2026-04-24
2026-04-24 15:16Z
CRIT

CVE-2026-31637 — Linux: In the Linux kernel, the following vulnerability has been resolved: rxrpc: reject undecryptable rxkad

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-31637

In the Linux kernel, the following vulnerability has been resolved: rxrpc: reject undecryptable rxkad response tickets rxkad_decrypt_ticket() decrypts the RXKAD response ticket and then parses the buffer as plaintext without checking whether crypto_skcipher_decrypt() succeeded. A malformed RESPONSE can therefore use a non-block-aligned ticket length, make the decrypt operation fail, and still drive the ticket parser with attacker-controlled bytes. Check the decrypt result CVSSv3.1 9.8 (CRITICAL) · EPSS 5th percentile

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-24
2026-04-24 15:16Z
CRIT

CVE-2026-31636 — Linux: Decoded from the original latest-net reproduction logs with scripts/decode_stacktrace.sh: BUG: KASAN: slab-out-of-bounds in rxgk_verify_response()

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-31636

In the Linux kernel, the following vulnerability has been resolved: rxrpc: fix RESPONSE authenticator parser OOB read rxgk_verify_authenticator() copies auth_len bytes into a temporary buffer and then passes p + auth_len as the parser limit to rxgk_do_verify_authenticator(). Since p is a __be32 *, that inflates the parser end pointer by a factor of four and lets malformed RESPONSE authenticators read past the kmalloc() buffer. Decoded from the original latest-net reproduct CVSSv3.1 9.1 (CRITICAL) · EPSS 4th percentile

TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-04-24
2026-04-24 15:16Z
CRIT

CVE-2026-31633 — Linux: In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix integer overflow

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-31633

In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix integer overflow in rxgk_verify_response() In rxgk_verify_response(), there's a potential integer overflow due to rounding up token_len before checking it, thereby allowing the length check to be bypassed. Fix this by checking the unrounded value against len too (len is limited as the response must fit in a single UDP packet). CVSSv3.1 9.8 (CRITICAL) · EPSS 4th percentile

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-24
2026-04-24 15:16Z
HIGH

CVE-2026-31631 — Linux: In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix buffer overread

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-31631

In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix buffer overread in rxgk_do_verify_authenticator() Fix rxgk_do_verify_authenticator() to check the buffer size before checking the nonce. CVSSv3.1 8.2 (HIGH) · EPSS 4th percentile

TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-04-24
2026-04-24 15:16Z
HIGH

CVE-2026-31629 — Linux: This results in a double release_sock() and a refcount underflow via double nfc_llcp_sock_put(), leading

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-31629

In the Linux kernel, the following vulnerability has been resolved: nfc: llcp: add missing return after LLCP_CLOSED checks In nfc_llcp_recv_hdlc() and nfc_llcp_recv_disc(), when the socket state is LLCP_CLOSED, the code correctly calls release_sock() and nfc_llcp_sock_put() but fails to return. Execution falls through to the remainder of the function, which calls release_sock() and nfc_llcp_sock_put() again. This results in a double release_sock() and a refcount underflow v CVSSv3.1 8.8 (HIGH) · EPSS 5th percentile

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-24
2026-04-24 15:16Z
HIGH

CVE-2026-31622 — Linux: In the Linux kernel, the following vulnerability has been resolved: NFC: digital: Bounds check

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-31622

In the Linux kernel, the following vulnerability has been resolved: NFC: digital: Bounds check NFC-A cascade depth in SDD response handler The NFC-A anti-collision cascade in digital_in_recv_sdd_res() appends 3 or 4 bytes to target->nfcid1 on each round, but the number of cascade rounds is controlled entirely by the peer device. The peer sets the cascade tag in the SDD_RES (deciding 3 vs 4 bytes) and the cascade-incomplete bit in the SEL_RES (deciding whether another round CVSSv3.1 8.8 (HIGH) · EPSS 5th percentile

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-24
2026-04-24 15:16Z
HIGH

CVE-2026-31613 — Linux: In the Linux kernel, the following vulnerability has been resolved: smb: client: fix OOB

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-31613

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix OOB reads parsing symlink error response When a CREATE returns STATUS_STOPPED_ON_SYMLINK, smb2_check_message() returns success without any length validation, leaving the symlink parsers as the only defense against an untrusted server. symlink_data() walks SMB 3.1.1 error contexts with the loop test "p < end", but reads p->ErrorId at offset 4 and p->ErrorDataLength at offset 0. When the se CVSSv3.1 8.1 (HIGH) · EPSS 5th percentile

TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-04-24
2026-04-24 15:16Z
HIGH

CVE-2026-31611 — Linux: In the Linux kernel, the following vulnerability has been resolved: ksmbd: require 3 sub-authorities

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-31611

In the Linux kernel, the following vulnerability has been resolved: ksmbd: require 3 sub-authorities before reading sub_auth[2] parse_dacl() compares each ACE SID against sid_unix_NFS_mode and on match reads sid.sub_auth[2] as the file mode. If sid_unix_NFS_mode is the prefix S-1-5-88-3 with num_subauth = 2 then compare_sids() compares only min(num_subauth, 2) sub-authorities so a client SID with num_subauth = 2 and sub_auth = {88, 3} will match. If num_subauth = 2 and th CVSSv3.1 8.6 (HIGH) · EPSS 5th percentile

TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-04-24
2026-04-24 15:16Z
CRIT

CVE-2026-31609 — Linux: In the Linux kernel, the following vulnerability has been resolved: smb: client: avoid double-free

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-31609

In the Linux kernel, the following vulnerability has been resolved: smb: client: avoid double-free in smbd_free_send_io() after smbd_send_batch_flush() smbd_send_batch_flush() already calls smbd_free_send_io(), so we should not call it again after smbd_post_send() moved it to the batch list. CVSSv3.1 9.8 (CRITICAL) · EPSS 4th percentile

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-24
2026-04-24 15:16Z
CRIT

CVE-2026-31608 — Linux: In the Linux kernel, the following vulnerability has been resolved: smb: server: avoid double-free

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-31608

In the Linux kernel, the following vulnerability has been resolved: smb: server: avoid double-free in smb_direct_free_sendmsg after smb_direct_flush_send_list() smb_direct_flush_send_list() already calls smb_direct_free_sendmsg(), so we should not call it again after post_sendmsg() moved it to the batch list. CVSSv3.1 9.8 (CRITICAL) · EPSS 4th percentile

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-24
2026-04-24 15:16Z
CRIT

CVE-2026-31607 — Linux: A malicious USB/IP server can set number_of_packets in the response to a value larger

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-31607

In the Linux kernel, the following vulnerability has been resolved: usbip: validate number_of_packets in usbip_pack_ret_submit() When a USB/IP client receives a RET_SUBMIT response, usbip_pack_ret_submit() unconditionally overwrites urb->number_of_packets from the network PDU. This value is subsequently used as the loop bound in usbip_recv_iso() and usbip_pad_iso() to iterate over urb->iso_frame_desc[], a flexible array whose size was fixed at URB allocation time based on t CVSSv3.1 9.8 (CRITICAL) · EPSS 5th percentile

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-24
2026-04-24 15:16Z
CRIT

CVE-2026-31589 — Linux: Otherwise, we've already removed the folio from the mapping so it no longer pins

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-31589

In the Linux kernel, the following vulnerability has been resolved: mm: call ->free_folio() directly in folio_unmap_invalidate() We can only call filemap_free_folio() if we have a reference to (or hold a lock on) the mapping. Otherwise, we've already removed the folio from the mapping so it no longer pins the mapping and the mapping can be removed, causing a use-after-free when accessing mapping->a_ops. Follow the same pattern as __remove_mapping() and load the free_folio CVSSv3.1 9.8 (CRITICAL) · EPSS 5th percentile

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-24
2026-04-24 15:16Z
HIGH

CVE-2026-31588 — Linux: This fixes a class of use-after-free bugs that occur when the emulator initiates a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-31588

In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Use scratch field in MMIO fragment to hold small write values When exiting to userspace to service an emulated MMIO write, copy the to-be-written value to a scratch field in the MMIO fragment if the size of the data payload is 8 bytes or less, i.e. can fit in a single chunk, instead of pointing the fragment directly at the source value. This fixes a class of use-after-free bugs that occur when th CVSSv3.1 8.8 (HIGH) · EPSS 5th percentile

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-24
2026-04-24 15:16Z
HIGH

CVE-2026-31570 — Linux: Confirmed with KASAN on linux-7.0-rc2: BUG: KASAN: slab-out-of-bounds in cgw_csum_crc8_rel+0x515/0x5b0 Read of size 1

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-31570

In the Linux kernel, the following vulnerability has been resolved: can: gw: fix OOB heap access in cgw_csum_crc8_rel() cgw_csum_crc8_rel() correctly computes bounds-safe indices via calc_idx(): int from = calc_idx(crc8->from_idx, cf->len); int to = calc_idx(crc8->to_idx, cf->len); int res = calc_idx(crc8->result_idx, cf->len); if (from < 0 || to < 0 || res < 0) return; However, the loop and the result write then use the raw s8 fields directl CVSSv3.1 8.8 (HIGH) · EPSS 7th percentile

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-24
2026-04-24 15:16Z
HIGH

CVE-2026-31558 — Linux: This fix an out-of-bounds access to kvm_arch::phyid_map::phys_map[].

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-31558

In the Linux kernel, the following vulnerability has been resolved: LoongArch: KVM: Make kvm_get_vcpu_by_cpuid() more robust kvm_get_vcpu_by_cpuid() takes a cpuid parameter whose type is int, so cpuid can be negative. Let kvm_get_vcpu_by_cpuid() return NULL for this case so as to make it more robust. This fix an out-of-bounds access to kvm_arch::phyid_map::phys_map[]. CVSSv3.1 8.8 (HIGH) · EPSS 5th percentile

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-24
2026-04-24 15:16Z
HIGH

CVE-2026-31553 — Linux: In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Fix the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-31553

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Fix the descriptor address in __kvm_at_swap_desc() Using "(u64 __user *)hva + offset" to get the virtual addresses of S1/S2 descriptors looks really wrong, if offset is not zero. What we want to get for swapping is hva + offset, not hva + offset*8. ;-) Fix it. CVSSv3.1 8.8 (HIGH) · EPSS 5th percentile

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-24
2026-04-24 15:16Z
CRIT

CVE-2026-31536 — Linux: In the Linux kernel, the following vulnerability has been resolved: smb: server: let send_done

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-31536

In the Linux kernel, the following vulnerability has been resolved: smb: server: let send_done handle a completion without IB_SEND_SIGNALED With smbdirect_send_batch processing we likely have requests without IB_SEND_SIGNALED, which will be destroyed in the final request that has IB_SEND_SIGNALED set. If the connection is broken all requests are signaled even without explicit IB_SEND_SIGNALED. CVSSv3.1 9.8 (CRITICAL) · EPSS 4th percentile

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-24
2026-04-24 14:16Z
CRIT

CVE-2026-25660 — Ericsson Codechecker: Authentication bypass occurs when the URL ends with Authentication with certain function calls.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-25660

CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Authentication bypass occurs when the URL ends with Authentication with certain function calls.  This bypass allows assigning arbitrary permission to any user existing in CodeChecker. This issue affects CodeChecker: through 6.27.3. CVSSv3.1 9.8 (CRITICAL) · EPSS 17th percentile

CWECWE 863CWECWE 290VNDEricssonVNDCodecheckerTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-24
2026-04-24 13:16Z
HIGH

CVE-2026-5367 — OVN: This out-of-bounds read can lead to the disclosure of sensitive information stored in heap

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5367

A flaw was found in OVN (Open Virtual Network). A remote attacker, by sending crafted DHCPv6 (Dynamic Host Configuration Protocol for IPv6) SOLICIT packets with an inflated Client ID length, could cause the ovn-controller to read beyond the bounds of a packet. This out-of-bounds read can lead to the disclosure of sensitive information stored in heap memory, which is then returned to the attacker's virtual machine port. CVSSv3.1 8.6 (HIGH)

CWECWE 130VNDOvnTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-04-24
2026-04-24 13:16Z
CRIT

CVE-2026-21515 — Exposure: of sensitive information to an unauthorized actor in Azure IOT Central allows an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-21515

Exposure of sensitive information to an unauthorized actor in Azure IOT Central allows an authorized attacker to elevate privileges over a network. CVSSv3.1 9.9 (CRITICAL)

CWECWE 200TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-04-24
2026-04-24 12:17Z
HIGH

CVE-2026-23902 — Incorrect: Authorization vulnerability in Apache DolphinScheduler allows authenticated users with system login permissions to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-23902

Incorrect Authorization vulnerability in Apache DolphinScheduler allows authenticated users with system login permissions to use tenants that are not defined on the platform during workflow execution. This issue affects Apache DolphinScheduler versions prior to 3.4.1.  Users are recommended to upgrade to version 3.4.1, which fixes this issue. CVSSv3.1 8.1 (HIGH)

CWECWE 863TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-04-24
2026-04-24 11:16Z
HIGH

CVE-2026-41044 — Input: Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41044

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ, Apache ActiveMQ Broker, Apache ActiveMQ All. An authenticated attacker can use the admin web console page to construct a malicious broker name that bypasses name validation to include an xbean binding that can be later used by a VM transport to load a remote Spring XML application. The attacker can then use the DestinationView mbean to send a message to trig CVSSv3.1 8.8 (HIGH)

CWECWE 94CWECWE 20VNDInputTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-24
2026-04-24 11:16Z
HIGH

CVE-2026-40466 — Input: Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40466

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. An authenticated attacker may bypass the fix in CVE-2026-34197 by adding a connector using an HTTP Discovery transport via BrokerView.addNetworkConnector or BrokerView.addConnector through Jolokia if the activemq-http module is on the classpath. A malicious HTTP endpoint can return a VM transport through the HTT CVSSv3.1 8.8 (HIGH)

CWECWE 94CWECWE 20VNDInputTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-24
2026-04-24 08:00Z
HIGH

PhantomRPC: A new privilege escalation technique in Windows RPC

Kaspersky Securelist·securelist.com

Kaspersky researchers disclosed PhantomRPC, a novel local privilege escalation vulnerability in Windows RPC architecture that allows processes with impersonation privileges to escalate to SYSTEM level. The vulnerability stems from RPC's lack of server legitimacy verification, enabling attackers to deploy fake RPC servers mimicking legitimate services like TermService. Microsoft has not issued a patch despite proper disclosure, and the researchers demonstrate five distinct exploitation paths affecting all Windows versions.

SRFOsTACTA0004TACTA0005VNDMicrosoftTYPResearchTYPVulnerabilitySTGPrivescSTGInitial Access
82
Edit Score
2026-04-24
2026-04-24 07:16Z
CRIT

CVE-2026-1952 — Delta: Electronics AS320T has denial of service via the undocumented subfunction vulnerability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-1952

Delta Electronics AS320T has denial of service via the undocumented subfunction vulnerability. CVSSv3.1 9.8 (CRITICAL)

CWECWE 912VNDDeltaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score