CVE-2025-39964
A race condition in the Linux kernel crypto subsystem allows local users to cause state inconsistencies via concurrent writes to an af_alg socket.
Critical vulnerabilities, curated daily for security professionals
Adobe accounted for most of yesterday's top-scoring disclosures, with several CVSS 9.9 to 10.0 vulnerabilities in Adobe Campaign Classic, Adobe Connect, and AEM 6.5 Forms JEE, alongside maximum-severity flaws in Lantronix console servers and RTI Connext Professional. Yesterday's disclosures included 42 critical CVEs (up 31% from 32 the prior day) and 96 high-priority CVEs (down 12% from 109). Notable critical entries include CVE-2026-75745 (CVSS 10) in Adobe AEM 6.5 Forms JEE, CVE-2026-80155 (CVSS 10) affecting Lantronix SLC8000 and EMG-series devices, and CVE-2026-7866 (CVSS 10) in RTI Connext Professional. The set spans enterprise marketing and collaboration platforms, out-of-band management hardware, and industrial and embedded middleware, and 8 vulnerabilities have confirmed active exploitation, including issues in F5 BIG-IP, Check Point Quantum, Arista VeloCloud Orchestrator, and the Linux kernel. Defenders should first restrict network access to Adobe Campaign Classic and AEM Forms servers, isolate Lantronix management interfaces from untrusted networks, and verify fix status with each vendor before scheduling remediation.
Immediate action: Put Adobe Campaign Classic, AEM 6.5 Forms JEE, and Adobe Connect deployments first in line, then network edge and management systems with confirmed exploitation: F5 BIG-IP, Check Point Quantum, Arista VeloCloud Orchestrator, Zyxel GS1900 switches, and Linux kernel hosts. Check each vendor's advisory to confirm fix status and affected versions. Until updates are applied, keep Lantronix console servers and other management interfaces off untrusted networks.
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
A race condition in the Linux kernel crypto subsystem allows local users to cause state inconsistencies via concurrent writes to an af_alg socket.
A memory corruption vulnerability in the Linux kernel netfilter bridge component allows for out of bounds writes during ARP packet processing.
A vulnerability in the Linux kernel TLS implementation allows for improper handling of zero-length records during recvmsg processing, potentially leading to unauthorized system state manipulation.
A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware allows potential remote command execution.
An improper certificate trust validation vulnerability exists in Check Point Quantum Security Gateways during VPN negotiation, allowing unauthenticated remote code execution.
VeloCloud Orchestrator (VCO) on-prem is vulnerable to improper input validation, allowing unauthenticated remote attackers to access privileged functionality and compromise the host.
A heap-based buffer overflow in F5 BIG-IP APM, when configured as an OAuth Authorization Server, allows unauthenticated attackers to achieve remote code execution via malicious traffic.
A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on the Check Point Management Server.
An unauthenticated path traversal vulnerability in the Lantronix web management portal allows attackers to bypass authentication and achieve remote code execution via file upload.
A stack-based buffer overflow in RTI Connext Professional core libraries allows for potential remote code execution by unauthenticated attackers.
Adobe Connect is vulnerable to SQL injection, allowing low privileged attackers to execute arbitrary SQL commands and achieve remote code execution.
Adobe Campaign Classic is vulnerable to SQL injection, which may allow a low-privileged attacker to achieve remote code execution without user interaction.
Adobe Campaign Classic is vulnerable to Server-Side Request Forgery, allowing low-privileged attackers to escalate privileges and access sensitive internal network resources.
Adobe Campaign Classic is vulnerable to a Server-Side Request Forgery (SSRF) flaw that permits unauthenticated attackers to perform privilege escalation.
Adobe AEM 6.5 Forms JEE is vulnerable to an incorrect authorization flaw allowing unauthenticated attackers to achieve arbitrary remote code execution with changed scope.
Adobe Campaign Classic is vulnerable to improper control of code generation, allowing unauthenticated attackers to execute arbitrary code.
Adobe Campaign Classic is vulnerable to code injection, allowing unauthenticated remote attackers to execute arbitrary code with the privileges of the application process.
Adobe Campaign Classic is vulnerable to remote code injection, allowing unauthenticated attackers to execute arbitrary code without user interaction.
Adobe Campaign Classic is susceptible to a code injection vulnerability allowing unauthenticated remote attackers to execute arbitrary code, leading to a full system compromise.
Adobe Campaign Classic contains an Incorrect Authorization vulnerability allowing unauthenticated remote code execution. No user interaction is required for successful exploitation.
Adobe Campaign Classic is vulnerable to code injection, allowing unauthenticated remote attackers to achieve arbitrary code execution.
Adobe Campaign Classic is vulnerable to improper code injection, allowing unauthenticated remote attackers to execute arbitrary code with elevated privileges.
Adobe Campaign Classic is vulnerable to improper input validation, allowing a low-privileged, authenticated attacker to achieve remote arbitrary code execution without user interaction.
Adobe Campaign Classic is vulnerable to code injection, allowing a low-privileged attacker to execute arbitrary code without user interaction.
HPE Analytics and Location Engine (ALE) contains hard-coded credentials for administrative accounts, allowing unauthenticated remote attackers to gain full system access.
An unauthenticated remote attacker can gain unauthorized write access to the file system with elevated privileges in HPE Analytics and Location Engine, leading to potential full system compromise.
Disclosed Sep 16 without a CVSS score; tracked by CVE Brief from Sep 17; scored Sep 19, analysis completed Sep 23.
A Server-Side Request Forgery vulnerability in Zenith Satellite Tracker 1.0 allows unauthenticated attackers to make arbitrary requests from the server.
SGLang's multimodal generation runtime is vulnerable to unauthenticated arbitrary code execution via insecure deserialization of ZeroMQ messages in the disaggregated-diffusion orchestrator.
A stack-based buffer overflow in the Fast FAC1203R Gigabit Edition Device Discovery Service allows unauthenticated remote attackers to achieve code execution via crafted UDP packets on port 5001.
IBM Financial Transaction Manager for RedHat OpenShift contains a deserialization vulnerability that allows remote, unauthenticated attackers to execute arbitrary code on the target system.
SolarWinds Observability Self-Hosted contains an unauthenticated remote code execution vulnerability caused by insufficient integrity checks in specific configurations.
LTSecurity LTK3500SF contains hard-coded credentials for root and guest accounts, which can be recovered via dictionary attacks to gain full root-level access to the operating system.
D-Link DAP-1360 is vulnerable to unauthenticated remote code execution via OS command injection in the formSystemCheck handler, allowing attackers to execute arbitrary commands as root.
ManageEngine ADSelfService Plus is vulnerable to OS command injection in the GINA client, allowing unauthenticated remote code execution.
A critical improper authorization vulnerability exists in the Qualcomm Snapdragon SocketIO interface, allowing unauthenticated remote code execution.
An authentication bypass in sooperset mcp-atlassian allows unauthenticated network clients to perform unauthorized read and write operations on linked Atlassian Jira and Confluence instances.
IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to a path traversal flaw caused by improper symbolic link validation, allowing information disclosure or system compromise.
IBM DataStage on Cloud Pak for Data 5.4.0.0 is vulnerable to OS command injection, allowing remote authenticated users to execute arbitrary commands on the underlying host.
IBM FTM for RedHat OpenShift contains a code injection vulnerability in the Function constructor, allowing unauthenticated remote attackers to execute arbitrary code.
Softaculous Virtualizor contains an OS command injection vulnerability in the billing module handler that allows unauthenticated remote attackers to execute arbitrary commands with root privileges.
The Classic portlet in plone.app.portlets is vulnerable to arbitrary code execution due to improper neutralization of user-supplied TALES path expressions, allowing authenticated users to escape context.
A stack-based buffer overflow in Lantronix out-of-band management devices allows authenticated attackers to execute arbitrary code via an undocumented EEPROM read command.
A stack-based buffer overflow in various Lantronix devices allows authenticated attackers to execute arbitrary code via an undocumented mfc eeprom write command.
KarelIPS contains a Blind SQL Injection vulnerability allowing unauthenticated attackers to manipulate SQL commands.
A command injection vulnerability in Lantronix out-of-band management devices allows authenticated users to execute arbitrary root-level shell commands via an undocumented EEPROM read command.
Lantronix out-of-band management devices contain a command injection vulnerability in the mfc eeprom write command, allowing authenticated users to execute arbitrary shell commands as root.
The lwIP TCP/IP Stack MQTT implementation is vulnerable to an out-of-bounds write, which may allow an unauthenticated attacker to achieve remote code execution on the affected device.
NVIDIA Infrastructure Controller for Linux contains a vulnerability involving the use of hard-coded credentials, allowing unauthenticated attackers to gain full system control.
Net::IDN::Punycode versions before 2.301 for Perl are vulnerable to a heap-based buffer overflow due to unchecked writes in the XS backend during the Punycode encoding process.
The web.py framework version 0.76 is vulnerable to session replay attacks due to insufficient session expiration logic.
A path traversal vulnerability in sooperset mcp-atlassian allows authenticated remote callers to read sensitive local files and upload them as attachments to Jira or Confluence.
openEQUELLA contains an authenticated remote code execution vulnerability via Java deserialization in the HTTP invoker endpoint, allowing attackers to bypass class-name denylists.
A path traversal vulnerability in the mcp-atlassian server allows unauthenticated attackers to read arbitrary local files by exploiting improper workspace validation in the Jira update_issue function.
A path traversal vulnerability in the mcp-atlassian server allows unauthenticated attackers to read arbitrary files from the host system via the confluence_upload_attachment function.
A cross-site scripting (XSS) vulnerability in IBM Financial Transaction Manager for RedHat OpenShift allows remote attackers to execute arbitrary JavaScript in an authenticated user's browser.
Kaneo contains a missing authorization vulnerability in the bulk task endpoint, allowing authenticated users with low privileges to modify or delete tasks without proper permission checks.
An insecure configuration in the Foxit PDF update daemon allows local users to modify files, potentially leading to arbitrary script execution with elevated privileges.
A local privilege escalation vulnerability in the Foxit PDF Editor installer for macOS allows local attackers to execute arbitrary commands with root privileges via unvalidated configuration values.
Foxit PDF Editor and Reader are vulnerable to local privilege escalation due to an uncontrolled search path element in the updater, allowing local attackers to execute code with elevated privileges.
Adobe Experience Manager Forms JEE is affected by a Server-Side Request Forgery (SSRF) vulnerability that allows highly privileged attackers to gain unauthorized access to internal resources.
A heap-based buffer overflow vulnerability in RTI Connext Professional core libraries may allow for memory corruption and potential system instability.
A race condition in the Foxit PDF update mechanism allows local attackers to replace update packages before extraction, potentially leading to arbitrary code execution with elevated privileges.
An incorrect calculation vulnerability in the RTI Connext Professional Core Libraries allows for the abuse of existing functionality.
Adobe Connect is vulnerable to path traversal, allowing unauthenticated attackers to perform arbitrary file reads on the affected system.
Adobe Campaign Classic is vulnerable to improper input validation, allowing low-privileged authenticated attackers to achieve arbitrary code execution.
WuzhiCMS 5.0.0 is vulnerable to arbitrary code execution via an unrestricted file upload in the thumbnail-upload endpoint.
Adobe AEM 6.5 Forms JEE is vulnerable to stored Cross-Site Scripting (XSS) that allows high-privileged attackers to inject malicious scripts into forms, potentially compromising victim sessions.
Disclosed Sep 17 without a CVSS score; tracked by CVE Brief from Sep 18; scored Sep 19, analysis completed Sep 19.
A local code execution vulnerability exists in Google Chrome for Windows due to incorrect reference resolution within the Tracing component.
A path traversal vulnerability in the mcp-atlassian server allows authenticated attackers to overwrite Python modules, leading to remote code execution.
Disclosed Sep 16; published with a limited analysis after repeated re-checks found no further public detail.
A high-severity vulnerability in the Oracle Siebel CRM Helpdesk component allows an authenticated, low-privileged attacker to achieve a full takeover of the application via HTTP.
Disclosed Sep 16; published with a limited analysis after repeated re-checks found no further public detail.
A vulnerability in the Resource Catalog Services component of Oracle JDeveloper allows low-privileged, network-based attackers to compromise the application.
Disclosed Sep 16; published with a limited analysis after repeated re-checks found no further public detail.
A vulnerability in the Oracle Applications Framework component of Oracle E-Business Suite allows a low privileged attacker to achieve full system takeover via HTTP.
Disclosed Sep 16; published with a limited analysis after repeated re-checks found no further public detail.
A vulnerability in the Oracle Business Intelligence Enterprise Edition Analytics Server allows a low-privileged attacker to achieve a complete system takeover via network-based HTTP requests.
Disclosed Sep 16; published with a limited analysis after repeated re-checks found no further public detail.
A vulnerability in the Oracle Diagnostics Interfaces component of Oracle Applications Manager allows a low privileged attacker to compromise the system via HTTP.
Disclosed Sep 16; published with a limited analysis after repeated re-checks found no further public detail.
A security vulnerability in Oracle Identity Manager allows low privileged attackers to take over the application via HTTP.
Disclosed Sep 16; published with a limited analysis after repeated re-checks found no further public detail.
A high-severity vulnerability in Oracle Coherence allows authenticated attackers with low privileges to gain full control of the application via network-based HTTP requests.
Disclosed Sep 16; published with a limited analysis after repeated re-checks found no further public detail.
A security framework vulnerability in Oracle JDeveloper allows authenticated, low privileged attackers to achieve full system takeover via network access.
Disclosed Sep 16; published with a limited analysis after repeated re-checks found no further public detail.
A vulnerability in Oracle Product Hub (Oracle E-Business Suite) allows a low-privileged, authenticated attacker to achieve full system takeover via network-based HTTP access.
Disclosed Sep 16; published with a limited analysis after repeated re-checks found no further public detail.
A vulnerability in the Internal Operations component of Oracle Complex Maintenance, Repair and Overhaul allows an authenticated low-privileged attacker to compromise the system via network access.
Apache Calcite Avatica suffers from an unsafe reflection vulnerability where improper input control during plugin instantiation allows the execution of arbitrary class static initializer blocks.
A path traversal vulnerability in the mcp-atlassian server allows authenticated clients to read arbitrary files from the host filesystem by manipulating path arguments in attachment upload tools.
The mcp-atlassian server fails to enforce project and space filters for Jira and Confluence, allowing authenticated users to access data outside their intended scope.
SolarWinds Observability Self-Hosted is vulnerable to unauthenticated remote code execution via the deserialization of untrusted data in specific communication configurations.
A Server-Side Request Forgery (SSRF) vulnerability in the Lantronix WebSSH/WebTelnet listener allows unauthenticated attackers to force the device to establish unauthorized SSH connections.
A server-side request forgery vulnerability in the WebSSH/WebTelnet listener of Lantronix devices allows unauthenticated attackers to redirect SSH connections to arbitrary internal network endpoints.
ManageEngine ADSelfService Plus contains an authentication bypass vulnerability within its REST API, allowing unauthenticated remote attackers to potentially compromise system integrity and availability.
A buffer overflow vulnerability in IBM Financial Transaction Manager for RedHat OpenShift allows a remote authenticated attacker to execute arbitrary code.
A missing authorization vulnerability in the sooperset mcp-atlassian server allows authenticated clients to bypass tool restrictions and invoke unauthorized read, write, or delete operations.
A backslash authority confusion in the validate_url_for_ssrf function allows unauthenticated attackers to bypass URL validation and perform Server-Side Request Forgery (SSRF) against internal resources.
An unauthenticated path traversal and authentication bypass vulnerability in mcp-atlassian allows remote attackers to read arbitrary files and upload them to Jira or Confluence.
CGServiSign contains an OS command injection vulnerability allowing unauthenticated remote attackers to execute arbitrary system commands via malicious web pages.
IBM Financial Transaction Manager for RedHat OpenShift contains an out-of-bounds write vulnerability that allows remote authenticated attackers to execute arbitrary code.
IBM DataStage on Cloud Pak for Data 5.4.0.0 is vulnerable to OS command injection, allowing a remote authenticated attacker to execute arbitrary commands on the underlying system.
IBM DataStage on Cloud Pak for Data is vulnerable to remote command injection due to improper neutralization of special elements in OS commands, allowing authenticated attackers to execute code.
IBM DataStage on Cloud Pak for Data 5.4.0.0 is vulnerable to OS command injection, which could allow a remote authenticated attacker to execute arbitrary code on the system.
IBM DataStage on Cloud Pak for Data 5.4.0.0 is vulnerable to OS command injection, allowing an authenticated remote attacker to execute arbitrary commands on the underlying system.
A double free vulnerability in the lwIP API allows unauthenticated attackers to trigger system crashes, denial of service, memory corruption, or potential remote code execution.
A local privilege escalation vulnerability in mcp-atlassian allows unauthorized access to OAuth tokens due to insecure file permission assignment during the token save process.
The mcp-atlassian server fails to sanitize file paths in its attachment upload functionality, allowing authenticated callers to read sensitive local files from the host system.
A Server-Side Request Forgery (SSRF) vulnerability exists in the mcp-atlassian server, allowing authenticated attackers to access internal or metadata-service URLs via crafted HTTP headers.
IBM Financial Transaction Manager for RedHat OpenShift is vulnerable to an XML External Entity (XXE) injection flaw, allowing authenticated remote attackers to access sensitive information.
Disclosed Sep 17 without a CVSS score; tracked by CVE Brief from Sep 18; scored Sep 19, analysis completed Sep 19.
A race condition in the Linux kernel NFC LLCP implementation allows local users to trigger a use after free vulnerability by racing getsockopt with an in flight bind operation.
IBM Financial Transaction Manager for RedHat OpenShift contains an improper authentication and missing authorization vulnerability that allows unauthenticated remote attackers to perform unauthorized actions.
A remote SQL injection vulnerability in IBM Financial Transaction Manager for RedHat OpenShift allows unauthenticated attackers to execute arbitrary ESQL commands via improper input neutralization.
IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to arbitrary code execution via deserialization of untrusted data by an adjacent-network attacker.
NVIDIA Infrastructure Controller for Linux is vulnerable to SQL injection, potentially allowing authenticated attackers to execute code, tamper with data, or cause a denial of service.
An exposed dangerous function in the gRPC server component of Qualcomm Snapdragon allows local attackers to achieve privilege escalation.
Qualcomm Snapdragon contains a privilege escalation vulnerability due to a weak configuration during the package extraction process, allowing for uncontrolled search path element exploitation.
A privilege escalation vulnerability in Qualcomm Snapdragon software allows local users to gain elevated system privileges due to insecure temporary file handling.
Notepad++ contains a stack-based buffer overflow in the plugin manager that can lead to arbitrary code execution when a malicious plugin is loaded.
A capture-replay vulnerability in ZenHive mpp allows attackers to reuse captured subscription activation credentials, resulting in unauthorized repeated charges to the payer.
IBM Financial Transaction Manager for RedHat OpenShift is vulnerable to arbitrary command execution by a local attacker due to the inclusion of functionality from an untrusted control sphere.
IBM Financial Transaction Manager for RedHat OpenShift contains a vulnerability involving insufficiently protected credentials, allowing local attackers to gain unauthorized access and sensitive data.
IBM Financial Transaction Manager for RedHat OpenShift contains hard-coded credentials, allowing local attackers to access sensitive information and modify transaction data.
A heap out-of-bounds write vulnerability in the Linux kernel RPC-over-RDMA server path allows for potential kernel heap corruption, leading to system crashes or remote code execution.
NVIDIA NeMo Speech contains a deserialization vulnerability in the TabularTokenizer class that allows execution of arbitrary code via untrusted .pkl files.
A cross-origin resource sharing (CORS) misconfiguration in the open-vsx.org deployment allows unauthorized sites to perform credentialed requests against authenticated user endpoints.
A vulnerability in the Netdata ndsudo helper allows a low-privileged service account to execute arbitrary code as root via a malicious UNIX socket and insecure deserialization.
NVIDIA Infrastructure Controller for Linux contains a vulnerability involving missing authentication for a critical function that allows unauthenticated access.
A memory allocation vulnerability in the Vector observability pipeline allows unauthenticated remote attackers to cause a denial of service via excessive memory consumption.
An unauthenticated remote attacker can cause a denial of service in Vector by sending specially crafted nested compressed frames to the Logstash source, exhausting worker thread resources.
NVIDIA Infrastructure Controller for Linux contains an improper authentication vulnerability that may allow unauthenticated attackers to escalate privileges and access sensitive data.
Vaultwarden versions through 1.37.3 contain an authorization bypass flaw where revoked or pending members retain unauthorized access to organization ciphers due to missing status validation.
Disclosed Sep 17 without a CVSS score; tracked by CVE Brief from Sep 18; scored Sep 19, analysis completed Sep 19.
A vulnerability in the Linux kernel ksmbd module allows authenticated users to bypass access control checks by crafting a DACL that places access-granting ACEs outside the defined DACL boundary.
Disclosed Sep 17 without a CVSS score; tracked by CVE Brief from Sep 18; scored Sep 19, analysis completed Sep 19.
A race condition in the Linux kernel IOMMU VT-d driver allows hardware to access partially cleared context entries, potentially leading to system instability or security compromises.
Disclosed Sep 17 without a CVSS score; tracked by CVE Brief from Sep 18; scored Sep 19, analysis completed Sep 19.
A race condition in the Linux kernel Bluetooth L2CAP implementation allows for unauthorized memory access during socket cleanup, potentially leading to privilege escalation or system instability.
Disclosed Sep 17 without a CVSS score; tracked by CVE Brief from Sep 18; scored Sep 19, analysis completed Sep 19.
A race condition in the Linux kernel Bluetooth L2CAP subsystem allows for a use-after-free vulnerability, potentially leading to privilege escalation or system instability.
Disclosed Sep 17 without a CVSS score; tracked by CVE Brief from Sep 18; scored Sep 19, analysis completed Sep 19.
A use-after-free vulnerability in the Linux kernel Bluetooth L2CAP subsystem allows local attackers to cause a system crash or potentially execute arbitrary code via unsafe socket operations.
Disclosed Sep 17 without a CVSS score; tracked by CVE Brief from Sep 18; scored Sep 19, analysis completed Sep 19.
A use-after-free vulnerability in the Linux kernel IPv6 multicast routing implementation allows a local attacker to trigger memory corruption and potential system instability.
Disclosed Sep 17 without a CVSS score; tracked by CVE Brief from Sep 18; scored Sep 19, analysis completed Sep 19.
A buffer overflow vulnerability exists in the Linux kernel NTFS driver, allowing out-of-bounds memory writes during decompression of corrupted NTFS data.
Disclosed Sep 17 without a CVSS score; tracked by CVE Brief from Sep 18; scored Sep 19, analysis completed Sep 19.
A heap out of bounds write vulnerability exists in the Linux kernel NTFS driver, where insufficient validation of index root entries can lead to memory corruption during copy operations.
Disclosed Sep 17 without a CVSS score; tracked by CVE Brief from Sep 18; scored Sep 19, analysis completed Sep 19.
A buffer overflow vulnerability in the Linux kernel virtio_net driver allows local attackers to cause memory corruption or system crashes via improper RX ring resizing.
Disclosed Sep 17 without a CVSS score; tracked by CVE Brief from Sep 18; scored Sep 19, analysis completed Sep 19.
A missing RCU read-side critical section in the Linux kernel KCM strparser allows BPF map operations to trigger kernel warnings, potentially leading to local privilege escalation or system instability.
Disclosed Sep 17 without a CVSS score; tracked by CVE Brief from Sep 18; scored Sep 19, analysis completed Sep 19.
A local privilege escalation vulnerability exists in the Linux kernel where BPF_LINK_UPDATE bypasses necessary device offload checks, allowing improper XDP program attachment.
Disclosed Sep 17 without a CVSS score; tracked by CVE Brief from Sep 18; scored Sep 19, analysis completed Sep 19.
The Linux kernel ntfs3 driver improperly validates virtual cluster numbers, potentially allowing a malformed on-disk attribute to trigger an out-of-bounds condition.
Disclosed Sep 17 without a CVSS score; tracked by CVE Brief from Sep 18; scored Sep 19, analysis completed Sep 19.
A use-after-free vulnerability in the Linux kernel BPF subsystem allows local attackers with low privileges to potentially trigger kernel-level memory corruption.
Disclosed Sep 17 without a CVSS score; tracked by CVE Brief from Sep 18; scored Sep 19, analysis completed Sep 19.
A use-after-free vulnerability in the Linux kernel module duplicate request handling allows local attackers to potentially achieve arbitrary code execution or system instability.
Disclosed Sep 17 without a CVSS score; tracked by CVE Brief from Sep 18; scored Sep 19, analysis completed Sep 19.
A race condition in the Linux kernel RDMA/erdma driver allows for a use-after-free vulnerability when handling Queue Pair (QP) references during asynchronous events.
Disclosed Sep 17 without a CVSS score; tracked by CVE Brief from Sep 18; scored Sep 19, analysis completed Sep 19.
A use-after-free vulnerability exists in the Linux kernel RDMA erdma driver due to improper reference counting during EQ event processing, potentially allowing local privilege escalation.
Disclosed Sep 17 without a CVSS score; tracked by CVE Brief from Sep 18; scored Sep 19, analysis completed Sep 19.
The Linux kernel drm/omap driver exhibits a use-after-free vulnerability due to improper handling of interrupt service routine tables, potentially allowing local privilege escalation.
Disclosed Sep 17 without a CVSS score; tracked by CVE Brief from Sep 18; scored Sep 19, analysis completed Sep 19.
A use-after-free vulnerability in the Linux kernel BPF subsystem allows local attackers to trigger memory corruption by failing to invalidate RCU pointers after a final spin lock release.
Disclosed Sep 17 without a CVSS score; tracked by CVE Brief from Sep 18; scored Sep 19, analysis completed Sep 19.
A memory safety flaw in the Linux kernel OCFS2 file system allows local attackers to trigger a use-after-free or out-of-bounds read via corrupted external extended attribute metadata.
Disclosed Sep 17 without a CVSS score; tracked by CVE Brief from Sep 18; scored Sep 19, analysis completed Sep 19.
A memory corruption vulnerability in the Linux kernel OCFS2 subsystem allows an attacker to trigger a use after free condition via specifically crafted inline extended attribute metadata.
Disclosed Sep 17 without a CVSS score; tracked by CVE Brief from Sep 18; scored Sep 19, analysis completed Sep 19.
A stack-based buffer overflow in the Linux kernel BPF x86 trampoline allows local attackers to cause memory corruption by improperly handling 128-bit function arguments.
Disclosed Sep 17 without a CVSS score; tracked by CVE Brief from Sep 18; scored Sep 19, analysis completed Sep 19.
A vulnerability in the Linux kernel SGI GRU driver allows local users to trigger unsafe page table walks, potentially leading to privilege escalation or system instability.
A heap use-after-free vulnerability in the Perl Net::IDN::Punycode XS backend allows attackers to corrupt memory during the decoding of punycode labels.