial of service or worse.
- CVE-2026-53277HIGH 8.8
CVE-2026-53277 is a synchronization bug in the Linux kernel's KVM (Kernel-based Virtual Machine) hypervisor for ARM64 systems. The vulnerability occurs when certain hypervisor operations that walk guest page tables fail to hold a required kernel lock (SRCU) that protects against concurrent memory slot changes. An attacker with local access and low privileges could exploit this race condition to cause memory corruption, information disclosure, or denial of service across privilege boundaries, including from a guest VM context into the host kernel.
- CVE-2026-53281HIGH 8.8
A flaw in the Linux kernel's Intel VT-d IOMMU (Input/Output Memory Management Unit) driver can cause a crash or memory corruption when certain PASID (Process Address Space ID) teardown operations are performed incorrectly. The vulnerability stems from code that attempts to clean up device-PASID associations even when no valid association exists, leading to either dereferencing a NULL pointer or corrupting internal reference counts. This could allow a local attacker with basic user privileges to cause a denial of service or potentially escalate to higher impact by exploiting the memory corruption.
- CVE-2026-53322HIGH 8.8
A timing vulnerability in the Linux kernel's VFIO (Virtual Function I/O) PCI driver creates a brief but exploitable window during device shutdown. When a PCIe function is disabled, the driver must revoke all direct memory access (DMABUF) mappings before clearing the Memory Space Enable (MSE) bit. If MSE is disabled first, a narrow race condition allows unprivileged local users to continue accessing device memory through existing DMABUF mappings even after the function should be inaccessible. This could lead to unauthorized data access, modification, or denial of service on systems where VFIO and DMABUFs are in active use.
- CVE-2026-53354HIGH 8.8
A hardware vulnerability affecting certain Arm-based processors can cause memory writes to appear incomplete even after the CPU signals they are finished. When the kernel invalidates cached address translations (TLB entries), it issues a TLBI instruction followed by a memory barrier (DSB). On affected CPUs, this sequence may complete before all memory writes translated by the old TLB entry have been globally observed by other processors—a race condition that violates expected memory ordering. The Linux kernel resolves this by issuing the TLBI;DSB sequence twice, ensuring the first set of writes are fully observed before execution continues.
- CVE-2026-53358HIGH 8.8
A lock-ordering vulnerability exists in the Linux kernel's Bluetooth L2CAP (Logical Link Control and Adaptation Protocol) implementation. When cleaning up listening channels, the kernel was acquiring locks in an unsafe sequence that could lead to deadlock or race conditions. The fix changes how channels are closed during cleanup—instead of closing them synchronously (which requires acquiring locks in the wrong order), the kernel now schedules them to be closed asynchronously through an existing timeout mechanism that acquires locks in the correct, established order. This prevents lock inversion and ensures channel cleanup happens safely without deadlock risk.
- CVE-2026-53359HIGH 8.8
A use-after-free vulnerability exists in Linux kernel shadow paging when the kernel's memory management code encounters a specific sequence: a page directory entry (PDE) is modified from outside a guest VM, converting a 2MB page into 4KB pages, and then a memory slot is deleted. The kernel reuses an internal page structure (kvm_mmu_page) despite a mismatch in how that page should be configured, leading to corrupted memory tracking. When the memory is freed, dangling references to it remain and can be dereferenced by subsequent memory operations, causing a crash or potential privilege escalation. An unprivileged local user with KVM access can trigger this.
- CVE-2026-53360HIGH 8.8
This Linux kernel vulnerability affects AMD SEV-SNP (Secure Encrypted Virtualization with Secure Nested Paging) virtual machines. A malicious guest operating system can exploit improper bounds checking in the Page State Change request handler to read and write memory outside the intended buffer boundaries. The attack allows the guest to leak sensitive information about the host kernel's memory layout and corrupt host kernel memory. The vulnerability requires the attacker to have already gained code execution within a virtual machine—it does not enable initial compromise of the host from an unprivileged network position.
- CVE-2026-9155HIGH 8.8
A command injection flaw in Rapid7's InsightConnect Sed Plugin allows authenticated users to run arbitrary system commands on Linux machines. An attacker with valid credentials can exploit insufficient input validation in the expression parameter to execute code with the privileges of the InsightConnect service. This is a local-to-remote escalation risk in automation environments where the plugin processes untrusted expressions.
- CVE-2026-9873HIGH 8.8
A use-after-free memory defect in Google Chrome's Network component allows attackers to run malicious code within the browser sandbox by sending a specially crafted HTML page. The vulnerability requires user interaction—the victim must visit or be directed to the malicious page—but no special browser configuration or privileges are needed to exploit it. Google has rated this as Critical severity due to code execution capabilities, though the CVSS 3.1 score of 8.8 reflects the HIGH severity classification.
- CVE-2026-9878HIGH 8.8
A use-after-free vulnerability exists in the ANGLE graphics library component of Google Chrome versions before 148.0.7778.216. An attacker can craft a malicious webpage that, when visited, exploits this flaw to execute arbitrary code within Chrome's sandbox environment. The vulnerability requires user interaction (clicking a link or visiting a site) but does not require any special privileges. While the code runs in a sandbox, successful exploitation could allow attackers to steal sensitive data or cause denial of service.
- CVE-2026-9879HIGH 8.8
A memory safety bug in Chrome's graphics rendering engine (ANGLE) allows attackers to write data outside of allocated memory boundaries. An attacker can craft a malicious HTML page that, when opened in vulnerable versions of Chrome, triggers this out-of-bounds write to execute arbitrary code on the user's system. The vulnerability requires user interaction—specifically, the victim must visit or be directed to the malicious webpage—but no special privileges are needed and the attack works over the network.
- CVE-2026-9883HIGH 8.8
Google Chrome contains a use-after-free memory safety flaw in its Base component that allows attackers to execute arbitrary code on a user's system when they visit a malicious webpage. The vulnerability requires user interaction (viewing the crafted HTML) but no special privileges, and the attacker can read sensitive data, modify files, or crash the browser. Chrome versions prior to 148.0.7778.216 are affected across Windows, macOS, and Linux platforms.
- CVE-2026-9887HIGH 8.8
A memory safety bug in Google Chrome's proxy handling system allows an attacker to craft a malicious Proxy Auto-Config (PAC) script that, when processed by the browser, causes the application to reference memory that has already been freed. This use-after-free condition can be leveraged to execute arbitrary code on a user's system. The vulnerability requires user interaction—specifically, the victim must visit a website or be directed to load a PAC script—but no special privileges are needed from the attacker's perspective. Chrome versions prior to 148.0.7778.216 are affected.
- CVE-2026-9896HIGH 8.8
A flaw in Google Chrome's V8 JavaScript engine allows attackers to write data outside intended memory boundaries. By crafting a malicious HTML page, an attacker can trigger arbitrary code execution within Chrome's sandbox. The vulnerability requires user interaction—the victim must visit or be directed to a malicious website—but no special privileges are needed. Chrome versions prior to 148.0.7778.216 are affected across Windows, macOS, and Linux platforms.
- CVE-2026-9897HIGH 8.8
Google Chrome versions prior to 148.0.7778.216 contain a use-after-free vulnerability in the DOM (Document Object Model) that allows attackers to execute arbitrary code within the browser sandbox by tricking users into visiting a crafted webpage. This vulnerability requires user interaction but poses a high risk because successful exploitation grants code execution capabilities inside the sandboxed browser process.
- CVE-2026-9910HIGH 8.8
A memory safety bug in Google Chrome's graphics engine (ANGLE) allows an attacker to run malicious code within Chrome's sandbox by sending a specially crafted web page to a victim. The vulnerability requires user interaction—specifically visiting a malicious webpage—but no special privileges. Once triggered, an attacker could read sensitive data, modify browser state, or crash the application. This affects Chrome on Windows, macOS, and Linux.
- CVE-2026-9927HIGH 8.8
A use-after-free vulnerability in ANGLE (the graphics translation layer used by Chrome) allows attackers to run malicious code within Chrome's sandbox by tricking users into visiting a specially crafted webpage. The vulnerability exists in Google Chrome versions prior to 148.0.7778.216 and affects Windows, macOS, and Linux systems. While sandboxed, successful exploitation could grant an attacker local execution capabilities on the victim's machine.
- CVE-2026-9938HIGH 8.8
A flaw in Google Chrome's V8 JavaScript engine allows attackers to execute arbitrary code within the browser's sandbox by tricking users into visiting a malicious webpage. The vulnerability affects Chrome versions before 148.0.7778.216 and requires user interaction (clicking a link or visiting a crafted site). While the code runs in a sandboxed environment, successful exploitation could allow an attacker to break out of Chrome's security boundaries and potentially access system resources or steal sensitive data.
- CVE-2026-9939HIGH 8.8
A heap buffer overflow vulnerability in Chrome's WebCodecs component allows attackers to execute arbitrary code within Chrome's sandbox by tricking users into visiting a malicious webpage. The vulnerability affects Chrome versions prior to 148.0.7778.216 across Windows, macOS, and Linux platforms. Because it requires user interaction (clicking a link or visiting a site) but can bypass Chrome's sandbox protections, it represents a significant remote code execution risk for Chrome users.
- CVE-2026-9940HIGH 8.8
A heap buffer overflow vulnerability exists in the ANGLE graphics library used by Google Chrome versions before 148.0.7778.216. An attacker can craft a malicious HTML page that, when visited by a user, corrupts heap memory in the browser process. This memory corruption could allow the attacker to execute arbitrary code or crash the browser. The vulnerability requires user interaction (visiting a malicious website) but does not require any special privileges or complex attack setup.
- CVE-2026-9947HIGH 8.8
A use-after-free memory vulnerability exists in Google Chrome's XML processing engine that allows an attacker to execute arbitrary code within Chrome's sandbox. An attacker can trigger this vulnerability by crafting a malicious HTML page and convincing a user to visit it. While the sandbox limits damage, successful exploitation could allow the attacker to steal sensitive data or escalate privileges. The vulnerability affects Chrome versions prior to 148.0.7778.216 on Windows, macOS, and Linux systems.
- CVE-2026-9952HIGH 8.8
A use-after-free vulnerability exists in Google Chrome's WebAudio component that allows attackers to execute arbitrary code within the Chrome sandbox by tricking users into visiting a malicious website. The vulnerability affects Chrome versions prior to 148.0.7778.216 and requires user interaction (clicking a link or visiting a page). While sandboxed, successful exploitation could allow an attacker to run code with the privileges of the Chrome process, potentially leading to data theft or system compromise.
- CVE-2026-9957HIGH 8.8
Google Chrome's PDF renderer contains a use-after-free vulnerability that allows attackers to run malicious code within Chrome's sandboxed PDF handling process. An attacker can exploit this by sending a specially crafted PDF file to a victim. If the victim opens the PDF in Chrome, the vulnerability triggers, potentially allowing the attacker to escape the sandbox and execute arbitrary code on the system. The vulnerability affects Chrome versions prior to 148.0.7778.216 and impacts users on Windows, macOS, and Linux.
- CVE-2026-9958HIGH 8.8
A use-after-free vulnerability in PDFium, the PDF rendering engine embedded in Google Chrome, allows attackers to corrupt heap memory when a victim opens a maliciously crafted PDF file. An attacker can trigger this flaw remotely simply by getting someone to view a rigged PDF—no special browser settings or plugins required. This can lead to information disclosure, data corruption, or arbitrary code execution depending on how an attacker chains the memory corruption with other techniques.
- CVE-2026-9961HIGH 8.8
A use-after-free memory vulnerability exists in Google Chrome's SurfaceCapture component that allows attackers to corrupt heap memory. An attacker can craft a malicious HTML page that, when visited by a user, triggers the flaw to potentially execute arbitrary code with the privileges of the Chrome process. The vulnerability requires user interaction (visiting a malicious site) but has high impact once triggered.
- CVE-2026-9962HIGH 8.8
A use-after-free memory vulnerability in Google Chrome's WebRTC component allows an attacker to execute arbitrary code within the browser's sandbox by tricking a user into visiting a specially crafted webpage. The attacker gains the ability to read sensitive data, modify information, or crash the browser without needing special privileges or authentication.
- CVE-2026-9965HIGH 8.8
A memory vulnerability in Google Chrome's ANGLE graphics library allows attackers to corrupt heap memory through a specially crafted webpage. When a user visits a malicious site, the attacker can trigger an out-of-bounds write operation that overwrites data beyond intended memory boundaries. This could lead to arbitrary code execution with the privileges of the browser process. The vulnerability requires user interaction (visiting a malicious page) but is otherwise trivial to deliver via normal web browsing.
- CVE-2026-9968HIGH 8.8
Google Chrome versions before 148.0.7778.216 contain a flaw in the V8 JavaScript engine that can be triggered by opening a malicious webpage. An attacker can exploit this to run malicious code within Chrome's sandbox—a security boundary meant to isolate the browser from the rest of your system. While the sandbox limits what an attacker can directly access, breaking out of it is a known follow-up risk. The vulnerability requires user interaction (visiting a malicious site) but poses a serious threat because it affects millions of Chrome users across Windows, macOS, and Linux.
- CVE-2026-9969HIGH 8.8
A vulnerability in Google Chrome's ANGLE graphics library (the translation layer that converts graphics commands to platform-specific formats) fails to properly check user-supplied input before processing it. An attacker can exploit this by hosting a specially crafted webpage; when a user visits that page in a vulnerable version of Chrome, the attacker gains the ability to run arbitrary code on the victim's machine with the same privileges as the Chrome process. The attack requires user interaction—specifically, the victim must visit the malicious page—but no special browser settings or additional permissions are needed.
- CVE-2026-9973HIGH 8.8
CVE-2026-9973 is a memory corruption vulnerability in Google Chrome's V8 JavaScript engine that allows attackers to run malicious code within the browser's sandbox by hosting a specially crafted HTML page. An attacker would need to trick a user into visiting the malicious site, but once there, the flaw provides a direct path to arbitrary code execution. Chrome versions before 148.0.7778.216 are vulnerable.
- CVE-2026-9976HIGH 8.8
Google Chrome versions before 148.0.7778.216 contain a flaw in how the browser handles USB device interactions. An attacker can craft a malicious HTML page that, when visited by a user, exploits this flaw to run arbitrary code on the victim's computer with the same privileges as the Chrome process. The vulnerability requires user interaction (visiting the page) but does not require the attacker to have special privileges or be on the same network—it can be delivered remotely via the internet.
- CVE-2026-9978HIGH 8.8
A use-after-free flaw in Google Chrome's Glic component allows attackers to run arbitrary code within the browser's sandbox by tricking users into visiting a malicious webpage. The vulnerability affects Chrome versions prior to 148.0.7778.216 across Windows, macOS, and Linux. While the code execution is confined to the sandbox, successful exploitation could lead to data theft, credential compromise, or lateral movement depending on the attacker's objectives and the system's security posture.
- CVE-2026-9983HIGH 8.8
A type confusion vulnerability in Chrome's Skia graphics engine allows attackers to execute arbitrary code within Chrome's sandbox by tricking users into visiting a malicious website. The attacker needs no special privileges—just the ability to craft a deceptive HTML page. Once code runs in the sandbox, it gains significant capabilities including reading sensitive data, modifying content, and disrupting the browser. Chrome version 148.0.7778.216 and later patch this flaw.
- CVE-2026-9992HIGH 8.8
Google Chrome versions prior to 148.0.7778.216 contain a use-after-free vulnerability in its Network component that allows attackers to execute arbitrary code within the browser's sandbox by tricking users into visiting a malicious website. The vulnerability requires user interaction (clicking a link or visiting a page) but no special privileges, making it a practical attack vector for widespread exploitation.
- CVE-2026-9995HIGH 8.8
Google Chrome contains a use-after-free memory vulnerability in its WebXR implementation that allows attackers to execute arbitrary code within the browser's sandbox. An attacker can craft a malicious HTML page that, when visited by a user, triggers this flaw to break out of memory protections and run code. This affects Chrome versions prior to 148.0.7778.216 on Windows, macOS, and Linux systems.
- CVE-2026-53230HIGH 8.7
A memory safety flaw exists in the Linux kernel's Mellanox (mlx5) network driver. When querying MAC address lists from a virtual function (VF) with custom network configuration, the driver allocates a buffer that is too small, causing the firmware response to overflow the buffer boundary. This can lead to kernel crashes or potentially allow local privilege escalation. The fix involves reading the correct capacity limits from each virtual function's own configuration rather than assuming all functions match the physical function's limits.
- CVE-2026-46273HIGH 8.6
A flaw in the Linux kernel's ibmveth driver can cause certain Power system network adapters to freeze when handling segmented network traffic with unusually small packet sizes. The adapter lockup stops all network traffic until manual intervention, creating a denial-of-service condition. The issue occurs only when the adapter's hardware segmentation feature (GSO) encounters packets smaller than 224 bytes that require splitting into multiple segments. The fix implements a software-based workaround that performs segmentation on the system side instead of relying on the hardware, preventing the adapter freeze.
- CVE-2026-53217HIGH 8.6
A memory synchronization bug in the Linux kernel's Marvell PPv2 network driver can cause the CPU to read stale data from network packets on systems with non-coherent DMA (direct memory access). The hardware writes received network data to a specific memory offset, but the kernel's cache synchronization was reading from the wrong location and size, potentially missing the end of incoming frames. This means an attacker sending crafted network traffic could cause the kernel to process corrupted or incomplete packet data, leading to crashes, information disclosure, or potential code execution.
- CVE-2026-46251HIGH 8.4
A vulnerability in the Linux kernel's Btrfs filesystem corrupts internal list structures when certain filesystem features are enabled. When the EXTENT_TREE_V2 compatibility flag is set, the kernel incorrectly manages the block group tree's tracking list during transaction commits. This causes the list's internal pointers to become invalid, leading to filesystem panics, transaction failures, and potential data loss. The issue manifests when the filesystem performs allocation operations on machines where this feature flag is active.
- CVE-2026-46270HIGH 8.4
A use-after-free vulnerability exists in the Linux kernel's RT9455 power supply driver. The bug stems from improper resource cleanup ordering during driver removal: an interrupt handler can fire after the power supply device has been deallocated but before the interrupt itself is disabled, causing the handler to reference freed memory. This can crash the system or corrupt kernel memory. The vulnerability can also manifest during driver initialization if an interrupt fires before the power supply is fully registered.
- CVE-2026-46288HIGH 8.4
CVE-2026-46288 is a use-after-free memory safety bug in the Linux kernel's device tree unit testing code. The vulnerability occurs because the code releases memory for a data structure but then continues to access that same memory through another variable pointing to the same location. This can lead to crashes, information disclosure, or potentially arbitrary code execution with local access. The issue is confined to kernel test infrastructure rather than production device tree handling, limiting its practical exposure, but it demonstrates a common class of memory management errors that merit fixing.
- CVE-2026-46326HIGH 8.4
A memory initialization flaw has been found in the Linux kernel's industrial I/O (IIO) pressure sensor driver for the MPRLS0025PA device. The driver fails to properly initialize a critical data structure (spi_transfer struct) before use, leaving it containing uninitialized memory. An attacker with local access could exploit this to read sensitive kernel memory, modify kernel state, or trigger a denial of service. This is a local privilege escalation risk primarily affecting embedded systems and IoT devices that use this specific pressure sensor.
- CVE-2026-53091HIGH 8.4
A vulnerability exists in how the Linux kernel handles network packets during transmission, specifically in code that processes Generic Segmentation Offload (GSO) packets. The kernel wasn't properly ensuring that packet headers were moved into the correct memory location before passing them to network drivers. This could allow a local user to craft malicious packets that crash the system or potentially cause other kernel instability. The issue has been addressed by ensuring headers are properly validated and moved into place, with the kernel now detecting and dropping obviously malformed GSO packets.
- CVE-2026-10001HIGH 8.3
A use-after-free flaw in Chrome's PerformanceManager could let an attacker escape the browser sandbox if they've already compromised the rendering engine. The attack requires a specially crafted web page and user interaction, but success could grant full system access. This affects Chrome versions before 148.0.7778.216.