2026-08-15
2026-08-15 06:21Z
HIGH

CVE-2026-72061 — Linux: In the Linux kernel, the following vulnerability has been resolved: net: sit: require CAP_NET_ADMIN

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72061

In the Linux kernel, the following vulnerability has been resolved: net: sit: require CAP_NET_ADMIN in the device netns for changelink ipip6_changelink() operates on at most two netns, dev_net(dev) and the tunnel link netns t->net. They differ once the device is created in or moved to a netns other than the one the request runs in. The rtnl changelink path checks CAP_NET_ADMIN only against dev_net(dev), so a caller privileged there but not in t->net can rewrite a tunnel tha CVSSv3.1 8.8 (HIGH) · EPSS 13th percentile

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-15
2026-08-15 06:21Z
HIGH

CVE-2026-72057 — Linux: In the Linux kernel, the following vulnerability has been resolved: net/sched: act_ct: preserve tc_skb_cb

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72057

In the Linux kernel, the following vulnerability has been resolved: net/sched: act_ct: preserve tc_skb_cb across defragmentation tcf_ct_handle_fragments() calls nf_ct_handle_fragments() without saving and restoring skb->cb. The defrag helper clears IPCB/IP6CB, which aliases the tc_skb_cb/qdisc_skb_cb control buffer. Fragmented traffic through act_ct therefore loses qdisc metadata such as pkt_segs and can trigger WARN_ON_ONCE() in qdisc_pkt_segs() when panic_on_warn is enabl CVSSv3.1 8.2 (HIGH) · EPSS 11th percentile

TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-15
2026-08-15 06:21Z
HIGH

CVE-2026-72055 — Linux: In the Linux kernel, the following vulnerability has been resolved: net: ip6_vti: require CAP_NET_ADMIN

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72055

In the Linux kernel, the following vulnerability has been resolved: net: ip6_vti: require CAP_NET_ADMIN in the device netns for changelink vti6_changelink() operates on at most two netns, dev_net(dev) and the tunnel link netns t->net. They differ once the device is created in or moved to a netns other than the one the request runs in. The rtnl changelink path checks CAP_NET_ADMIN only against dev_net(dev), so a caller privileged there but not in t->net can rewrite a tunnel CVSSv3.1 8.8 (HIGH) · EPSS 12th percentile

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-15
2026-08-15 06:21Z
HIGH

CVE-2026-72054 — Linux: In the Linux kernel, the following vulnerability has been resolved: net: ip_vti: require CAP_NET_ADMIN

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72054

In the Linux kernel, the following vulnerability has been resolved: net: ip_vti: require CAP_NET_ADMIN in the device netns for changelink vti_changelink() operates on at most two netns, dev_net(dev) and the tunnel link netns t->net. They differ once the device is created in or moved to a netns other than the one the request runs in. The rtnl changelink path checks CAP_NET_ADMIN only against dev_net(dev), so a caller privileged there but not in t->net can rewrite a tunnel th CVSSv3.1 8.8 (HIGH) · EPSS 12th percentile

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-15
2026-08-15 06:21Z
HIGH

CVE-2026-72053 — Linux: In the Linux kernel, the following vulnerability has been resolved: net: ipip: require CAP_NET_ADMIN

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72053

In the Linux kernel, the following vulnerability has been resolved: net: ipip: require CAP_NET_ADMIN in the device netns for changelink ipip_changelink() operates on at most two netns, dev_net(dev) and the tunnel link netns t->net. They differ once the device is created in or moved to a netns other than the one the request runs in. The rtnl changelink path checks CAP_NET_ADMIN only against dev_net(dev), so a caller privileged there but not in t->net can rewrite a tunnel tha CVSSv3.1 8.8 (HIGH) · EPSS 11th percentile

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-15
2026-08-15 06:21Z
HIGH

CVE-2026-72052 — Linux: In the Linux kernel, the following vulnerability has been resolved: net: ip6_gre: require CAP_NET_ADMIN

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72052

In the Linux kernel, the following vulnerability has been resolved: net: ip6_gre: require CAP_NET_ADMIN in the device netns for changelink ip6gre_changelink() and ip6erspan_changelink() operate on at most two netns, dev_net(dev) and the tunnel link netns t->net. They differ once the device is created in or moved to a netns other than the one the request runs in. The rtnl changelink path checks CAP_NET_ADMIN only against dev_net(dev), so a caller privileged there but not in CVSSv3.1 8.8 (HIGH) · EPSS 12th percentile

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-15
2026-08-15 06:21Z
HIGH

CVE-2026-72051 — Linux: In the Linux kernel, the following vulnerability has been resolved: net: ip6_tunnel: require CAP_NET_ADMIN

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72051

In the Linux kernel, the following vulnerability has been resolved: net: ip6_tunnel: require CAP_NET_ADMIN in the device netns for changelink ip6_tnl_changelink() operates on at most two netns, dev_net(dev) and the tunnel link netns t->net. They differ once the device is created in or moved to a netns other than the one the request runs in. The rtnl changelink path checks CAP_NET_ADMIN only against dev_net(dev), so a caller privileged there but not in t->net can rewrite a t CVSSv3.1 8.8 (HIGH) · EPSS 10th percentile

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-08-15
2026-08-15 06:21Z
CRIT

CVE-2026-72046 — Linux: That results in two problems: 1.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72046

In the Linux kernel, the following vulnerability has been resolved: gve: fix header buffer corruption with header-split and HW-GRO The DQO RX datapath programs a per-buffer-queue-descriptor header_buf_addr at post time and reads the split header back at completion time. Both the post and the read currently index the header buffer by queue position rather than by the buffer's identity: - post (gve_rx_post_buffers_dqo): header_buf_addr is computed from bufq->tail - r CVSSv3.1 9.8 (CRITICAL) · EPSS 10th percentile

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-15
2026-08-15 06:21Z
HIGH

CVE-2026-72045 — Linux: In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: cn10k: restrict VF

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72045

In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: cn10k: restrict VF LMTLINE sharing to its own PF rvu_mbox_handler_lmtst_tbl_setup() uses req->base_pcifunc as a direct index into the LMT map table to read another function's LMTLINE physical base address and copy it into the caller's own LMT map table entry. The mailbox dispatcher authenticates req->hdr.pcifunc from the IRQ source, but req->base_pcifunc is a separate payload field and is not CVSSv3.1 8.8 (HIGH) · EPSS 10th percentile

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-15
2026-08-15 06:21Z
CRIT

CVE-2026-72041 — Linux: In the Linux kernel, the following vulnerability has been resolved: espintcp: use sk_msg_free_partial to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72041

In the Linux kernel, the following vulnerability has been resolved: espintcp: use sk_msg_free_partial to fix partial send sk_msg_free_partial() ensures consistency of the skmsg at every iteration, without having to manually handle uncharges and offsets. This simplifies the code, and fixes some bugs in skmsg accounting when we don't send the full contents. CVSSv3.1 9.8 (CRITICAL) · EPSS 10th percentile

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-15
2026-08-15 06:21Z
HIGH

CVE-2026-72035 — Linux: In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_taprio: Replace direct

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72035

In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_taprio: Replace direct dequeue call with peek and qdisc_dequeue_peeked When taprio's software path peeks a non-work-conserving child qdisc, the child stashes the peeked skb in its gso_skb; taprio_dequeue_from_txq() then takes the packet with a direct child ->dequeue() call, which ignores that stash, orphans the peeked skb and desyncs the child's qlen/backlog. With a qfq child this re-enters t CVSSv3.1 8.2 (HIGH) · EPSS 10th percentile

TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-15
2026-08-15 06:21Z
CRIT

CVE-2026-72033 — Linux: An entry length near U32_MAX wraps it to a small value, bypasses the bounds

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72033

In the Linux kernel, the following vulnerability has been resolved: orangefs: keep the readdir entry size 64-bit in fill_from_part() fill_from_part() computes the size of a directory entry in size_t but stores it in a __u32. An entry length near U32_MAX wraps it to a small value, bypasses the bounds check, and is then used to index the entry, reading far past the directory part -- an out-of-bounds read that oopses the kernel. Compute the size as a u64 so it cannot truncate CVSSv3.1 9.8 (CRITICAL) · EPSS 13th percentile

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-15
2026-08-15 06:21Z
HIGH

CVE-2026-72029 — Linux: A modem that reports an index or a length past the downlink buffer makes

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72029

In the Linux kernel, the following vulnerability has been resolved: net: wwan: iosm: bound device offsets in the MUX downlink decoder mux_dl_adb_decode() walks a chain of aggregated datagram tables using offsets and lengths taken from the modem. first_table_index, next_table_index, table_length, datagram_index and datagram_length are all device supplied le values. Only first_table_index was checked, and only for being non zero. The decoder then formed adth = block + adth_in CVSSv3.1 8.8 (HIGH) · EPSS 12th percentile

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-15
2026-08-15 06:21Z
HIGH

CVE-2026-72021 — Linux: In the Linux kernel, the following vulnerability has been resolved: ipvs: use parsed transport

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72021

In the Linux kernel, the following vulnerability has been resolved: ipvs: use parsed transport offset in SCTP state lookup set_sctp_state() reads the SCTP chunk header again in order to drive the IPVS SCTP state table. For IPv6 it computes the offset with sizeof(struct ipv6hdr), while the surrounding IPVS code uses iph.len from ip_vs_fill_iph_skb(), where ipv6_find_hdr() has already skipped extension headers and found the real transport header. This makes the state machine CVSSv3.1 8.2 (HIGH) · EPSS 12th percentile

TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-15
2026-08-15 06:21Z
CRIT

CVE-2026-72020 — Linux: In the Linux kernel, the following vulnerability has been resolved: ipvs: reset full ip_vs_seq

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72020

In the Linux kernel, the following vulnerability has been resolved: ipvs: reset full ip_vs_seq structs in ip_vs_conn_new Commit 9a05475cebdd ("ipvs: avoid kmem_cache_zalloc in ip_vs_conn_new") changed ip_vs_conn_new() to allocate an ip_vs_conn object with kmem_cache_alloc(). The function then initializes many fields explicitly, but only resets in_seq.delta and out_seq.delta in the two struct ip_vs_seq members. That leaves init_seq and previous_delta uninitialized. This i CVSSv3.1 9.8 (CRITICAL) · EPSS 12th percentile

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-15
2026-08-15 06:21Z
CRIT

CVE-2026-72014 — Linux: In the Linux kernel, the following vulnerability has been resolved: drbd: reject data replies

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72014

In the Linux kernel, the following vulnerability has been resolved: drbd: reject data replies with an out-of-range payload size recv_dless_read() receives a P_DATA_REPLY from a peer into the bio of an outstanding read request. The peer-supplied payload length reaches it as the signed int data_size, and two peer-controlled inputs can make it negative. With a negotiated data-integrity-alg the digest length is subtracted first, so a reply whose payload is smaller than the dige CVSSv3.1 9.8 (CRITICAL) · EPSS 10th percentile

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-15
2026-08-15 06:20Z
HIGH

CVE-2026-72003 — Linux: In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: cyw: fix

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72003

In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: cyw: fix heap overflow on a short auth frame brcmf_notify_auth_frame_rx() takes the frame length from the firmware event and copies the frame body with the management header offset subtracted: u32 mgmt_frame_len = e->datalen - sizeof(struct brcmf_rx_mgmt_data); ... memcpy(&mgmt_frame->u, frame, mgmt_frame_len - offsetof(struct ieee80211_mgmt, u)); The only length check is e->dat CVSSv3.1 8.8 (HIGH) · EPSS 12th percentile

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-15
2026-08-15 06:20Z
CRIT

CVE-2026-68477 — Linux: In the Linux kernel, the following vulnerability has been resolved: ipvs: fix more places

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-68477

In the Linux kernel, the following vulnerability has been resolved: ipvs: fix more places with wrong ipv6 transport offsets Sashiko reports for more incorrect IPv6 transport offsets. The app code for TCP was assuming IPv4 network header even after the ipvsh argument was provided. This can cause problems with apps over IPv6. As for the only official app in the kernel tree (FTP) this problem is harmless because we use Netfilter to mangle the FTP ports and we do not adjust th CVSSv3.1 9.8 (CRITICAL) · EPSS 12th percentile

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-15
2026-08-15 06:20Z
CRIT

CVE-2026-68476 — Linux: In the Linux kernel, the following vulnerability has been resolved: ipvs: reload ip header

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-68476

In the Linux kernel, the following vulnerability has been resolved: ipvs: reload ip header after head reallocation __ip_vs_get_out_rt() calls skb_ensure_writable() which may reallocate skb->head. CVSSv3.1 9.8 (CRITICAL) · EPSS 10th percentile

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-15
2026-08-15 06:20Z
HIGH

CVE-2026-68472 — Linux: In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: validate EHT

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-68472

In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: validate EHT MLE before MLD ID read cfg80211_gen_new_ie() copies ML probe response elements from the parent frame when the parent EHT multi-link element has an MLD ID matching the nontransmitted BSSID index. The code only checked that the extension element had more than one byte before calling ieee80211_mle_get_mld_id(). That helper assumes a BASIC MLE with enough common info and documents CVSSv3.1 8.1 (HIGH) · EPSS 10th percentile

TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-15
2026-08-15 06:20Z
HIGH

CVE-2026-68471 — Linux: In the Linux kernel, the following vulnerability has been resolved: wifi: ieee80211: validate MLE

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-68471

In the Linux kernel, the following vulnerability has been resolved: wifi: ieee80211: validate MLE common info length ieee80211_mle_common_size() uses the first common-info octet as the common information length for all known MLE types. However, ieee80211_mle_size_ok() only validates that octet for Basic, Probe Request, and TDLS MLEs. Reconfiguration MLEs also skipped the length octet when calculating the minimum common size, and Priority Access MLEs skipped validation of t CVSSv3.1 8.8 (HIGH) · EPSS 10th percentile

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-15
2026-08-15 06:19Z
HIGH

CVE-2026-68470 — Linux: In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: validate extension-frame

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-68470

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: validate extension-frame layout before RX Extension frames only have the extension header at the regular 802.11 header offset. The generic RX path can still reach helpers and interface dispatch code that read regular header address fields before unsupported extension subtypes are dropped. mac80211 currently only handles S1G beacon extension frames. Drop other extension subtypes before they CVSSv3.1 8.8 (HIGH) · EPSS 9th percentile

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-15
2026-08-15 06:19Z
HIGH

CVE-2026-68466 — Linux: In the Linux kernel, the following vulnerability has been resolved: mtd: rawnand: lpc32xx_slc: fail

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-68466

In the Linux kernel, the following vulnerability has been resolved: mtd: rawnand: lpc32xx_slc: fail DMA transfer on completion timeout lpc32xx_xmit_dma() waits for the DMA completion callback but ignores wait_for_completion_timeout(). A timed out DMA transfer is therefore unmapped and reported as successful to the NAND read/write path. Return -ETIMEDOUT when the completion wait expires. Terminate the DMA channel before unmapping the scatterlist so the timed out transfer ca CVSSv3.1 8.8 (HIGH) · EPSS 7th percentile

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-15
2026-08-15 06:17Z
CRIT

CVE-2026-68457 — Linux: In the Linux kernel, the following vulnerability has been resolved: ksmbd: use opener credentials

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-68457

In the Linux kernel, the following vulnerability has been resolved: ksmbd: use opener credentials for FSCTL mutations SET_SPARSE, SET_ZERO_DATA and SET_COMPRESSION operate on an open SMB handle but call VFS xattr, fallocate or fileattr helpers with the current ksmbd worker credentials. Those helpers can revalidate inode permissions, ownership and LSM policy independently of the SMB handle access mask. Run each operation with the credentials captured in the target file when CVSSv3.1 9.1 (CRITICAL) · EPSS 7th percentile

TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-15
2026-08-15 03:16Z
HIGH

CVE-2026-15965 — MaxUpload: The MaxUpload – Big File Uploads – Increase Maximum File Upload Size plugin for

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15965

The MaxUpload – Big File Uploads – Increase Maximum File Upload Size plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.4.0 via the handle_upload function. This is due to a filename-validation mismatch in the handle_upload function where extension and MIME checks are applied to the uploaded chunk's filename but not to the final assembled filename derived from the resumableFilename parameter. This makes it possible for unauthent CVSSv3.1 8.8 (HIGH) · EPSS 45th percentile

CWECWE 434VNDMaxuploadTYPVulnerability
8.8
CVSS v3.1
94
Edit Score