129Articles
7Categories
2026-04-26Date
🚨
Security Affairs newsletter Round 574 by Pierluigi Paganini – INTERNATIONAL EDITIONA new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. U.S. CISA adds SimpleHelp, Sa…
KEV
🐛
CVE-2022-2068 The c_rehash script allows command injection
🐛
CVE-2026-31619 ALSA: fireworks: bound device-supplied status before string array lookup
🐛
CVE-2026-41079 OpenPrinting CUPS: Heap out-of-bounds read in SNMP supply-level polling leaks stack memory to authenticated users
🐛
CVE-2026-31557 nvmet: move async event work off nvmet-wq
🐛
CVE-2026-31606 usb: gadget: f_hid: don't call cdev_init while cdev in use
🐛
CVE-2026-31646 net: lan966x: fix page_pool error handling in lan966x_fdma_rx_alloc_page_pool()
🐛
CVE-2026-31620 ALSA: usx2y: us144mkii: fix NULL deref on missing interface 0
🐛
CVE-2026-31593 KVM: SEV: Reject attempts to sync VMSA of an already-launched/encrypted vCPU
🐛
CVE-2026-31667 Input: uinput - fix circular locking dependency with ff-core
🐛
CVE-2026-31590 KVM: SEV: Drop WARN on large size for KVM_MEMORY_ENCRYPT_REG_REGION
🐛
CVE-2026-31618 fbdev: tdfxfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO
🐛
CVE-2026-31617 usb: gadget: f_ncm: validate minimum block_len in ncm_unwrap_ntb()
🐛
CVE-2026-31589 mm: call ->free_folio() directly in folio_unmap_invalidate()
🐛
CVE-2026-31660 nfc: pn533: allocate rx skb before consuming bytes
🐛
CVE-2026-31605 fbdev: udlfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO
🐛
CVE-2026-31566 drm/amdgpu: Fix fence put before wait in amdgpu_amdkfd_submit_ib
🐛
CVE-2026-31599 media: vidtv: fix NULL pointer dereference in vidtv_channel_pmt_match_sections
🐛
CVE-2026-31602 ALSA: ctxfi: Limit PTP to a single page
🐛
CVE-2026-31637 rxrpc: reject undecryptable rxkad response tickets
🐛
CVE-2026-31570 can: gw: fix OOB heap access in cgw_csum_crc8_rel()
🐛
CVE-2026-31624 HID: core: clamp report_size in s32ton() to avoid undefined shift
🐛
CVE-2026-31651 mmc: vub300: fix NULL-deref on disconnect
🐛
CVE-2026-23420 wifi: wlcore: Fix a locking bug
🐛
CVE-2026-31672 wifi: rt2x00usb: fix devres lifetime
🐛
CVE-2026-23422 dpaa2-switch: Fix interrupt storm after receiving bad if_id in IRQ handler
🐛
CVE-2026-31565 RDMA/irdma: Fix deadlock during netdev reset with active connections
🐛
CVE-2026-31621 bnge: return after auxiliary_device_uninit() in error path
🐛
CVE-2026-31626 staging: rtl8723bs: initialize le_tmp64 in rtw_BIP_verify()
🐛
CVE-2026-31663 xfrm: hold dev ref until after transport_finish NF_HOOK
🐛
CVE-2026-31615 usb: gadget: renesas_usb3: validate endpoint index in standard request handlers
🐛
CVE-2026-31610 ksmbd: fix mechToken leak when SPNEGO decode fails after token alloc
🐛
CVE-2026-41066 lxml: Default configuration of iterparse() and ETCompatXMLParser() allows XXE to local files
🐛
CVE-2026-31645 net: lan966x: fix page pool leak in error paths
🐛
CVE-2026-41907 uuid: Missing buffer bounds check in `v3`/`v5`/`v6` when `buf` is provided
🐛
CVE-2026-41411 Vim: Command injection via backtick expansion in tag filenames
🐛
CVE-2026-31598 ocfs2: fix possible deadlock between unlink and dio_end_io_write
🐛
CVE-2026-31537 smb: server: make use of smbdirect_socket.send_io.bcredits
🐛
CVE-2026-23414 tls: Purge async_hold in tls_decrypt_async_wait()
🐛
CVE-2026-31603 staging: sm750fb: fix division by zero in ps_to_hz()
🐛
CVE-2026-31608 smb: server: avoid double-free in smb_direct_free_sendmsg after smb_direct_flush_send_list()
🐛
CVE-2026-31611 ksmbd: require 3 sub-authorities before reading sub_auth[2]
🐛
CVE-2026-32147 SFTP chroot bypass via path traversal in SSH_FXP_FSETSTAT
🐛
CVE-2026-31600 arm64: mm: Handle invalid large leaf mappings correctly
🐛
CVE-2026-41676 rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1
🐛
CVE-2026-31627 i2c: s3c24xx: check the size of the SMBUS message before using it
🐛
CVE-2026-31671 xfrm_user: fix info leak in build_report()
🐛
CVE-2026-31560 spi: spi-dw-dma: fix print error log when wait finish transaction
🐛
CVE-2026-41678 rust-openssl: Incorrect bounds assertion in aes key wrap
🐛
CVE-2026-31612 ksmbd: validate EaNameLength in smb2_get_ea()
🐛
CVE-2026-31568 s390/mm: Add missing secure storage access fixups for donated memory
🐛
CVE-2026-31587 ASoC: qcom: q6apm: move component registration to unmanaged version
🐛
CVE-2026-31575 mm/userfaultfd: fix hugetlb fault mutex hash calculation
🐛
CVE-2026-31662 tipc: fix bc_ackers underflow on duplicate GRP_ACK_MSG
🐛
CVE-2026-31580 bcache: fix cached_dev.sb_bio use-after-free and crash
🐛
CVE-2026-41681 rust-openssl: MdCtxRef::digest_final() writes past caller buffer with no length check
🐛
CVE-2026-31639 rxrpc: Fix key reference count leak from call->key
🐛
CVE-2026-31657 batman-adv: hold claim backbone gateways by reference
🐛
CVE-2026-31591 KVM: SEV: Lock all vCPUs when synchronzing VMSAs for SNP launch finish
🐛
CVE-2026-31629 nfc: llcp: add missing return after LLCP_CLOSED checks
🐛
CVE-2026-31579 wireguard: device: use exit_rtnl callback instead of manual rtnl_lock in pre_exit
🐛
CVE-2026-31628 x86/CPU: Fix FPDSS on Zen1
🐛
CVE-2026-31630 rxrpc: proc: size address buffers for %pISpc output
🐛
CVE-2026-31655 pmdomain: imx8mp-blk-ctrl: Keep the NOC_HDCP clock enabled
🐛
CVE-2026-31685 netfilter: ip6t_eui64: reject invalid MAC header for all packets
🐛
CVE-2026-31649 net: stmmac: fix integer underflow in chain mode
🐛
CVE-2026-31669 mptcp: fix slab-use-after-free in __inet_lookup_established
🐛
CVE-2026-31680 net: ipv6: flowlabel: defer exclusive option free until RCU teardown
🐛
CVE-2026-31576 media: hackrf: fix to not free memory after the device is registered in hackrf_probe()
🐛
CVE-2026-31678 openvswitch: defer tunnel netdev_put to RCU release
🐛
CVE-2026-31595 PCI: endpoint: pci-epf-vntb: Stop cmd_handler work in epf_ntb_epc_cleanup
🐛
CVE-2026-31681 netfilter: xt_multiport: validate range encoding in checkentry
🐛
CVE-2026-31586 mm: blk-cgroup: fix use-after-free in cgwb_release_workfn()
🐛
CVE-2026-31578 media: as102: fix to not free memory after the device is registered in as102_usb_probe()
🐛
CVE-2026-31682 bridge: br_nd_send: linearize skb before parsing ND options
🐛
CVE-2026-31659 batman-adv: reject oversized global TT response buffers
🐛
CVE-2026-31625 HID: alps: fix NULL pointer dereference in alps_raw_event()
🐛
CVE-2026-31679 openvswitch: validate MPLS set/set_masked payload length
🐛
CVE-2026-31674 netfilter: ip6t_rt: reject oversized addrnr in rt_mt6_check()
🐛
CVE-2026-31673 af_unix: read UNIX_DIAG_VFS data under unix_state_lock
🐛
CVE-2026-31664 xfrm: clear trailing padding in build_polexpire()
🐛
CVE-2026-31622 NFC: digital: Bounds check NFC-A cascade depth in SDD response handler
🐛
CVE-2026-31597 ocfs2: fix use-after-free in ocfs2_fault() when VM_FAULT_RETRY
🐛
CVE-2026-31592 KVM: SEV: Protect *all* of sev_mem_enc_register_region() with kvm->lock
🐛
CVE-2026-31656 drm/i915/gt: fix refcount underflow in intel_engine_park_heartbeat
🐛
CVE-2026-23401 KVM: x86/mmu: Drop/zap existing present SPTE even when creating an MMIO SPTE
🐛
CVE-2026-31555 futex: Clear stale exiting pointer in futex_lock_pi() retry path
🐛
CVE-2026-31607 usbip: validate number_of_packets in usbip_pack_ret_submit()
🐛
CVE-2026-31536 smb: server: let send_done handle a completion without IB_SEND_SIGNALED
🐛
CVE-2026-31583 media: em28xx: fix use-after-free in em28xx_v4l2_open()
🐛
CVE-2026-31638 rxrpc: Only put the call ref if one was acquired
🐛
CVE-2026-31574 clockevents: Add missing resets of the next_event_forced flag
KEV
🐛
CVE-2026-31596 ocfs2: handle invalid dinode in ocfs2_group_extend
🐛
CVE-2026-31581 ALSA: 6fire: fix use-after-free on disconnect
🐛
CVE-2026-31604 wifi: rtw88: fix device leak on probe failure
🐛
CVE-2026-31585 media: vidtv: fix nfeeds state corruption on start_streaming failure
🐛
CVE-2026-31577 nilfs2: fix NULL i_assoc_inode dereference in nilfs_mdt_save_to_shadow_map
🐛
CVE-2026-41140 Poetry: Path traversal in tar extraction on Python 3.10.0 - 3.10.12 and 3.11.0 - 3.11.4
🐛
CVE-2026-31665 netfilter: nft_ct: fix use-after-free in timeout object destroy
🐛
CVE-2026-31670 net: rfkill: prevent unlimited numbers of rfkill events from being created
🐛
CVE-2026-31642 rxrpc: Fix call removal to use RCU safe deletion
🐛
CVE-2026-31613 smb: client: fix OOB reads parsing symlink error response
🐛
CVE-2026-31623 net: usb: cdc-phonet: fix skb frags[] overflow in rx_complete()
🐛
CVE-2026-31594 PCI: endpoint: pci-epf-vntb: Remove duplicate resource teardown
🐛
CVE-2026-31609 smb: client: avoid double-free in smbd_free_send_io() after smbd_send_batch_flush()
🐛
CVE-2026-41677 rust-openssl: Out-of-bounds read in PEM password callback when user callback returns an oversized length
🐛
CVE-2026-31616 usb: gadget: f_phonet: fix skb frags[] overflow in pn_rx_complete()
🐛
CVE-2026-31601 vfio/xe: Reorganize the init to decouple migration from reset
🐛
CVE-2026-31668 seg6: separate dst_cache for input and output paths in seg6 lwtunnel
🐛
CVE-2026-31582 hwmon: (powerz) Fix use-after-free on USB disconnect
🐛
CVE-2026-31676 rxrpc: only handle RESPONSE during service challenge
🐛
CVE-2026-31588 KVM: x86: Use scratch field in MMIO fragment to hold small write values
🐛
CVE-2026-31677 crypto: af_alg - limit RX SG extraction by receive buffer budget
🐛
CVE-2026-31675 net/sched: sch_netem: fix out-of-bounds access in packet corruption
🐛
CVE-2026-31634 rxrpc: fix reference count leak in rxrpc_server_keyring()
🐛
CVE-2026-31684 net: sched: act_csum: validate nested VLAN headers
🐛
CVE-2026-31658 net: altera-tse: fix skb leak on DMA mapping error in tse_start_xmit()
🐛
CVE-2026-23394 af_unix: Give up GC if MSG_PEEK intervened.
🐛
CVE-2026-23362 can: bcm: fix locking for bcm_op runtime updates
🐛
CVE-2026-31788 xen/privcmd: restrict usage in unprivileged domU
🐛
CVE-2026-23360 nvme: fix admin queue leak on controller reset
🐛
Critical bug in CrowdStrike LogScale let attackers access files
⚠️
Week in review: Claude Mythos finds 271 Firefox flaws, Vercel breach
🔥
Trigona ransomware adopts custom tool to steal data and evade detection
🕵️
XChat launches standalone iOS app as security concerns remain
🕵️
GopherWhisper: new China-linked APT targets Mongolia with Go-based malware
🕵️
Npm Slop & Wonky Software Supply Chains
🌐
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 94
📡
California Engineer Identified in Suspected Shooting at White House Correspondents' Dinner