By vendor
Linux vulnerabilities
Known CVEs affecting Linux products, prioritized by severity, with SEC.co remediation and detection guidance.
1178 published vulnerabilities · page 8 of 12
- CVE-2026-11299MEDIUM 6.5
A flaw in how Google Chrome handles font data can lead to information disclosure when a user visits a malicious webpage. An attacker can craft a specially designed HTML page that exploits an integer overflow vulnerability in Chrome's font processing code, potentially allowing them to read sensitive data from the browser's memory. The vulnerability affects Chrome versions before 149.0.7827.53 and requires user interaction (visiting the malicious site) to trigger.
- CVE-2026-11653MEDIUM 6.5
Google Chrome versions before 149.0.7827.103 contain a flaw in how browser extensions are implemented that could allow an attacker to bypass site isolation—Chrome's core security mechanism that prevents websites from accessing each other's data. The attack requires two conditions: the attacker must first compromise Chrome's renderer process (the component that executes web pages), and then serve a specially crafted HTML page to the victim. While the technical barrier is high, successful exploitation would let malicious code access data across site boundaries, violating the security boundary that normally isolates sensitive information from different origins.
- CVE-2026-11658MEDIUM 6.5
A vulnerability in Google Chrome's extension validation system allows an attacker who has already compromised Chrome's renderer process to bypass site isolation—a critical security boundary that prevents malicious websites from accessing data across different sites. The flaw stems from insufficient checking of untrusted input in the Extensions subsystem. An attacker would need to trick a user into visiting a specially crafted HTML page while the renderer is already compromised, making this a secondary attack that compounds an existing breach rather than a standalone entry point.
- CVE-2026-11906MEDIUM 6.5
IBM Db2 contains a vulnerability that allows authenticated users to crash the database by submitting specially crafted queries involving XMLTable-derived columns. An attacker with valid database credentials can trigger a denial of service condition, making the database unavailable to legitimate users. This requires authentication, so it is not exploitable by anonymous attackers, but it represents a risk from insider threats or compromised accounts.
- CVE-2026-12024MEDIUM 6.5
A flaw in Google Chrome's Developer Tools (DevTools) allows attackers to bypass the same-origin policy—a fundamental browser security boundary that prevents one website from accessing another's data. An attacker crafting a malicious HTML page could trick a user into visiting it, potentially gaining unauthorized access to sensitive information from other sites the user is logged into. The vulnerability affects Chrome versions before 149.0.7827.115 across Windows, macOS, and Linux.
- CVE-2026-12450MEDIUM 6.5
A flaw in Google Chrome's media handling allows attackers to extract sensitive information from your browser's memory through a specially crafted webpage. An attacker could trick you into visiting a malicious site and potentially access data that shouldn't be exposed—passwords, tokens, or other secrets processed by the browser. This requires user interaction (clicking or visiting the page) but no special permissions, making it a realistic threat for targeted attacks.
- CVE-2026-13022MEDIUM 6.5
Google Chrome versions prior to 149.0.7827.197 contain a flaw in the Autofill feature that allows an attacker with control of the browser's renderer process to extract sensitive data across website boundaries using a specially crafted web page. This is a moderate-severity issue that requires both the renderer process to be compromised and user interaction to exploit.
- CVE-2026-13793MEDIUM 6.5
Google Chrome versions before 150.0.7871.47 contain a flaw in how it enforces security policies for SVG (Scalable Vector Graphics) content. An attacker can craft a malicious web page that, when visited, leaks data from other websites the user has accessed or logged into. The attack requires user interaction—the victim must visit the attacker's page—but does not require special browser settings or privileges. This is a cross-origin data exposure vulnerability, meaning it breaks the browser's fundamental protection that prevents one website from accessing another's private information.
- CVE-2026-13810MEDIUM 6.5
A flaw in how Google Chrome on Linux handles user input can allow attackers to steal sensitive information from the browser's memory. An attacker would craft a malicious webpage and trick a user into visiting it; the browser would then leak data that should have been protected. This affects Chrome versions prior to 150.0.7871.47 on Linux systems.
- CVE-2026-13828MEDIUM 6.5
A flaw in Google Chrome's Enterprise implementation allows attackers to extract sensitive data from browser memory by tricking users into visiting a specially crafted webpage. The vulnerability requires user interaction (clicking a link or viewing a page) but does not require any special privileges. While the underlying browser processes are not compromised or harmed, the attacker gains unauthorized access to information that may be confidential. This affects Chrome versions prior to 150.0.7871.47 across Windows, macOS, and Linux systems.
- CVE-2026-13873MEDIUM 6.5
A memory reading flaw in Google Chrome's Layout component allows attackers to trick users into visiting a malicious webpage that reads sensitive data from the browser process. The attacker gains no ability to modify data or crash the system, but can potentially expose information that should remain private. This affects Chrome versions before 150.0.7871.47 across Windows, macOS, and Linux systems.
- CVE-2026-13879MEDIUM 6.5
Google Chrome contains a use-after-free memory vulnerability in its Bluetooth implementation that allows attackers on the same local network to extract sensitive data from the browser's memory by using a specially crafted Bluetooth device. This occurs before Chrome version 150.0.7871.47. The vulnerability is rated Medium severity and does not affect system stability or enable attackers to modify data, but it does create a risk of information disclosure from process memory.
- CVE-2026-13881MEDIUM 6.5
A flaw in how Google Chrome handles web app installations allows attackers to bypass the same-origin policy—a critical browser security boundary—by tricking users into visiting a malicious HTML page. The vulnerability affects Chrome versions before 150.0.7871.47 across Windows, macOS, and Linux. An attacker could craft a page that tricks Chrome into loading or interacting with resources from a different origin than the user expects, potentially enabling credential theft, session hijacking, or unauthorized data access.
- CVE-2026-13886MEDIUM 6.5
Google Chrome versions prior to 150.0.7871.47 contain a flaw in how Isolated Web Apps enforce content security policies. An attacker can craft a malicious HTML page that, when visited by a user, bypasses these protections—potentially allowing unauthorized modifications to web content or application behavior. The vulnerability requires user interaction (clicking a link or visiting a page) but does not require the victim to be logged in or have special privileges.
- CVE-2026-13894MEDIUM 6.5
Google Chrome prior to version 150.0.7871.47 contains a policy enforcement gap that allows an attacker positioned on the same network to manipulate how the browser handles navigation. By serving a specially crafted HTML page, an attacker can circumvent restrictions designed to prevent users from accessing certain sites or resources. The vulnerability requires the attacker to be in a network position to intercept or serve malicious content, and the user must interact with the page (clicking a link or performing an action), but does not result in direct data theft or system access.
- CVE-2026-13896MEDIUM 6.5
Google Chrome versions prior to 150.0.7871.47 contain a flaw in the Glic component that allows attackers to bypass navigation restrictions—mechanisms that prevent unauthorized page transitions or frame navigation. An attacker who crafts a malicious HTML page and tricks a user into visiting it can circumvent these protections, potentially redirecting the user to unintended destinations or manipulating browser navigation in ways that violate security policies. The vulnerability requires user interaction (clicking a link or visiting a page) but needs no special privileges to exploit.
- CVE-2026-14035MEDIUM 6.5
Google Chrome versions prior to 150.0.7871.47 contain a Bluetooth-related security flaw that allows an attacker to extract sensitive information from the browser's memory. An attacker would need to trick a user into visiting a malicious webpage; if successful, the attacker could read data that shouldn't be accessible, such as authentication tokens, session data, or other confidential information stored in memory. Chrome itself rates this as low severity, though the CVSS score reflects moderate risk due to the ease of exploitation and the sensitivity of potential data exposure.
- CVE-2026-14048MEDIUM 6.5
A use-after-free flaw in Google Chrome's Chromecast component allows an attacker positioned on the same local network to extract sensitive data from the browser's memory using a specially crafted malicious peripheral device. The vulnerability affects Chrome versions before 150.0.7871.47 across Windows, macOS, and Linux systems.
- CVE-2026-14051MEDIUM 6.5
A memory disclosure vulnerability exists in Google Chrome's GamepadAPI prior to version 150.0.7871.47. An attacker who has already compromised Chrome's renderer process can craft a malicious webpage to read uninitialized memory, potentially exposing sensitive data. The vulnerability requires user interaction (visiting a crafted page) and prior renderer compromise, making it a secondary risk in multi-stage attack chains rather than an entry vector.
- CVE-2026-14059MEDIUM 6.5
A security weakness in Google Chrome's Related-Website-Sets feature allows attackers to trick users into visiting a malicious webpage that can steal data from other websites the user is logged into. The vulnerability affects Chrome versions before 150.0.7871.47 and requires user interaction (clicking a link or visiting the malicious page). While the Chromium project rated this as low severity, the CVSS score reflects a medium-risk profile because of its potential to expose sensitive cross-origin information without the user's knowledge.
- CVE-2026-14061MEDIUM 6.5
A flaw in Google Chrome's Dawn graphics component allows attackers to trick users into visiting specially crafted web pages that can leak sensitive information from the browser's memory. The vulnerability requires user interaction—the victim must visit a malicious site—but once they do, attackers may be able to read data that should remain private, such as authentication tokens or other browser state. This affects Chrome versions before 150.0.7871.47 across Windows, macOS, and Linux systems.
- CVE-2026-14065MEDIUM 6.5
CVE-2026-14065 is a navigation-bypass vulnerability in Google Chrome versions before 150.0.7871.47. An attacker who has already compromised Chrome's renderer process (the component that executes web page content) can craft a malicious HTML page to circumvent built-in navigation security controls. While this requires prior renderer compromise, the impact allows unauthorized navigation to restricted destinations. The Chromium project rates this as low severity, though the CVSS score of 6.5 reflects the potential for integrity violation.
- CVE-2026-14069MEDIUM 6.5
An integer overflow vulnerability exists in the WebNN (Web Neural Network) component of Google Chrome versions before 150.0.7871.47. An attacker could craft a malicious HTML page that, when visited, exploits this flaw to read sensitive data from the browser's memory. The vulnerability requires user interaction (visiting a malicious site) but does not require any special privileges or system access.
- CVE-2026-14070MEDIUM 6.5
A memory safety vulnerability in Google Chrome's WebNN (Web Neural Network) component allows attackers to leak sensitive data from the browser's memory. An attacker can craft a malicious webpage that, when visited by a user, exploits an integer overflow to read unintended data from the running process. While Chrome classified this as low severity internally, the confidentiality impact warrants attention from a defense perspective.
- CVE-2026-14071MEDIUM 6.5
Google Chrome versions before 150.0.7871.47 contain a side-channel vulnerability in the WebAudio component that allows attackers to extract sensitive cross-origin data through a specially crafted webpage. An attacker would need to trick a user into visiting a malicious site, but once there, they could potentially read data from other websites the user has open—a serious breach of browser security boundaries. The vulnerability is rated MEDIUM severity due to its reliance on user interaction and limited scope of impact.
- CVE-2026-14081MEDIUM 6.5
Google Chrome versions before 150.0.7871.47 contain a flaw in DevTools policy enforcement that could allow an attacker to extract sensitive data from browser process memory. The vulnerability requires social engineering—convincing a user to install a malicious extension—but once installed, the extension can bypass DevTools restrictions to access confidential information. This is not a flaw users can trigger by visiting a website; it hinges on the user's decision to add untrusted code to their browser.
- CVE-2026-14098MEDIUM 6.5
A flaw in how Google Chrome handles CSS allows an attacker to craft a malicious webpage that can read data from websites on different domains—a cross-origin information leak. The vulnerability affects Chrome versions before 150.0.7871.47. While the attack requires user interaction (visiting the malicious page), the potential impact is significant: sensitive information from other websites could be exposed to the attacker. This is classified as a medium-severity issue, though Chromium's own assessment rated the underlying CSS implementation flaw as low severity.
- CVE-2026-14100MEDIUM 6.5
CVE-2026-14100 is a data leakage vulnerability in Google Chrome's NetworkCache component that allows attackers to extract sensitive information across website boundaries. An attacker crafts a malicious HTML page and tricks a user into visiting it; the flaw then permits unauthorized access to data that should remain isolated between different websites. While Google rates the underlying defect as low severity, the practical impact—cross-origin data exposure—warrants a medium CVSS score because it requires user interaction but reliably compromises confidentiality.
- CVE-2026-14125MEDIUM 6.5
A flaw in the ANGLE graphics library used by Google Chrome can leak sensitive data from a user's computer memory to an attacker through a malicious webpage. When a user visits a crafted HTML page, uninitialized memory containing potentially sensitive information becomes accessible, allowing the attacker to read data that should have been protected. The vulnerability requires user interaction—specifically visiting a malicious site—but no special privileges or complex setup are needed on the attacker's side.
- CVE-2026-14148MEDIUM 6.5
A type confusion flaw in Google Chrome's CSS handling allows a remote attacker to trick a user into visiting a malicious webpage and potentially read sensitive data from the browser's process memory. The vulnerability requires user interaction (clicking a link or visiting a page) but no special privileges. While Chromium rates the severity as low, the ability to leak memory contents elevates practical risk for targeted attacks.
- CVE-2026-9153MEDIUM 6.5
A vulnerability in the Rapid7 InsightConnect Sed Plugin allows authenticated users on Linux systems to read files they shouldn't have access to. The flaw exists because the plugin doesn't properly validate input in the expression parameter, enabling attackers to craft malicious commands that bypass restrictions and access sensitive files on the server.
- CVE-2026-9639MEDIUM 6.5
CVE-2026-9639 is a denial-of-service vulnerability in LXD, Canonical's container and virtual machine management platform. An authenticated user with permission to create storage volumes can crash the LXD daemon by uploading a malformed backup file that is missing a required field. The vulnerability affects LXD versions up to 6.8 and 5.21 on Linux systems. An attacker would need valid credentials and specific permissions to exploit this, but no advanced technical skill is required once access is obtained.
- CVE-2026-9882MEDIUM 6.5
CVE-2026-9882 is a memory safety flaw in the ANGLE graphics library used by Google Chrome that allows attackers to steal data from websites you're visiting, provided they trick you into viewing a specially crafted web page. The vulnerability stems from an integer overflow—a programming error where a number wraps around unexpectedly—enabling unauthorized cross-origin data leakage. While the Chromium team rated this as "Critical," the CVSS base score of 6.5 reflects that successful exploitation requires user interaction (clicking or viewing content) and doesn't enable code execution or system-level damage. The flaw affects Chrome on Windows, macOS, and Linux systems.
- CVE-2026-9953MEDIUM 6.5
CVE-2026-9953 is a memory safety bug in the ANGLE graphics library used by Google Chrome that allows an attacker to read sensitive data from the browser process. An attacker can craft a malicious HTML page that, when visited by a user, exploits an out-of-bounds read to leak information like passwords, session tokens, or other confidential data stored in Chrome's memory. The vulnerability requires user interaction (clicking a link or visiting a page) but does not require special privileges and works across Windows, macOS, and Linux. Google has assigned it high severity within Chromium's security framework.
- CVE-2026-9981MEDIUM 6.5
A flaw in the Skia graphics rendering library within Google Chrome allows attackers to trick users into visiting malicious web pages that expose sensitive data from the browser's memory. The vulnerability requires user interaction (clicking a link or visiting a site) but needs no special privileges to exploit, making it a realistic threat to everyday Chrome users.
- CVE-2026-11181MEDIUM 6.3
Google Chrome versions before 149.0.7827.53 contain a flaw in how the Media Session feature is implemented. An attacker can craft a malicious HTML page that, when visited by a user, bypasses the browser's same-origin policy—a fundamental security boundary that prevents websites from accessing data or functionality from other sites without permission. This could allow the attacker to read sensitive information, make unauthorized changes, or disrupt functionality within the context of other websites the user has open. The vulnerability requires user interaction (clicking a link or visiting a page) but does not require any special browser configuration.
- CVE-2026-11184MEDIUM 6.3
Google Chrome versions before 149.0.7827.53 contain a flaw that allows attackers to bypass navigation controls through a specially crafted webpage. An attacker could craft a malicious HTML page that, when visited by a user, circumvents Chrome's built-in protections that normally restrict where the browser can navigate. This requires user interaction—the victim must visit the malicious page—but the barrier to exploitation is otherwise low. The vulnerability affects Chrome on Windows, macOS, and Linux systems.
- CVE-2026-11187MEDIUM 6.3
Google Chrome versions prior to 149.0.7827.53 contain a flaw in the Glic component that allows an attacker to bypass navigation restrictions by tricking users into visiting a specially crafted webpage. The vulnerability requires user interaction (clicking a link or visiting the malicious page) and affects users across Windows, macOS, and Linux platforms. While the immediate impact is moderate, the ability to circumvent navigation safeguards could enable follow-on attacks or unauthorized content access.
- CVE-2026-11308MEDIUM 6.3
CVE-2026-11308 is a privilege escalation vulnerability in Google Chrome's extension system that allows an attacker to gain elevated permissions on a user's system. The attack requires social engineering—convincing a user to install a malicious browser extension—but once installed, the flaw in how Chrome enforces extension permissions allows the attacker to break out of the extension sandbox and perform actions at a higher privilege level than the extension should be allowed. This affects Windows, macOS, and Linux systems running Chrome versions prior to 149.0.7827.53.
- CVE-2026-9989MEDIUM 6.3
Google Chrome contained a flaw in how it handles media files that allowed attackers to bypass the same-origin policy—a critical browser security boundary. An attacker could craft a malicious video file that, when opened by a user in Chrome, would enable unauthorized access to sensitive data from other websites the user was visiting. The vulnerability requires user interaction (clicking a link or opening a file) but does not require special privileges or complex attack setup.
- CVE-2026-45491MEDIUM 6.2
A flaw in .NET's file handling allows an attacker with local access to manipulate files through improper link resolution. The vulnerability stems from the system failing to properly validate symbolic links or similar path references before opening files, which means an attacker could redirect file operations to unintended targets. While this requires local access and does not compromise confidentiality, it can lead to unauthorized modification of sensitive data or system files.
- CVE-2026-10916MEDIUM 6.1
CVE-2026-10916 is a cross-site scripting vulnerability in Google Chrome's developer tools that allows an attacker to inject malicious scripts or HTML content into a webpage. The attack requires two conditions: first, the attacker must have already compromised Chrome's renderer process (the component that executes web content), and second, the user must be tricked into visiting a specially crafted HTML page. While the initial compromise is a significant prerequisite, once achieved, this vulnerability enables the attacker to execute arbitrary code with the privileges of the browser session, potentially stealing sensitive data or performing actions on behalf of the user.
- CVE-2026-11122MEDIUM 6.1
Google Chrome versions before 149.0.7827.53 contain a flaw in how the keyboard input handler processes certain HTML page elements. An attacker can craft a malicious webpage that, when visited by an unsuspecting user, injects arbitrary scripts or HTML content that executes in a security context where it shouldn't be allowed—a technique called Uniform Cross-Site Scripting (UXSS). This bypasses the browser's same-origin policy protections that normally prevent cross-domain attacks. The vulnerability requires user interaction (clicking or viewing the page) but affects all major platforms where Chrome runs.
- CVE-2026-11150MEDIUM 6.1
Google Chrome versions prior to 149.0.7827.53 contain a flaw in how the browser processes XML within HTML pages. An attacker can craft a malicious webpage that, when visited, injects arbitrary scripts or HTML content that execute in the context of unrelated sites (a technique known as Universal Cross-Site Scripting or UXSS). This bypasses the same-origin policy that normally prevents one site from accessing data or performing actions on another. The vulnerability requires user interaction—a victim must visit the attacker's page—but does not require any special browser configuration or user privileges to trigger.
- CVE-2026-11186MEDIUM 6.1
Google Chrome versions prior to 149.0.7827.53 contain a vulnerability in CSS handling that allows attackers to inject malicious scripts or HTML into web pages users visit. An attacker would craft a specially designed webpage that, when opened in a vulnerable version of Chrome, bypasses security boundaries and executes unauthorized code in the context of other websites. This type of attack, known as Universal XSS (UXSS), is particularly dangerous because it affects the browser itself rather than individual websites, potentially compromising user data across multiple domains.
- CVE-2026-11229MEDIUM 6.1
Google Chrome versions before 149.0.7827.53 contain a flaw in how the application handles certain enterprise features that could allow someone with physical access to your device to gain elevated privileges. The vulnerability requires an attacker to be present at the machine itself and does not need you to take any action—they can exploit it directly. This is a local-only threat and cannot be exploited remotely over the internet.
- CVE-2026-11273MEDIUM 6.1
Google Chrome versions before 149.0.7827.53 contain a vulnerability in the Omnibox (the address/search bar) that fails to properly validate user input. An attacker can craft a malicious HTML page that, when visited by a user who interacts with the Omnibox through specific UI actions, allows injection of arbitrary scripts or HTML content. This is a cross-site scripting variant (UXSS) that bypasses the normal security boundary between web pages. The attack requires user interaction and social engineering to be effective, but once triggered, can compromise the integrity and confidentiality of the browsing session.
- CVE-2026-12459MEDIUM 6.1
Google Chrome versions prior to 149.0.7827.155 contain a vulnerability in the Serial component that allows attackers to inject malicious scripts or HTML into web pages through a specially crafted HTML file. The attack requires user interaction (clicking or otherwise engaging with the malicious page) but does not require the victim to have special privileges. The injected content can compromise page integrity and access sensitive user data within the affected browser context.
- CVE-2026-8658MEDIUM 6.0
A command injection flaw in Rapid7's InsightConnect Tcpdump Plugin allows authenticated users with high-level privileges to run arbitrary system commands on Linux servers. The vulnerability exists because user-supplied options and filter parameters aren't properly sanitized before being passed to shell commands. An attacker with administrative or equivalent access to InsightConnect could exploit this to execute malicious code with the privileges of the plugin process.
- CVE-2026-8659MEDIUM 6.0
A security flaw in Rapid7 InsightConnect's SQLmap plugin allows authenticated users with administrative privileges to run arbitrary commands on affected Linux systems. The vulnerability exists in how the plugin processes connection configuration parameters—specifically the api_host and api_port fields—without properly validating or sanitizing the input. An attacker with legitimate access to the InsightConnect platform could exploit this to execute unintended system commands on the underlying Linux host, potentially compromising system integrity or confidentiality.
- CVE-2026-8663MEDIUM 6.0
A flaw in Rapid7's InsightConnect RPM Plugin for Linux allows authenticated users to run arbitrary commands on affected systems. The vulnerability stems from the plugin's failure to properly sanitize user input when constructing shell commands—specifically in how it handles repository names, package keys, and package names. An attacker with valid credentials could exploit this to execute unauthorized operating system commands, potentially compromising system integrity or accessing sensitive data.
- CVE-2026-11199MEDIUM 5.9
Google Chrome versions before 149.0.7827.53 contain a flaw in how WebRTC handles network traffic that could allow an attacker positioned on the same network to steal sensitive information across website boundaries. The vulnerability requires the attacker to be in a privileged network position—such as on a shared Wi-Fi network or controlling network infrastructure—but does not require user interaction or special permissions. The risk is limited to information disclosure; the flaw cannot be used to modify data or crash the browser.
- CVE-2026-11238MEDIUM 5.9
Google Chrome versions before 149.0.7827.53 contain a flaw in how DevTools handles extension interactions that could allow an attacker to extract sensitive data from process memory. The attack requires social engineering—convincing a user to install a malicious Chrome extension—but if successful, an attacker gains access to potentially confidential information stored in memory that the extension can observe. This is classified as a medium-severity issue despite Chromium's internal 'Low' rating, reflecting the real-world impact of memory disclosure combined with the user-interaction barrier.
- CVE-2026-24266MEDIUM 5.9
NVIDIA's Triton Inference Server for Linux contains a use-after-free vulnerability that allows attackers to disrupt service availability. The flaw exists in memory management logic, where freed memory is accessed again, potentially causing the application to crash. While the attack requires specific network conditions to exploit reliably, the impact is limited to denial of service rather than data theft or system compromise.
- CVE-2026-9320MEDIUM 5.9
IBM WebSphere Application Server versions 9.0 and 8.5, along with WebSphere Liberty versions 17.0.0.3 through 26.0.0.6, contain a denial-of-service vulnerability triggered by specially-crafted network requests. An attacker can exploit this remotely without authentication to exhaust server memory, causing service degradation or outages. The vulnerability does not compromise confidentiality or integrity—its impact is purely on availability.
- CVE-2026-14063MEDIUM 5.7
CVE-2026-14063 is a memory disclosure vulnerability in Google Chrome's Chromecast component that allows a local attacker to read sensitive data from the browser process. The flaw requires the attacker to be on the same network and the user to interact with malicious network traffic, but does not require elevated privileges. While individual impact is modest, this type of information leak can enable reconnaissance for more sophisticated attacks. Google rated the underlying issue as low severity, but the combination of local network access, user interaction requirement, and memory disclosure capability warrants MEDIUM priority in most enterprise environments.
- CVE-2025-36372MEDIUM 5.5
IBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.4 contain a flaw that allows authenticated database users to access sensitive information from internal monitoring and event tables they should not be able to view. An attacker with valid database credentials could exploit this to extract confidential data, though they cannot modify information or disrupt service. This affects Db2 installations on Linux, Unix, and Windows platforms, including Db2 Connect Server deployments.
- CVE-2025-71313MEDIUM 5.5
A memory allocation failure in the Linux kernel's PCI endpoint driver could cause the system to crash. When the kernel tries to create a work queue for handling PCI endpoint-to-endpoint communication, it doesn't properly check whether that operation succeeded. If memory is scarce and the allocation fails, the driver continues anyway and later attempts to use the non-existent queue, triggering a NULL pointer dereference that halts the affected system. The fix is straightforward: check whether the allocation succeeded before proceeding.
- CVE-2025-71314MEDIUM 5.5
A vulnerability in the Linux kernel's Panthor GPU driver can cause the graphics system to hang indefinitely when memory subsystem operations fail to complete. The issue arises because the driver lacks proper recovery mechanisms for stuck cache-flush operations. When a GPU memory flush times out, the driver now schedules a reset and recovers gracefully instead of hanging. This affects systems using Panthor-based GPUs (primarily ARM Mali GPUs in certain SoCs).
- CVE-2025-71315MEDIUM 5.5
A flaw exists in the Linux kernel's virtual kernel modesetting (vkms) driver related to how it manages display refresh timing. The vkms driver previously used its own custom timer implementation for vblank (vertical blank) events, which are critical synchronization points for display rendering. The vulnerability stems from inconsistencies between this custom implementation and the standard DRM (Direct Rendering Manager) vblank timer framework. When the kernel converts vkms to use the standardized DRM vblank timer, it removes the custom hrtimer mechanism, but improper handling during this transition can cause denial-of-service conditions—specifically, the system may become unresponsive or crash when display refresh timing is disrupted.
- CVE-2026-12444MEDIUM 5.5
A memory reading vulnerability exists in Google Chrome's Chromoting feature (Google's remote desktop tool) on Windows systems running versions prior to 149.0.7827.155. An attacker with local access to a machine can craft a malicious file that, when interacted with by a user, causes Chrome to read data outside its intended memory boundaries. This out-of-bounds read could expose sensitive information already present in the process's memory—such as cached authentication tokens, encryption keys, or other confidential data—without requiring elevated privileges or special system access. The vulnerability is not currently known to be exploited in the wild.
- CVE-2026-34657MEDIUM 5.5
CAI Content Credentials, a library used to manage and verify digital content authenticity, contains a path traversal flaw in versions [email protected], c2pa-v0.80.1 and earlier. The vulnerability allows an attacker to write files to arbitrary locations on a system by crafting a malicious archive that, when extracted by a user, exploits insufficient pathname validation. This is a local attack requiring user interaction—an end user must actively extract or open the malicious file for the attack to succeed.
- CVE-2026-46104MEDIUM 5.5
A flaw exists in how the Linux kernel's SELinux security module accesses socket security data when multiple security modules are stacked together. The vulnerability occurs because SELinux directly reads socket security information from a hardcoded memory location, assuming it will always find its own data there. When another security module is loaded first, SELinux reads the wrong data instead, potentially using invalid security identifiers in permission checks. This can cause the kernel to crash due to invalid memory access or improper security decisions.
- CVE-2026-46106MEDIUM 5.5
A race condition in the Linux kernel's eventfs subsystem can cause memory corruption or system crashes when users simultaneously remount the tracefs filesystem (which hosts performance monitoring tools) while creating or deleting tracepoints. The vulnerability arises because the kernel walks through a list of event structures during remount without proper synchronization, allowing concurrent operations to corrupt data structures or access freed memory. This is a local issue affecting only users with permission to remount filesystems and modify tracing events.
- CVE-2026-46108MEDIUM 5.5
A flaw in the Linux kernel's IPMI serial interface (SI) driver can leave the system in an abnormal state when message allocation fails. Normally, failed operations trigger cleanup routines that reset the driver to a ready state. This vulnerability occurs because certain error paths skip that reset logic, potentially causing the driver to remain hung or unresponsive. An attacker with local system access could trigger memory allocation failures under specific conditions, degrading system availability until the driver is manually restarted or the system reboots.
- CVE-2026-46109MEDIUM 5.5
A memory leak exists in the Linux kernel's USB ULPI (UTMI Low Pin Interface) driver registration code. When certain initialization steps fail early in the device registration process, allocated memory is not properly freed, allowing memory to accumulate over repeated failures. This is a residual issue from a prior fix that addressed a different memory safety problem. The vulnerability requires local access and elevated privileges to trigger.
- CVE-2026-46118MEDIUM 5.5
A flaw in the Linux kernel's PAPR hypervisor pipe driver can cause the kernel to crash when attempting to create a device handle. The issue stems from a recent code refactoring that changed how the driver manages memory allocation and cleanup. When the driver tries to reuse a data structure after it has been cleared, the kernel attempts to access invalid memory, leading to a null pointer dereference and system panic. An unprivileged local user with ioctl access can trigger this crash, resulting in a denial of service.
- CVE-2026-46126MEDIUM 5.5
CVE-2026-46126 is a memory cleanup bug in the Linux kernel's RDMA/mana driver that occurs during queue pair creation with RSS (Receive Side Scaling) support. When certain operations fail during setup, the kernel fails to properly release allocated work queue objects, leaving dangling resources. An unprivileged local user can trigger this condition to cause a denial of service by exhausting kernel resources or crashing the system.
- CVE-2026-46127MEDIUM 5.5
A local memory safety issue exists in the Linux kernel's RDMA over Converged Ethernet (OCRDMA) driver. During certain error conditions in the protection domain setup function, the code attempts to dereference a null pointer instead of using a valid reference, potentially crashing the system. The vulnerability requires local access and specific user privileges to trigger, making it a moderate-severity issue affecting system stability rather than confidentiality or integrity.
- CVE-2026-46128MEDIUM 5.5
A vulnerability in the Linux kernel's IPMI (Intelligent Platform Management Interface) subsystem allows local authenticated users to cause a denial of service. The issue stems from insufficient validation of event message buffer responses from Baseboard Management Controllers (BMCs). Some BMCs may return empty or malformed event messages instead of proper error responses, which the kernel fails to validate immediately. This can lead to kernel crashes or hangs when processing these invalid responses. The vulnerability requires local access and authenticated privileges to trigger, limiting its immediate blast radius but requiring attention in environments where untrusted local users have system access.
- CVE-2026-46131MEDIUM 5.5
A flaw exists in the Linux kernel's virtualization layer (KVM) where the hypervisor incorrectly validates guest memory operations in nested virtual machines. The vulnerability occurs when checking whether a guest is running nested virtualization—the code currently checks only whether an L2 guest exists, but fails to verify that nested EPT (Extended Page Tables) or NPT (Nested Page Tables) is actually enabled. This mismatch allows a local process running inside a nested guest to trigger denial-of-service conditions by invoking hypercalls that attempt invalid memory translations. The impact is limited to availability; an attacker cannot read or modify data.
- CVE-2026-46132MEDIUM 5.5
CVE-2026-46132 is a kernel memory leak in the Linux networking subsystem that allows unprivileged local users to read up to 26 bytes of uninitialized kernel stack memory per virtual function (VF) per request. The vulnerability exists in the rtnetlink interface handler that reports virtual NIC configuration. When a user requests virtual function information, the kernel fails to zero-initialize a buffer before partially filling it with MAC broadcast data, leaving residual stack contents exposed to userspace. An attacker needs only basic local network namespace access to trigger repeated information leaks.
- CVE-2026-46134MEDIUM 5.5
A Linux kernel vulnerability in the Chrome OS Embedded Controller (cros_ec) Thunderbolt registration code fails to initialize a mutex lock, causing the system to crash when the uninitialized lock is later accessed. This affects devices that use the affected kernel code path during Thunderbolt device registration and mode switching. An unprivileged local user can trigger the crash by interacting with Thunderbolt/USB-C functionality, resulting in a denial of service.
- CVE-2026-46139MEDIUM 5.5
A flaw in the Linux kernel's SMB client code leaves a security descriptor buffer partially uninitialized when building access control lists. Specifically, a 2-byte reserved field in the ACL structure—which must be zero according to the SMB protocol specification—is left containing whatever garbage data happened to be in that heap memory. When Samba or other SMB servers validate the descriptor, they reject it if those bytes are non-zero, causing file permission operations like chmod to fail with an invalid argument error. The fix is straightforward: replace the memory allocation function with one that zeroes the buffer before use.
- CVE-2026-46141MEDIUM 5.5
A memory leak vulnerability exists in the Linux kernel's PowerPC XIVE interrupt handling code. When allocating MSI-X interrupt vectors for NVMe devices, the kernel creates interrupt data structures but fails to properly clean them up when the interrupt domain is freed. This occurs because the code looks for the data in the wrong place during cleanup, causing allocated memory to be abandoned. While this is a localized memory management issue, repeated device allocation and deallocation cycles could gradually consume system memory and degrade performance.
- CVE-2026-46142MEDIUM 5.5
A flaw in the Linux kernel's libwx network driver allows a virtual machine or container running as a non-privileged user to trigger a system hang by reading a hardware register that should only be accessible to the physical device owner. During virtual function (VF) initialization, the driver incorrectly attempts to access a restricted register (WX_CFG_PORT_ST), causing the system to hang. The issue stems from the driver not properly distinguishing between physical function (PF) and virtual function device contexts when accessing low-level hardware state.
- CVE-2026-46143MEDIUM 5.5
CVE-2026-46143 is a memory leak vulnerability in the Linux kernel's QCOM audio subsystem. The issue occurs in the ASoC (ALSA System on Chip) driver for QCOM Q6APM LPASS audio interfaces, where the prepare function can be invoked multiple times. Each invocation opens a new graph for the playback path without checking if one is already open, resulting in cumulative resource exhaustion. While the vulnerability requires local access and low-privilege execution context, the impact is availability disruption through memory exhaustion.
- CVE-2026-46144MEDIUM 5.5
A memory cleanup issue exists in the Linux kernel's RDMA/mana driver when creating RSS (Receive-Side Scaling) queue pairs. If an error occurs during queue pair creation, a virtual port steering configuration is not properly freed, leading to a resource leak. While this is a memory management issue rather than a direct data breach risk, it can degrade system stability under error conditions or be exploited to exhaust kernel memory resources on systems with RDMA/mana network adapters.
- CVE-2026-46146MEDIUM 5.5
A vulnerability exists in the Linux kernel's USB audio driver that could cause the system to hang indefinitely when processing a specially crafted USB device descriptor. The flaw is in the convert_chmap_v3() function, which processes audio channel mapping information without properly validating the descriptor size field. An attacker with local access could trigger this endless loop, causing a denial of service. The issue affects multiple versions of the Linux kernel and requires local access to exploit.
- CVE-2026-46147MEDIUM 5.5
A flaw in the Linux kernel's ARM64 KVM (virtualization) implementation can cause system resource leaks and expose partially initialized virtual CPU objects to concurrent access. When vCPU initialization encounters an error partway through, cleanup code fails to release pinned memory references, accumulating leak over time. Additionally, the vCPU object is published to shared state without proper synchronization barriers, risking observers seeing an incompletely initialized structure. This affects hypervisor deployments using ARM64-based KVM virtualization.
- CVE-2026-46148MEDIUM 5.5
A flaw in the Linux kernel's Microchip CoreQSPI SPI controller driver causes incorrect chip select (CS) line management when multiple SPI devices are connected. The hardware's built-in CS is automatically controlled by design, but this automatic behavior conflicts with proper operation when GPIO-based chip selects are also in use. The driver was modified to manually control the CS line instead, allowing correct behavior for both active-low and active-high devices, and preventing the built-in CS from being asserted while other GPIO-controlled devices are being accessed.
- CVE-2026-46151MEDIUM 5.5
A flaw in the Linux kernel's USB printer driver (usblp) allows a malicious or malfunctioning printer to leak uninitialized kernel memory to local users. When a printer responds to a device ID request with fewer bytes than claimed in its length header, the driver fails to zero out the remaining buffer before exposing it via sysfs or an ioctl. An attacker with local access could craft a printer (or intercept USB traffic) to trigger this and read sensitive kernel memory.
- CVE-2026-46153MEDIUM 5.5
A memory leak exists in the Linux kernel's VLAN (802.1Q) network driver. When network administrators repeatedly configure and then clear egress QoS priority mappings on VLAN interfaces, the kernel fails to properly delete the cleared mappings. Instead, it retains them as empty placeholders (tombstones) in memory. Over time, this causes memory to accumulate and leak, eventually exhausting system resources when the VLAN device is torn down. The fix involves properly deleting these cleared mappings after a safe grace period rather than leaving them in place.
- CVE-2026-46156MEDIUM 5.5
A flaw in the Linux kernel's Loongson GPU driver can cause a system crash when the code attempts to read from an invalid memory address during hardware initialization. The vulnerability occurs in the `loongson_gpu_fixup_dma_hang()` function, which uses incorrect logic to identify and configure GPU devices on certain Loongarch-based systems. When a discrete GPU is present in a non-standard PCI slot configuration, the driver may try to access memory at a random address, triggering a kernel panic. This is a local issue that requires prior system access and affects the stability and availability of affected systems.
- CVE-2026-46158MEDIUM 5.5
CVE-2026-46158 is a resource leak in the Linux kernel's MPTCP (Multipath TCP) protocol implementation. When the kernel retransmits an ADD_ADDR control message, it fails to properly release a reference to a socket object in certain error paths, allowing the socket's memory to remain allocated longer than necessary. This leak occurs only when specific unlikely conditions are met during ADD_ADDR retransmission, making it a localized but real availability concern on systems handling MPTCP traffic.
- CVE-2026-46160MEDIUM 5.5
A flaw in the Linux kernel's Btrfs filesystem can corrupt the transaction log during recovery if a directory is removed while a process still holds an open file descriptor to it and performs an fsync operation. When the system crashes after this sequence, the filesystem becomes inconsistent and fails to mount, resulting in data loss or extended downtime. This is a local issue requiring user-level access and specific conditions to trigger.
- CVE-2026-46161MEDIUM 5.5
A divide-by-zero vulnerability exists in the Linux kernel's RAID10 disk management code. When a user configures RAID10 with a "far_copies" value of zero, the kernel crashes instead of rejecting the invalid configuration. This requires local access and root-level privileges to trigger, making it a local denial-of-service risk rather than a remote compromise threat.
- CVE-2026-46165MEDIUM 5.5
A self-deadlock vulnerability exists in the Linux kernel's Open vSwitch module when tunnel ports are released. The issue occurs because the code attempts to clean up network device references while holding locks that prevent the cleanup from completing, causing the system to hang during tunnel port deletion. This is a local denial-of-service condition that affects systems running vulnerable kernel versions with Open vSwitch configured.
- CVE-2026-46167MEDIUM 5.5
A flaw in the Linux kernel's USB printer driver (usblp) allows uninitialized kernel memory to leak to user-space applications through the LPGETSTATUS ioctl command. When a USB printer responds with fewer bytes than expected, the driver fails to initialize the response buffer properly, potentially exposing stale heap memory to callers. This can occur even with standard-behaving printers; the vulnerability is particularly concerning in multi-user environments where one user's application could inadvertently receive residual kernel memory from prior operations.
- CVE-2026-46168MEDIUM 5.5
A vulnerability in the Linux kernel's multipath TCP (MPTCP) implementation allows a local attacker with standard user privileges to trigger a denial-of-service condition. The issue stems from improper locking during socket option handling for timestamps. When the kernel attempts to set timestamp options, it uses a fast atomic lock that cannot safely call functions designed to sleep, resulting in a kernel panic. An unprivileged user can exploit this by making specific socket option calls, causing the system to crash or become unresponsive.
- CVE-2026-46169MEDIUM 5.5
CVE-2026-46169 is a memory initialization bug in the Linux kernel's HFS+ filesystem driver. When mounting a corrupted HFS+ filesystem, the kernel may read incomplete catalog records and fail to detect that the data is truncated. This leaves portions of a kernel data structure uninitialized. Later, when the filesystem code attempts to process the incomplete record—such as performing case-insensitive string comparison—it uses the uninitialized memory as array indices, triggering a kernel warning. An unprivileged local attacker with the ability to mount a crafted filesystem image could trigger this condition, potentially causing a denial of service or information disclosure.
- CVE-2026-46170MEDIUM 5.5
A flaw in the Linux kernel's MPTCP (Multipath TCP) path manager can cause a denial of service when certain network protocol messages are retransmitted. Specifically, when an ADD_ADDR message is resent, the kernel may mismanage internal reference counting for a socket object, potentially leading to a deadlock or crash. An unprivileged local user can trigger this condition, causing the affected system to become unresponsive.
- CVE-2026-46171MEDIUM 5.5
A memory leak exists in the Linux kernel's RISC-V KVM (virtualization) subsystem. When the kernel attempts to allocate memory for virtual CPU vector context during guest setup, it allocates two separate memory blocks. If the second allocation fails, the first block is not freed, causing a memory leak. This leak occurs in unprivileged code paths and can gradually exhaust kernel memory, leading to system denial of service.
- CVE-2026-46172MEDIUM 5.5
A memory leak vulnerability exists in the Linux kernel's IPv6 IPsec handling code. When the kernel processes certain incoming IPv6 packets with IPsec encapsulation, it performs a route lookup but fails to properly clean up a reference to the routing information in error conditions. An attacker with local access could trigger this flaw repeatedly, exhausting kernel memory and causing a denial of service.
- CVE-2026-46179MEDIUM 5.5
A vulnerability in the Linux kernel's ASoC (ALSA System on Chip) audio subsystem allows local users to trigger a divide-by-zero condition when working with compressed audio streams. The kernel fails to validate that critical stream configuration parameters are properly initialized before performing calculations with them, creating a denial-of-service vector for any local process with audio subsystem access.
- CVE-2026-46182MEDIUM 5.5
A vulnerability in the Linux kernel's IBM POWER Systems (pseries) PAPR hypervisor pipe driver allows uninitialized kernel memory to be exposed to unprivileged users. When the driver copies a header structure to userspace, it fails to zero out reserved padding fields within that structure, inadvertently leaking sensitive kernel data. An attacker with local access could read this leaked memory to potentially gather information about the running kernel state.
- CVE-2026-46184MEDIUM 5.5
A USB audio device driver in the Linux kernel can crash if a malformed device provides zero audio channels. The driver fails to validate a critical USB descriptor field before using it in calculations, leading to a division-by-zero error when the device is connected. An attacker with physical access to plug in a crafted USB device could trigger a kernel panic on vulnerable systems.
- CVE-2026-46186MEDIUM 5.5
A flaw in the Linux kernel's Bluetooth virtio driver fails to validate that incoming packets contain enough data before processing them. When a malformed or truncated packet arrives, the driver can read beyond the packet's actual boundaries, potentially accessing uninitialized memory. This could cause the system to crash or misbehave, particularly on systems with active Bluetooth connections.
- CVE-2026-46188MEDIUM 5.5
A flaw exists in the Linux kernel's Cavium Octeon EP VF driver where a memory allocation function can fail but the code doesn't check for failure. When this happens, the driver tries to use the failed allocation as if it were valid, causing the system to crash. This is a local issue requiring user-level access to trigger.
- CVE-2026-46192MEDIUM 5.5
A flaw exists in the Linux kernel's Microchip QSPI (Quad SPI) driver that causes read operations to fail when using dual or quad-mode communication. The driver incorrectly attempts to transmit garbage data to generate clock cycles during read-only operations, but QSPI lacks a dedicated output line for this purpose in these modes. This causes the transfer to stall, effectively making data reads unreliable or impossible on affected systems using this driver.