2026 · Medium

Medium-severity vulnerabilities disclosed in 2026

Medium-rated CVEs published in 2026, with SEC.co remediation and prioritization guidance.

4010 published vulnerabilities · page 20 of 41

  • CVE-2026-36910MEDIUM 5.5

    MPC-BE, a media player application, contains a flaw in how it reads MP4 video files. An attacker can craft a specially designed MP4 file that triggers an access violation when the player tries to read it, causing the application to crash. This is a local attack that requires a user to open the malicious file, but once they do, the player becomes unavailable until restarted.

  • CVE-2026-36911MEDIUM 5.5

    A division-by-zero bug in MPC-BE, a popular open-source media player, can be triggered by opening a specially crafted MP4 file. The vulnerability crashes the application, denying service to the user. An attacker would need local access or the ability to trick a user into opening a malicious file, but no special privileges are required.

  • CVE-2026-39031MEDIUM 5.5

    Lansweeper's credential encryption in lsrunase 2.0 and lsencrypt 2.0 relies on a weak cryptographic approach: all encrypted passwords use the same hardcoded 142-byte key derived from RC4. Because an 8-character prefix of each encrypted credential is stored unencrypted, an attacker with local system access can recover any plaintext password by performing a single SHA-1 hash and RC4 decryption—no guessing, no brute force. This is a local privilege/credential exposure issue affecting users who depend on Lansweeper for credential management on compromised or physically accessible systems.

  • CVE-2026-39243MEDIUM 5.5

    decompress before version 4.2.2 contains a vulnerability that allows attackers to create hardlinks to arbitrary files on a system during archive extraction. When a malicious archive is extracted, an attacker can craft hardlink entries that point to sensitive files elsewhere on the filesystem, creating a link inside the extraction directory that shares the same underlying file. This enables the attacker to read the contents of files they shouldn't have access to, or potentially modify those files. The vulnerability requires user interaction (extracting an archive) but doesn't require elevated privileges to exploit.

  • CVE-2026-40257MEDIUM 5.5

    OP-TEE, a Trusted Execution Environment for ARM processors, contains a critical memory corruption bug in its SHA-3 cryptographic implementation when using ARM Crypto Extensions. The vulnerability stems from an off-by-one error in the SHA-3 accelerated code path that triggers a heap overflow, potentially corrupting the entire TEE kernel memory. This affects deployments running OP-TEE versions 3.21.0 through 4.10.x on ARMv8.2+ platforms with SHA3 Crypto Extensions enabled. Organizations must upgrade to version 4.11.0 or disable the affected acceleration feature.

  • CVE-2026-40722MEDIUM 5.5

    Yoast SEO Premium contains a missing authorization flaw that allows authenticated administrators to perform actions they shouldn't be able to perform, potentially modifying content or causing service disruption. The vulnerability affects versions up to and including 26.6. While exploitation requires administrative-level access and doesn't compromise confidentiality, it does enable unauthorized modification of system state and availability.

  • CVE-2026-41047MEDIUM 5.5

    qSnapper, a snapshot management tool from Presire, contains a missing authentication control in its snapshot diff feature. This allows a local user to view sensitive information that should be restricted, even if they lack normal read permissions. The vulnerability affects versions prior to 1.3.3 and requires local system access to exploit.

  • CVE-2026-41155MEDIUM 5.5

    CVE-2026-41155 is a medium-severity flaw in a GPU kernel module that allows a local attacker to interfere with secure GPU processes running on the same system. By exploiting how the kernel manages shared secure memory between GPU workloads, an attacker can either pass unauthorized data between isolated processes or deliberately corrupt GPU memory, causing image corruption and triggering hardware recovery. The vulnerability requires local access and valid user privileges, but does not enable direct data theft—the damage is primarily availability-focused.

  • CVE-2026-41979MEDIUM 5.5

    CVE-2026-41979 is a permission control vulnerability in a print module that could allow an attacker with local access to modify or read sensitive data. The vulnerability requires user interaction to exploit but does not require elevated privileges beforehand. While the impact is limited to data integrity and confidentiality concerns, it represents a meaningful risk in multi-user or shared-system environments where print functionality is commonly accessed.

  • CVE-2026-41980MEDIUM 5.5

    A permission control flaw in a file preview module allows unauthorized access to sensitive file contents. An attacker with local access to a system can bypass intended access restrictions and view files they should not be able to preview, potentially exposing confidential information. The vulnerability requires user interaction to trigger but does not require special privileges to exploit.

  • CVE-2026-42906MEDIUM 5.5

    CVE-2026-42906 is a moderate-severity information disclosure vulnerability in Windows Shell that allows an authenticated attacker with local access to read sensitive information on a system. The flaw does not enable privilege escalation, system modification, or denial of service—it is purely about unauthorized data exposure. An attacker must already have valid login credentials and local system access to exploit it, which limits the attack surface but remains a realistic threat in environments where user account compromise is a concern.

  • CVE-2026-42915MEDIUM 5.5

    Windows VMSwitch, the virtual networking component in Windows, contains a flaw in how it calculates memory buffer sizes. An attacker with local access to an affected system can exploit this miscalculation to crash the VMSwitch service, causing a denial of service. The attacker needs valid credentials to trigger the issue, so this is not a remote or unauthenticated attack vector. The vulnerability affects Windows 10, Windows 11, and Windows Server 2022/2025.

  • CVE-2026-42968MEDIUM 5.5

    Windows Telephony Service contains a flaw that allows a local, authenticated user to read data from a portion of memory that the program doesn't properly protect. An attacker must already have legitimate login credentials and local system access; they cannot exploit this remotely. The leaked information could include sensitive data, but the attacker cannot modify systems or prevent them from functioning. This affects a wide range of Windows 10 and Windows 11 versions, as well as Windows Server 2012 through 2025.

  • CVE-2026-42969MEDIUM 5.5

    CVE-2026-42969 is a local information disclosure vulnerability in Windows Push Notifications that affects an authorized user's ability to access sensitive data on their own system. An attacker who already has local access and user-level privileges can exploit uninitialized memory in the Push Notifications service to read information they shouldn't normally see. This is not a remote vulnerability—the attacker must already have a foothold on the machine. The issue carries medium severity because it requires pre-existing access but can leak confidential data.

  • CVE-2026-42970MEDIUM 5.5

    A flaw in Windows Push Notifications can allow a user with local access to a computer to read sensitive information that should be protected. An attacker with an existing local account on the system could potentially view data in the push notification system without authorization. This is not a remote vulnerability and requires the attacker to already have some level of access to the machine.

  • CVE-2026-42971MEDIUM 5.5

    A vulnerability in Windows Push Notifications can allow an authorized user on a system to access sensitive information they should not be able to see. The flaw requires local access and valid credentials, but once those conditions are met, an attacker can read confidential data without further user interaction. This is a local information disclosure issue affecting multiple Windows versions from Windows 10 through Windows 11, as well as Windows Server 2016 through 2025.

  • CVE-2026-42972MEDIUM 5.5

    A flaw in Windows Hyper-V can leak sensitive information to users who already have local access to a system. An attacker with a standard user account on the machine could exploit this to read data they shouldn't be able to access. While the vulnerability requires existing local privileges, the information exposure is significant enough to warrant attention, particularly in multi-tenant or shared system environments.

  • CVE-2026-42973MEDIUM 5.5

    CVE-2026-42973 is a Windows Push Notifications vulnerability that allows an authorized user on a local machine to read sensitive information they should not have access to. This is not a remote attack—an attacker must already have a valid user account on the system. The flaw exposes confidential data without modifying or disabling any systems, making it a disclosure risk rather than a system-breaking vulnerability.

  • CVE-2026-4367MEDIUM 5.5

    CVE-2026-4367 is a flaw in libXpm, the X Window System image library, that allows a local attacker with basic user privileges to crash applications by crafting or providing a malformed XPM image file. The vulnerability stems from improper validation in the xpmNextWord() function, which can read memory beyond the file boundary, triggering denial of service. An attacker needs local access and user interaction (or the ability to supply a file to a vulnerable application) to exploit it.

  • CVE-2026-43722MEDIUM 5.5

    A vulnerability in Apple's operating systems allows apps running on a device to access sensitive information stored in the kernel—the core of the operating system. An attacker would need to already have an app installed on the target device to exploit this issue. The vulnerability stems from insufficient validation of user-supplied input before the kernel processes it. Apple has patched this across iPhone, iPad, and Mac by improving how the system sanitizes input data.

  • CVE-2026-44018MEDIUM 5.5

    Docling, a document processing library that integrates with AI systems, contains a vulnerability in how it handles METS-GBS (a specialized XML-based document archive format) files. Versions 2.45.0 through 2.90.x lack proper security checks when parsing these archives. An attacker could create a malicious METS-GBS file that, when opened by a user in an application using vulnerable Docling, could read files from the system, consume excessive memory or CPU, or crash the application. The vulnerability requires user interaction—the file must be opened—but doesn't require special privileges to trigger.

  • CVE-2026-44022MEDIUM 5.5

    Docling, a document processing library, contains a path traversal vulnerability in how it handles LaTeX file inclusion commands. An attacker can craft a malicious LaTeX document that, when processed by Docling, reads arbitrary files from the system and includes them in the converted output. This affects versions 2.73.0 through 2.90.x. The vulnerability requires user interaction—someone must process the attacker-supplied LaTeX document—but once triggered, the attacker gains read access to any file the Docling process can access, potentially exposing credentials, configuration data, or other sensitive information.

  • CVE-2026-44119MEDIUM 5.5

    Apache HTTP Server versions 2.4.67 and earlier contain a privilege escalation vulnerability that allows local users who can author .htaccess files to read arbitrary files with the permissions of the httpd daemon user. This is a local-only vulnerability requiring existing system access and the ability to modify .htaccess configuration files, but it can expose sensitive application data and system files to unprivileged users.

  • CVE-2026-44362MEDIUM 5.5

    OP-TEE, a security-focused execution environment used in Arm-based systems, contains a flaw that bypasses protections against loading outdated or revoked code signing keys. When Trusted Applications (TAs)—sensitive code components that run in the secure environment—are loaded, the system should verify that the signing keys used haven't been revoked or rolled back to older versions. However, a bug in the key loading process discards version information, causing the system to forget it ever saw a particular key version. This allows attackers to load TAs that were signed with deliberately downgraded or revoked keys, undermining a critical security boundary. The flaw affects OP-TEE versions 3.20.0 through 4.10.x, with a fix available in version 4.11.0.

  • CVE-2026-44512MEDIUM 5.5

    ONNX (Open Neural Network Exchange), a widely-used standard for sharing machine learning models across frameworks, contains a vulnerability in its version converter tool. When this tool processes a specially crafted model file—specifically one with an Upsample component that lacks the required inputs—the software crashes due to a null pointer dereference. An attacker can exploit this by distributing a malicious model file; anyone who attempts to convert it using affected ONNX versions will experience a denial-of-service condition. The vulnerability affects ONNX versions 1.9.0 through 1.21.x and is resolved in version 1.22.0.

  • CVE-2026-44805MEDIUM 5.5

    A use-after-free vulnerability exists in Windows Network Controller Host Agent that allows a logged-in user to crash or hang the affected service, disrupting network configuration and management capabilities. The attacker must already have local user privileges on the system to exploit this flaw. While this is not currently known to be exploited in the wild, it represents a local denial-of-service risk that can render critical network infrastructure management unavailable.

  • CVE-2026-44814MEDIUM 5.5

    A flaw in Windows Desktop Window Manager (DWM) Core Library allows an authorized local user to read memory they shouldn't have access to. The vulnerability doesn't let attackers modify data or crash the system, but it does enable unauthorized disclosure of sensitive information resident in memory. This is a local-only issue—remote exploitation isn't possible—and requires the attacker to already have user-level access to the system.

  • CVE-2026-44821MEDIUM 5.5

    CVE-2026-44821 is a medium-severity memory flaw in Microsoft Office products that allows an attacker with local access to read sensitive information from memory without user interaction beyond opening a file. The vulnerability does not enable modification of data or disruption of the application, but the confidentiality risk is significant—particularly in multi-user or shared-device environments where an attacker can extract information resident in Office's memory footprint.

  • CVE-2026-44885MEDIUM 5.5

    Portainer Community Edition versions 2.33.0 through 2.33.7 contain a directory traversal flaw in the backup restore function. When administrators upload a .tar.gz backup file to restore Portainer's configuration, the extraction process fails to properly validate file paths. A malicious backup archive can exploit this to write files outside the intended directory, potentially placing them anywhere on the server filesystem—for instance, in cron job directories or other sensitive locations. An attacker with high-level privileges (such as admin access) can craft a backup to inject malicious files into the host system during restoration. The vulnerability is resolved in version 2.33.8.

  • CVE-2026-44918MEDIUM 5.5

    OpenStack Ironic, a service that manages bare metal computing resources, contains an authorization flaw that allows privileged users to create or modify compute nodes belonging to other projects without proper access controls. An attacker with administrative credentials in one project could gain visibility and control over infrastructure resources that should be isolated to separate projects or organizations, though they cannot read sensitive data or cause service outages directly.

  • CVE-2026-45078MEDIUM 5.5

    Synapse, an open-source Matrix homeserver, contains a denial-of-service vulnerability affecting versions prior to 1.152.1. An authenticated local user can craft requests that consume excessive CPU resources, starving other legitimate requests and causing service degradation for other users. The attack requires valid credentials and local system access but does not require user interaction.

  • CVE-2026-45256MEDIUM 5.5

    A permission-checking flaw in FreeBSD's thr_kill2() system call allows unprivileged local users to send signals to processes they shouldn't be able to reach. The kernel performs a permission check but ignores the result before actually delivering the signal, meaning the signal arrives even though it was denied. An attacker with local access can exploit this to stop or crash critical system processes, causing service outages. The vulnerability is made more practical because thread IDs are assigned sequentially and globally, allowing attackers to discover targets through brute-force enumeration without needing detailed system knowledge.

  • CVE-2026-45287MEDIUM 5.5

    OpenTelemetry-Go versions prior to 0.0.17 contain a resource leak that causes file descriptor exhaustion. When an application repeatedly parses OpenTelemetry schema files using the `ParseFile` function, each call opens a file but fails to close it. In a long-running service, an attacker who can trigger repeated schema parsing—such as by supplying attacker-controlled file paths—can exhaust the process's file descriptor limit, forcing a denial of service. The vulnerability requires the consuming application to expose schema parsing to external input; it is not a direct remote attack vector.

  • CVE-2026-45581MEDIUM 5.5

    A logging flaw in Hyperledger Fabric's Java chaincode implementation exposes TLS private key passwords in plaintext when running in chaincode-as-a-service mode with TLS enabled. Affected versions 2.3.1 through 2.5.9 write sensitive credential material to INFO-level logs, which could allow attackers with log access to extract the password and, if they also obtain the private key itself, impersonate the chaincode server. The vulnerability has been resolved in version 2.5.10.

  • CVE-2026-45594MEDIUM 5.5

    CVE-2026-45594 is a medium-severity information disclosure vulnerability in Windows Application Identity (AppID) Subsystem. An attacker who already has local access to a Windows machine can exploit this flaw to read sensitive information that should not be accessible to them. The vulnerability requires the attacker to have user-level privileges and does not involve any user interaction. It affects Windows 10 and Windows 11 across multiple versions, as well as Windows Server 2016 through 2025.

  • CVE-2026-45604MEDIUM 5.5

    A flaw in Windows Application Identity (AppID) Subsystem allows an already-logged-in user to read memory they shouldn't have access to, potentially exposing sensitive information. An attacker would need legitimate local credentials and active system access to exploit it. This is a local-only disclosure issue with no ability to crash the system or modify data.

  • CVE-2026-45606MEDIUM 5.5

    A flaw in Microsoft's UxTheme Library (uxtheme.dll) can be exploited by a user with local access to cause a denial of service. The vulnerability stems from reading data outside the bounds of allocated memory. An attacker would need existing login credentials or physical access to the machine to trigger the issue, which could crash or hang the affected application, disrupting work but not exposing sensitive data.

  • CVE-2026-45634MEDIUM 5.5

    CVE-2026-45634 is a memory reading flaw in Windows DHCP Server that allows a logged-in attacker to extract sensitive information from the system. An attacker with local access and standard user privileges can exploit an out-of-bounds read condition to leak data in memory, potentially exposing credentials, encryption keys, or other confidential information. This is not a remote vulnerability and does not enable code execution, but it can compromise the confidentiality of data stored on affected systems.

  • CVE-2026-45647MEDIUM 5.5

    Microsoft Defender for Endpoint contains a time-of-check time-of-use (TOCTOU) race condition that allows an authorized local user to escalate their privileges. An attacker with valid credentials on a system running the affected software can exploit a window between a security check and a subsequent action to bypass protections and gain elevated access. This is not an unauthenticated remote attack; the attacker must already have local system access.

  • CVE-2026-45676MEDIUM 5.5

    OpenTelemetry eBPF Instrumentation, a tool that uses eBPF technology to gather observability data, contains a flaw in how it parses ELF executable files. An attacker with local access can craft a malicious executable that tricks the instrumentation agent into reading invalid memory locations or accessing incorrect parts of files, causing the agent to crash. This prevents the agent from operating until it's restarted, which could disrupt monitoring visibility in affected environments. The issue affects all versions prior to 0.9.0.

  • CVE-2026-45792MEDIUM 5.5

    RTK (Rust Token Killer), a tool that filters and compresses command outputs for large language models, contains a configuration trust vulnerability in versions before 0.32.0. An attacker who gains write access to a repository can place a malicious filter configuration file (.rtk/filters.toml) that automatically loads with highest priority, allowing them to silently modify or suppress command outputs—such as file contents, code diffs, or security scan results—before they reach an LLM. This could enable concealment of malicious code during AI-assisted code review or development workflows without the developer's knowledge.

  • CVE-2026-46104MEDIUM 5.5

    A flaw exists in how the Linux kernel's SELinux security module accesses socket security data when multiple security modules are stacked together. The vulnerability occurs because SELinux directly reads socket security information from a hardcoded memory location, assuming it will always find its own data there. When another security module is loaded first, SELinux reads the wrong data instead, potentially using invalid security identifiers in permission checks. This can cause the kernel to crash due to invalid memory access or improper security decisions.

  • CVE-2026-46106MEDIUM 5.5

    A race condition in the Linux kernel's eventfs subsystem can cause memory corruption or system crashes when users simultaneously remount the tracefs filesystem (which hosts performance monitoring tools) while creating or deleting tracepoints. The vulnerability arises because the kernel walks through a list of event structures during remount without proper synchronization, allowing concurrent operations to corrupt data structures or access freed memory. This is a local issue affecting only users with permission to remount filesystems and modify tracing events.

  • CVE-2026-46108MEDIUM 5.5

    A flaw in the Linux kernel's IPMI serial interface (SI) driver can leave the system in an abnormal state when message allocation fails. Normally, failed operations trigger cleanup routines that reset the driver to a ready state. This vulnerability occurs because certain error paths skip that reset logic, potentially causing the driver to remain hung or unresponsive. An attacker with local system access could trigger memory allocation failures under specific conditions, degrading system availability until the driver is manually restarted or the system reboots.

  • CVE-2026-46109MEDIUM 5.5

    A memory leak exists in the Linux kernel's USB ULPI (UTMI Low Pin Interface) driver registration code. When certain initialization steps fail early in the device registration process, allocated memory is not properly freed, allowing memory to accumulate over repeated failures. This is a residual issue from a prior fix that addressed a different memory safety problem. The vulnerability requires local access and elevated privileges to trigger.

  • CVE-2026-46118MEDIUM 5.5

    A flaw in the Linux kernel's PAPR hypervisor pipe driver can cause the kernel to crash when attempting to create a device handle. The issue stems from a recent code refactoring that changed how the driver manages memory allocation and cleanup. When the driver tries to reuse a data structure after it has been cleared, the kernel attempts to access invalid memory, leading to a null pointer dereference and system panic. An unprivileged local user with ioctl access can trigger this crash, resulting in a denial of service.

  • CVE-2026-46126MEDIUM 5.5

    CVE-2026-46126 is a memory cleanup bug in the Linux kernel's RDMA/mana driver that occurs during queue pair creation with RSS (Receive Side Scaling) support. When certain operations fail during setup, the kernel fails to properly release allocated work queue objects, leaving dangling resources. An unprivileged local user can trigger this condition to cause a denial of service by exhausting kernel resources or crashing the system.

  • CVE-2026-46127MEDIUM 5.5

    A local memory safety issue exists in the Linux kernel's RDMA over Converged Ethernet (OCRDMA) driver. During certain error conditions in the protection domain setup function, the code attempts to dereference a null pointer instead of using a valid reference, potentially crashing the system. The vulnerability requires local access and specific user privileges to trigger, making it a moderate-severity issue affecting system stability rather than confidentiality or integrity.

  • CVE-2026-46128MEDIUM 5.5

    A vulnerability in the Linux kernel's IPMI (Intelligent Platform Management Interface) subsystem allows local authenticated users to cause a denial of service. The issue stems from insufficient validation of event message buffer responses from Baseboard Management Controllers (BMCs). Some BMCs may return empty or malformed event messages instead of proper error responses, which the kernel fails to validate immediately. This can lead to kernel crashes or hangs when processing these invalid responses. The vulnerability requires local access and authenticated privileges to trigger, limiting its immediate blast radius but requiring attention in environments where untrusted local users have system access.

  • CVE-2026-46131MEDIUM 5.5

    A flaw exists in the Linux kernel's virtualization layer (KVM) where the hypervisor incorrectly validates guest memory operations in nested virtual machines. The vulnerability occurs when checking whether a guest is running nested virtualization—the code currently checks only whether an L2 guest exists, but fails to verify that nested EPT (Extended Page Tables) or NPT (Nested Page Tables) is actually enabled. This mismatch allows a local process running inside a nested guest to trigger denial-of-service conditions by invoking hypercalls that attempt invalid memory translations. The impact is limited to availability; an attacker cannot read or modify data.

  • CVE-2026-46132MEDIUM 5.5

    CVE-2026-46132 is a kernel memory leak in the Linux networking subsystem that allows unprivileged local users to read up to 26 bytes of uninitialized kernel stack memory per virtual function (VF) per request. The vulnerability exists in the rtnetlink interface handler that reports virtual NIC configuration. When a user requests virtual function information, the kernel fails to zero-initialize a buffer before partially filling it with MAC broadcast data, leaving residual stack contents exposed to userspace. An attacker needs only basic local network namespace access to trigger repeated information leaks.

  • CVE-2026-46134MEDIUM 5.5

    A Linux kernel vulnerability in the Chrome OS Embedded Controller (cros_ec) Thunderbolt registration code fails to initialize a mutex lock, causing the system to crash when the uninitialized lock is later accessed. This affects devices that use the affected kernel code path during Thunderbolt device registration and mode switching. An unprivileged local user can trigger the crash by interacting with Thunderbolt/USB-C functionality, resulting in a denial of service.

  • CVE-2026-46139MEDIUM 5.5

    A flaw in the Linux kernel's SMB client code leaves a security descriptor buffer partially uninitialized when building access control lists. Specifically, a 2-byte reserved field in the ACL structure—which must be zero according to the SMB protocol specification—is left containing whatever garbage data happened to be in that heap memory. When Samba or other SMB servers validate the descriptor, they reject it if those bytes are non-zero, causing file permission operations like chmod to fail with an invalid argument error. The fix is straightforward: replace the memory allocation function with one that zeroes the buffer before use.

  • CVE-2026-46141MEDIUM 5.5

    A memory leak vulnerability exists in the Linux kernel's PowerPC XIVE interrupt handling code. When allocating MSI-X interrupt vectors for NVMe devices, the kernel creates interrupt data structures but fails to properly clean them up when the interrupt domain is freed. This occurs because the code looks for the data in the wrong place during cleanup, causing allocated memory to be abandoned. While this is a localized memory management issue, repeated device allocation and deallocation cycles could gradually consume system memory and degrade performance.

  • CVE-2026-46142MEDIUM 5.5

    A flaw in the Linux kernel's libwx network driver allows a virtual machine or container running as a non-privileged user to trigger a system hang by reading a hardware register that should only be accessible to the physical device owner. During virtual function (VF) initialization, the driver incorrectly attempts to access a restricted register (WX_CFG_PORT_ST), causing the system to hang. The issue stems from the driver not properly distinguishing between physical function (PF) and virtual function device contexts when accessing low-level hardware state.

  • CVE-2026-46143MEDIUM 5.5

    CVE-2026-46143 is a memory leak vulnerability in the Linux kernel's QCOM audio subsystem. The issue occurs in the ASoC (ALSA System on Chip) driver for QCOM Q6APM LPASS audio interfaces, where the prepare function can be invoked multiple times. Each invocation opens a new graph for the playback path without checking if one is already open, resulting in cumulative resource exhaustion. While the vulnerability requires local access and low-privilege execution context, the impact is availability disruption through memory exhaustion.

  • CVE-2026-46144MEDIUM 5.5

    A memory cleanup issue exists in the Linux kernel's RDMA/mana driver when creating RSS (Receive-Side Scaling) queue pairs. If an error occurs during queue pair creation, a virtual port steering configuration is not properly freed, leading to a resource leak. While this is a memory management issue rather than a direct data breach risk, it can degrade system stability under error conditions or be exploited to exhaust kernel memory resources on systems with RDMA/mana network adapters.

  • CVE-2026-46146MEDIUM 5.5

    A vulnerability exists in the Linux kernel's USB audio driver that could cause the system to hang indefinitely when processing a specially crafted USB device descriptor. The flaw is in the convert_chmap_v3() function, which processes audio channel mapping information without properly validating the descriptor size field. An attacker with local access could trigger this endless loop, causing a denial of service. The issue affects multiple versions of the Linux kernel and requires local access to exploit.

  • CVE-2026-46147MEDIUM 5.5

    A flaw in the Linux kernel's ARM64 KVM (virtualization) implementation can cause system resource leaks and expose partially initialized virtual CPU objects to concurrent access. When vCPU initialization encounters an error partway through, cleanup code fails to release pinned memory references, accumulating leak over time. Additionally, the vCPU object is published to shared state without proper synchronization barriers, risking observers seeing an incompletely initialized structure. This affects hypervisor deployments using ARM64-based KVM virtualization.

  • CVE-2026-46148MEDIUM 5.5

    A flaw in the Linux kernel's Microchip CoreQSPI SPI controller driver causes incorrect chip select (CS) line management when multiple SPI devices are connected. The hardware's built-in CS is automatically controlled by design, but this automatic behavior conflicts with proper operation when GPIO-based chip selects are also in use. The driver was modified to manually control the CS line instead, allowing correct behavior for both active-low and active-high devices, and preventing the built-in CS from being asserted while other GPIO-controlled devices are being accessed.

  • CVE-2026-46151MEDIUM 5.5

    A flaw in the Linux kernel's USB printer driver (usblp) allows a malicious or malfunctioning printer to leak uninitialized kernel memory to local users. When a printer responds to a device ID request with fewer bytes than claimed in its length header, the driver fails to zero out the remaining buffer before exposing it via sysfs or an ioctl. An attacker with local access could craft a printer (or intercept USB traffic) to trigger this and read sensitive kernel memory.

  • CVE-2026-46153MEDIUM 5.5

    A memory leak exists in the Linux kernel's VLAN (802.1Q) network driver. When network administrators repeatedly configure and then clear egress QoS priority mappings on VLAN interfaces, the kernel fails to properly delete the cleared mappings. Instead, it retains them as empty placeholders (tombstones) in memory. Over time, this causes memory to accumulate and leak, eventually exhausting system resources when the VLAN device is torn down. The fix involves properly deleting these cleared mappings after a safe grace period rather than leaving them in place.

  • CVE-2026-46156MEDIUM 5.5

    A flaw in the Linux kernel's Loongson GPU driver can cause a system crash when the code attempts to read from an invalid memory address during hardware initialization. The vulnerability occurs in the `loongson_gpu_fixup_dma_hang()` function, which uses incorrect logic to identify and configure GPU devices on certain Loongarch-based systems. When a discrete GPU is present in a non-standard PCI slot configuration, the driver may try to access memory at a random address, triggering a kernel panic. This is a local issue that requires prior system access and affects the stability and availability of affected systems.

  • CVE-2026-46158MEDIUM 5.5

    CVE-2026-46158 is a resource leak in the Linux kernel's MPTCP (Multipath TCP) protocol implementation. When the kernel retransmits an ADD_ADDR control message, it fails to properly release a reference to a socket object in certain error paths, allowing the socket's memory to remain allocated longer than necessary. This leak occurs only when specific unlikely conditions are met during ADD_ADDR retransmission, making it a localized but real availability concern on systems handling MPTCP traffic.

  • CVE-2026-46160MEDIUM 5.5

    A flaw in the Linux kernel's Btrfs filesystem can corrupt the transaction log during recovery if a directory is removed while a process still holds an open file descriptor to it and performs an fsync operation. When the system crashes after this sequence, the filesystem becomes inconsistent and fails to mount, resulting in data loss or extended downtime. This is a local issue requiring user-level access and specific conditions to trigger.

  • CVE-2026-46161MEDIUM 5.5

    A divide-by-zero vulnerability exists in the Linux kernel's RAID10 disk management code. When a user configures RAID10 with a "far_copies" value of zero, the kernel crashes instead of rejecting the invalid configuration. This requires local access and root-level privileges to trigger, making it a local denial-of-service risk rather than a remote compromise threat.

  • CVE-2026-46165MEDIUM 5.5

    A self-deadlock vulnerability exists in the Linux kernel's Open vSwitch module when tunnel ports are released. The issue occurs because the code attempts to clean up network device references while holding locks that prevent the cleanup from completing, causing the system to hang during tunnel port deletion. This is a local denial-of-service condition that affects systems running vulnerable kernel versions with Open vSwitch configured.

  • CVE-2026-46167MEDIUM 5.5

    A flaw in the Linux kernel's USB printer driver (usblp) allows uninitialized kernel memory to leak to user-space applications through the LPGETSTATUS ioctl command. When a USB printer responds with fewer bytes than expected, the driver fails to initialize the response buffer properly, potentially exposing stale heap memory to callers. This can occur even with standard-behaving printers; the vulnerability is particularly concerning in multi-user environments where one user's application could inadvertently receive residual kernel memory from prior operations.

  • CVE-2026-46168MEDIUM 5.5

    A vulnerability in the Linux kernel's multipath TCP (MPTCP) implementation allows a local attacker with standard user privileges to trigger a denial-of-service condition. The issue stems from improper locking during socket option handling for timestamps. When the kernel attempts to set timestamp options, it uses a fast atomic lock that cannot safely call functions designed to sleep, resulting in a kernel panic. An unprivileged user can exploit this by making specific socket option calls, causing the system to crash or become unresponsive.

  • CVE-2026-46169MEDIUM 5.5

    CVE-2026-46169 is a memory initialization bug in the Linux kernel's HFS+ filesystem driver. When mounting a corrupted HFS+ filesystem, the kernel may read incomplete catalog records and fail to detect that the data is truncated. This leaves portions of a kernel data structure uninitialized. Later, when the filesystem code attempts to process the incomplete record—such as performing case-insensitive string comparison—it uses the uninitialized memory as array indices, triggering a kernel warning. An unprivileged local attacker with the ability to mount a crafted filesystem image could trigger this condition, potentially causing a denial of service or information disclosure.

  • CVE-2026-46170MEDIUM 5.5

    A flaw in the Linux kernel's MPTCP (Multipath TCP) path manager can cause a denial of service when certain network protocol messages are retransmitted. Specifically, when an ADD_ADDR message is resent, the kernel may mismanage internal reference counting for a socket object, potentially leading to a deadlock or crash. An unprivileged local user can trigger this condition, causing the affected system to become unresponsive.

  • CVE-2026-46171MEDIUM 5.5

    A memory leak exists in the Linux kernel's RISC-V KVM (virtualization) subsystem. When the kernel attempts to allocate memory for virtual CPU vector context during guest setup, it allocates two separate memory blocks. If the second allocation fails, the first block is not freed, causing a memory leak. This leak occurs in unprivileged code paths and can gradually exhaust kernel memory, leading to system denial of service.

  • CVE-2026-46172MEDIUM 5.5

    A memory leak vulnerability exists in the Linux kernel's IPv6 IPsec handling code. When the kernel processes certain incoming IPv6 packets with IPsec encapsulation, it performs a route lookup but fails to properly clean up a reference to the routing information in error conditions. An attacker with local access could trigger this flaw repeatedly, exhausting kernel memory and causing a denial of service.

  • CVE-2026-46179MEDIUM 5.5

    A vulnerability in the Linux kernel's ASoC (ALSA System on Chip) audio subsystem allows local users to trigger a divide-by-zero condition when working with compressed audio streams. The kernel fails to validate that critical stream configuration parameters are properly initialized before performing calculations with them, creating a denial-of-service vector for any local process with audio subsystem access.

  • CVE-2026-46182MEDIUM 5.5

    A vulnerability in the Linux kernel's IBM POWER Systems (pseries) PAPR hypervisor pipe driver allows uninitialized kernel memory to be exposed to unprivileged users. When the driver copies a header structure to userspace, it fails to zero out reserved padding fields within that structure, inadvertently leaking sensitive kernel data. An attacker with local access could read this leaked memory to potentially gather information about the running kernel state.

  • CVE-2026-46184MEDIUM 5.5

    A USB audio device driver in the Linux kernel can crash if a malformed device provides zero audio channels. The driver fails to validate a critical USB descriptor field before using it in calculations, leading to a division-by-zero error when the device is connected. An attacker with physical access to plug in a crafted USB device could trigger a kernel panic on vulnerable systems.

  • CVE-2026-46186MEDIUM 5.5

    A flaw in the Linux kernel's Bluetooth virtio driver fails to validate that incoming packets contain enough data before processing them. When a malformed or truncated packet arrives, the driver can read beyond the packet's actual boundaries, potentially accessing uninitialized memory. This could cause the system to crash or misbehave, particularly on systems with active Bluetooth connections.

  • CVE-2026-46188MEDIUM 5.5

    A flaw exists in the Linux kernel's Cavium Octeon EP VF driver where a memory allocation function can fail but the code doesn't check for failure. When this happens, the driver tries to use the failed allocation as if it were valid, causing the system to crash. This is a local issue requiring user-level access to trigger.

  • CVE-2026-46192MEDIUM 5.5

    A flaw exists in the Linux kernel's Microchip QSPI (Quad SPI) driver that causes read operations to fail when using dual or quad-mode communication. The driver incorrectly attempts to transmit garbage data to generate clock cycles during read-only operations, but QSPI lacks a dedicated output line for this purpose in these modes. This causes the transfer to stall, effectively making data reads unreliable or impossible on affected systems using this driver.

  • CVE-2026-46193MEDIUM 5.5

    A flaw in the Linux kernel's AH (Authentication Header) implementation causes incorrect packet authentication when Extended Sequence Numbers (ESN) are enabled and async cryptographic operations are used. The kernel miscalculates where authentication data is stored during async callbacks, leading to the comparison of wrong bytes and packet validation failures. This breaks IPsec AH protection on affected systems.

  • CVE-2026-46196MEDIUM 5.5

    A flaw in the Linux kernel's tracepoint subsystem can leave internal state in an inconsistent condition when probe registration fails. Specifically, when the kernel tries to activate a tracepoint for the first time and the activation succeeds but the probe installation fails (e.g., due to out-of-memory conditions), the cleanup routine is never called. This leaves persistent overhead on every task in the system—most notably for syscall tracing—until the system is rebooted. The issue is a resource leak of kernel state rather than a direct security bypass, but it degrades performance and system stability under memory pressure or specific tracepoint registration sequences.

  • CVE-2026-46200MEDIUM 5.5

    A flaw in the Linux kernel's MPC52xx SPI controller driver can cause a system crash or denial of service when the driver is unloaded. The issue stems from improper resource cleanup during driver removal—specifically, the controller is disabled and its resources (interrupts, GPIOs) are released before the controller is properly deregistered from the kernel, leaving dangling references that can trigger a crash.

  • CVE-2026-46202MEDIUM 5.5

    A locking bug in the Linux kernel's Apple Touch Bar keyboard driver (hid-appletb-kbd) causes the system to attempt sleeping operations from atomic (interrupt) contexts where sleeping is forbidden. The bug occurs in two code paths that adjust keyboard backlight brightness: a periodic inactivity timer and a user-activity reset handler. Both trigger calls to the backlight subsystem's brightness function, which tries to acquire a mutex while running in softirq or IRQ context, causing kernel warnings and potential system instability. The fix moves these blocking operations to a workqueue, allowing them to run safely in process context.

  • CVE-2026-46207MEDIUM 5.5

    A flaw in the Linux kernel's vsock/virtio module causes monitoring tools to receive incomplete data when handling certain network packets. Specifically, when the kernel processes non-linear network buffers for the virtual socket monitoring interface (vsockmon), it fails to properly initialize a data structure that controls how much information gets copied. This leaves monitoring tools unable to see the full payload of these packets, potentially obscuring network activity. The issue affects local processes with standard privileges and could be exploited to hide data from network inspection.

  • CVE-2026-46211MEDIUM 5.5

    A flaw in the Linux kernel's graphics driver (msm/gem) causes an ioctl function to report success even when it fails. When userspace attempts to retrieve metadata about graphics objects, the function incorrectly returns 0 (success) even if the underlying operations—such as copying data to userspace or allocating memory—actually fail. Additionally, if memory allocation fails, the code does not check for a NULL pointer, leading to a crash. This allows applications to think they've successfully retrieved metadata when they haven't, or to trigger a denial of service.

  • CVE-2026-46214MEDIUM 5.5

    A flaw in the Linux kernel's virtual socket (vsock) implementation can cause connection listeners to stop accepting new connections after a small number of transport negotiation failures. The bug occurs in the virtio transport layer when the code increments an internal counter to track pending connections but fails to decrement it if the transport negotiation fails. After enough failed attempts, the listener incorrectly believes its connection queue is full and rejects all new incoming connections, effectively causing a denial of service for applications relying on vsock communication.

  • CVE-2026-46216MEDIUM 5.5

    A flaw in the Linux kernel's GPU driver for Intel Arc graphics allows a local attacker with basic user privileges to crash the system. The vulnerability occurs when certain GPU components (specifically the media GT) are disabled through system configuration. Under these conditions, the driver attempts to access memory that hasn't been allocated, causing a kernel panic. An attacker with local access can trigger this crash, resulting in a denial of service. This is a localized memory safety issue that requires local access to exploit.

  • CVE-2026-46220MEDIUM 5.5

    A vulnerability in the Linux kernel's AMD GPU driver allows an unprivileged user to crash the system by submitting specially crafted graphics commands. The driver was using an overly aggressive error check (BUG_ON) that would panic the entire kernel when it detected a misaligned memory address—even though the real fix should have happened earlier in the validation pipeline. By replacing these fatal assertions with warnings, the system can log the problem without crashing, while proper validation is moved to the correct layer of the code.

  • CVE-2026-46221MEDIUM 5.5

    A memory leak exists in the Linux kernel's EDAC (Error Detection and Correction) versalnet driver. When the driver initializes memory controller devices, it allocates memory for a device name string but fails to properly free it during normal driver removal. The kernel's device registration process copies the name internally and then loses track of the original allocation, leaving orphaned memory that cannot be reclaimed. This gradually consumes system memory over repeated device initialization and removal cycles.

  • CVE-2026-46222MEDIUM 5.5

    A flaw exists in the Linux kernel's Rockchip RKCam Interface (rkcif) media driver where certain data connection points (pads) lack proper validation checks. When a video stream is started on a device where these pads are not correctly connected, the kernel attempts to access memory that doesn't exist, causing the system to crash. This is a local issue—only users with login access to the affected system can trigger it, typically through video application commands.

  • CVE-2026-46223MEDIUM 5.5

    This Linux kernel vulnerability centers on a deadlock condition in cgroup resource management during container shutdown. When a system administrator removes a cgroup (via rmdir), the kernel's cleanup logic can become stuck waiting for tasks to exit under certain conditions—specifically when the process performing the removal is also responsible for reaping zombie processes. This creates a circular dependency where the cleanup cannot proceed because the reaper is blocked, and the zombies cannot be cleaned because the reaper is stuck. The fix defers the actual cleanup work to run asynchronously after tasks have already left the cgroup, allowing the rmdir operation to return promptly while kernel-side cleanup continues in the background.

  • CVE-2026-46224MEDIUM 5.5

    A memory leak vulnerability exists in the Linux kernel's DRM (Direct Rendering Manager) Xe driver. When the driver attempts to initialize a DMA buffer object and encounters an allocation failure, it fails to properly clean up a pre-allocated buffer object, causing it to leak into memory. The vulnerability requires local system access and affects the kernel's ability to manage GPU memory correctly. While this is not a critical security issue, it can lead to denial of service through memory exhaustion over time.

  • CVE-2026-46225MEDIUM 5.5

    A flaw has been found in how the Linux kernel's SPI (Serial Peripheral Interface) RSPI driver shuts down. When a system stops using the driver, it wasn't properly cleaning up in the right order—specifically, it was releasing DMA (direct memory access) resources before telling the SPI controller to stop. This ordering problem can cause the system to become unstable or crash.

  • CVE-2026-46226MEDIUM 5.5

    A flaw in the Linux kernel's Freescale SPI controller driver can cause a system crash when the driver is unloaded. The issue occurs because the driver releases hardware resources (like DMA) before properly shutting down the SPI controller, leaving it in an inconsistent state. An attacker with local system access could trigger this crash by unloading the driver, resulting in a denial of service.

  • CVE-2026-46228MEDIUM 5.5

    A memory management flaw in the Linux kernel's SPI CH341 USB driver can cause memory to persist after the driver is unloaded, potentially leading to denial of service. The issue arises because device resources tied to a USB driver are incorrectly managed at the parent device level rather than at the individual interface level, preventing proper cleanup when drivers unbind without physical device disconnection.

  • CVE-2026-46229MEDIUM 5.5

    A vulnerability in the Linux kernel's AMD KFD (Kernel Fusion Driver) GPU memory management allows stale data from previous GPU memory allocations to remain accessible to new compute tasks. When GPU VRAM is allocated for new workloads, the kernel does not properly clear it, leaving behind fragments of prior page tables and data. Compute kernels can observe this leftover information, which can corrupt GPU-to-GPU communication protocols and cause application crashes, particularly in high-performance computing scenarios involving NVIDIA RCCL P2P transport operations.

  • CVE-2026-46231MEDIUM 5.5

    A flaw in the Linux kernel's batman-adv (B.A.T.M.A.N. Advanced) networking module leaks memory when certain network claim operations fail. Specifically, when the system attempts to record a new claim in an internal hash table but the insertion fails, it forgets to release a reference to a network backbone object, causing that object to remain in memory indefinitely. This gradual accumulation of unreleased objects can eventually degrade system performance or trigger a denial of service.

  • CVE-2026-46233MEDIUM 5.5

    A flaw in the Linux kernel's Batman-adv bridge loop avoidance (BLA) subsystem can cause a crash when the system attempts to clean up stale network bridge claims. The issue occurs because the cleanup routine doesn't properly check whether a claim is still valid before trying to access it, potentially leading to a null pointer dereference. An attacker with local access could trigger this condition to cause a denial of service.

  • CVE-2026-46235MEDIUM 5.5

    The Linux kernel's saa7164 media driver failed to properly validate whether memory mapping operations succeeded before using the results. When the kernel tries to map I/O memory regions for certain hardware (specifically PCI base address registers 0 and 2), it could receive a null pointer if the operation failed. The driver would then attempt to use these null pointers, causing a system crash. This patch adds defensive checks: if memory mapping fails, the driver now properly cleans up any partially allocated resources and safely reports an error instead of proceeding with unusable pointers.

  • CVE-2026-46236MEDIUM 5.5

    A flaw has been identified in the Linux kernel's Xbox remote control driver that mishandles memory buffers used for direct hardware communication (DMA). The driver incorrectly stores DMA buffers as part of the device structure, violating fundamental DMA coherency rules. This misconfiguration can cause the system to become unstable or unresponsive, though it requires local access to trigger. The issue affects systems running vulnerable versions of the Linux kernel with the Xbox remote driver enabled.