container statistics
11 container package(s) · generated 2026-10-09T04:57:32Z
ghcr.io/openvoxproject/openbolt
ghcr.io/openvoxproject/openbolt:latest (2026-08-27)
Trivy
HIGH 2
MEDIUM 2
| Severity | ID | Package | Installed | Fixed | Title / target |
|---|---|---|---|---|---|
| HIGH | CVE-2026-80212 | resolv | 0.2.3 | ~> 0.3.2, >= 0.7.2 | resolv: resolv gem: Denial of Service via uncontrolled memory growth from crafted DNS responses — Ruby |
| HIGH | CVE-2026-85396 | rubyzip | 2.4.1 | >= 3.4.0 | rubyzip: rubyzip: Arbitrary file write via path traversal — Ruby |
| MEDIUM | CVE-2026-85091 | zlib | 1.3.2-r0 | 1.3.2-r1 | zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vul ... — ghcr.io/openvoxproject/openbolt:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-80213 | resolv | 0.2.3 | ~> 0.3.2, >= 0.7.2 | resolv: Resolv gem: DNS allowlist and egress bypass, and cache poisoning via crafted hostnames — Ruby |
Grype
HIGH 2
NVD/CPE filtered 29
| Severity | ID | Package | Installed | Fixed | Title / target |
|---|---|---|---|---|---|
| HIGH | CVE-2026-85091 | zlib | 1.3.2-r0 | 1.3.2-r1 | /lib/apk/db/installed |
| HIGH | GHSA-47m2-wp7j-p9vc | rubyzip | 2.4.1 | 3.4.0 | rubyzip path traversal vulnerability — /opt/openbolt/vendor/bundle/ruby/3.2.0/specifications/rubyzip-2.4.1.gemspec |
Filtered NVD/CPE matches (29)
These broad CPE matches are unconfirmed for the distribution package and excluded from scanner totals.
| Severity | ID | Package | Installed | Fixed | Title / target |
|---|---|---|---|---|---|
| HIGH | CVE-2026-54873 | libcrypto3 | 3.5.8-r0 | Issue summary: QUIC process may keep memory for QUIC packet buffer for much longer period than necessary. Impact summary: Remote peer can exploit this vulnerability by sending maliciously crafted packets, making the local QUIC stack to keep the memory for packet buffers allocated. The time for which the memory remains allocated is entirely under the control of the potentially malicious remote peer. CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: To save copy operation from the packet buffer to the stream reassemble buffer the QUIC stack leaves the stream data on the packet buffer waiting to be copied to a buffer provided by the local receiving application. The QUIC stack releases a reference to the packet buffer only after the data are copied to the application buffer. This design is more efficient for legitimate data transfers but enables an attacker to allocate a lot more memory than actually required by the data kept in the receiving stream buffer. To mitigate the vulnerability, the QUIC stack now calculates and monitors memory overhead for every stream. The memory overhead for a single stream frame is calculated as a difference between the size of the whole packet that carries the stream frame and the size of the stream frame itself. The memory overhead for a single stream frame is added to the total (cumulative) memory overhead QUIC stack keeps for each stream. Once the cumulative memory overhead exceeds 64kB, the QUIC stack moves the stream frame data from the packet buffer to the stream buffer, starting with the next packet received. FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| HIGH | CVE-2026-54873 | libssl3 | 3.5.8-r0 | Issue summary: QUIC process may keep memory for QUIC packet buffer for much longer period than necessary. Impact summary: Remote peer can exploit this vulnerability by sending maliciously crafted packets, making the local QUIC stack to keep the memory for packet buffers allocated. The time for which the memory remains allocated is entirely under the control of the potentially malicious remote peer. CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: To save copy operation from the packet buffer to the stream reassemble buffer the QUIC stack leaves the stream data on the packet buffer waiting to be copied to a buffer provided by the local receiving application. The QUIC stack releases a reference to the packet buffer only after the data are copied to the application buffer. This design is more efficient for legitimate data transfers but enables an attacker to allocate a lot more memory than actually required by the data kept in the receiving stream buffer. To mitigate the vulnerability, the QUIC stack now calculates and monitors memory overhead for every stream. The memory overhead for a single stream frame is calculated as a difference between the size of the whole packet that carries the stream frame and the size of the stream frame itself. The memory overhead for a single stream frame is added to the total (cumulative) memory overhead QUIC stack keeps for each stream. Once the cumulative memory overhead exceeds 64kB, the QUIC stack moves the stream frame data from the packet buffer to the stream buffer, starting with the next packet received. FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| HIGH | CVE-2026-84782 | libcrypto3 | 3.5.8-r0 | Issue summary: The DTLS retransmission logic does not correctly handle a handshake message write that is suspended part-way through. The retransmitted message can be read past the message buffer and the retransmission overwrites the internal state the suspended write needs to resume correctly. Impact summary: The retransmitted message can disclose a heap memory to the peer as plaintext handshake data or cause a crash and a Denial of Service when the read reaches an unmapped memory region. CWE: CWE-125: Out-of-bounds Read Description: DTLS handshake messages can be written out in multiple fragments, and a write can suspend mid-message (returning WANT_WRITE) if the underlying transport temporarily cannot accept more data. While such a write is suspended, the DTLS retransmission timer may independently fire and ask the retransmission logic to resend an earlier, already-acknowledged-as-sent message from its retransmit queue. The retransmission logic reused the same internal buffer and position tracking as the message that was still being written, without resetting the position back to the start of the message being retransmitted. As a result the retransmission was read starting from wherever the suspended write had left off, producing a mislabelled message whose body was leftover bytes from the other, larger message still in flight - content that was never meant to be sent at that point, and which could run past the end of the allocated buffer. Separately, even when the retransmission is positioned correctly, allowing it to run to completion while another write is suspended overwrites the same shared bookkeeping that the suspended write depends on to resume. When the application later resumes the suspended write (via a subsequent SSL_read(), SSL_write(), SSL_accept(), or SSL_connect() call), it finds that bookkeeping in a state inconsistent with the message and aborts the process in a debugging build. The fix resets the retransmission's read position to the start of the message before resending, and skips retransmission entirely whenever a handshake write is still suspended, deferring to the next call that resumes it instead. FIPS impact: no The affected code is outside the FIPS module boundary. — /lib/apk/db/installed | |
| HIGH | CVE-2026-84782 | libssl3 | 3.5.8-r0 | Issue summary: The DTLS retransmission logic does not correctly handle a handshake message write that is suspended part-way through. The retransmitted message can be read past the message buffer and the retransmission overwrites the internal state the suspended write needs to resume correctly. Impact summary: The retransmitted message can disclose a heap memory to the peer as plaintext handshake data or cause a crash and a Denial of Service when the read reaches an unmapped memory region. CWE: CWE-125: Out-of-bounds Read Description: DTLS handshake messages can be written out in multiple fragments, and a write can suspend mid-message (returning WANT_WRITE) if the underlying transport temporarily cannot accept more data. While such a write is suspended, the DTLS retransmission timer may independently fire and ask the retransmission logic to resend an earlier, already-acknowledged-as-sent message from its retransmit queue. The retransmission logic reused the same internal buffer and position tracking as the message that was still being written, without resetting the position back to the start of the message being retransmitted. As a result the retransmission was read starting from wherever the suspended write had left off, producing a mislabelled message whose body was leftover bytes from the other, larger message still in flight - content that was never meant to be sent at that point, and which could run past the end of the allocated buffer. Separately, even when the retransmission is positioned correctly, allowing it to run to completion while another write is suspended overwrites the same shared bookkeeping that the suspended write depends on to resume. When the application later resumes the suspended write (via a subsequent SSL_read(), SSL_write(), SSL_accept(), or SSL_connect() call), it finds that bookkeeping in a state inconsistent with the message and aborts the process in a debugging build. The fix resets the retransmission's read position to the start of the message before resending, and skips retransmission entirely whenever a handshake write is still suspended, deferring to the next call that resumes it instead. FIPS impact: no The affected code is outside the FIPS module boundary. — /lib/apk/db/installed | |
| HIGH | CVE-2026-84784 | libcrypto3 | 3.5.8-r0 | Issue summary: A malicious remote peer may flood the local QUIC stack with NEW_CONNECTION_ID frames by avoiding a limit check on how many connection IDs the remote QUIC stack can use. Impact summary: The local QUIC stack sends a RETIRE_CONN_ID frame for every NEW_CONNECTION_ID frame it receives. The RETIRE_CONN_ID frame is dispatched via the Control Frame Queue (CFQ). If the remote peer also withholds ACKs, then it can force the local stack to allocate ~400MB (depending on ACK delay). CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: RFC 9000 sections 5.1.1 and 5.1.2 [1] describe the mechanism by which a remote peer can notify the local QUIC stack to change the destination connection ID (a.k.a. CID) the local stack uses to identify the connection at the remote peer. Each CID is associated with a sequence number. The sequence number is transmitted in NEW_CONNECTION_ID and RETIRE_CONNECTION_ID frames to identify the CID which is being either associated with a connection or retired. The remote peer sends a NEW_CONNECTION_ID frame to let the local stack know a new CID is being associated with an existing connection. The NEW_CONNECTION_ID frame carries the new CID, its sequence number, and the retire-prior-to number. The retire-prior-to identifies existing CIDs that are to be retired. The local QUIC stack must send a RETIRE_CONNECTION_ID for every destination CID whose sequence number is less than retire-prior-to. The CID becomes retired after the local stack receives an ACK for its RETIRE_CONNECTION_ID frame. Although the OpenSSL QUIC stack supports at most one destination CID for every connection, it can be tricked into processing more than one RETIRE_CONNECTION_ID frame per connection. The OpenSSL QUIC stack currently retires the destination CID as soon as it receives the NEW_CONNECTION_ID, while in fact the destination CID must be retired after an ACK for the RETIRE_CONNECTION_ID frame is received. Correcting the flawed logic also fixes the backlog growth. [1] https://datatracker.ietf.org/doc/html/rfc9000#name-issuing-connection-ids FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| HIGH | CVE-2026-84784 | libssl3 | 3.5.8-r0 | Issue summary: A malicious remote peer may flood the local QUIC stack with NEW_CONNECTION_ID frames by avoiding a limit check on how many connection IDs the remote QUIC stack can use. Impact summary: The local QUIC stack sends a RETIRE_CONN_ID frame for every NEW_CONNECTION_ID frame it receives. The RETIRE_CONN_ID frame is dispatched via the Control Frame Queue (CFQ). If the remote peer also withholds ACKs, then it can force the local stack to allocate ~400MB (depending on ACK delay). CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: RFC 9000 sections 5.1.1 and 5.1.2 [1] describe the mechanism by which a remote peer can notify the local QUIC stack to change the destination connection ID (a.k.a. CID) the local stack uses to identify the connection at the remote peer. Each CID is associated with a sequence number. The sequence number is transmitted in NEW_CONNECTION_ID and RETIRE_CONNECTION_ID frames to identify the CID which is being either associated with a connection or retired. The remote peer sends a NEW_CONNECTION_ID frame to let the local stack know a new CID is being associated with an existing connection. The NEW_CONNECTION_ID frame carries the new CID, its sequence number, and the retire-prior-to number. The retire-prior-to identifies existing CIDs that are to be retired. The local QUIC stack must send a RETIRE_CONNECTION_ID for every destination CID whose sequence number is less than retire-prior-to. The CID becomes retired after the local stack receives an ACK for its RETIRE_CONNECTION_ID frame. Although the OpenSSL QUIC stack supports at most one destination CID for every connection, it can be tricked into processing more than one RETIRE_CONNECTION_ID frame per connection. The OpenSSL QUIC stack currently retires the destination CID as soon as it receives the NEW_CONNECTION_ID, while in fact the destination CID must be retired after an ACK for the RETIRE_CONNECTION_ID frame is received. Correcting the flawed logic also fixes the backlog growth. [1] https://datatracker.ietf.org/doc/html/rfc9000#name-issuing-connection-ids FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| HIGH | CVE-2026-72897 | libcrypto3 | 3.5.8-r0 | Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a connection to a different SSL_CTX part way through a handshake may access memory beyond the end of an internal array if the replacement context knows about more provider signature algorithms than the context the connection was created from. Applications which never call SSL_set_SSL_CTX() are not affected. Impact summary: A remote peer may be able to cause a small out-of-bounds read, and in some circumstances a fixed-value out-of-bounds write, on the server heap. This may lead to a Denial of Service. CWE: CWE-787: Out-of-bounds Write Description: A TLS connection records how many certificate slots it has when it is created, taken from the SSL_CTX that created it: the built-in certificate types plus one slot for each provider TLS-SIGALG entry that context was aware of. That count sizes an internal array of per-slot certificate validity flags. An application may replace a connection's SSL_CTX part way through the handshake by calling SSL_set_SSL_CTX(), most commonly from a servername callback in order to serve a different virtual host. Doing so did not refresh the recorded count. A provider signature algorithm's slot index is its position in the list of whichever context resolves it, so if the replacement context is aware of more of them than the original, an algorithm offered by the peer can resolve to an index beyond the end of the array. Processing the peer's signature algorithms then reads one four byte word past the end for each such algorithm and, where the word read is zero, writes a fixed value over it. A peer offering many of them can corrupt heap metadata and abort the process. Only provider signature algorithms which occupy one of the excess slots, and which the server also has configured, have this effect. Codepoints the replacement context does not recognise are discarded without being resolved to a slot, and provider signature algorithms are usable only from TLS 1.3. The two contexts must therefore be aware of different numbers of provider signature algorithms, which requires separate library contexts, a provider loaded between the two being created, or providers which differ in what they advertise - in 4.0, for example, the default provider advertises SM2 where the FIPS provider does not. A deployment meeting the condition is also unable to negotiate the affected algorithms with legitimate clients, since the same stale count hides the corresponding certificates, so the misconfiguration is likely to be noticed. For that reason, and because the configuration is not the default, this issue has been assessed as Low severity. FIPS impact: no No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| HIGH | CVE-2026-72897 | libssl3 | 3.5.8-r0 | Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a connection to a different SSL_CTX part way through a handshake may access memory beyond the end of an internal array if the replacement context knows about more provider signature algorithms than the context the connection was created from. Applications which never call SSL_set_SSL_CTX() are not affected. Impact summary: A remote peer may be able to cause a small out-of-bounds read, and in some circumstances a fixed-value out-of-bounds write, on the server heap. This may lead to a Denial of Service. CWE: CWE-787: Out-of-bounds Write Description: A TLS connection records how many certificate slots it has when it is created, taken from the SSL_CTX that created it: the built-in certificate types plus one slot for each provider TLS-SIGALG entry that context was aware of. That count sizes an internal array of per-slot certificate validity flags. An application may replace a connection's SSL_CTX part way through the handshake by calling SSL_set_SSL_CTX(), most commonly from a servername callback in order to serve a different virtual host. Doing so did not refresh the recorded count. A provider signature algorithm's slot index is its position in the list of whichever context resolves it, so if the replacement context is aware of more of them than the original, an algorithm offered by the peer can resolve to an index beyond the end of the array. Processing the peer's signature algorithms then reads one four byte word past the end for each such algorithm and, where the word read is zero, writes a fixed value over it. A peer offering many of them can corrupt heap metadata and abort the process. Only provider signature algorithms which occupy one of the excess slots, and which the server also has configured, have this effect. Codepoints the replacement context does not recognise are discarded without being resolved to a slot, and provider signature algorithms are usable only from TLS 1.3. The two contexts must therefore be aware of different numbers of provider signature algorithms, which requires separate library contexts, a provider loaded between the two being created, or providers which differ in what they advertise - in 4.0, for example, the default provider advertises SM2 where the FIPS provider does not. A deployment meeting the condition is also unable to negotiate the affected algorithms with legitimate clients, since the same stale count hides the corresponding certificates, so the misconfiguration is likely to be noticed. For that reason, and because the configuration is not the default, this issue has been assessed as Low severity. FIPS impact: no No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-75805 | libssl3 | 3.5.8-r0 | Issue summary: A CMP client that requests certificate revocation on the basis of a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when processing a crafted revocation response. Impact summary: The NULL pointer dereference happens on a read which leads to a crash and a Denial of Service for the affected client application. CWE: CWE-476: NULL-pointer dereference Description: A CMP client revoking a certificate has to tell the server which certificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the certificate itself or its issuer name and serial number. This is 'openssl cmp -cmd rr -csr <file>' on the command line, or OSSL_CMP_exec_RR_ses() with the certificate supplied via OSSL_CMP_CTX_set1_p10CSR() through the API. A CSR does not contain the issuer name and serial number of the certificate, so the client does not send them. A server may optionally name the certificate it revoked in its response, and the client then compares that name against what it sent. Having sent neither an issuer name nor a serial number, it has nothing to compare against, and a server returning a specially crafted name causes the client to read from a NULL pointer and crash. The revocation response is checked for valid message protection before the affected code is reached, so an attacker must be a malicious or compromised CMP server, or a man-in-the-middle in possession of the secret used for message protection. Clients that identify the certificate to be revoked by a certificate or by issuer and serial number rather than by a PKCS#10 CSR are not affected. FIPS impact: no No FIPS modules are affected by this issue, as the CMP protocol implementation is outside the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-75805 | libcrypto3 | 3.5.8-r0 | Issue summary: A CMP client that requests certificate revocation on the basis of a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when processing a crafted revocation response. Impact summary: The NULL pointer dereference happens on a read which leads to a crash and a Denial of Service for the affected client application. CWE: CWE-476: NULL-pointer dereference Description: A CMP client revoking a certificate has to tell the server which certificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the certificate itself or its issuer name and serial number. This is 'openssl cmp -cmd rr -csr <file>' on the command line, or OSSL_CMP_exec_RR_ses() with the certificate supplied via OSSL_CMP_CTX_set1_p10CSR() through the API. A CSR does not contain the issuer name and serial number of the certificate, so the client does not send them. A server may optionally name the certificate it revoked in its response, and the client then compares that name against what it sent. Having sent neither an issuer name nor a serial number, it has nothing to compare against, and a server returning a specially crafted name causes the client to read from a NULL pointer and crash. The revocation response is checked for valid message protection before the affected code is reached, so an attacker must be a malicious or compromised CMP server, or a man-in-the-middle in possession of the secret used for message protection. Clients that identify the certificate to be revoked by a certificate or by issuer and serial number rather than by a PKCS#10 CSR are not affected. FIPS impact: no No FIPS modules are affected by this issue, as the CMP protocol implementation is outside the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-35189 | libssl3 | 3.5.8-r0 | Issue summary: A certificate with many nameRelativeToCRLIssuer CRL distribution points causes disproportionate heap growth when OpenSSL caches X.509 extensions. Impact summary: Receiving a crafted certificate from a malicious peer can lead to significant memory pressure and possible Denial of Service in clients or in servers that solicit client certificates. CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: A certificate or a set of certificates that fits under the limit for size of certificates accepted from the peer (~100 KiB) can result in allocation of several hundred MiB of resident memory on the receiving side during a normal TLS handshake. This may be enough to crash the client or server, if multiple concurrent connections lead to similarly large memory allocations. The fix postpones processing of the CRL distribution points extensions in certificates to the time when the processed value is required for CRL processing. This avoids keeping large memory allocations for a long time when such certificates are received. FIPS impact: no The affected code is outside the FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-35189 | libcrypto3 | 3.5.8-r0 | Issue summary: A certificate with many nameRelativeToCRLIssuer CRL distribution points causes disproportionate heap growth when OpenSSL caches X.509 extensions. Impact summary: Receiving a crafted certificate from a malicious peer can lead to significant memory pressure and possible Denial of Service in clients or in servers that solicit client certificates. CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: A certificate or a set of certificates that fits under the limit for size of certificates accepted from the peer (~100 KiB) can result in allocation of several hundred MiB of resident memory on the receiving side during a normal TLS handshake. This may be enough to crash the client or server, if multiple concurrent connections lead to similarly large memory allocations. The fix postpones processing of the CRL distribution points extensions in certificates to the time when the processed value is required for CRL processing. This avoids keeping large memory allocations for a long time when such certificates are received. FIPS impact: no The affected code is outside the FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-60876 | ssl_client | 1.37.0-r30 | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-60876 | busybox-binsh | 1.37.0-r30 | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-60876 | busybox | 1.37.0-r30 | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-42772 | libssl3 | 3.5.8-r0 | Issue summary: The QUIC stream reassembly algorithm performance deteriorates progressively as packets are arriving out of order. The worst case has a quadratic complexity proportional to the number of stream frames kept in the buffer for the received stream data. Impact summary: A remote QUIC peer that completes the handshake can create a connection-scoped CPU pressure and potentially a Denial of Service using compliant STREAM frames inside the advertised receive window, with low attacker bandwidth. CWE: CWE-407: Inefficient Algorithmic Complexity Description: OpenSSL manages received QUIC stream fragments using a doubly-linked list. While it optimizes for append operations (at the end of the list), it falls back to a head-to-tail linear search for any fragment that does not immediately follow the current `tail`. By manipulating the sequence of offsets, an attacker can force the server to perform O(n^2) operations, consuming excessive CPU time for the QUIC process. FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-42772 | libcrypto3 | 3.5.8-r0 | Issue summary: The QUIC stream reassembly algorithm performance deteriorates progressively as packets are arriving out of order. The worst case has a quadratic complexity proportional to the number of stream frames kept in the buffer for the received stream data. Impact summary: A remote QUIC peer that completes the handshake can create a connection-scoped CPU pressure and potentially a Denial of Service using compliant STREAM frames inside the advertised receive window, with low attacker bandwidth. CWE: CWE-407: Inefficient Algorithmic Complexity Description: OpenSSL manages received QUIC stream fragments using a doubly-linked list. While it optimizes for append operations (at the end of the list), it falls back to a head-to-tail linear search for any fragment that does not immediately follow the current `tail`. By manipulating the sequence of offsets, an attacker can force the server to perform O(n^2) operations, consuming excessive CPU time for the QUIC process. FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-75804 | libssl3 | 3.5.8-r0 | Issue summary: OpenSSL QUIC stack does not enforce connection level flow control for streams. Remote peers may send more bytes as long as they fit within the stream flow control limits. Impact summary: A malicious remote peer may exploit the lack of connection flow control for streams to make the QUIC stack receive ~100MB of memory instead of 768 KiB (default flow control window size). CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: The local QUIC stack advertises two flow control limits to its remote peer: stream flow control limit and connection flow control limit. The remote peer must follow both limits when transmitting stream data. Whenever the local QUIC stack receives a stream frame, it validates that the size of the received stream frame stays within flow control limits. If either limit is exceeded (stream level or connection level), then the QUIC stack must close the connection with a flow control error. The vulnerable OpenSSL QUIC stack enforces the stream-level but not the connection-level limit. To exploit the issue, three conditions must be met: - the remote peer opens several streams - each stream must stay within the stream-level flow control limit - there must be no zero-offset byte sent on any of the streams (to prevent the vulnerable QUIC stack from consuming data). By meeting the conditions above, the remote peer may make the local stack allocate 2 x MAX_STREAMS x (stream flow control limit) bytes of memory. MAX_STREAMS defaults to 100, and the limit applies to both bidirectional and unidirectional streams, making it 200 in total. The default flow control window for a stream is 512kB. The remote peer may force the vulnerable QUIC stack to allocate 100MB of heap per connection. FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-75804 | libcrypto3 | 3.5.8-r0 | Issue summary: OpenSSL QUIC stack does not enforce connection level flow control for streams. Remote peers may send more bytes as long as they fit within the stream flow control limits. Impact summary: A malicious remote peer may exploit the lack of connection flow control for streams to make the QUIC stack receive ~100MB of memory instead of 768 KiB (default flow control window size). CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: The local QUIC stack advertises two flow control limits to its remote peer: stream flow control limit and connection flow control limit. The remote peer must follow both limits when transmitting stream data. Whenever the local QUIC stack receives a stream frame, it validates that the size of the received stream frame stays within flow control limits. If either limit is exceeded (stream level or connection level), then the QUIC stack must close the connection with a flow control error. The vulnerable OpenSSL QUIC stack enforces the stream-level but not the connection-level limit. To exploit the issue, three conditions must be met: - the remote peer opens several streams - each stream must stay within the stream-level flow control limit - there must be no zero-offset byte sent on any of the streams (to prevent the vulnerable QUIC stack from consuming data). By meeting the conditions above, the remote peer may make the local stack allocate 2 x MAX_STREAMS x (stream flow control limit) bytes of memory. MAX_STREAMS defaults to 100, and the limit applies to both bidirectional and unidirectional streams, making it 200 in total. The default flow control window for a stream is 512kB. The remote peer may force the vulnerable QUIC stack to allocate 100MB of heap per connection. FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-75806 | libssl3 | 3.5.8-r0 | Issue summary: An established DTLS 1.2 association using an AEAD cipher suite can be terminated by a single unauthenticated datagram whose encrypted fragment is shorter than the mandatory explicit IV and authentication tag overhead. Impact summary: An attacker who can send a datagram that is routed to an existing DTLS 1.2 association can tear that association down without knowing any key material. This is a Denial of Service limited to the targeted association. There is no memory safety or confidentiality impact. CWE: CWE-1284: Improper Validation of Specified Quantity in Input Description: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher suite carries an explicit IV followed by the ciphertext and an authentication tag. When decrypting such a record the record layer passed the record length to the cipher implementation before checking that the record was long enough to contain the explicit IV and the tag. For a record shorter than that overhead the cipher implementation rejected the impossible length, and the record layer treated this as an internal failure and raised a fatal internal_error alert instead of treating the record as one that failed authentication. In TLS 1.2 the same record causes a fatal internal_error alert instead of the expected bad_record_mac alert. Since any undecryptable record already terminates a TLS connection, this is a protocol conformance issue rather than a security issue in TLS. The fix validates the record length against the explicit IV and tag length before any AEAD processing, so that TLS reports bad_record_mac and DTLS silently discards the record. FIPS impact: no The affected code is outside the FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-75806 | libcrypto3 | 3.5.8-r0 | Issue summary: An established DTLS 1.2 association using an AEAD cipher suite can be terminated by a single unauthenticated datagram whose encrypted fragment is shorter than the mandatory explicit IV and authentication tag overhead. Impact summary: An attacker who can send a datagram that is routed to an existing DTLS 1.2 association can tear that association down without knowing any key material. This is a Denial of Service limited to the targeted association. There is no memory safety or confidentiality impact. CWE: CWE-1284: Improper Validation of Specified Quantity in Input Description: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher suite carries an explicit IV followed by the ciphertext and an authentication tag. When decrypting such a record the record layer passed the record length to the cipher implementation before checking that the record was long enough to contain the explicit IV and the tag. For a record shorter than that overhead the cipher implementation rejected the impossible length, and the record layer treated this as an internal failure and raised a fatal internal_error alert instead of treating the record as one that failed authentication. In TLS 1.2 the same record causes a fatal internal_error alert instead of the expected bad_record_mac alert. Since any undecryptable record already terminates a TLS connection, this is a protocol conformance issue rather than a security issue in TLS. The fix validates the record length against the explicit IV and tag length before any AEAD processing, so that TLS reports bad_record_mac and DTLS silently discards the record. FIPS impact: no The affected code is outside the FIPS module boundary. — /lib/apk/db/installed | |
| LOW | CVE-2026-35191 | libcrypto3 | 3.5.8-r0 | Issue summary: The OpenSSL QUIC server, when configured to not preform address validation, can be forced to count incoming packets multiple times in its unvalidated credit computation, leading to a violation of the RFC 9000 unvalidated connection amplification limit of 3 times the amount of data received. Impact summary: A remote attacker able to spoof packets to a server using the OpenSSL QUIC implementation might use the server for an amplification of a DDoS attack. CWE: CWE-440: Expected Behavior Violation Description: OpenSSL's QUIC stack, when operating as a server, enforces client address validation (RFC 9000, Section 8), to confirm the peer address is not used for a traffic amplification attack. If this feature is disabled on the server, the QUIC stack limits the amount of server data that can be sent to 3 times the amount of data received from the peer address, until such time as the TLS handshake is completed. The OpenSSL QUIC server, when operating in non-validation mode, adds the length of the whole datagram received to the unvalidated credit limit when processing each QUIC packet in the datagram. A remote peer may, after establishing a connection with an initial client hello frame, send a subsequent datagram containing multiple QUIC packets, leading the server to account the entire datagram length for each packet in the datagram, resulting in the server believing that the peer has sent more data than it actually has, thereby violating the 3x amplification limit mandated by the RFC. FIPS impact: no As the QUIC stack lives outside the FIPS module boundary, no FIPS modules are affected by this CVE. — /lib/apk/db/installed | |
| LOW | CVE-2026-35191 | libssl3 | 3.5.8-r0 | Issue summary: The OpenSSL QUIC server, when configured to not preform address validation, can be forced to count incoming packets multiple times in its unvalidated credit computation, leading to a violation of the RFC 9000 unvalidated connection amplification limit of 3 times the amount of data received. Impact summary: A remote attacker able to spoof packets to a server using the OpenSSL QUIC implementation might use the server for an amplification of a DDoS attack. CWE: CWE-440: Expected Behavior Violation Description: OpenSSL's QUIC stack, when operating as a server, enforces client address validation (RFC 9000, Section 8), to confirm the peer address is not used for a traffic amplification attack. If this feature is disabled on the server, the QUIC stack limits the amount of server data that can be sent to 3 times the amount of data received from the peer address, until such time as the TLS handshake is completed. The OpenSSL QUIC server, when operating in non-validation mode, adds the length of the whole datagram received to the unvalidated credit limit when processing each QUIC packet in the datagram. A remote peer may, after establishing a connection with an initial client hello frame, send a subsequent datagram containing multiple QUIC packets, leading the server to account the entire datagram length for each packet in the datagram, resulting in the server believing that the peer has sent more data than it actually has, thereby violating the 3x amplification limit mandated by the RFC. FIPS impact: no As the QUIC stack lives outside the FIPS module boundary, no FIPS modules are affected by this CVE. — /lib/apk/db/installed | |
| LOW | CVE-2026-54875 | libcrypto3 | 3.5.8-r0 | Issue summary: A non-constant-time optimized implementation of scalar point multiplication is used for SM2 private key operations on ARM64 and RISC-V platforms. Impact summary: An attacker able to measure the time taken by, or to observe the cache-line access pattern of SM2 signing or decryption on an affected platform can learn information about the secret scalar. CWE: CWE-208: Observable Timing Discrepancy Description: On ARM64 and RISC-V processors, the SM2 curve uses an optimized scalar multiplication implementation whose conditional branches and table look ups are chosen according to the bits of the secret scalar. The execution time and the cache-access pattern therefore depend on the long-term private key (during SM2 decryption) or the per-signature nonce (during SM2 signature generation), forming a timing and cache side-channel. FIPS Impact: no SM2 is not a FIPS algorithm and the optimized SM2 implementation is not part of the FIPS module. OpenSSL 4.0, 3.6, 3.5 and 3.4 are vulnerable to this issue on AArch64 and RISC-V. OpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue. OpenSSL 4.0 users should upgrade to OpenSSL 4.0.3. OpenSSL 3.6 users should upgrade to OpenSSL 3.6.5. OpenSSL 3.5 users should upgrade to OpenSSL 3.5.9. OpenSSL 3.4 users should upgrade to OpenSSL 3.4.8. This issue was reported on 2 May 2026 by Abhinav Agarwal. It was independently reported on 6 June 2026 by Feng Xue. The fix was developed by Igor Ustinov. -- cut (non-publishing metadata for internal use) -- Reported by: Abhinav Agarwal, Feng Xue Fixed by: Igor Ustinov — /lib/apk/db/installed | |
| LOW | CVE-2026-54875 | libssl3 | 3.5.8-r0 | Issue summary: A non-constant-time optimized implementation of scalar point multiplication is used for SM2 private key operations on ARM64 and RISC-V platforms. Impact summary: An attacker able to measure the time taken by, or to observe the cache-line access pattern of SM2 signing or decryption on an affected platform can learn information about the secret scalar. CWE: CWE-208: Observable Timing Discrepancy Description: On ARM64 and RISC-V processors, the SM2 curve uses an optimized scalar multiplication implementation whose conditional branches and table look ups are chosen according to the bits of the secret scalar. The execution time and the cache-access pattern therefore depend on the long-term private key (during SM2 decryption) or the per-signature nonce (during SM2 signature generation), forming a timing and cache side-channel. FIPS Impact: no SM2 is not a FIPS algorithm and the optimized SM2 implementation is not part of the FIPS module. OpenSSL 4.0, 3.6, 3.5 and 3.4 are vulnerable to this issue on AArch64 and RISC-V. OpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue. OpenSSL 4.0 users should upgrade to OpenSSL 4.0.3. OpenSSL 3.6 users should upgrade to OpenSSL 3.6.5. OpenSSL 3.5 users should upgrade to OpenSSL 3.5.9. OpenSSL 3.4 users should upgrade to OpenSSL 3.4.8. This issue was reported on 2 May 2026 by Abhinav Agarwal. It was independently reported on 6 June 2026 by Feng Xue. The fix was developed by Igor Ustinov. -- cut (non-publishing metadata for internal use) -- Reported by: Abhinav Agarwal, Feng Xue Fixed by: Igor Ustinov — /lib/apk/db/installed | |
| LOW | CVE-2026-54872 | libcrypto3 | 3.5.8-r0 | Issue summary: The generic elliptic-curve scalar multiplication used for ECDSA and SM2 signature operations with curves that do not have a dedicated implementation leaks information about the secret nonce through timing. Impact summary: An attacker able to measure signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key. CWE: CWE-208: Observable Timing Discrepancy Description: The generic elliptic-curve scalar multiplication used for curves that do not have a dedicated constant-time implementation pads the secret scalar with non-constant-time BIGNUM operations, so the time taken depends on the value of the secret scalar derived from the ECDSA and SM2 nonce. The leak is very small; observing it requires a large number of measurements. The effect is largest for curves whose group order lies on a machine-word boundary, such as brainpoolP384r1. Applications using ECDSA signing over the Brainpool and other generic prime curves, and SM2 signing on platforms that use the generic implementation, are vulnerable to this issue. The NIST curves P-256, P-384 and P-521 use dedicated constant-time implementations and are not affected. FIPS Impact: no The FIPS modules are not affected: the approved NIST curves used in the FIPS provider have dedicated constant-time implementations and do not use the affected code path. — /lib/apk/db/installed | |
| LOW | CVE-2026-54872 | libssl3 | 3.5.8-r0 | Issue summary: The generic elliptic-curve scalar multiplication used for ECDSA and SM2 signature operations with curves that do not have a dedicated implementation leaks information about the secret nonce through timing. Impact summary: An attacker able to measure signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key. CWE: CWE-208: Observable Timing Discrepancy Description: The generic elliptic-curve scalar multiplication used for curves that do not have a dedicated constant-time implementation pads the secret scalar with non-constant-time BIGNUM operations, so the time taken depends on the value of the secret scalar derived from the ECDSA and SM2 nonce. The leak is very small; observing it requires a large number of measurements. The effect is largest for curves whose group order lies on a machine-word boundary, such as brainpoolP384r1. Applications using ECDSA signing over the Brainpool and other generic prime curves, and SM2 signing on platforms that use the generic implementation, are vulnerable to this issue. The NIST curves P-256, P-384 and P-521 use dedicated constant-time implementations and are not affected. FIPS Impact: no The FIPS modules are not affected: the approved NIST curves used in the FIPS provider have dedicated constant-time implementations and do not use the affected code path. — /lib/apk/db/installed | |
| LOW | CVE-2026-77696 | libcrypto3 | 3.5.8-r0 | Issue summary: SM2 signature generation uses non-constant-time arithmetic on secret values, forming a timing side-channel. Impact summary: An attacker able to measure SM2 signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key. CWE: CWE-208: Observable Timing Discrepancy Description: SM2 signature generation computes the signature value using variable-time BIGNUM operations on the secret nonce and the private key, so the time taken to produce an SM2 signature depends on these secret values, forming a timing side-channel. Applications performing SM2 signature generation are affected on all platforms. FIPS Impact: no SM2 is not a FIPS algorithm. — /lib/apk/db/installed | |
| LOW | CVE-2026-77696 | libssl3 | 3.5.8-r0 | Issue summary: SM2 signature generation uses non-constant-time arithmetic on secret values, forming a timing side-channel. Impact summary: An attacker able to measure SM2 signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key. CWE: CWE-208: Observable Timing Discrepancy Description: SM2 signature generation computes the signature value using variable-time BIGNUM operations on the secret nonce and the private key, so the time taken to produce an SM2 signature depends on these secret values, forming a timing side-channel. Applications performing SM2 signature generation are affected on all platforms. FIPS Impact: no SM2 is not a FIPS algorithm. — /lib/apk/db/installed |
ghcr.io/openvoxproject/openvoxagent
Downloads
ghcr.io/openvoxproject/openvoxagent:latest (2026-08-27)
Trivy
HIGH 11
MEDIUM 114
LOW 48
UNKNOWN 13
| Severity | ID | Package | Installed | Fixed | Title / target |
|---|---|---|---|---|---|
| HIGH | CVE-2026-56862 | stdlib | v1.26.5 | 1.25.13, 1.26.6, 1.27.0-rc.3 | crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages — usr/bin/pebble |
| HIGH | CVE-2026-56860 | stdlib | v1.26.5 | 1.25.13, 1.26.6, 1.27.0-rc.3 | net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution — usr/bin/pebble |
| HIGH | CVE-2026-56859 | stdlib | v1.26.5 | 1.25.13, 1.26.6, 1.27.0-rc.3 | encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue — usr/bin/pebble |
| HIGH | CVE-2026-56858 | stdlib | v1.26.5 | 1.25.13, 1.26.6, 1.27.0-rc.3 | html/template: golang: Go html/template: Cross-Site Scripting via pathological input — usr/bin/pebble |
| HIGH | CVE-2026-56853 | stdlib | v1.26.5 | 1.25.13, 1.26.6, 1.27.0-rc.3 | net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service — usr/bin/pebble |
| HIGH | CVE-2026-46600 | stdlib | v1.26.5 | 1.26.6, 1.27.0-rc.3 | golang.org/x/net/dns/dnsmessage: golang.org/x/net/dns/dnsmessage: Denial of Service via invalid DNS record parsing — usr/bin/pebble |
| HIGH | CVE-2026-39821 | stdlib | v1.26.5 | 1.25.13, 1.26.6, 1.27.0-rc.3 | golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing — usr/bin/pebble |
| HIGH | CVE-2026-33818 | stdlib | v1.26.5 | 1.25.13, 1.26.6, 1.27.0-rc.3 | encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal — usr/bin/pebble |
| HIGH | CVE-2026-84782 | openssl | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | openssl: compat-openssl: openssl: Information disclosure via DTLS handshake retransmission — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| HIGH | CVE-2026-84782 | openssl-provider-legacy | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | openssl: compat-openssl: openssl: Information disclosure via DTLS handshake retransmission — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| HIGH | CVE-2026-84782 | libssl3t64 | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | openssl: compat-openssl: openssl: Information disclosure via DTLS handshake retransmission — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-53615 | mount | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | [Integer Overflow or Wraparound in libblkid/src/partitions/dos.c] — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-53614 | mount | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: SUID mount(8) allows nosuid/noexec bypass via LIBMOUNT_FORCE_MOUNT2 — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-53613 | mount | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-53612 | mount | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: TOCTOU in the mount program when applying post-mount ownership/mode changes — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-3184 | mount | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: Access control bypass due to improper hostname canonicalization — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-27456 | mount | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: TOCTOU in the mount program when setting up loop devices — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-13595 | mount | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: heap use-after-free in libblkid nested partition probing — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-12087 | perl-base | 5.40.1-7ubuntu0.1 | 5.40.1-7ubuntu0.3 | perl-Socket: perl-Socket: Information Disclosure due to Out-of-Bounds Read — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-13221 | perl-base | 5.40.1-7ubuntu0.1 | 5.40.1-7ubuntu0.3 | perl: Perl: Incorrect regular expression processing via large regular expressions — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-15534 | perl-base | 5.40.1-7ubuntu0.1 | 5.40.1-7ubuntu0.2 | perl: Perl: Arbitrary code execution via out-of-bounds memory access in regular expression engine. — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-19487 | perl-base | 5.40.1-7ubuntu0.1 | 5.40.1-7ubuntu0.2 | perl: Perl: Incorrect regular expression matching can lead to wrong access or filtering decisions. — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-57432 | perl-base | 5.40.1-7ubuntu0.1 | 5.40.1-7ubuntu0.3 | perl: Perl: Information disclosure via integer overflow in pack/unpack operations — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-57433 | perl-base | 5.40.1-7ubuntu0.1 | 5.40.1-7ubuntu0.3 | Storable: Storable: Denial of Service via signed integer overflow in deserialization — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-53615 | login | 1:4.16.0-2+really2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | [Integer Overflow or Wraparound in libblkid/src/partitions/dos.c] — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-53614 | login | 1:4.16.0-2+really2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: SUID mount(8) allows nosuid/noexec bypass via LIBMOUNT_FORCE_MOUNT2 — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-53613 | login | 1:4.16.0-2+really2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-53612 | login | 1:4.16.0-2+really2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: TOCTOU in the mount program when applying post-mount ownership/mode changes — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-3184 | login | 1:4.16.0-2+really2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: Access control bypass due to improper hostname canonicalization — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-27456 | login | 1:4.16.0-2+really2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: TOCTOU in the mount program when setting up loop devices — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-13595 | login | 1:4.16.0-2+really2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: heap use-after-free in libblkid nested partition probing — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-53615 | libuuid1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | [Integer Overflow or Wraparound in libblkid/src/partitions/dos.c] — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-53614 | libuuid1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: SUID mount(8) allows nosuid/noexec bypass via LIBMOUNT_FORCE_MOUNT2 — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-53613 | libuuid1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-53612 | libuuid1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: TOCTOU in the mount program when applying post-mount ownership/mode changes — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-3184 | libuuid1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: Access control bypass due to improper hostname canonicalization — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-27456 | libuuid1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: TOCTOU in the mount program when setting up loop devices — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-13595 | libuuid1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: heap use-after-free in libblkid nested partition probing — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-85091 | zlib1g | 1:1.3.dfsg+really1.3.1-1ubuntu3 | zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vul ... — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53615 | util-linux | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | [Integer Overflow or Wraparound in libblkid/src/partitions/dos.c] — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-53614 | util-linux | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: SUID mount(8) allows nosuid/noexec bypass via LIBMOUNT_FORCE_MOUNT2 — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-53613 | util-linux | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-53612 | util-linux | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: TOCTOU in the mount program when applying post-mount ownership/mode changes — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-3184 | util-linux | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: Access control bypass due to improper hostname canonicalization — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-27456 | util-linux | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: TOCTOU in the mount program when setting up loop devices — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-13595 | util-linux | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: heap use-after-free in libblkid nested partition probing — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-18508 | tar | 1.35+dfsg-4ubuntu0.4 | tar: tar: --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-18477 | tar | 1.35+dfsg-4ubuntu0.4 | tar: tar: TOCTOU in incremental dumpdir 'X' rename handling allows restore path escape — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35377 | rust-coreutils | 0.8.0-0ubuntu3 | A logic error in the env utility of uutils coreutils causes a failure ... — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35374 | rust-coreutils | 0.8.0-0ubuntu3 | A Time-of-Check to Time-of-Use (TOCTOU) vulnerability exists in the sp ... — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35373 | rust-coreutils | 0.8.0-0ubuntu3 | A logic error in the ln utility of uutils coreutils causes the program ... — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35371 | rust-coreutils | 0.8.0-0ubuntu3 | The id utility in uutils coreutils exhibits incorrect behavior in its ... — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35370 | rust-coreutils | 0.8.0-0ubuntu3 | The id utility in uutils coreutils miscalculates the groups= section o ... — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35368 | rust-coreutils | 0.8.0-0ubuntu3 | A vulnerability exists in the chroot utility of uutils coreutils when ... — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35367 | rust-coreutils | 0.8.0-0ubuntu3 | The nohup utility in uutils coreutils creates its default output file, ... — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35364 | rust-coreutils | 0.8.0-0ubuntu3 | A Time-of-Check to Time-of-Use (TOCTOU) race condition exists in the m ... — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35363 | rust-coreutils | 0.8.0-0ubuntu3 | A vulnerability in the rm utility of uutils coreutils allows the bypas ... — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35360 | rust-coreutils | 0.8.0-0ubuntu3 | The touch utility in uutils coreutils is vulnerable to a Time-of-Check ... — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35359 | rust-coreutils | 0.8.0-0ubuntu3 | A Time-of-Check to Time-of-Use (TOCTOU) vulnerability in the cp utilit ... — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35357 | rust-coreutils | 0.8.0-0ubuntu3 | The cp utility in uutils coreutils is vulnerable to an information dis ... — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35354 | rust-coreutils | 0.8.0-0ubuntu3 | A Time-of-Check to Time-of-Use (TOCTOU) vulnerability exists in the mv ... — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35352 | rust-coreutils | 0.8.0-0ubuntu3 | A Time-of-Check to Time-of-Use (TOCTOU) race condition exists in the m ... — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35351 | rust-coreutils | 0.8.0-0ubuntu3 | The mv utility in uutils coreutils fails to preserve file ownership du ... — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35350 | rust-coreutils | 0.8.0-0ubuntu3 | The cp utility in uutils coreutils fails to properly handle setuid and ... — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35348 | rust-coreutils | 0.8.0-0ubuntu3 | The sort utility in uutils coreutils is vulnerable to a process panic ... — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35345 | rust-coreutils | 0.8.0-0ubuntu3 | A vulnerability in the tail utility of uutils coreutils allows for the ... — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35344 | rust-coreutils | 0.8.0-0ubuntu3 | The dd utility in uutils coreutils suppresses errors during file trunc ... — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35341 | rust-coreutils | 0.8.0-0ubuntu3 | A vulnerability in uutils coreutils mkfifo allows for the unauthorized ... — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-27456 | libmount1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: TOCTOU in the mount program when setting up loop devices — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-13595 | libmount1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: heap use-after-free in libblkid nested partition probing — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-53612 | libblkid1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: TOCTOU in the mount program when applying post-mount ownership/mode changes — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-53613 | libblkid1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-53614 | libblkid1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: SUID mount(8) allows nosuid/noexec bypass via LIBMOUNT_FORCE_MOUNT2 — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-53615 | libblkid1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | [Integer Overflow or Wraparound in libblkid/src/partitions/dos.c] — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-18374 | libc-bin | 2.43-2ubuntu2.3 | glibc: glibc: Heap buffer overflow via attacker-controlled fopen mode string — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-19499 | libc-bin | 2.43-2ubuntu2.3 | 2.43-2ubuntu2.4 | glibc: Buffer Overflow in strfmon right-justification padding — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-19542 | libc-bin | 2.43-2ubuntu2.3 | 2.43-2ubuntu2.4 | glibc: Fix out-of-bounds array write in tdelete — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-6368 | libc-bin | 2.43-2ubuntu2.3 | 2.43-2ubuntu2.4 | glibc: glibc: Process abort due to invalid memory in wordexp — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-6791 | libc-bin | 2.43-2ubuntu2.3 | 2.43-2ubuntu2.4 | glibc: Glibc: Denial of Service via stack exhaustion during tilde expansion — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-77117 | libc-bin | 2.43-2ubuntu2.3 | 2.43-2ubuntu2.4 | glibc: Non-progress DoS in SHIFT_JISX0213 -> — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80489 | libc-bin | 2.43-2ubuntu2.3 | 2.43-2ubuntu2.4 | glibc: Non-progress DoS in EUC_JISX0213 -> UCS-4 conversion state — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-89092 | libc-bin | 2.43-2ubuntu2.3 | glibc: nscd stack overflow leads to degraded DNS resolution — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-18374 | libc-gconv-modules-extra | 2.43-2ubuntu2.3 | glibc: glibc: Heap buffer overflow via attacker-controlled fopen mode string — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-19499 | libc-gconv-modules-extra | 2.43-2ubuntu2.3 | 2.43-2ubuntu2.4 | glibc: Buffer Overflow in strfmon right-justification padding — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-19542 | libc-gconv-modules-extra | 2.43-2ubuntu2.3 | 2.43-2ubuntu2.4 | glibc: Fix out-of-bounds array write in tdelete — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-6368 | libc-gconv-modules-extra | 2.43-2ubuntu2.3 | 2.43-2ubuntu2.4 | glibc: glibc: Process abort due to invalid memory in wordexp — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-6791 | libc-gconv-modules-extra | 2.43-2ubuntu2.3 | 2.43-2ubuntu2.4 | glibc: Glibc: Denial of Service via stack exhaustion during tilde expansion — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-77117 | libc-gconv-modules-extra | 2.43-2ubuntu2.3 | 2.43-2ubuntu2.4 | glibc: Non-progress DoS in SHIFT_JISX0213 -> — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80489 | libc-gconv-modules-extra | 2.43-2ubuntu2.3 | 2.43-2ubuntu2.4 | glibc: Non-progress DoS in EUC_JISX0213 -> UCS-4 conversion state — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-89092 | libc-gconv-modules-extra | 2.43-2ubuntu2.3 | glibc: nscd stack overflow leads to degraded DNS resolution — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-18374 | libc6 | 2.43-2ubuntu2.3 | glibc: glibc: Heap buffer overflow via attacker-controlled fopen mode string — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-19499 | libc6 | 2.43-2ubuntu2.3 | 2.43-2ubuntu2.4 | glibc: Buffer Overflow in strfmon right-justification padding — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-19542 | libc6 | 2.43-2ubuntu2.3 | 2.43-2ubuntu2.4 | glibc: Fix out-of-bounds array write in tdelete — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-6368 | libc6 | 2.43-2ubuntu2.3 | 2.43-2ubuntu2.4 | glibc: glibc: Process abort due to invalid memory in wordexp — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-6791 | libc6 | 2.43-2ubuntu2.3 | 2.43-2ubuntu2.4 | glibc: Glibc: Denial of Service via stack exhaustion during tilde expansion — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-77117 | libc6 | 2.43-2ubuntu2.3 | 2.43-2ubuntu2.4 | glibc: Non-progress DoS in SHIFT_JISX0213 -> — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80489 | libc6 | 2.43-2ubuntu2.3 | 2.43-2ubuntu2.4 | glibc: Non-progress DoS in EUC_JISX0213 -> UCS-4 conversion state — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-89092 | libc6 | 2.43-2ubuntu2.3 | glibc: nscd stack overflow leads to degraded DNS resolution — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-13595 | bsdutils | 1:2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: heap use-after-free in libblkid nested partition probing — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-27456 | bsdutils | 1:2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: TOCTOU in the mount program when setting up loop devices — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-3184 | bsdutils | 1:2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: Access control bypass due to improper hostname canonicalization — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-53612 | bsdutils | 1:2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: TOCTOU in the mount program when applying post-mount ownership/mode changes — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-53613 | bsdutils | 1:2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-53614 | bsdutils | 1:2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: SUID mount(8) allows nosuid/noexec bypass via LIBMOUNT_FORCE_MOUNT2 — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-53615 | bsdutils | 1:2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | [Integer Overflow or Wraparound in libblkid/src/partitions/dos.c] — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-53910 | diffutils | 1:3.12-1 | 1:3.12-1ubuntu0.1 | diffutils: heap‑based buffer overflow due to multiple signed integer overflows in line‑mapping calculations — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-56391 | gnu-coreutils | 9.7-3ubuntu2 | 9.7-3ubuntu2.1 | coreutils: GNU coreutils uniq: Denial of Service and information disclosure via out-of-bounds read with multibyte input — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-54371 | libattr1 | 1:2.5.2-4 | 1:2.5.2-4ubuntu0.1 | attr: attr: Symlink Traversal Privilege Escalation via getfattr and setfattr — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-13595 | libblkid1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: heap use-after-free in libblkid nested partition probing — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-27456 | libblkid1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: TOCTOU in the mount program when setting up loop devices — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-53615 | libsmartcols1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | [Integer Overflow or Wraparound in libblkid/src/partitions/dos.c] — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-53614 | libsmartcols1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: SUID mount(8) allows nosuid/noexec bypass via LIBMOUNT_FORCE_MOUNT2 — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-3184 | libmount1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: Access control bypass due to improper hostname canonicalization — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-53612 | libmount1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: TOCTOU in the mount program when applying post-mount ownership/mode changes — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-53613 | libmount1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-53614 | libmount1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: SUID mount(8) allows nosuid/noexec bypass via LIBMOUNT_FORCE_MOUNT2 — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-53615 | libmount1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | [Integer Overflow or Wraparound in libblkid/src/partitions/dos.c] — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-86145 | libpcre2-8-0 | 10.46-1build1 | pcre2: PCRE2: Out-of-bounds write allows arbitrary code execution via crafted regular expressions — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-3184 | libblkid1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: Access control bypass due to improper hostname canonicalization — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-89161 | libpcre2-8-0 | 10.46-1build1 | pcre2: PCRE2: Memory corruption vulnerability in pcre2_jit_match — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-13595 | libsmartcols1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: heap use-after-free in libblkid nested partition probing — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-27456 | libsmartcols1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: TOCTOU in the mount program when setting up loop devices — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-3184 | libsmartcols1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: Access control bypass due to improper hostname canonicalization — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-53612 | libsmartcols1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: TOCTOU in the mount program when applying post-mount ownership/mode changes — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-53613 | libsmartcols1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| LOW | CVE-2026-27171 | zlib1g | 1:1.3.dfsg+really1.3.1-1ubuntu3 | 1:1.3.dfsg+really1.3.1-1ubuntu3.1 | zlib: zlib: Denial of Service via infinite loop in CRC32 combine functions — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| LOW | CVE-2025-5278 | gnu-coreutils | 9.7-3ubuntu2 | 9.7-3ubuntu2.1 | coreutils: Heap Buffer Under-Read in GNU Coreutils sort via Key Specification — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| LOW | CVE-2026-42250 | libbz2-1.0 | 1.0.8-6build2 | 1.0.8-6ubuntu0.1 | bzip2: bzip2: Denial of Service in bzip2recover via a specially crafted file — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| LOW | CVE-2026-57062 | gpgv | 2.4.8-4ubuntu3 | 2.4.8-4ubuntu3.1 | GnuPG: Incorrect cryptographic message parsing — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| LOW | CVE-2026-54875 | openssl | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | openssl: openssl: information disclosure via non-constant-time SM2 scalar multiplication on ARM64 and RISC-V — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| LOW | CVE-2026-54873 | openssl | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.7 | openssl: openssl: Denial of Service via excessive QUIC packet buffer retention — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| LOW | CVE-2026-54872 | openssl | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | openssl: OpenSSL: Private key recovery via timing side-channel in generic elliptic curve operations — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| LOW | CVE-2026-42772 | openssl | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.7 | openssl: openssl: Denial of Service via inefficient QUIC stream reassembly — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| LOW | CVE-2026-35191 | openssl | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | openssl: openssl: Traffic amplification Denial of Service via QUIC packet over-accounting — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| LOW | CVE-2026-35189 | openssl | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | openssl: openssl: Denial of Service via excessive memory allocation in CRL distribution point processing — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| LOW | CVE-2024-56433 | login.defs | 1:4.17.4-2ubuntu3 | shadow-utils: Default subordinate ID configuration in /etc/login.defs could lead to compromise — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| LOW | CVE-2026-35189 | libssl3t64 | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | openssl: openssl: Denial of Service via excessive memory allocation in CRL distribution point processing — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| LOW | CVE-2026-35191 | libssl3t64 | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | openssl: openssl: Traffic amplification Denial of Service via QUIC packet over-accounting — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| LOW | CVE-2026-42772 | libssl3t64 | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.7 | openssl: openssl: Denial of Service via inefficient QUIC stream reassembly — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| LOW | CVE-2026-54872 | libssl3t64 | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | openssl: OpenSSL: Private key recovery via timing side-channel in generic elliptic curve operations — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| LOW | CVE-2026-54873 | libssl3t64 | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.7 | openssl: openssl: Denial of Service via excessive QUIC packet buffer retention — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| LOW | CVE-2026-54875 | libssl3t64 | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | openssl: openssl: information disclosure via non-constant-time SM2 scalar multiplication on ARM64 and RISC-V — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| LOW | CVE-2026-40228 | libudev1 | 259.5-0ubuntu3.4 | systemd: systemd-journald: Unintended output to user terminals via logger command — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| LOW | CVE-2026-40228 | libsystemd0 | 259.5-0ubuntu3.4 | systemd: systemd-journald: Unintended output to user terminals via logger command — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| LOW | CVE-2026-84784 | libssl3t64 | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | openssl: OpenSSL: Denial of Service via unbounded QUIC connection identifier backlog — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| LOW | CVE-2026-77696 | libssl3t64 | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | openssl: OpenSSL: Private key recovery via SM2 timing side-channel — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| LOW | CVE-2026-75806 | libssl3t64 | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | openssl: OpenSSL: Denial of Service via undersized DTLS record — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| LOW | CVE-2026-75805 | libssl3t64 | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | openssl: openssl: Denial of Service via crafted CMP certificate revocation response — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| LOW | CVE-2026-75804 | libssl3t64 | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | openssl: OpenSSL: Denial of Service via unenforced QUIC connection flow control — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| LOW | CVE-2026-75803 | libssl3t64 | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.5 | openssl: openssl: AEAD forgeries possible with empty ciphertext in EVP_Cipher() — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| LOW | CVE-2026-72897 | libssl3t64 | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | openssl: openssl: Denial of Service via out-of-bounds write during TLS context switch — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| LOW | CVE-2024-56433 | passwd | 1:4.17.4-2ubuntu3 | shadow-utils: Default subordinate ID configuration in /etc/login.defs could lead to compromise — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) | |
| LOW | CVE-2026-84784 | openssl-provider-legacy | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | openssl: OpenSSL: Denial of Service via unbounded QUIC connection identifier backlog — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| LOW | CVE-2026-77696 | openssl-provider-legacy | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | openssl: OpenSSL: Private key recovery via SM2 timing side-channel — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| LOW | CVE-2026-75806 | openssl-provider-legacy | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | openssl: OpenSSL: Denial of Service via undersized DTLS record — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| LOW | CVE-2026-75805 | openssl-provider-legacy | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | openssl: openssl: Denial of Service via crafted CMP certificate revocation response — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| LOW | CVE-2026-75804 | openssl-provider-legacy | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | openssl: OpenSSL: Denial of Service via unenforced QUIC connection flow control — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| LOW | CVE-2026-75803 | openssl-provider-legacy | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.5 | openssl: openssl: AEAD forgeries possible with empty ciphertext in EVP_Cipher() — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| LOW | CVE-2026-72897 | openssl-provider-legacy | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | openssl: openssl: Denial of Service via out-of-bounds write during TLS context switch — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| LOW | CVE-2026-54875 | openssl-provider-legacy | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | openssl: openssl: information disclosure via non-constant-time SM2 scalar multiplication on ARM64 and RISC-V — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| LOW | CVE-2026-54873 | openssl-provider-legacy | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.7 | openssl: openssl: Denial of Service via excessive QUIC packet buffer retention — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| LOW | CVE-2026-54872 | openssl-provider-legacy | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | openssl: OpenSSL: Private key recovery via timing side-channel in generic elliptic curve operations — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| LOW | CVE-2026-72897 | openssl | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | openssl: openssl: Denial of Service via out-of-bounds write during TLS context switch — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| LOW | CVE-2026-75803 | openssl | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.5 | openssl: openssl: AEAD forgeries possible with empty ciphertext in EVP_Cipher() — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| LOW | CVE-2026-75804 | openssl | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | openssl: OpenSSL: Denial of Service via unenforced QUIC connection flow control — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| LOW | CVE-2026-75805 | openssl | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | openssl: openssl: Denial of Service via crafted CMP certificate revocation response — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| LOW | CVE-2026-75806 | openssl | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | openssl: OpenSSL: Denial of Service via undersized DTLS record — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| LOW | CVE-2026-77696 | openssl | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | openssl: OpenSSL: Private key recovery via SM2 timing side-channel — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| LOW | CVE-2026-84784 | openssl | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | openssl: OpenSSL: Denial of Service via unbounded QUIC connection identifier backlog — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| LOW | CVE-2024-2236 | libgcrypt20 | 1.12.0-2ubuntu1 | 1.12.0-2ubuntu1.1 | libgcrypt: vulnerable to Marvin Attack — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| LOW | CVE-2026-35189 | openssl-provider-legacy | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | openssl: openssl: Denial of Service via excessive memory allocation in CRL distribution point processing — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| LOW | CVE-2026-35191 | openssl-provider-legacy | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | openssl: openssl: Traffic amplification Denial of Service via QUIC packet over-accounting — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| LOW | CVE-2026-42772 | openssl-provider-legacy | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.7 | openssl: openssl: Denial of Service via inefficient QUIC stream reassembly — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04) |
| UNKNOWN | CVE-2026-97032 | stdlib | v1.26.5 | 1.26.9, 1.27.2 | HTTP/2 server crash due to HPACK encoder race in net/http — usr/bin/pebble |
| UNKNOWN | CVE-2026-97031 | stdlib | v1.26.5 | 1.26.9, 1.27.2 | Reject malformed ECH outer extension references in crypto/tls — usr/bin/pebble |
| UNKNOWN | CVE-2026-97030 | stdlib | v1.26.5 | 1.26.9, 1.27.2 | Recognize yield as regexp preceder keyword in html/template — usr/bin/pebble |
| UNKNOWN | CVE-2026-94448 | stdlib | v1.26.5 | 1.26.9, 1.27.2 | Reset context tracking on consecutive template expressions in html/template — usr/bin/pebble |
| UNKNOWN | CVE-2026-94440 | stdlib | v1.26.5 | 1.26.9, 1.27.2 | Memory limit bypass when parsing MIME headers in net/textproto, mime/multipart — usr/bin/pebble |
| UNKNOWN | CVE-2026-94439 | stdlib | v1.26.5 | 1.26.9, 1.27.2 | HTTP/1 server connection desynchronization after 2xx CONNECT response in net/http — usr/bin/pebble |
| UNKNOWN | CVE-2026-78669 | stdlib | v1.26.5 | 1.26.9, 1.27.2 | Excessive CPU consumption from repeated initial window changes in net/http — usr/bin/pebble |
| UNKNOWN | CVE-2026-78667 | stdlib | v1.26.5 | 1.26.9, 1.27.2 | Lack of limit on size of parsed Range headers in net/http — usr/bin/pebble |
| UNKNOWN | CVE-2026-78663 | stdlib | v1.26.5 | 1.26.9, 1.27.2 | Double flow control refund on HTTP/2 server streams in net/http — usr/bin/pebble |
| UNKNOWN | CVE-2026-78660 | stdlib | v1.26.5 | 1.26.9, 1.27.2 | HTTP/2 transport accepts malformed framing-related headers in net/http — usr/bin/pebble |
| UNKNOWN | CVE-2026-78659 | stdlib | v1.26.5 | 1.26.9, 1.27.2 | HTTP/2 server memory exhaustion due to Trailer headers in net/http — usr/bin/pebble |
| UNKNOWN | CVE-2026-56866 | stdlib | v1.26.5 | 1.26.9, 1.27.2 | HTTP/1 client connection desynchronization after CONNECT rejection in net/http — usr/bin/pebble |
| UNKNOWN | CVE-2026-56857 | stdlib | v1.26.5 | 1.26.9, 1.27.2 | Root.Mkdir(All) can follow junctions out of the root on Windows in os — usr/bin/pebble |
Grype
HIGH 7
MEDIUM 179
LOW 50
| Severity | ID | Package | Installed | Fixed | Title / target |
|---|---|---|---|---|---|
| HIGH | CVE-2026-84782 | openssl-provider-legacy | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| HIGH | CVE-2026-84782 | openssl | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| HIGH | CVE-2026-84782 | libssl3t64 | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| HIGH | GO-2026-5026 | stdlib | go1.26.5 | 1.25.13, 1.26.6, 1.27.0-rc.3 | The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com". — /usr/bin/pebble |
| HIGH | GO-2026-6090 | stdlib | go1.26.5 | 1.25.13, 1.26.6, 1.27.0-rc.3 | Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely. — /usr/bin/pebble |
| HIGH | GO-2026-5972 | stdlib | go1.26.5 | 1.25.13, 1.26.6, 1.27.0-rc.3 | Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures. — /usr/bin/pebble |
| HIGH | GO-2026-6089 | stdlib | go1.26.5 | 1.25.13, 1.26.6, 1.27.0-rc.3 | When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this. — /usr/bin/pebble |
| MEDIUM | CVE-2026-102474 | dash | 0.5.12-12ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-18374 | libc-bin | 2.43-2ubuntu2.3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-18374 | libc-gconv-modules-extra | 2.43-2ubuntu2.3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-18374 | libc6 | 2.43-2ubuntu2.3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35341 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-18508 | tar | 1.35+dfsg-4ubuntu0.4 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35351 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-93658 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35371 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35373 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35348 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-6368 | libc6 | 2.43-2ubuntu2.3 | 2.43-2ubuntu2.4 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-6368 | libc-gconv-modules-extra | 2.43-2ubuntu2.3 | 2.43-2ubuntu2.4 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-35350 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35344 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-102473 | dash | 0.5.12-12ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35367 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-95818 | libc-bin | 2.43-2ubuntu2.3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-95818 | libc-gconv-modules-extra | 2.43-2ubuntu2.3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-95818 | libc6 | 2.43-2ubuntu2.3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2025-15649 | perl-base | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35370 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-89161 | libpcre2-8-0 | 10.46-1build1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35377 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-86805 | libc-bin | 2.43-2ubuntu2.3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53614 | libblkid1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-97399 | libc-gconv-modules-extra | 2.43-2ubuntu2.3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-13595 | libsmartcols1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-13595 | libuuid1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-13595 | login | 1:4.16.0-2+really2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-13595 | mount | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-13595 | util-linux | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-89162 | libpcre2-8-0 | 10.46-1build1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-78410 | bsdutils | 1:2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-78410 | libblkid1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-78410 | libmount1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-78410 | libsmartcols1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-78410 | libuuid1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-78410 | login | 1:4.16.0-2+really2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-78410 | mount | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-78410 | util-linux | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-78409 | bsdutils | 1:2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-78409 | libblkid1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-78409 | libmount1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-78409 | libsmartcols1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-78409 | libuuid1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-78409 | login | 1:4.16.0-2+really2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-78409 | mount | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-78409 | util-linux | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-54369 | libacl1 | 2.3.2-2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35368 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-6368 | libc-bin | 2.43-2ubuntu2.3 | 2.43-2ubuntu2.4 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-53615 | libblkid1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-53612 | libmount1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-53613 | libmount1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-53614 | libmount1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-53615 | libmount1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-53612 | libsmartcols1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-53613 | libsmartcols1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-53614 | libsmartcols1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-53615 | libsmartcols1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-53612 | libuuid1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-53613 | libuuid1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-53614 | libuuid1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-53615 | libuuid1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-53612 | login | 1:4.16.0-2+really2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-53613 | login | 1:4.16.0-2+really2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-53614 | login | 1:4.16.0-2+really2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-53615 | login | 1:4.16.0-2+really2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-53612 | mount | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-53613 | mount | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-53614 | mount | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-53615 | mount | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-53612 | util-linux | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-53613 | util-linux | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-53614 | util-linux | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-53615 | util-linux | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-86805 | libc-gconv-modules-extra | 2.43-2ubuntu2.3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-86805 | libc6 | 2.43-2ubuntu2.3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35352 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-27456 | bsdutils | 1:2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-27456 | libblkid1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-27456 | libmount1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-27456 | libsmartcols1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-27456 | libuuid1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-27456 | login | 1:4.16.0-2+really2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-27456 | mount | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-27456 | util-linux | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-54370 | libacl1 | 2.3.2-2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35359 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35360 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35345 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35364 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35357 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35354 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35374 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-18477 | tar | 1.35+dfsg-4ubuntu0.4 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53612 | bsdutils | 1:2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-53613 | bsdutils | 1:2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-53614 | bsdutils | 1:2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-53615 | bsdutils | 1:2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-53612 | libblkid1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-53613 | libblkid1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-19542 | libc6 | 2.43-2ubuntu2.3 | 2.43-2ubuntu2.4 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-53910 | diffutils | 1:3.12-1 | 1:3.12-1ubuntu0.1 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-8674 | libc6 | 2.43-2ubuntu2.3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-8674 | libc-gconv-modules-extra | 2.43-2ubuntu2.3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-76642 | bsdutils | 1:2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-76642 | libblkid1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-76642 | libmount1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-76642 | libsmartcols1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-8674 | libc-bin | 2.43-2ubuntu2.3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-57433 | perl-base | 5.40.1-7ubuntu0.1 | 5.40.1-7ubuntu0.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-12087 | perl-base | 5.40.1-7ubuntu0.1 | 5.40.1-7ubuntu0.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-76642 | libuuid1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-76642 | login | 1:4.16.0-2+really2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-76642 | mount | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-76642 | util-linux | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-86145 | libpcre2-8-0 | 10.46-1build1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-48961 | perl-base | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-77117 | libc6 | 2.43-2ubuntu2.3 | 2.43-2ubuntu2.4 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-77117 | libc-gconv-modules-extra | 2.43-2ubuntu2.3 | 2.43-2ubuntu2.4 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-97399 | libc-bin | 2.43-2ubuntu2.3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-97399 | libc6 | 2.43-2ubuntu2.3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-89157 | libpcre2-8-0 | 10.46-1build1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-89156 | libpcre2-8-0 | 10.46-1build1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-19499 | libc6 | 2.43-2ubuntu2.3 | 2.43-2ubuntu2.4 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-19499 | libc-gconv-modules-extra | 2.43-2ubuntu2.3 | 2.43-2ubuntu2.4 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-89160 | libpcre2-8-0 | 10.46-1build1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-89092 | libc-bin | 2.43-2ubuntu2.3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-89092 | libc-gconv-modules-extra | 2.43-2ubuntu2.3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-89092 | libc6 | 2.43-2ubuntu2.3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-15534 | perl-base | 5.40.1-7ubuntu0.1 | 5.40.1-7ubuntu0.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-19499 | libc-bin | 2.43-2ubuntu2.3 | 2.43-2ubuntu2.4 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-6791 | libc6 | 2.43-2ubuntu2.3 | 2.43-2ubuntu2.4 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-7017 | perl-base | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-89158 | libpcre2-8-0 | 10.46-1build1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-6791 | libc-gconv-modules-extra | 2.43-2ubuntu2.3 | 2.43-2ubuntu2.4 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-6791 | libc-bin | 2.43-2ubuntu2.3 | 2.43-2ubuntu2.4 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-19542 | libc-bin | 2.43-2ubuntu2.3 | 2.43-2ubuntu2.4 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-19542 | libc-gconv-modules-extra | 2.43-2ubuntu2.3 | 2.43-2ubuntu2.4 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-48962 | perl-base | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-85091 | zlib1g | 1:1.3.dfsg+really1.3.1-1ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | GO-2026-6218 | stdlib | go1.26.5 | 1.25.13, 1.26.6, 1.27.0-rc.3 | Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations. — /usr/bin/pebble |
| MEDIUM | CVE-2026-48959 | perl-base | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-3184 | util-linux | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-3184 | mount | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-3184 | login | 1:4.16.0-2+really2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-3184 | libuuid1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-3184 | libsmartcols1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-3184 | libmount1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-3184 | libblkid1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-3184 | bsdutils | 1:2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-82560 | perl-base | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35363 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-56391 | coreutils | 9.5-1ubuntu2+0.0.0~ubuntu25 | 9.7-3ubuntu2.1 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-56391 | gnu-coreutils | 9.7-3ubuntu2 | 9.7-3ubuntu2.1 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-13595 | bsdutils | 1:2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-13595 | libblkid1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-13595 | libmount1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-77117 | libc-bin | 2.43-2ubuntu2.3 | 2.43-2ubuntu2.4 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-80489 | libc6 | 2.43-2ubuntu2.3 | 2.43-2ubuntu2.4 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-103111 | libpcre2-8-0 | 10.46-1build1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-80489 | libc-gconv-modules-extra | 2.43-2ubuntu2.3 | 2.43-2ubuntu2.4 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-80489 | libc-bin | 2.43-2ubuntu2.3 | 2.43-2ubuntu2.4 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-19487 | perl-base | 5.40.1-7ubuntu0.1 | 5.40.1-7ubuntu0.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-57432 | perl-base | 5.40.1-7ubuntu0.1 | 5.40.1-7ubuntu0.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-13221 | perl-base | 5.40.1-7ubuntu0.1 | 5.40.1-7ubuntu0.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-9538 | perl-base | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-42497 | perl-base | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-78408 | bsdutils | 1:2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-78408 | libblkid1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-78408 | libmount1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-78408 | libsmartcols1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-78408 | libuuid1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-78408 | login | 1:4.16.0-2+really2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-78408 | mount | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-78408 | util-linux | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-54371 | libattr1 | 1:2.5.2-4 | 1:2.5.2-4ubuntu0.1 | /var/lib/dpkg/status |
| LOW | CVE-2026-57062 | gpgv | 2.4.8-4ubuntu3 | 2.4.8-4ubuntu3.1 | /var/lib/dpkg/status |
| LOW | CVE-2024-2236 | libgcrypt20 | 1.12.0-2ubuntu1 | 1.12.0-2ubuntu1.1 | /var/lib/dpkg/status |
| LOW | CVE-2026-40228 | libsystemd0 | 259.5-0ubuntu3.4 | /var/lib/dpkg/status | |
| LOW | CVE-2026-40228 | libudev1 | 259.5-0ubuntu3.4 | /var/lib/dpkg/status | |
| LOW | CVE-2026-105712 | gpgv | 2.4.8-4ubuntu3 | /var/lib/dpkg/status | |
| LOW | CVE-2026-42250 | libbz2-1.0 | 1.0.8-6build2 | 1.0.8-6ubuntu0.1 | /var/lib/dpkg/status |
| LOW | CVE-2026-77696 | openssl | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-77696 | libssl3t64 | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-75804 | libssl3t64 | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-75804 | openssl | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-75804 | openssl-provider-legacy | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-42772 | libssl3t64 | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.7 | /var/lib/dpkg/status |
| LOW | CVE-2026-42772 | openssl | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.7 | /var/lib/dpkg/status |
| LOW | CVE-2026-42772 | openssl-provider-legacy | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.7 | /var/lib/dpkg/status |
| LOW | CVE-2026-54875 | libssl3t64 | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-54875 | openssl | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-54875 | openssl-provider-legacy | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2025-5278 | coreutils | 9.5-1ubuntu2+0.0.0~ubuntu25 | 9.7-3ubuntu2.1 | /var/lib/dpkg/status |
| LOW | CVE-2025-5278 | gnu-coreutils | 9.7-3ubuntu2 | 9.7-3ubuntu2.1 | /var/lib/dpkg/status |
| LOW | CVE-2026-54872 | openssl-provider-legacy | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-54872 | openssl | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-54872 | libssl3t64 | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-72897 | openssl-provider-legacy | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-72897 | openssl | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-72897 | libssl3t64 | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-35189 | openssl-provider-legacy | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-35189 | openssl | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-35189 | libssl3t64 | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-27171 | zlib1g | 1:1.3.dfsg+really1.3.1-1ubuntu3 | 1:1.3.dfsg+really1.3.1-1ubuntu3.1 | /var/lib/dpkg/status |
| LOW | CVE-2026-54873 | libssl3t64 | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.7 | /var/lib/dpkg/status |
| LOW | CVE-2026-54873 | openssl | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.7 | /var/lib/dpkg/status |
| LOW | CVE-2026-54873 | openssl-provider-legacy | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.7 | /var/lib/dpkg/status |
| LOW | CVE-2024-56433 | login.defs | 1:4.17.4-2ubuntu3 | /var/lib/dpkg/status | |
| LOW | CVE-2024-56433 | passwd | 1:4.17.4-2ubuntu3 | /var/lib/dpkg/status | |
| LOW | CVE-2026-84784 | libssl3t64 | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-84784 | openssl | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-84784 | openssl-provider-legacy | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-75806 | libssl3t64 | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-75806 | openssl | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-75806 | openssl-provider-legacy | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-75805 | openssl-provider-legacy | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-75805 | openssl | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-75805 | libssl3t64 | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-75803 | openssl-provider-legacy | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.5 | /var/lib/dpkg/status |
| LOW | CVE-2026-75803 | openssl | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.5 | /var/lib/dpkg/status |
| LOW | CVE-2026-75803 | libssl3t64 | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.5 | /var/lib/dpkg/status |
| LOW | CVE-2026-35191 | libssl3t64 | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-35191 | openssl | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-35191 | openssl-provider-legacy | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-77696 | openssl-provider-legacy | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
ghcr.io/openvoxproject/openvoxdb
Downloads
ghcr.io/openvoxproject/openvoxdb:latest (2026-08-27)
Trivy
HIGH 17
MEDIUM 151
LOW 50
UNKNOWN 13
| Severity | ID | Package | Installed | Fixed | Title / target |
|---|---|---|---|---|---|
| HIGH | CVE-2026-84782 | openssl-provider-legacy | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | openssl: compat-openssl: openssl: Information disclosure via DTLS handshake retransmission — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| HIGH | CVE-2026-84782 | openssl | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | openssl: compat-openssl: openssl: Information disclosure via DTLS handshake retransmission — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| HIGH | CVE-2026-89407 | com.fasterxml.jackson.core:jackson-core | 2.21.5 | 2.18.11, 2.21.7, 2.22.3 | com.fasterxml.jackson/jackson-core: tools.jackson.core/jackson-core: Jackson-core: Denial of Service via regular expression backtracking — Java |
| HIGH | CVE-2026-89425 | com.fasterxml.jackson.core:jackson-core | 2.21.5 | 2.21.7, 2.22.3, 2.18.11 | com.fasterxml.jackson.core/jackson-core: Jackson-core: Denial of Service via unbounded StringBuilder growth during malformed token processing — Java |
| HIGH | CVE-2026-68497 | com.fasterxml.jackson.core:jackson-databind | 2.21.5 | 2.18.10, 2.21.6, 2.22.2 | com.fasterxml.jackson.core/jackson-databind: tools.jackson.core/jackson-databind: jackson-databind: CPU Denial of Service via unbounded numeric parsing — Java |
| HIGH | CVE-2026-91776 | com.fasterxml.jackson.core:jackson-databind | 2.21.5 | 2.18.11, 2.21.7, 2.22.3 | jackson-databind: com.fasterxml.jackson/jackson-core: jackson-databind: Denial of Service via unbounded cache growth in TypeDeserializerBase — Java |
| HIGH | CVE-2026-91777 | com.fasterxml.jackson.core:jackson-databind | 2.21.5 | 2.21.7, 2.18.11, 2.22.3 | com.fasterxml.jackson.core/jackson-databind: Jackson-databind: Denial of Service via quadratic forward-reference completion — Java |
| HIGH | CVE-2026-84782 | libssl3t64 | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | openssl: compat-openssl: openssl: Information disclosure via DTLS handshake retransmission — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| HIGH | CVE-2022-41404 | org.ini4j:ini4j | 0.5.4 | org.ini4j: unspecified DoS — Java | |
| HIGH | CVE-2026-33818 | stdlib | v1.26.5 | 1.25.13, 1.26.6, 1.27.0-rc.3 | encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal — usr/bin/pebble |
| HIGH | CVE-2026-39821 | stdlib | v1.26.5 | 1.25.13, 1.26.6, 1.27.0-rc.3 | golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing — usr/bin/pebble |
| HIGH | CVE-2026-46600 | stdlib | v1.26.5 | 1.26.6, 1.27.0-rc.3 | golang.org/x/net/dns/dnsmessage: golang.org/x/net/dns/dnsmessage: Denial of Service via invalid DNS record parsing — usr/bin/pebble |
| HIGH | CVE-2026-56853 | stdlib | v1.26.5 | 1.25.13, 1.26.6, 1.27.0-rc.3 | net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service — usr/bin/pebble |
| HIGH | CVE-2026-56858 | stdlib | v1.26.5 | 1.25.13, 1.26.6, 1.27.0-rc.3 | html/template: golang: Go html/template: Cross-Site Scripting via pathological input — usr/bin/pebble |
| HIGH | CVE-2026-56859 | stdlib | v1.26.5 | 1.25.13, 1.26.6, 1.27.0-rc.3 | encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue — usr/bin/pebble |
| HIGH | CVE-2026-56860 | stdlib | v1.26.5 | 1.25.13, 1.26.6, 1.27.0-rc.3 | net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution — usr/bin/pebble |
| HIGH | CVE-2026-56862 | stdlib | v1.26.5 | 1.25.13, 1.26.6, 1.27.0-rc.3 | crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages — usr/bin/pebble |
| MEDIUM | CVE-2026-53613 | mount | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-53614 | mount | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: SUID mount(8) allows nosuid/noexec bypass via LIBMOUNT_FORCE_MOUNT2 — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-53615 | mount | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | [Integer Overflow or Wraparound in libblkid/src/partitions/dos.c] — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-12087 | perl | 5.40.1-7ubuntu0.1 | 5.40.1-7ubuntu0.3 | perl-Socket: perl-Socket: Information Disclosure due to Out-of-Bounds Read — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-13221 | perl | 5.40.1-7ubuntu0.1 | 5.40.1-7ubuntu0.3 | perl: Perl: Incorrect regular expression processing via large regular expressions — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-15534 | perl | 5.40.1-7ubuntu0.1 | 5.40.1-7ubuntu0.2 | perl: Perl: Arbitrary code execution via out-of-bounds memory access in regular expression engine. — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-19487 | perl | 5.40.1-7ubuntu0.1 | 5.40.1-7ubuntu0.2 | perl: Perl: Incorrect regular expression matching can lead to wrong access or filtering decisions. — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-57432 | perl | 5.40.1-7ubuntu0.1 | 5.40.1-7ubuntu0.3 | perl: Perl: Information disclosure via integer overflow in pack/unpack operations — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-57433 | perl | 5.40.1-7ubuntu0.1 | 5.40.1-7ubuntu0.3 | Storable: Storable: Denial of Service via signed integer overflow in deserialization — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-12087 | perl-base | 5.40.1-7ubuntu0.1 | 5.40.1-7ubuntu0.3 | perl-Socket: perl-Socket: Information Disclosure due to Out-of-Bounds Read — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-13221 | perl-base | 5.40.1-7ubuntu0.1 | 5.40.1-7ubuntu0.3 | perl: Perl: Incorrect regular expression processing via large regular expressions — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-15534 | perl-base | 5.40.1-7ubuntu0.1 | 5.40.1-7ubuntu0.2 | perl: Perl: Arbitrary code execution via out-of-bounds memory access in regular expression engine. — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-19487 | perl-base | 5.40.1-7ubuntu0.1 | 5.40.1-7ubuntu0.2 | perl: Perl: Incorrect regular expression matching can lead to wrong access or filtering decisions. — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-57432 | perl-base | 5.40.1-7ubuntu0.1 | 5.40.1-7ubuntu0.3 | perl: Perl: Information disclosure via integer overflow in pack/unpack operations — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-57433 | perl-base | 5.40.1-7ubuntu0.1 | 5.40.1-7ubuntu0.3 | Storable: Storable: Denial of Service via signed integer overflow in deserialization — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-12087 | perl-modules-5.40 | 5.40.1-7ubuntu0.1 | 5.40.1-7ubuntu0.3 | perl-Socket: perl-Socket: Information Disclosure due to Out-of-Bounds Read — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-13595 | libuuid1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: heap use-after-free in libblkid nested partition probing — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-27456 | libuuid1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: TOCTOU in the mount program when setting up loop devices — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-3184 | libuuid1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: Access control bypass due to improper hostname canonicalization — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-53612 | libuuid1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: TOCTOU in the mount program when applying post-mount ownership/mode changes — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-53613 | libuuid1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-53614 | libuuid1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: SUID mount(8) allows nosuid/noexec bypass via LIBMOUNT_FORCE_MOUNT2 — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-53615 | libuuid1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | [Integer Overflow or Wraparound in libblkid/src/partitions/dos.c] — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-13595 | login | 1:4.16.0-2+really2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: heap use-after-free in libblkid nested partition probing — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-27456 | login | 1:4.16.0-2+really2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: TOCTOU in the mount program when setting up loop devices — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-3184 | login | 1:4.16.0-2+really2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: Access control bypass due to improper hostname canonicalization — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-53612 | login | 1:4.16.0-2+really2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: TOCTOU in the mount program when applying post-mount ownership/mode changes — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-53613 | login | 1:4.16.0-2+really2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-53614 | login | 1:4.16.0-2+really2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: SUID mount(8) allows nosuid/noexec bypass via LIBMOUNT_FORCE_MOUNT2 — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-53615 | login | 1:4.16.0-2+really2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | [Integer Overflow or Wraparound in libblkid/src/partitions/dos.c] — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-13595 | mount | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: heap use-after-free in libblkid nested partition probing — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-27456 | mount | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: TOCTOU in the mount program when setting up loop devices — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-3184 | mount | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: Access control bypass due to improper hostname canonicalization — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-53612 | mount | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: TOCTOU in the mount program when applying post-mount ownership/mode changes — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-13221 | perl-modules-5.40 | 5.40.1-7ubuntu0.1 | 5.40.1-7ubuntu0.3 | perl: Perl: Incorrect regular expression processing via large regular expressions — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-35368 | rust-coreutils | 0.8.0-0ubuntu3 | A vulnerability exists in the chroot utility of uutils coreutils when ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35370 | rust-coreutils | 0.8.0-0ubuntu3 | The id utility in uutils coreutils miscalculates the groups= section o ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35371 | rust-coreutils | 0.8.0-0ubuntu3 | The id utility in uutils coreutils exhibits incorrect behavior in its ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35373 | rust-coreutils | 0.8.0-0ubuntu3 | A logic error in the ln utility of uutils coreutils causes the program ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35374 | rust-coreutils | 0.8.0-0ubuntu3 | A Time-of-Check to Time-of-Use (TOCTOU) vulnerability exists in the sp ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35377 | rust-coreutils | 0.8.0-0ubuntu3 | A logic error in the env utility of uutils coreutils causes a failure ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-18477 | tar | 1.35+dfsg-4ubuntu0.4 | tar: tar: TOCTOU in incremental dumpdir 'X' rename handling allows restore path escape — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-18508 | tar | 1.35+dfsg-4ubuntu0.4 | tar: tar: --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-13595 | util-linux | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: heap use-after-free in libblkid nested partition probing — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-27456 | util-linux | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: TOCTOU in the mount program when setting up loop devices — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-3184 | util-linux | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: Access control bypass due to improper hostname canonicalization — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-53612 | util-linux | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: TOCTOU in the mount program when applying post-mount ownership/mode changes — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-53613 | util-linux | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-53614 | util-linux | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: SUID mount(8) allows nosuid/noexec bypass via LIBMOUNT_FORCE_MOUNT2 — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-53615 | util-linux | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | [Integer Overflow or Wraparound in libblkid/src/partitions/dos.c] — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-85091 | zlib1g | 1:1.3.dfsg+really1.3.1-1ubuntu3 | zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vul ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-19032 | com.fasterxml.jackson.core:jackson-databind | 2.21.5 | 2.18.10, 2.21.6, 2.22.2 | com.fasterxml.jackson.core/jackson-databind: tools.jackson.core/jackson-databind: Jackson-databind: Uncontrolled URI scheme resolution in Path deserialization — Java |
| MEDIUM | CVE-2026-83557 | com.fasterxml.jackson.core:jackson-databind | 2.21.5 | 2.18.10, 2.21.6, 2.22.2 | com.fasterxml.jackson.core/jackson-databind: tools.jackson.core/jackson-databind: jackson-databind: Path traversal via incomplete type validation — Java |
| MEDIUM | CVE-2026-15534 | perl-modules-5.40 | 5.40.1-7ubuntu0.1 | 5.40.1-7ubuntu0.2 | perl: Perl: Arbitrary code execution via out-of-bounds memory access in regular expression engine. — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-19487 | perl-modules-5.40 | 5.40.1-7ubuntu0.1 | 5.40.1-7ubuntu0.2 | perl: Perl: Incorrect regular expression matching can lead to wrong access or filtering decisions. — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-57432 | perl-modules-5.40 | 5.40.1-7ubuntu0.1 | 5.40.1-7ubuntu0.3 | perl: Perl: Information disclosure via integer overflow in pack/unpack operations — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-57433 | perl-modules-5.40 | 5.40.1-7ubuntu0.1 | 5.40.1-7ubuntu0.3 | Storable: Storable: Denial of Service via signed integer overflow in deserialization — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-35341 | rust-coreutils | 0.8.0-0ubuntu3 | A vulnerability in uutils coreutils mkfifo allows for the unauthorized ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35344 | rust-coreutils | 0.8.0-0ubuntu3 | The dd utility in uutils coreutils suppresses errors during file trunc ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35345 | rust-coreutils | 0.8.0-0ubuntu3 | A vulnerability in the tail utility of uutils coreutils allows for the ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35348 | rust-coreutils | 0.8.0-0ubuntu3 | The sort utility in uutils coreutils is vulnerable to a process panic ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35350 | rust-coreutils | 0.8.0-0ubuntu3 | The cp utility in uutils coreutils fails to properly handle setuid and ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35351 | rust-coreutils | 0.8.0-0ubuntu3 | The mv utility in uutils coreutils fails to preserve file ownership du ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35352 | rust-coreutils | 0.8.0-0ubuntu3 | A Time-of-Check to Time-of-Use (TOCTOU) race condition exists in the m ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35354 | rust-coreutils | 0.8.0-0ubuntu3 | A Time-of-Check to Time-of-Use (TOCTOU) vulnerability exists in the mv ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35357 | rust-coreutils | 0.8.0-0ubuntu3 | The cp utility in uutils coreutils is vulnerable to an information dis ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35359 | rust-coreutils | 0.8.0-0ubuntu3 | A Time-of-Check to Time-of-Use (TOCTOU) vulnerability in the cp utilit ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35360 | rust-coreutils | 0.8.0-0ubuntu3 | The touch utility in uutils coreutils is vulnerable to a Time-of-Check ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35363 | rust-coreutils | 0.8.0-0ubuntu3 | A vulnerability in the rm utility of uutils coreutils allows the bypas ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35364 | rust-coreutils | 0.8.0-0ubuntu3 | A Time-of-Check to Time-of-Use (TOCTOU) race condition exists in the m ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35367 | rust-coreutils | 0.8.0-0ubuntu3 | The nohup utility in uutils coreutils creates its default output file, ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-77117 | libc-gconv-modules-extra | 2.43-2ubuntu2.3 | 2.43-2ubuntu2.4 | glibc: Non-progress DoS in SHIFT_JISX0213 -> — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-6791 | libc-gconv-modules-extra | 2.43-2ubuntu2.3 | 2.43-2ubuntu2.4 | glibc: Glibc: Denial of Service via stack exhaustion during tilde expansion — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-6368 | libc-gconv-modules-extra | 2.43-2ubuntu2.3 | 2.43-2ubuntu2.4 | glibc: glibc: Process abort due to invalid memory in wordexp — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-19542 | libc-gconv-modules-extra | 2.43-2ubuntu2.3 | 2.43-2ubuntu2.4 | glibc: Fix out-of-bounds array write in tdelete — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-19499 | libc-gconv-modules-extra | 2.43-2ubuntu2.3 | 2.43-2ubuntu2.4 | glibc: Buffer Overflow in strfmon right-justification padding — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-18374 | libc-gconv-modules-extra | 2.43-2ubuntu2.3 | glibc: glibc: Heap buffer overflow via attacker-controlled fopen mode string — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89092 | libc-bin | 2.43-2ubuntu2.3 | glibc: nscd stack overflow leads to degraded DNS resolution — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80489 | libc-bin | 2.43-2ubuntu2.3 | 2.43-2ubuntu2.4 | glibc: Non-progress DoS in EUC_JISX0213 -> UCS-4 conversion state — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-77117 | libc-bin | 2.43-2ubuntu2.3 | 2.43-2ubuntu2.4 | glibc: Non-progress DoS in SHIFT_JISX0213 -> — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-6791 | libc-bin | 2.43-2ubuntu2.3 | 2.43-2ubuntu2.4 | glibc: Glibc: Denial of Service via stack exhaustion during tilde expansion — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-6368 | libc-bin | 2.43-2ubuntu2.3 | 2.43-2ubuntu2.4 | glibc: glibc: Process abort due to invalid memory in wordexp — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-19542 | libc-bin | 2.43-2ubuntu2.3 | 2.43-2ubuntu2.4 | glibc: Fix out-of-bounds array write in tdelete — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-19499 | libc-bin | 2.43-2ubuntu2.3 | 2.43-2ubuntu2.4 | glibc: Buffer Overflow in strfmon right-justification padding — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-53614 | libmount1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: SUID mount(8) allows nosuid/noexec bypass via LIBMOUNT_FORCE_MOUNT2 — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-18374 | libc-bin | 2.43-2ubuntu2.3 | glibc: glibc: Heap buffer overflow via attacker-controlled fopen mode string — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-53615 | libblkid1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | [Integer Overflow or Wraparound in libblkid/src/partitions/dos.c] — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-53614 | libblkid1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: SUID mount(8) allows nosuid/noexec bypass via LIBMOUNT_FORCE_MOUNT2 — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-53613 | libblkid1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-53612 | libblkid1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: TOCTOU in the mount program when applying post-mount ownership/mode changes — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-3184 | libblkid1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: Access control bypass due to improper hostname canonicalization — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-27456 | libblkid1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: TOCTOU in the mount program when setting up loop devices — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-19499 | libc6 | 2.43-2ubuntu2.3 | 2.43-2ubuntu2.4 | glibc: Buffer Overflow in strfmon right-justification padding — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-19542 | libc6 | 2.43-2ubuntu2.3 | 2.43-2ubuntu2.4 | glibc: Fix out-of-bounds array write in tdelete — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-6368 | libc6 | 2.43-2ubuntu2.3 | 2.43-2ubuntu2.4 | glibc: glibc: Process abort due to invalid memory in wordexp — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-6791 | libc6 | 2.43-2ubuntu2.3 | 2.43-2ubuntu2.4 | glibc: Glibc: Denial of Service via stack exhaustion during tilde expansion — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-77117 | libc6 | 2.43-2ubuntu2.3 | 2.43-2ubuntu2.4 | glibc: Non-progress DoS in SHIFT_JISX0213 -> — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80489 | libc6 | 2.43-2ubuntu2.3 | 2.43-2ubuntu2.4 | glibc: Non-progress DoS in EUC_JISX0213 -> UCS-4 conversion state — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-89092 | libc6 | 2.43-2ubuntu2.3 | glibc: nscd stack overflow leads to degraded DNS resolution — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-13608 | libcurl4t64 | 8.18.0-1ubuntu2.4 | 8.18.0-1ubuntu2.7 | curl: curl: Authentication bypass in OpenLDAP SASL negotiation via Man-in-the-Middle (MITM) attack — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-18924 | libcurl4t64 | 8.18.0-1ubuntu2.4 | 8.18.0-1ubuntu2.7 | curl: libcurl: Use-after-free in HTTP/2 Server Push with shared connections — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80229 | libcurl4t64 | 8.18.0-1ubuntu2.4 | 8.18.0-1ubuntu2.7 | When performing transfers via libcurl\u2019s multi interface, pooled T ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80230 | libcurl4t64 | 8.18.0-1ubuntu2.4 | 8.18.0-1ubuntu2.7 | curl: curl: Public key pinning bypass allows unauthenticated connections — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80255 | libcurl4t64 | 8.18.0-1ubuntu2.4 | 8.18.0-1ubuntu2.7 | curl: curl: Information disclosure due to secure cookie attribute bypass — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-82209 | libcurl4t64 | 8.18.0-1ubuntu2.4 | 8.18.0-1ubuntu2.7 | curl: libcurl: Information disclosure via improper Public Suffix List boundary check — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-18374 | libc6 | 2.43-2ubuntu2.3 | glibc: glibc: Heap buffer overflow via attacker-controlled fopen mode string — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89092 | libc-gconv-modules-extra | 2.43-2ubuntu2.3 | glibc: nscd stack overflow leads to degraded DNS resolution — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-13595 | libmount1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: heap use-after-free in libblkid nested partition probing — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-27456 | libmount1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: TOCTOU in the mount program when setting up loop devices — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-3184 | libmount1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: Access control bypass due to improper hostname canonicalization — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-53612 | libmount1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: TOCTOU in the mount program when applying post-mount ownership/mode changes — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-53613 | libmount1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80489 | libc-gconv-modules-extra | 2.43-2ubuntu2.3 | 2.43-2ubuntu2.4 | glibc: Non-progress DoS in EUC_JISX0213 -> UCS-4 conversion state — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-53613 | libsmartcols1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-53614 | libsmartcols1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: SUID mount(8) allows nosuid/noexec bypass via LIBMOUNT_FORCE_MOUNT2 — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-53615 | libsmartcols1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | [Integer Overflow or Wraparound in libblkid/src/partitions/dos.c] — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-39113 | libsqlite3-0 | 3.46.1-9ubuntu0.2 | 3.46.1-9ubuntu0.3 | Buffer Overflow vulnerability in SQLite affected version source s ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-66032 | libssh2-1t64 | 1.11.1-1ubuntu0.26.04.3 | 1.11.1-1ubuntu0.26.04.4 | libssh2: libssh2: Arbitrary code execution via double-free in SFTP session — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-66033 | libssh2-1t64 | 1.11.1-1ubuntu0.26.04.3 | 1.11.1-1ubuntu0.26.04.4 | libssh2: libssh2: Denial of Service via integer underflow in AES-GCM cipher negotiation — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-66035 | libssh2-1t64 | 1.11.1-1ubuntu0.26.04.3 | 1.11.1-1ubuntu0.26.04.4 | libssh2: libssh2: Arbitrary code execution via heap buffer overflow during SSH negotiation — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-53910 | diffutils | 1:3.12-1 | 1:3.12-1ubuntu0.1 | diffutils: heap‑based buffer overflow due to multiple signed integer overflows in line‑mapping calculations — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-82209 | curl | 8.18.0-1ubuntu2.4 | 8.18.0-1ubuntu2.7 | curl: libcurl: Information disclosure via improper Public Suffix List boundary check — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80255 | curl | 8.18.0-1ubuntu2.4 | 8.18.0-1ubuntu2.7 | curl: curl: Information disclosure due to secure cookie attribute bypass — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80230 | curl | 8.18.0-1ubuntu2.4 | 8.18.0-1ubuntu2.7 | curl: curl: Public key pinning bypass allows unauthenticated connections — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80229 | curl | 8.18.0-1ubuntu2.4 | 8.18.0-1ubuntu2.7 | When performing transfers via libcurl\u2019s multi interface, pooled T ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-18924 | curl | 8.18.0-1ubuntu2.4 | 8.18.0-1ubuntu2.7 | curl: libcurl: Use-after-free in HTTP/2 Server Push with shared connections — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-13608 | curl | 8.18.0-1ubuntu2.4 | 8.18.0-1ubuntu2.7 | curl: curl: Authentication bypass in OpenLDAP SASL negotiation via Man-in-the-Middle (MITM) attack — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-53615 | bsdutils | 1:2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | [Integer Overflow or Wraparound in libblkid/src/partitions/dos.c] — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-53614 | bsdutils | 1:2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: SUID mount(8) allows nosuid/noexec bypass via LIBMOUNT_FORCE_MOUNT2 — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-53613 | bsdutils | 1:2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-53612 | bsdutils | 1:2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: TOCTOU in the mount program when applying post-mount ownership/mode changes — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-3184 | bsdutils | 1:2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: Access control bypass due to improper hostname canonicalization — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-27456 | bsdutils | 1:2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: TOCTOU in the mount program when setting up loop devices — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-13595 | bsdutils | 1:2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: heap use-after-free in libblkid nested partition probing — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-13595 | libblkid1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: heap use-after-free in libblkid nested partition probing — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-54371 | libattr1 | 1:2.5.2-4 | 1:2.5.2-4ubuntu0.1 | attr: attr: Symlink Traversal Privilege Escalation via getfattr and setfattr — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-53615 | libmount1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | [Integer Overflow or Wraparound in libblkid/src/partitions/dos.c] — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-13757 | libp11-kit0 | 0.26.2-2 | p11-kit: Stack exhaustion via unbounded recursion in RPC attribute parsing — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-86145 | libpcre2-8-0 | 10.46-1build1 | pcre2: PCRE2: Out-of-bounds write allows arbitrary code execution via crafted regular expressions — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89161 | libpcre2-8-0 | 10.46-1build1 | pcre2: PCRE2: Memory corruption vulnerability in pcre2_jit_match — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-12087 | libperl5.40 | 5.40.1-7ubuntu0.1 | 5.40.1-7ubuntu0.3 | perl-Socket: perl-Socket: Information Disclosure due to Out-of-Bounds Read — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-13221 | libperl5.40 | 5.40.1-7ubuntu0.1 | 5.40.1-7ubuntu0.3 | perl: Perl: Incorrect regular expression processing via large regular expressions — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-15534 | libperl5.40 | 5.40.1-7ubuntu0.1 | 5.40.1-7ubuntu0.2 | perl: Perl: Arbitrary code execution via out-of-bounds memory access in regular expression engine. — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-19487 | libperl5.40 | 5.40.1-7ubuntu0.1 | 5.40.1-7ubuntu0.2 | perl: Perl: Incorrect regular expression matching can lead to wrong access or filtering decisions. — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-56391 | gnu-coreutils | 9.7-3ubuntu2 | 9.7-3ubuntu2.1 | coreutils: GNU coreutils uniq: Denial of Service and information disclosure via out-of-bounds read with multibyte input — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-57432 | libperl5.40 | 5.40.1-7ubuntu0.1 | 5.40.1-7ubuntu0.3 | perl: Perl: Information disclosure via integer overflow in pack/unpack operations — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-57433 | libperl5.40 | 5.40.1-7ubuntu0.1 | 5.40.1-7ubuntu0.3 | Storable: Storable: Denial of Service via signed integer overflow in deserialization — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-13595 | libsmartcols1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: heap use-after-free in libblkid nested partition probing — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-27456 | libsmartcols1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: TOCTOU in the mount program when setting up loop devices — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-3184 | libsmartcols1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: Access control bypass due to improper hostname canonicalization — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-53612 | libsmartcols1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | util-linux: util-linux: TOCTOU in the mount program when applying post-mount ownership/mode changes — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| LOW | CVE-2026-8932 | curl | 8.18.0-1ubuntu2.4 | 8.18.0-1ubuntu2.5 | libcurl: libcurl: Security feature bypass due to improper mTLS connection reuse — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| LOW | CVE-2026-42250 | libbz2-1.0 | 1.0.8-6build2 | 1.0.8-6ubuntu0.1 | bzip2: bzip2: Denial of Service in bzip2recover via a specially crafted file — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| LOW | CVE-2026-27171 | zlib1g | 1:1.3.dfsg+really1.3.1-1ubuntu3 | 1:1.3.dfsg+really1.3.1-1ubuntu3.1 | zlib: zlib: Denial of Service via infinite loop in CRC32 combine functions — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| LOW | CVE-2025-5278 | gnu-coreutils | 9.7-3ubuntu2 | 9.7-3ubuntu2.1 | coreutils: Heap Buffer Under-Read in GNU Coreutils sort via Key Specification — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| LOW | CVE-2026-57062 | gpgv | 2.4.8-4ubuntu3 | 2.4.8-4ubuntu3.1 | GnuPG: Incorrect cryptographic message parsing — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| LOW | CVE-2026-8932 | libcurl4t64 | 8.18.0-1ubuntu2.4 | 8.18.0-1ubuntu2.5 | libcurl: libcurl: Security feature bypass due to improper mTLS connection reuse — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| LOW | CVE-2026-54875 | openssl | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | openssl: openssl: information disclosure via non-constant-time SM2 scalar multiplication on ARM64 and RISC-V — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| LOW | CVE-2026-54873 | openssl | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.7 | openssl: openssl: Denial of Service via excessive QUIC packet buffer retention — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| LOW | CVE-2026-54872 | openssl | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | openssl: OpenSSL: Private key recovery via timing side-channel in generic elliptic curve operations — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| LOW | CVE-2026-42772 | openssl | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.7 | openssl: openssl: Denial of Service via inefficient QUIC stream reassembly — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| LOW | CVE-2026-35191 | openssl | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | openssl: openssl: Traffic amplification Denial of Service via QUIC packet over-accounting — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| LOW | CVE-2026-35189 | openssl | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | openssl: openssl: Denial of Service via excessive memory allocation in CRL distribution point processing — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| LOW | CVE-2024-56433 | login.defs | 1:4.17.4-2ubuntu3 | shadow-utils: Default subordinate ID configuration in /etc/login.defs could lead to compromise — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| LOW | CVE-2026-35189 | libssl3t64 | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | openssl: openssl: Denial of Service via excessive memory allocation in CRL distribution point processing — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| LOW | CVE-2026-40228 | libudev1 | 259.5-0ubuntu3.4 | systemd: systemd-journald: Unintended output to user terminals via logger command — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| LOW | CVE-2026-40228 | libsystemd0 | 259.5-0ubuntu3.4 | systemd: systemd-journald: Unintended output to user terminals via logger command — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| LOW | CVE-2026-84784 | libssl3t64 | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | openssl: OpenSSL: Denial of Service via unbounded QUIC connection identifier backlog — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| LOW | CVE-2026-77696 | libssl3t64 | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | openssl: OpenSSL: Private key recovery via SM2 timing side-channel — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| LOW | CVE-2026-75806 | libssl3t64 | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | openssl: OpenSSL: Denial of Service via undersized DTLS record — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| LOW | CVE-2026-75805 | libssl3t64 | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | openssl: openssl: Denial of Service via crafted CMP certificate revocation response — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| LOW | CVE-2026-75804 | libssl3t64 | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | openssl: OpenSSL: Denial of Service via unenforced QUIC connection flow control — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| LOW | CVE-2026-75803 | libssl3t64 | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.5 | openssl: openssl: AEAD forgeries possible with empty ciphertext in EVP_Cipher() — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| LOW | CVE-2026-72897 | libssl3t64 | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | openssl: openssl: Denial of Service via out-of-bounds write during TLS context switch — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| LOW | CVE-2026-54875 | libssl3t64 | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | openssl: openssl: information disclosure via non-constant-time SM2 scalar multiplication on ARM64 and RISC-V — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| LOW | CVE-2026-54873 | libssl3t64 | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.7 | openssl: openssl: Denial of Service via excessive QUIC packet buffer retention — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| LOW | CVE-2026-54872 | libssl3t64 | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | openssl: OpenSSL: Private key recovery via timing side-channel in generic elliptic curve operations — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| LOW | CVE-2026-42772 | libssl3t64 | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.7 | openssl: openssl: Denial of Service via inefficient QUIC stream reassembly — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| LOW | CVE-2026-35191 | libssl3t64 | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | openssl: openssl: Traffic amplification Denial of Service via QUIC packet over-accounting — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| LOW | CVE-2024-2236 | libgcrypt20 | 1.12.0-2ubuntu1 | 1.12.0-2ubuntu1.1 | libgcrypt: vulnerable to Marvin Attack — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| LOW | CVE-2024-56433 | passwd | 1:4.17.4-2ubuntu3 | shadow-utils: Default subordinate ID configuration in /etc/login.defs could lead to compromise — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) | |
| LOW | CVE-2026-84784 | openssl-provider-legacy | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | openssl: OpenSSL: Denial of Service via unbounded QUIC connection identifier backlog — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| LOW | CVE-2026-77696 | openssl-provider-legacy | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | openssl: OpenSSL: Private key recovery via SM2 timing side-channel — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| LOW | CVE-2026-75806 | openssl-provider-legacy | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | openssl: OpenSSL: Denial of Service via undersized DTLS record — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| LOW | CVE-2026-75805 | openssl-provider-legacy | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | openssl: openssl: Denial of Service via crafted CMP certificate revocation response — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| LOW | CVE-2026-75804 | openssl-provider-legacy | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | openssl: OpenSSL: Denial of Service via unenforced QUIC connection flow control — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| LOW | CVE-2026-75803 | openssl-provider-legacy | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.5 | openssl: openssl: AEAD forgeries possible with empty ciphertext in EVP_Cipher() — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| LOW | CVE-2026-72897 | openssl-provider-legacy | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | openssl: openssl: Denial of Service via out-of-bounds write during TLS context switch — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| LOW | CVE-2026-54875 | openssl-provider-legacy | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | openssl: openssl: information disclosure via non-constant-time SM2 scalar multiplication on ARM64 and RISC-V — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| LOW | CVE-2026-72897 | openssl | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | openssl: openssl: Denial of Service via out-of-bounds write during TLS context switch — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| LOW | CVE-2026-75803 | openssl | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.5 | openssl: openssl: AEAD forgeries possible with empty ciphertext in EVP_Cipher() — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| LOW | CVE-2026-75804 | openssl | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | openssl: OpenSSL: Denial of Service via unenforced QUIC connection flow control — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| LOW | CVE-2026-75805 | openssl | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | openssl: openssl: Denial of Service via crafted CMP certificate revocation response — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| LOW | CVE-2026-75806 | openssl | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | openssl: OpenSSL: Denial of Service via undersized DTLS record — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| LOW | CVE-2026-77696 | openssl | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | openssl: OpenSSL: Private key recovery via SM2 timing side-channel — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| LOW | CVE-2026-84784 | openssl | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | openssl: OpenSSL: Denial of Service via unbounded QUIC connection identifier backlog — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| LOW | CVE-2026-35189 | openssl-provider-legacy | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | openssl: openssl: Denial of Service via excessive memory allocation in CRL distribution point processing — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| LOW | CVE-2026-35191 | openssl-provider-legacy | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | openssl: openssl: Traffic amplification Denial of Service via QUIC packet over-accounting — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| LOW | CVE-2026-42772 | openssl-provider-legacy | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.7 | openssl: openssl: Denial of Service via inefficient QUIC stream reassembly — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| LOW | CVE-2026-54872 | openssl-provider-legacy | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | openssl: OpenSSL: Private key recovery via timing side-channel in generic elliptic curve operations — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| LOW | CVE-2026-54873 | openssl-provider-legacy | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.7 | openssl: openssl: Denial of Service via excessive QUIC packet buffer retention — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04) |
| UNKNOWN | CVE-2026-97032 | stdlib | v1.26.5 | 1.26.9, 1.27.2 | HTTP/2 server crash due to HPACK encoder race in net/http — usr/bin/pebble |
| UNKNOWN | CVE-2026-97031 | stdlib | v1.26.5 | 1.26.9, 1.27.2 | Reject malformed ECH outer extension references in crypto/tls — usr/bin/pebble |
| UNKNOWN | CVE-2026-97030 | stdlib | v1.26.5 | 1.26.9, 1.27.2 | Recognize yield as regexp preceder keyword in html/template — usr/bin/pebble |
| UNKNOWN | CVE-2026-94448 | stdlib | v1.26.5 | 1.26.9, 1.27.2 | Reset context tracking on consecutive template expressions in html/template — usr/bin/pebble |
| UNKNOWN | CVE-2026-94440 | stdlib | v1.26.5 | 1.26.9, 1.27.2 | Memory limit bypass when parsing MIME headers in net/textproto, mime/multipart — usr/bin/pebble |
| UNKNOWN | CVE-2026-94439 | stdlib | v1.26.5 | 1.26.9, 1.27.2 | HTTP/1 server connection desynchronization after 2xx CONNECT response in net/http — usr/bin/pebble |
| UNKNOWN | CVE-2026-78669 | stdlib | v1.26.5 | 1.26.9, 1.27.2 | Excessive CPU consumption from repeated initial window changes in net/http — usr/bin/pebble |
| UNKNOWN | CVE-2026-78667 | stdlib | v1.26.5 | 1.26.9, 1.27.2 | Lack of limit on size of parsed Range headers in net/http — usr/bin/pebble |
| UNKNOWN | CVE-2026-78663 | stdlib | v1.26.5 | 1.26.9, 1.27.2 | Double flow control refund on HTTP/2 server streams in net/http — usr/bin/pebble |
| UNKNOWN | CVE-2026-78660 | stdlib | v1.26.5 | 1.26.9, 1.27.2 | HTTP/2 transport accepts malformed framing-related headers in net/http — usr/bin/pebble |
| UNKNOWN | CVE-2026-78659 | stdlib | v1.26.5 | 1.26.9, 1.27.2 | HTTP/2 server memory exhaustion due to Trailer headers in net/http — usr/bin/pebble |
| UNKNOWN | CVE-2026-56866 | stdlib | v1.26.5 | 1.26.9, 1.27.2 | HTTP/1 client connection desynchronization after CONNECT rejection in net/http — usr/bin/pebble |
| UNKNOWN | CVE-2026-56857 | stdlib | v1.26.5 | 1.26.9, 1.27.2 | Root.Mkdir(All) can follow junctions out of the root on Windows in os — usr/bin/pebble |
Grype
HIGH 13
MEDIUM 250
LOW 53
| Severity | ID | Package | Installed | Fixed | Title / target |
|---|---|---|---|---|---|
| HIGH | GHSA-jr6h-r7vg-f9mc | ini4j | 0.5.4 | org.ini4j allows attackers to cause a Denial of Service (DoS) — /opt/puppetlabs/server/apps/puppetdb/puppetdb.jar | |
| HIGH | GO-2026-5026 | stdlib | go1.26.5 | 1.25.13, 1.26.6, 1.27.0-rc.3 | The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com". — /usr/bin/pebble |
| HIGH | GHSA-q4xh-88c3-wmh7 | jackson-databind | 2.21.5 | 2.21.6 | jackson-databind: Duration XMLGregorianCalendar Unbounded Number Parse DoS — /opt/puppetlabs/server/apps/puppetdb/puppetdb.jar |
| HIGH | GO-2026-6090 | stdlib | go1.26.5 | 1.25.13, 1.26.6, 1.27.0-rc.3 | Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely. — /usr/bin/pebble |
| HIGH | GO-2026-5972 | stdlib | go1.26.5 | 1.25.13, 1.26.6, 1.27.0-rc.3 | Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures. — /usr/bin/pebble |
| HIGH | GO-2026-6089 | stdlib | go1.26.5 | 1.25.13, 1.26.6, 1.27.0-rc.3 | When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this. — /usr/bin/pebble |
| HIGH | GHSA-p6pp-m3f8-5c89 | jackson-core | 2.21.5 | 2.21.7 | jackson-core: ReDoS: quadratic backtracking in NumberInput.PATTERN_FLOAT via looksLikeValidNumber() — /opt/puppetlabs/server/apps/puppetdb/puppetdb.jar |
| HIGH | GHSA-7hhh-6rmp-j9qf | jackson-core | 2.21.5 | 2.21.7 | jackson-core: UTF8DataInputJsonParser._reportInvalidToken() missing maxErrorTokenLength limit -> unbounded StringBuilder growth (DoS) — /opt/puppetlabs/server/apps/puppetdb/puppetdb.jar |
| HIGH | GHSA-cxp5-3px4-pw24 | jackson-databind | 2.21.5 | 2.21.7 | jackson-databind quadratic forward-reference completion — /opt/puppetlabs/server/apps/puppetdb/puppetdb.jar |
| HIGH | GHSA-wv8q-qhhj-9h54 | jackson-databind | 2.21.5 | 2.21.7 | jackson-databind retains every unknown raw type ID — /opt/puppetlabs/server/apps/puppetdb/puppetdb.jar |
| HIGH | CVE-2026-84782 | openssl-provider-legacy | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| HIGH | CVE-2026-84782 | libssl3t64 | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| HIGH | CVE-2026-84782 | openssl | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-78409 | libblkid1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-78409 | libmount1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-78409 | libsmartcols1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-78409 | libuuid1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-78409 | login | 1:4.16.0-2+really2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-78409 | mount | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53614 | libsmartcols1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-78409 | bsdutils | 1:2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-78410 | util-linux | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-78410 | mount | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-78410 | login | 1:4.16.0-2+really2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-78410 | libuuid1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-78410 | libsmartcols1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-78410 | libmount1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-78410 | libblkid1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-78408 | libuuid1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35348 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35373 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35371 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-93658 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35351 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-18508 | tar | 1.35+dfsg-4ubuntu0.4 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35341 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-18374 | libc6 | 2.43-2ubuntu2.3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-18374 | libc-gconv-modules-extra | 2.43-2ubuntu2.3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-18374 | libc-bin | 2.43-2ubuntu2.3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-102474 | dash | 0.5.12-12ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-6368 | libc6 | 2.43-2ubuntu2.3 | 2.43-2ubuntu2.4 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-6368 | libc-gconv-modules-extra | 2.43-2ubuntu2.3 | 2.43-2ubuntu2.4 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-6368 | libc-bin | 2.43-2ubuntu2.3 | 2.43-2ubuntu2.4 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-35368 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-18938 | libp11-kit0 | 0.26.2-2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-54369 | libacl1 | 2.3.2-2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-78409 | util-linux | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-78408 | libsmartcols1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-78408 | libmount1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-78408 | libblkid1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-78408 | bsdutils | 1:2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-39113 | libsqlite3-0 | 3.46.1-9ubuntu0.2 | 3.46.1-9ubuntu0.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-13757 | libp11-kit0 | 0.26.2-2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-57432 | perl-modules-5.40 | 5.40.1-7ubuntu0.1 | 5.40.1-7ubuntu0.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-57432 | perl-base | 5.40.1-7ubuntu0.1 | 5.40.1-7ubuntu0.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-57432 | perl | 5.40.1-7ubuntu0.1 | 5.40.1-7ubuntu0.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-57432 | libperl5.40 | 5.40.1-7ubuntu0.1 | 5.40.1-7ubuntu0.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-103111 | libpcre2-8-0 | 10.46-1build1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-76642 | util-linux | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-76642 | mount | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-76642 | login | 1:4.16.0-2+really2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-76642 | libuuid1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-57433 | perl-base | 5.40.1-7ubuntu0.1 | 5.40.1-7ubuntu0.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-78410 | bsdutils | 1:2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-89162 | libpcre2-8-0 | 10.46-1build1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-13595 | util-linux | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-13595 | mount | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-13595 | login | 1:4.16.0-2+really2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-13595 | libuuid1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-13595 | libsmartcols1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-13595 | libmount1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-13595 | libblkid1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-13595 | bsdutils | 1:2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-56391 | gnu-coreutils | 9.7-3ubuntu2 | 9.7-3ubuntu2.1 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-56391 | coreutils | 9.5-1ubuntu2+0.0.0~ubuntu25 | 9.7-3ubuntu2.1 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-35363 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-54371 | libattr1 | 1:2.5.2-4 | 1:2.5.2-4ubuntu0.1 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-78408 | util-linux | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-78408 | mount | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-78408 | login | 1:4.16.0-2+really2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53613 | libsmartcols1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-53612 | libsmartcols1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-53615 | libmount1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-53614 | libmount1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-53613 | libmount1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-53612 | libmount1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-53615 | libblkid1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-53614 | libblkid1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-53613 | libblkid1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-53612 | libblkid1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-53615 | bsdutils | 1:2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-53614 | bsdutils | 1:2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-53613 | bsdutils | 1:2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-53612 | bsdutils | 1:2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-18477 | tar | 1.35+dfsg-4ubuntu0.4 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-86805 | libc6 | 2.43-2ubuntu2.3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53615 | util-linux | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-53614 | util-linux | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-53613 | util-linux | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-53612 | util-linux | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-53615 | mount | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-53614 | mount | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-53613 | mount | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-53612 | mount | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-53615 | login | 1:4.16.0-2+really2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-53614 | login | 1:4.16.0-2+really2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-53613 | login | 1:4.16.0-2+really2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-53612 | login | 1:4.16.0-2+really2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-53615 | libuuid1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-53614 | libuuid1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-53613 | libuuid1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-53612 | libuuid1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-53615 | libsmartcols1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-86805 | libc-gconv-modules-extra | 2.43-2ubuntu2.3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-86805 | libc-bin | 2.43-2ubuntu2.3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35377 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-89161 | libpcre2-8-0 | 10.46-1build1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35370 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2025-15649 | perl-modules-5.40 | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2025-15649 | perl-base | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2025-15649 | perl | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2025-15649 | libperl5.40 | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-95818 | libc6 | 2.43-2ubuntu2.3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-95818 | libc-gconv-modules-extra | 2.43-2ubuntu2.3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-95818 | libc-bin | 2.43-2ubuntu2.3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35367 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-102473 | dash | 0.5.12-12ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35344 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35350 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35374 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35354 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35357 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35364 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35345 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35360 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35359 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-54370 | libacl1 | 2.3.2-2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-27456 | util-linux | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-27456 | mount | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-27456 | login | 1:4.16.0-2+really2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-27456 | libuuid1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-27456 | libsmartcols1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-27456 | libmount1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-27456 | libblkid1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-27456 | bsdutils | 1:2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-35352 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-80489 | libc6 | 2.43-2ubuntu2.3 | 2.43-2ubuntu2.4 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-80489 | libc-gconv-modules-extra | 2.43-2ubuntu2.3 | 2.43-2ubuntu2.4 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-80489 | libc-bin | 2.43-2ubuntu2.3 | 2.43-2ubuntu2.4 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-19487 | perl-modules-5.40 | 5.40.1-7ubuntu0.1 | 5.40.1-7ubuntu0.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-19487 | perl-base | 5.40.1-7ubuntu0.1 | 5.40.1-7ubuntu0.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-19487 | perl | 5.40.1-7ubuntu0.1 | 5.40.1-7ubuntu0.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-19487 | libperl5.40 | 5.40.1-7ubuntu0.1 | 5.40.1-7ubuntu0.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-83408 | openjdk-21-jre-headless | 21.0.12+8-1~26.04 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-13221 | perl-modules-5.40 | 5.40.1-7ubuntu0.1 | 5.40.1-7ubuntu0.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-13221 | perl-base | 5.40.1-7ubuntu0.1 | 5.40.1-7ubuntu0.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-13221 | perl | 5.40.1-7ubuntu0.1 | 5.40.1-7ubuntu0.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-13221 | libperl5.40 | 5.40.1-7ubuntu0.1 | 5.40.1-7ubuntu0.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-66032 | libssh2-1t64 | 1.11.1-1ubuntu0.26.04.3 | 1.11.1-1ubuntu0.26.04.4 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-9538 | perl-modules-5.40 | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-9538 | perl-base | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-9538 | perl | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-9538 | libperl5.40 | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-83357 | openjdk-21-jre-headless | 21.0.12+8-1~26.04 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-47057 | openjdk-21-jre-headless | 21.0.12+8-1~26.04 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-57433 | perl | 5.40.1-7ubuntu0.1 | 5.40.1-7ubuntu0.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-57433 | libperl5.40 | 5.40.1-7ubuntu0.1 | 5.40.1-7ubuntu0.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-80230 | libcurl4t64 | 8.18.0-1ubuntu2.4 | 8.18.0-1ubuntu2.7 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-80230 | curl | 8.18.0-1ubuntu2.4 | 8.18.0-1ubuntu2.7 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-82209 | libcurl4t64 | 8.18.0-1ubuntu2.4 | 8.18.0-1ubuntu2.7 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-82209 | curl | 8.18.0-1ubuntu2.4 | 8.18.0-1ubuntu2.7 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-12087 | perl-modules-5.40 | 5.40.1-7ubuntu0.1 | 5.40.1-7ubuntu0.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-12087 | perl-base | 5.40.1-7ubuntu0.1 | 5.40.1-7ubuntu0.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-12087 | perl | 5.40.1-7ubuntu0.1 | 5.40.1-7ubuntu0.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-12087 | libperl5.40 | 5.40.1-7ubuntu0.1 | 5.40.1-7ubuntu0.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-47058 | openjdk-21-jre-headless | 21.0.12+8-1~26.04 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-86145 | libpcre2-8-0 | 10.46-1build1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-48961 | perl-modules-5.40 | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-48961 | perl-base | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-48961 | perl | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-48961 | libperl5.40 | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-77117 | libc6 | 2.43-2ubuntu2.3 | 2.43-2ubuntu2.4 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-77117 | libc-gconv-modules-extra | 2.43-2ubuntu2.3 | 2.43-2ubuntu2.4 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-77117 | libc-bin | 2.43-2ubuntu2.3 | 2.43-2ubuntu2.4 | /var/lib/dpkg/status |
| MEDIUM | GO-2026-6218 | stdlib | go1.26.5 | 1.25.13, 1.26.6, 1.27.0-rc.3 | Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations. — /usr/bin/pebble |
| MEDIUM | CVE-2026-48959 | perl-modules-5.40 | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-48959 | perl-base | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-48959 | perl | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-48959 | libperl5.40 | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-3184 | util-linux | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-3184 | mount | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-3184 | login | 1:4.16.0-2+really2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-3184 | libuuid1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-3184 | libsmartcols1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-3184 | libmount1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-3184 | libblkid1 | 2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-3184 | bsdutils | 1:2.41.3-3ubuntu2 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-82560 | perl-modules-5.40 | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-82560 | perl-base | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-82560 | perl | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-82560 | libperl5.40 | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-66033 | libssh2-1t64 | 1.11.1-1ubuntu0.26.04.3 | 1.11.1-1ubuntu0.26.04.4 | /var/lib/dpkg/status |
| MEDIUM | GHSA-gx83-3vf8-gh7j | jackson-databind | 2.21.5 | 2.21.6 | jackson-databind: Comparable missing from DefaultBaseTypeLimitingValidator's unsafe base types (incomplete PolymorphicTypeValidator denylist) — /opt/puppetlabs/server/apps/puppetdb/puppetdb.jar |
| MEDIUM | CVE-2026-42497 | perl-modules-5.40 | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-42497 | perl-base | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-42497 | perl | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-42497 | libperl5.40 | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-80255 | libcurl4t64 | 8.18.0-1ubuntu2.4 | 8.18.0-1ubuntu2.7 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-80255 | curl | 8.18.0-1ubuntu2.4 | 8.18.0-1ubuntu2.7 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-13608 | libcurl4t64 | 8.18.0-1ubuntu2.4 | 8.18.0-1ubuntu2.7 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-13608 | curl | 8.18.0-1ubuntu2.4 | 8.18.0-1ubuntu2.7 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-48962 | perl-modules-5.40 | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-48962 | perl-base | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-48962 | perl | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-48962 | libperl5.40 | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | GHSA-wjgm-6hv5-3cvf | jackson-databind | 2.21.5 | 2.21.6 | jackson-databind: Path Deserialization Missing Scheme Allowlist for FileSystemProvider Resolution — /opt/puppetlabs/server/apps/puppetdb/puppetdb.jar |
| MEDIUM | CVE-2026-66035 | libssh2-1t64 | 1.11.1-1ubuntu0.26.04.3 | 1.11.1-1ubuntu0.26.04.4 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-80229 | libcurl4t64 | 8.18.0-1ubuntu2.4 | 8.18.0-1ubuntu2.7 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-80229 | curl | 8.18.0-1ubuntu2.4 | 8.18.0-1ubuntu2.7 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-18924 | libcurl4t64 | 8.18.0-1ubuntu2.4 | 8.18.0-1ubuntu2.7 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-18924 | curl | 8.18.0-1ubuntu2.4 | 8.18.0-1ubuntu2.7 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-85091 | zlib1g | 1:1.3.dfsg+really1.3.1-1ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-75466 | libjpeg-turbo8 | 2.1.5-4ubuntu4 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-89156 | libpcre2-8-0 | 10.46-1build1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-97399 | libc-bin | 2.43-2ubuntu2.3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-97399 | libc-gconv-modules-extra | 2.43-2ubuntu2.3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-97399 | libc6 | 2.43-2ubuntu2.3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-89157 | libpcre2-8-0 | 10.46-1build1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-70907 | openjdk-21-jre-headless | 21.0.12+8-1~26.04 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-7017 | perl-base | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-19542 | libc-gconv-modules-extra | 2.43-2ubuntu2.3 | 2.43-2ubuntu2.4 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-7017 | perl-modules-5.40 | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-89158 | libpcre2-8-0 | 10.46-1build1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-19542 | libc-bin | 2.43-2ubuntu2.3 | 2.43-2ubuntu2.4 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-15534 | perl-modules-5.40 | 5.40.1-7ubuntu0.1 | 5.40.1-7ubuntu0.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-15534 | perl-base | 5.40.1-7ubuntu0.1 | 5.40.1-7ubuntu0.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-15534 | perl | 5.40.1-7ubuntu0.1 | 5.40.1-7ubuntu0.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-83368 | openjdk-21-jre-headless | 21.0.12+8-1~26.04 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-89160 | libpcre2-8-0 | 10.46-1build1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-89092 | libc-bin | 2.43-2ubuntu2.3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-89092 | libc-gconv-modules-extra | 2.43-2ubuntu2.3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-89092 | libc6 | 2.43-2ubuntu2.3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-60589 | openjdk-21-jre-headless | 21.0.12+8-1~26.04 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-15534 | libperl5.40 | 5.40.1-7ubuntu0.1 | 5.40.1-7ubuntu0.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-8674 | libc-bin | 2.43-2ubuntu2.3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-8674 | libc-gconv-modules-extra | 2.43-2ubuntu2.3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-8674 | libc6 | 2.43-2ubuntu2.3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-76642 | libmount1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-53910 | diffutils | 1:3.12-1 | 1:3.12-1ubuntu0.1 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-6791 | libc-bin | 2.43-2ubuntu2.3 | 2.43-2ubuntu2.4 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-76642 | libsmartcols1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-6791 | libc-gconv-modules-extra | 2.43-2ubuntu2.3 | 2.43-2ubuntu2.4 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-57433 | perl-modules-5.40 | 5.40.1-7ubuntu0.1 | 5.40.1-7ubuntu0.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-76642 | libblkid1 | 2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-76642 | bsdutils | 1:2.41.3-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-6791 | libc6 | 2.43-2ubuntu2.3 | 2.43-2ubuntu2.4 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-61308 | openjdk-21-jre-headless | 21.0.12+8-1~26.04 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-19499 | libc-bin | 2.43-2ubuntu2.3 | 2.43-2ubuntu2.4 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-19499 | libc-gconv-modules-extra | 2.43-2ubuntu2.3 | 2.43-2ubuntu2.4 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-19542 | libc6 | 2.43-2ubuntu2.3 | 2.43-2ubuntu2.4 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-7017 | libperl5.40 | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-7017 | perl | 5.40.1-7ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-19499 | libc6 | 2.43-2ubuntu2.3 | 2.43-2ubuntu2.4 | /var/lib/dpkg/status |
| LOW | CVE-2026-42772 | openssl-provider-legacy | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.7 | /var/lib/dpkg/status |
| LOW | CVE-2026-105712 | gpgv | 2.4.8-4ubuntu3 | /var/lib/dpkg/status | |
| LOW | CVE-2026-8932 | curl | 8.18.0-1ubuntu2.4 | 8.18.0-1ubuntu2.5 | /var/lib/dpkg/status |
| LOW | CVE-2026-84784 | openssl-provider-legacy | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-84784 | openssl | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-84784 | libssl3t64 | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2024-56433 | passwd | 1:4.17.4-2ubuntu3 | /var/lib/dpkg/status | |
| LOW | CVE-2026-42772 | openssl | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.7 | /var/lib/dpkg/status |
| LOW | CVE-2026-42772 | libssl3t64 | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.7 | /var/lib/dpkg/status |
| LOW | CVE-2026-8932 | libcurl4t64 | 8.18.0-1ubuntu2.4 | 8.18.0-1ubuntu2.5 | /var/lib/dpkg/status |
| LOW | CVE-2026-75806 | libssl3t64 | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-75806 | openssl | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-75806 | openssl-provider-legacy | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-75804 | openssl-provider-legacy | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-75804 | openssl | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-75804 | libssl3t64 | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-35191 | openssl-provider-legacy | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-35191 | openssl | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-35191 | libssl3t64 | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2024-2236 | libgcrypt20 | 1.12.0-2ubuntu1 | 1.12.0-2ubuntu1.1 | /var/lib/dpkg/status |
| LOW | CVE-2018-10126 | libjpeg-turbo8 | 2.1.5-4ubuntu4 | /var/lib/dpkg/status | |
| LOW | CVE-2026-72897 | openssl-provider-legacy | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-54872 | libssl3t64 | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-54872 | openssl | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-54872 | openssl-provider-legacy | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-54873 | openssl-provider-legacy | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.7 | /var/lib/dpkg/status |
| LOW | CVE-2026-54873 | openssl | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.7 | /var/lib/dpkg/status |
| LOW | CVE-2026-54873 | libssl3t64 | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.7 | /var/lib/dpkg/status |
| LOW | CVE-2026-75805 | openssl-provider-legacy | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-75805 | openssl | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-75805 | libssl3t64 | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-75803 | openssl-provider-legacy | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.5 | /var/lib/dpkg/status |
| LOW | CVE-2026-75803 | openssl | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.5 | /var/lib/dpkg/status |
| LOW | CVE-2026-75803 | libssl3t64 | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.5 | /var/lib/dpkg/status |
| LOW | CVE-2026-77696 | openssl-provider-legacy | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-77696 | openssl | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-77696 | libssl3t64 | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-54875 | libssl3t64 | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-40228 | libudev1 | 259.5-0ubuntu3.4 | /var/lib/dpkg/status | |
| LOW | CVE-2026-40228 | libsystemd0 | 259.5-0ubuntu3.4 | /var/lib/dpkg/status | |
| LOW | CVE-2026-57062 | gpgv | 2.4.8-4ubuntu3 | 2.4.8-4ubuntu3.1 | /var/lib/dpkg/status |
| LOW | CVE-2026-54875 | openssl | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-54875 | openssl-provider-legacy | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2025-5278 | coreutils | 9.5-1ubuntu2+0.0.0~ubuntu25 | 9.7-3ubuntu2.1 | /var/lib/dpkg/status |
| LOW | CVE-2025-5278 | gnu-coreutils | 9.7-3ubuntu2 | 9.7-3ubuntu2.1 | /var/lib/dpkg/status |
| LOW | CVE-2024-56433 | login.defs | 1:4.17.4-2ubuntu3 | /var/lib/dpkg/status | |
| LOW | CVE-2026-42250 | libbz2-1.0 | 1.0.8-6build2 | 1.0.8-6ubuntu0.1 | /var/lib/dpkg/status |
| LOW | CVE-2026-27171 | zlib1g | 1:1.3.dfsg+really1.3.1-1ubuntu3 | 1:1.3.dfsg+really1.3.1-1ubuntu3.1 | /var/lib/dpkg/status |
| LOW | CVE-2026-35189 | libssl3t64 | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-35189 | openssl | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-35189 | openssl-provider-legacy | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-72897 | libssl3t64 | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-72897 | openssl | 3.5.5-1ubuntu3.4 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
ghcr.io/openvoxproject/openvoxdb:latest-alpine (2026-08-27)
Trivy
HIGH 13
MEDIUM 11
LOW 12
UNKNOWN 2
| Severity | ID | Package | Installed | Fixed | Title / target |
|---|---|---|---|---|---|
| HIGH | CVE-2022-41404 | org.ini4j:ini4j | 0.5.4 | org.ini4j: unspecified DoS — Java | |
| HIGH | CVE-2026-53612 | runuser | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: TOCTOU in the mount program when applying post-mount ownership/mode changes — ghcr.io/openvoxproject/openvoxdb:latest-alpine (alpine 3.24.1) |
| HIGH | CVE-2026-91777 | com.fasterxml.jackson.core:jackson-databind | 2.21.5 | 2.21.7, 2.18.11, 2.22.3 | com.fasterxml.jackson.core/jackson-databind: Jackson-databind: Denial of Service via quadratic forward-reference completion — Java |
| HIGH | CVE-2026-91776 | com.fasterxml.jackson.core:jackson-databind | 2.21.5 | 2.18.11, 2.21.7, 2.22.3 | jackson-databind: com.fasterxml.jackson/jackson-core: jackson-databind: Denial of Service via unbounded cache growth in TypeDeserializerBase — Java |
| HIGH | CVE-2026-68497 | com.fasterxml.jackson.core:jackson-databind | 2.21.5 | 2.18.10, 2.21.6, 2.22.2 | com.fasterxml.jackson.core/jackson-databind: tools.jackson.core/jackson-databind: jackson-databind: CPU Denial of Service via unbounded numeric parsing — Java |
| HIGH | CVE-2026-89425 | com.fasterxml.jackson.core:jackson-core | 2.21.5 | 2.21.7, 2.22.3, 2.18.11 | com.fasterxml.jackson.core/jackson-core: Jackson-core: Denial of Service via unbounded StringBuilder growth during malformed token processing — Java |
| HIGH | CVE-2026-89407 | com.fasterxml.jackson.core:jackson-core | 2.21.5 | 2.18.11, 2.21.7, 2.22.3 | com.fasterxml.jackson/jackson-core: tools.jackson.core/jackson-core: Jackson-core: Denial of Service via regular expression backtracking — Java |
| HIGH | CVE-2026-53613 | runuser | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path — ghcr.io/openvoxproject/openvoxdb:latest-alpine (alpine 3.24.1) |
| HIGH | CVE-2026-53614 | runuser | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: SUID mount(8) allows nosuid/noexec bypass via LIBMOUNT_FORCE_MOUNT2 — ghcr.io/openvoxproject/openvoxdb:latest-alpine (alpine 3.24.1) |
| HIGH | CVE-2026-78410 | runuser | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: restricted bind mounts do not pin the source, allowing X-mount.owner/group/mode redirection — ghcr.io/openvoxproject/openvoxdb:latest-alpine (alpine 3.24.1) |
| HIGH | CVE-2026-78409 | runuser | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: X-mount.subdir detached-tree resolution can escape via intermediate symlinks — ghcr.io/openvoxproject/openvoxdb:latest-alpine (alpine 3.24.1) |
| HIGH | CVE-2026-78408 | runuser | 2.42.1-r0 | 2.42.3-r1 | util-linux: util-linux: nsenter --join-cgroup leaks root cgroup migration authority — ghcr.io/openvoxproject/openvoxdb:latest-alpine (alpine 3.24.1) |
| HIGH | CVE-2026-76642 | runuser | 2.42.1-r0 | 2.42.3-r0 | util-linux: util-linux: failed external mount helper still runs privileged X-mount post-hooks — ghcr.io/openvoxproject/openvoxdb:latest-alpine (alpine 3.24.1) |
| MEDIUM | CVE-2026-58055 | nghttp2-libs | 1.69.0-r0 | 1.70.0-r0 | nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests — ghcr.io/openvoxproject/openvoxdb:latest-alpine (alpine 3.24.1) |
| MEDIUM | CVE-2026-27456 | runuser | 2.42.1-r0 | 2.42.3-r0 | util-linux: TOCTOU in the mount program when setting up loop devices — ghcr.io/openvoxproject/openvoxdb:latest-alpine (alpine 3.24.1) |
| MEDIUM | CVE-2026-85091 | zlib | 1.3.2-r0 | 1.3.2-r1 | zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vul ... — ghcr.io/openvoxproject/openvoxdb:latest-alpine (alpine 3.24.1) |
| MEDIUM | CVE-2026-19032 | com.fasterxml.jackson.core:jackson-databind | 2.21.5 | 2.18.10, 2.21.6, 2.22.2 | com.fasterxml.jackson.core/jackson-databind: tools.jackson.core/jackson-databind: Jackson-databind: Uncontrolled URI scheme resolution in Path deserialization — Java |
| MEDIUM | CVE-2026-83557 | com.fasterxml.jackson.core:jackson-databind | 2.21.5 | 2.18.10, 2.21.6, 2.22.2 | com.fasterxml.jackson.core/jackson-databind: tools.jackson.core/jackson-databind: jackson-databind: Path traversal via incomplete type validation — Java |
| MEDIUM | CVE-2026-19931 | curl | 8.21.0-r0 | 8.22.0-r0 | curl: libcurl: Information disclosure via incorrect connection reuse with Negotiate authentication — ghcr.io/openvoxproject/openvoxdb:latest-alpine (alpine 3.24.1) |
| MEDIUM | CVE-2026-80229 | curl | 8.21.0-r0 | 8.22.0-r0 | When performing transfers via libcurl\u2019s multi interface, pooled T ... — ghcr.io/openvoxproject/openvoxdb:latest-alpine (alpine 3.24.1) |
| MEDIUM | CVE-2026-82208 | curl | 8.21.0-r0 | 8.22.0-r0 | curl: libcurl: Improper certificate validation when using wolfSSL CA cache — ghcr.io/openvoxproject/openvoxdb:latest-alpine (alpine 3.24.1) |
| MEDIUM | CVE-2026-82208 | libcurl | 8.21.0-r0 | 8.22.0-r0 | curl: libcurl: Improper certificate validation when using wolfSSL CA cache — ghcr.io/openvoxproject/openvoxdb:latest-alpine (alpine 3.24.1) |
| MEDIUM | CVE-2026-80229 | libcurl | 8.21.0-r0 | 8.22.0-r0 | When performing transfers via libcurl\u2019s multi interface, pooled T ... — ghcr.io/openvoxproject/openvoxdb:latest-alpine (alpine 3.24.1) |
| MEDIUM | CVE-2026-19931 | libcurl | 8.21.0-r0 | 8.22.0-r0 | curl: libcurl: Information disclosure via incorrect connection reuse with Negotiate authentication — ghcr.io/openvoxproject/openvoxdb:latest-alpine (alpine 3.24.1) |
| LOW | CVE-2026-13608 | curl | 8.21.0-r0 | 8.22.0-r0 | curl: curl: Authentication bypass in OpenLDAP SASL negotiation via Man-in-the-Middle (MITM) attack — ghcr.io/openvoxproject/openvoxdb:latest-alpine (alpine 3.24.1) |
| LOW | CVE-2026-18924 | curl | 8.21.0-r0 | 8.22.0-r0 | curl: libcurl: Use-after-free in HTTP/2 Server Push with shared connections — ghcr.io/openvoxproject/openvoxdb:latest-alpine (alpine 3.24.1) |
| LOW | CVE-2026-80230 | curl | 8.21.0-r0 | 8.22.0-r0 | curl: curl: Public key pinning bypass allows unauthenticated connections — ghcr.io/openvoxproject/openvoxdb:latest-alpine (alpine 3.24.1) |
| LOW | CVE-2026-80231 | curl | 8.21.0-r0 | 8.22.0-r0 | curl: curl: Incorrect HTTPS connection reuse with Native CA Store — ghcr.io/openvoxproject/openvoxdb:latest-alpine (alpine 3.24.1) |
| LOW | CVE-2026-80255 | curl | 8.21.0-r0 | 8.22.0-r0 | curl: curl: Information disclosure due to secure cookie attribute bypass — ghcr.io/openvoxproject/openvoxdb:latest-alpine (alpine 3.24.1) |
| LOW | CVE-2026-82209 | curl | 8.21.0-r0 | 8.22.0-r0 | curl: libcurl: Information disclosure via improper Public Suffix List boundary check — ghcr.io/openvoxproject/openvoxdb:latest-alpine (alpine 3.24.1) |
| LOW | CVE-2026-13608 | libcurl | 8.21.0-r0 | 8.22.0-r0 | curl: curl: Authentication bypass in OpenLDAP SASL negotiation via Man-in-the-Middle (MITM) attack — ghcr.io/openvoxproject/openvoxdb:latest-alpine (alpine 3.24.1) |
| LOW | CVE-2026-18924 | libcurl | 8.21.0-r0 | 8.22.0-r0 | curl: libcurl: Use-after-free in HTTP/2 Server Push with shared connections — ghcr.io/openvoxproject/openvoxdb:latest-alpine (alpine 3.24.1) |
| LOW | CVE-2026-80230 | libcurl | 8.21.0-r0 | 8.22.0-r0 | curl: curl: Public key pinning bypass allows unauthenticated connections — ghcr.io/openvoxproject/openvoxdb:latest-alpine (alpine 3.24.1) |
| LOW | CVE-2026-80231 | libcurl | 8.21.0-r0 | 8.22.0-r0 | curl: curl: Incorrect HTTPS connection reuse with Native CA Store — ghcr.io/openvoxproject/openvoxdb:latest-alpine (alpine 3.24.1) |
| LOW | CVE-2026-80255 | libcurl | 8.21.0-r0 | 8.22.0-r0 | curl: curl: Information disclosure due to secure cookie attribute bypass — ghcr.io/openvoxproject/openvoxdb:latest-alpine (alpine 3.24.1) |
| LOW | CVE-2026-82209 | libcurl | 8.21.0-r0 | 8.22.0-r0 | curl: libcurl: Information disclosure via improper Public Suffix List boundary check — ghcr.io/openvoxproject/openvoxdb:latest-alpine (alpine 3.24.1) |
| UNKNOWN | CVE-2026-80256 | curl | 8.21.0-r0 | 8.22.0-r0 | Title Not Available — ghcr.io/openvoxproject/openvoxdb:latest-alpine (alpine 3.24.1) |
| UNKNOWN | CVE-2026-80256 | libcurl | 8.21.0-r0 | 8.22.0-r0 | Title Not Available — ghcr.io/openvoxproject/openvoxdb:latest-alpine (alpine 3.24.1) |
Grype
CRITICAL 4
HIGH 25
MEDIUM 4
UNKNOWN 5
NVD/CPE filtered 57
| Severity | ID | Package | Installed | Fixed | Title / target |
|---|---|---|---|---|---|
| CRITICAL | CVE-2026-19931 | curl | 8.21.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| CRITICAL | CVE-2026-19931 | libcurl | 8.21.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| CRITICAL | CVE-2026-18924 | curl | 8.21.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| CRITICAL | CVE-2026-18924 | libcurl | 8.21.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-13608 | libcurl | 8.21.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | GHSA-cxp5-3px4-pw24 | jackson-databind | 2.21.5 | 2.21.7 | jackson-databind quadratic forward-reference completion — /opt/puppetlabs/server/apps/puppetdb/puppetdb.jar |
| HIGH | GHSA-wv8q-qhhj-9h54 | jackson-databind | 2.21.5 | 2.21.7 | jackson-databind retains every unknown raw type ID — /opt/puppetlabs/server/apps/puppetdb/puppetdb.jar |
| HIGH | CVE-2026-82208 | curl | 8.21.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-82208 | libcurl | 8.21.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-82209 | curl | 8.21.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-82209 | libcurl | 8.21.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-80230 | curl | 8.21.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-80230 | libcurl | 8.21.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-76642 | runuser | 2.42.1-r0 | 2.42.3-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-78408 | runuser | 2.42.1-r0 | 2.42.3-r1 | /lib/apk/db/installed |
| HIGH | CVE-2026-78410 | runuser | 2.42.1-r0 | 2.42.3-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-78409 | runuser | 2.42.1-r0 | 2.42.3-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-13608 | curl | 8.21.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-80255 | libcurl | 8.21.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-80255 | curl | 8.21.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | GHSA-7hhh-6rmp-j9qf | jackson-core | 2.21.5 | 2.21.7 | jackson-core: UTF8DataInputJsonParser._reportInvalidToken() missing maxErrorTokenLength limit -> unbounded StringBuilder growth (DoS) — /opt/puppetlabs/server/apps/puppetdb/puppetdb.jar |
| HIGH | GHSA-p6pp-m3f8-5c89 | jackson-core | 2.21.5 | 2.21.7 | jackson-core: ReDoS: quadratic backtracking in NumberInput.PATTERN_FLOAT via looksLikeValidNumber() — /opt/puppetlabs/server/apps/puppetdb/puppetdb.jar |
| HIGH | CVE-2026-80229 | libcurl | 8.21.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-80229 | curl | 8.21.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | GHSA-q4xh-88c3-wmh7 | jackson-databind | 2.21.5 | 2.21.6 | jackson-databind: Duration XMLGregorianCalendar Unbounded Number Parse DoS — /opt/puppetlabs/server/apps/puppetdb/puppetdb.jar |
| HIGH | GHSA-jr6h-r7vg-f9mc | ini4j | 0.5.4 | org.ini4j allows attackers to cause a Denial of Service (DoS) — /opt/puppetlabs/server/apps/puppetdb/puppetdb.jar | |
| HIGH | CVE-2026-80231 | curl | 8.21.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-85091 | zlib | 1.3.2-r0 | 1.3.2-r1 | /lib/apk/db/installed |
| HIGH | CVE-2026-80231 | libcurl | 8.21.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-27456 | runuser | 2.42.1-r0 | 2.41.4-r0, 2.42.3-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-58055 | nghttp2-libs | 1.69.0-r0 | 1.70.0-r0 | /lib/apk/db/installed |
| MEDIUM | GHSA-wjgm-6hv5-3cvf | jackson-databind | 2.21.5 | 2.21.6 | jackson-databind: Path Deserialization Missing Scheme Allowlist for FileSystemProvider Resolution — /opt/puppetlabs/server/apps/puppetdb/puppetdb.jar |
| MEDIUM | GHSA-gx83-3vf8-gh7j | jackson-databind | 2.21.5 | 2.21.6 | jackson-databind: Comparable missing from DefaultBaseTypeLimitingValidator's unsafe base types (incomplete PolymorphicTypeValidator denylist) — /opt/puppetlabs/server/apps/puppetdb/puppetdb.jar |
| UNKNOWN | CVE-2026-80256 | curl | 8.21.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| UNKNOWN | CVE-2026-80256 | libcurl | 8.21.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| UNKNOWN | CVE-2026-53612 | runuser | 2.42.1-r0 | 2.42.3-r0 | /lib/apk/db/installed |
| UNKNOWN | CVE-2026-53613 | runuser | 2.42.1-r0 | 2.42.3-r0 | /lib/apk/db/installed |
| UNKNOWN | CVE-2026-53614 | runuser | 2.42.1-r0 | 2.42.3-r0 | /lib/apk/db/installed |
Filtered NVD/CPE matches (57)
These broad CPE matches are unconfirmed for the distribution package and excluded from scanner totals.
| Severity | ID | Package | Installed | Fixed | Title / target |
|---|---|---|---|---|---|
| HIGH | CVE-2026-72897 | openssl | 3.5.8-r0 | Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a connection to a different SSL_CTX part way through a handshake may access memory beyond the end of an internal array if the replacement context knows about more provider signature algorithms than the context the connection was created from. Applications which never call SSL_set_SSL_CTX() are not affected. Impact summary: A remote peer may be able to cause a small out-of-bounds read, and in some circumstances a fixed-value out-of-bounds write, on the server heap. This may lead to a Denial of Service. CWE: CWE-787: Out-of-bounds Write Description: A TLS connection records how many certificate slots it has when it is created, taken from the SSL_CTX that created it: the built-in certificate types plus one slot for each provider TLS-SIGALG entry that context was aware of. That count sizes an internal array of per-slot certificate validity flags. An application may replace a connection's SSL_CTX part way through the handshake by calling SSL_set_SSL_CTX(), most commonly from a servername callback in order to serve a different virtual host. Doing so did not refresh the recorded count. A provider signature algorithm's slot index is its position in the list of whichever context resolves it, so if the replacement context is aware of more of them than the original, an algorithm offered by the peer can resolve to an index beyond the end of the array. Processing the peer's signature algorithms then reads one four byte word past the end for each such algorithm and, where the word read is zero, writes a fixed value over it. A peer offering many of them can corrupt heap metadata and abort the process. Only provider signature algorithms which occupy one of the excess slots, and which the server also has configured, have this effect. Codepoints the replacement context does not recognise are discarded without being resolved to a slot, and provider signature algorithms are usable only from TLS 1.3. The two contexts must therefore be aware of different numbers of provider signature algorithms, which requires separate library contexts, a provider loaded between the two being created, or providers which differ in what they advertise - in 4.0, for example, the default provider advertises SM2 where the FIPS provider does not. A deployment meeting the condition is also unable to negotiate the affected algorithms with legitimate clients, since the same stale count hides the corresponding certificates, so the misconfiguration is likely to be noticed. For that reason, and because the configuration is not the default, this issue has been assessed as Low severity. FIPS impact: no No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| HIGH | CVE-2026-72897 | libssl3 | 3.5.8-r0 | Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a connection to a different SSL_CTX part way through a handshake may access memory beyond the end of an internal array if the replacement context knows about more provider signature algorithms than the context the connection was created from. Applications which never call SSL_set_SSL_CTX() are not affected. Impact summary: A remote peer may be able to cause a small out-of-bounds read, and in some circumstances a fixed-value out-of-bounds write, on the server heap. This may lead to a Denial of Service. CWE: CWE-787: Out-of-bounds Write Description: A TLS connection records how many certificate slots it has when it is created, taken from the SSL_CTX that created it: the built-in certificate types plus one slot for each provider TLS-SIGALG entry that context was aware of. That count sizes an internal array of per-slot certificate validity flags. An application may replace a connection's SSL_CTX part way through the handshake by calling SSL_set_SSL_CTX(), most commonly from a servername callback in order to serve a different virtual host. Doing so did not refresh the recorded count. A provider signature algorithm's slot index is its position in the list of whichever context resolves it, so if the replacement context is aware of more of them than the original, an algorithm offered by the peer can resolve to an index beyond the end of the array. Processing the peer's signature algorithms then reads one four byte word past the end for each such algorithm and, where the word read is zero, writes a fixed value over it. A peer offering many of them can corrupt heap metadata and abort the process. Only provider signature algorithms which occupy one of the excess slots, and which the server also has configured, have this effect. Codepoints the replacement context does not recognise are discarded without being resolved to a slot, and provider signature algorithms are usable only from TLS 1.3. The two contexts must therefore be aware of different numbers of provider signature algorithms, which requires separate library contexts, a provider loaded between the two being created, or providers which differ in what they advertise - in 4.0, for example, the default provider advertises SM2 where the FIPS provider does not. A deployment meeting the condition is also unable to negotiate the affected algorithms with legitimate clients, since the same stale count hides the corresponding certificates, so the misconfiguration is likely to be noticed. For that reason, and because the configuration is not the default, this issue has been assessed as Low severity. FIPS impact: no No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| HIGH | CVE-2026-72897 | libcrypto3 | 3.5.8-r0 | Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a connection to a different SSL_CTX part way through a handshake may access memory beyond the end of an internal array if the replacement context knows about more provider signature algorithms than the context the connection was created from. Applications which never call SSL_set_SSL_CTX() are not affected. Impact summary: A remote peer may be able to cause a small out-of-bounds read, and in some circumstances a fixed-value out-of-bounds write, on the server heap. This may lead to a Denial of Service. CWE: CWE-787: Out-of-bounds Write Description: A TLS connection records how many certificate slots it has when it is created, taken from the SSL_CTX that created it: the built-in certificate types plus one slot for each provider TLS-SIGALG entry that context was aware of. That count sizes an internal array of per-slot certificate validity flags. An application may replace a connection's SSL_CTX part way through the handshake by calling SSL_set_SSL_CTX(), most commonly from a servername callback in order to serve a different virtual host. Doing so did not refresh the recorded count. A provider signature algorithm's slot index is its position in the list of whichever context resolves it, so if the replacement context is aware of more of them than the original, an algorithm offered by the peer can resolve to an index beyond the end of the array. Processing the peer's signature algorithms then reads one four byte word past the end for each such algorithm and, where the word read is zero, writes a fixed value over it. A peer offering many of them can corrupt heap metadata and abort the process. Only provider signature algorithms which occupy one of the excess slots, and which the server also has configured, have this effect. Codepoints the replacement context does not recognise are discarded without being resolved to a slot, and provider signature algorithms are usable only from TLS 1.3. The two contexts must therefore be aware of different numbers of provider signature algorithms, which requires separate library contexts, a provider loaded between the two being created, or providers which differ in what they advertise - in 4.0, for example, the default provider advertises SM2 where the FIPS provider does not. A deployment meeting the condition is also unable to negotiate the affected algorithms with legitimate clients, since the same stale count hides the corresponding certificates, so the misconfiguration is likely to be noticed. For that reason, and because the configuration is not the default, this issue has been assessed as Low severity. FIPS impact: no No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| HIGH | CVE-2026-84784 | openssl | 3.5.8-r0 | Issue summary: A malicious remote peer may flood the local QUIC stack with NEW_CONNECTION_ID frames by avoiding a limit check on how many connection IDs the remote QUIC stack can use. Impact summary: The local QUIC stack sends a RETIRE_CONN_ID frame for every NEW_CONNECTION_ID frame it receives. The RETIRE_CONN_ID frame is dispatched via the Control Frame Queue (CFQ). If the remote peer also withholds ACKs, then it can force the local stack to allocate ~400MB (depending on ACK delay). CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: RFC 9000 sections 5.1.1 and 5.1.2 [1] describe the mechanism by which a remote peer can notify the local QUIC stack to change the destination connection ID (a.k.a. CID) the local stack uses to identify the connection at the remote peer. Each CID is associated with a sequence number. The sequence number is transmitted in NEW_CONNECTION_ID and RETIRE_CONNECTION_ID frames to identify the CID which is being either associated with a connection or retired. The remote peer sends a NEW_CONNECTION_ID frame to let the local stack know a new CID is being associated with an existing connection. The NEW_CONNECTION_ID frame carries the new CID, its sequence number, and the retire-prior-to number. The retire-prior-to identifies existing CIDs that are to be retired. The local QUIC stack must send a RETIRE_CONNECTION_ID for every destination CID whose sequence number is less than retire-prior-to. The CID becomes retired after the local stack receives an ACK for its RETIRE_CONNECTION_ID frame. Although the OpenSSL QUIC stack supports at most one destination CID for every connection, it can be tricked into processing more than one RETIRE_CONNECTION_ID frame per connection. The OpenSSL QUIC stack currently retires the destination CID as soon as it receives the NEW_CONNECTION_ID, while in fact the destination CID must be retired after an ACK for the RETIRE_CONNECTION_ID frame is received. Correcting the flawed logic also fixes the backlog growth. [1] https://datatracker.ietf.org/doc/html/rfc9000#name-issuing-connection-ids FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| HIGH | CVE-2026-84784 | libssl3 | 3.5.8-r0 | Issue summary: A malicious remote peer may flood the local QUIC stack with NEW_CONNECTION_ID frames by avoiding a limit check on how many connection IDs the remote QUIC stack can use. Impact summary: The local QUIC stack sends a RETIRE_CONN_ID frame for every NEW_CONNECTION_ID frame it receives. The RETIRE_CONN_ID frame is dispatched via the Control Frame Queue (CFQ). If the remote peer also withholds ACKs, then it can force the local stack to allocate ~400MB (depending on ACK delay). CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: RFC 9000 sections 5.1.1 and 5.1.2 [1] describe the mechanism by which a remote peer can notify the local QUIC stack to change the destination connection ID (a.k.a. CID) the local stack uses to identify the connection at the remote peer. Each CID is associated with a sequence number. The sequence number is transmitted in NEW_CONNECTION_ID and RETIRE_CONNECTION_ID frames to identify the CID which is being either associated with a connection or retired. The remote peer sends a NEW_CONNECTION_ID frame to let the local stack know a new CID is being associated with an existing connection. The NEW_CONNECTION_ID frame carries the new CID, its sequence number, and the retire-prior-to number. The retire-prior-to identifies existing CIDs that are to be retired. The local QUIC stack must send a RETIRE_CONNECTION_ID for every destination CID whose sequence number is less than retire-prior-to. The CID becomes retired after the local stack receives an ACK for its RETIRE_CONNECTION_ID frame. Although the OpenSSL QUIC stack supports at most one destination CID for every connection, it can be tricked into processing more than one RETIRE_CONNECTION_ID frame per connection. The OpenSSL QUIC stack currently retires the destination CID as soon as it receives the NEW_CONNECTION_ID, while in fact the destination CID must be retired after an ACK for the RETIRE_CONNECTION_ID frame is received. Correcting the flawed logic also fixes the backlog growth. [1] https://datatracker.ietf.org/doc/html/rfc9000#name-issuing-connection-ids FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| HIGH | CVE-2026-84784 | libcrypto3 | 3.5.8-r0 | Issue summary: A malicious remote peer may flood the local QUIC stack with NEW_CONNECTION_ID frames by avoiding a limit check on how many connection IDs the remote QUIC stack can use. Impact summary: The local QUIC stack sends a RETIRE_CONN_ID frame for every NEW_CONNECTION_ID frame it receives. The RETIRE_CONN_ID frame is dispatched via the Control Frame Queue (CFQ). If the remote peer also withholds ACKs, then it can force the local stack to allocate ~400MB (depending on ACK delay). CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: RFC 9000 sections 5.1.1 and 5.1.2 [1] describe the mechanism by which a remote peer can notify the local QUIC stack to change the destination connection ID (a.k.a. CID) the local stack uses to identify the connection at the remote peer. Each CID is associated with a sequence number. The sequence number is transmitted in NEW_CONNECTION_ID and RETIRE_CONNECTION_ID frames to identify the CID which is being either associated with a connection or retired. The remote peer sends a NEW_CONNECTION_ID frame to let the local stack know a new CID is being associated with an existing connection. The NEW_CONNECTION_ID frame carries the new CID, its sequence number, and the retire-prior-to number. The retire-prior-to identifies existing CIDs that are to be retired. The local QUIC stack must send a RETIRE_CONNECTION_ID for every destination CID whose sequence number is less than retire-prior-to. The CID becomes retired after the local stack receives an ACK for its RETIRE_CONNECTION_ID frame. Although the OpenSSL QUIC stack supports at most one destination CID for every connection, it can be tricked into processing more than one RETIRE_CONNECTION_ID frame per connection. The OpenSSL QUIC stack currently retires the destination CID as soon as it receives the NEW_CONNECTION_ID, while in fact the destination CID must be retired after an ACK for the RETIRE_CONNECTION_ID frame is received. Correcting the flawed logic also fixes the backlog growth. [1] https://datatracker.ietf.org/doc/html/rfc9000#name-issuing-connection-ids FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| HIGH | CVE-2026-84782 | openssl | 3.5.8-r0 | Issue summary: The DTLS retransmission logic does not correctly handle a handshake message write that is suspended part-way through. The retransmitted message can be read past the message buffer and the retransmission overwrites the internal state the suspended write needs to resume correctly. Impact summary: The retransmitted message can disclose a heap memory to the peer as plaintext handshake data or cause a crash and a Denial of Service when the read reaches an unmapped memory region. CWE: CWE-125: Out-of-bounds Read Description: DTLS handshake messages can be written out in multiple fragments, and a write can suspend mid-message (returning WANT_WRITE) if the underlying transport temporarily cannot accept more data. While such a write is suspended, the DTLS retransmission timer may independently fire and ask the retransmission logic to resend an earlier, already-acknowledged-as-sent message from its retransmit queue. The retransmission logic reused the same internal buffer and position tracking as the message that was still being written, without resetting the position back to the start of the message being retransmitted. As a result the retransmission was read starting from wherever the suspended write had left off, producing a mislabelled message whose body was leftover bytes from the other, larger message still in flight - content that was never meant to be sent at that point, and which could run past the end of the allocated buffer. Separately, even when the retransmission is positioned correctly, allowing it to run to completion while another write is suspended overwrites the same shared bookkeeping that the suspended write depends on to resume. When the application later resumes the suspended write (via a subsequent SSL_read(), SSL_write(), SSL_accept(), or SSL_connect() call), it finds that bookkeeping in a state inconsistent with the message and aborts the process in a debugging build. The fix resets the retransmission's read position to the start of the message before resending, and skips retransmission entirely whenever a handshake write is still suspended, deferring to the next call that resumes it instead. FIPS impact: no The affected code is outside the FIPS module boundary. — /lib/apk/db/installed | |
| HIGH | CVE-2026-84782 | libssl3 | 3.5.8-r0 | Issue summary: The DTLS retransmission logic does not correctly handle a handshake message write that is suspended part-way through. The retransmitted message can be read past the message buffer and the retransmission overwrites the internal state the suspended write needs to resume correctly. Impact summary: The retransmitted message can disclose a heap memory to the peer as plaintext handshake data or cause a crash and a Denial of Service when the read reaches an unmapped memory region. CWE: CWE-125: Out-of-bounds Read Description: DTLS handshake messages can be written out in multiple fragments, and a write can suspend mid-message (returning WANT_WRITE) if the underlying transport temporarily cannot accept more data. While such a write is suspended, the DTLS retransmission timer may independently fire and ask the retransmission logic to resend an earlier, already-acknowledged-as-sent message from its retransmit queue. The retransmission logic reused the same internal buffer and position tracking as the message that was still being written, without resetting the position back to the start of the message being retransmitted. As a result the retransmission was read starting from wherever the suspended write had left off, producing a mislabelled message whose body was leftover bytes from the other, larger message still in flight - content that was never meant to be sent at that point, and which could run past the end of the allocated buffer. Separately, even when the retransmission is positioned correctly, allowing it to run to completion while another write is suspended overwrites the same shared bookkeeping that the suspended write depends on to resume. When the application later resumes the suspended write (via a subsequent SSL_read(), SSL_write(), SSL_accept(), or SSL_connect() call), it finds that bookkeeping in a state inconsistent with the message and aborts the process in a debugging build. The fix resets the retransmission's read position to the start of the message before resending, and skips retransmission entirely whenever a handshake write is still suspended, deferring to the next call that resumes it instead. FIPS impact: no The affected code is outside the FIPS module boundary. — /lib/apk/db/installed | |
| HIGH | CVE-2026-84782 | libcrypto3 | 3.5.8-r0 | Issue summary: The DTLS retransmission logic does not correctly handle a handshake message write that is suspended part-way through. The retransmitted message can be read past the message buffer and the retransmission overwrites the internal state the suspended write needs to resume correctly. Impact summary: The retransmitted message can disclose a heap memory to the peer as plaintext handshake data or cause a crash and a Denial of Service when the read reaches an unmapped memory region. CWE: CWE-125: Out-of-bounds Read Description: DTLS handshake messages can be written out in multiple fragments, and a write can suspend mid-message (returning WANT_WRITE) if the underlying transport temporarily cannot accept more data. While such a write is suspended, the DTLS retransmission timer may independently fire and ask the retransmission logic to resend an earlier, already-acknowledged-as-sent message from its retransmit queue. The retransmission logic reused the same internal buffer and position tracking as the message that was still being written, without resetting the position back to the start of the message being retransmitted. As a result the retransmission was read starting from wherever the suspended write had left off, producing a mislabelled message whose body was leftover bytes from the other, larger message still in flight - content that was never meant to be sent at that point, and which could run past the end of the allocated buffer. Separately, even when the retransmission is positioned correctly, allowing it to run to completion while another write is suspended overwrites the same shared bookkeeping that the suspended write depends on to resume. When the application later resumes the suspended write (via a subsequent SSL_read(), SSL_write(), SSL_accept(), or SSL_connect() call), it finds that bookkeeping in a state inconsistent with the message and aborts the process in a debugging build. The fix resets the retransmission's read position to the start of the message before resending, and skips retransmission entirely whenever a handshake write is still suspended, deferring to the next call that resumes it instead. FIPS impact: no The affected code is outside the FIPS module boundary. — /lib/apk/db/installed | |
| HIGH | CVE-2026-54873 | openssl | 3.5.8-r0 | Issue summary: QUIC process may keep memory for QUIC packet buffer for much longer period than necessary. Impact summary: Remote peer can exploit this vulnerability by sending maliciously crafted packets, making the local QUIC stack to keep the memory for packet buffers allocated. The time for which the memory remains allocated is entirely under the control of the potentially malicious remote peer. CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: To save copy operation from the packet buffer to the stream reassemble buffer the QUIC stack leaves the stream data on the packet buffer waiting to be copied to a buffer provided by the local receiving application. The QUIC stack releases a reference to the packet buffer only after the data are copied to the application buffer. This design is more efficient for legitimate data transfers but enables an attacker to allocate a lot more memory than actually required by the data kept in the receiving stream buffer. To mitigate the vulnerability, the QUIC stack now calculates and monitors memory overhead for every stream. The memory overhead for a single stream frame is calculated as a difference between the size of the whole packet that carries the stream frame and the size of the stream frame itself. The memory overhead for a single stream frame is added to the total (cumulative) memory overhead QUIC stack keeps for each stream. Once the cumulative memory overhead exceeds 64kB, the QUIC stack moves the stream frame data from the packet buffer to the stream buffer, starting with the next packet received. FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| HIGH | CVE-2026-54873 | libssl3 | 3.5.8-r0 | Issue summary: QUIC process may keep memory for QUIC packet buffer for much longer period than necessary. Impact summary: Remote peer can exploit this vulnerability by sending maliciously crafted packets, making the local QUIC stack to keep the memory for packet buffers allocated. The time for which the memory remains allocated is entirely under the control of the potentially malicious remote peer. CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: To save copy operation from the packet buffer to the stream reassemble buffer the QUIC stack leaves the stream data on the packet buffer waiting to be copied to a buffer provided by the local receiving application. The QUIC stack releases a reference to the packet buffer only after the data are copied to the application buffer. This design is more efficient for legitimate data transfers but enables an attacker to allocate a lot more memory than actually required by the data kept in the receiving stream buffer. To mitigate the vulnerability, the QUIC stack now calculates and monitors memory overhead for every stream. The memory overhead for a single stream frame is calculated as a difference between the size of the whole packet that carries the stream frame and the size of the stream frame itself. The memory overhead for a single stream frame is added to the total (cumulative) memory overhead QUIC stack keeps for each stream. Once the cumulative memory overhead exceeds 64kB, the QUIC stack moves the stream frame data from the packet buffer to the stream buffer, starting with the next packet received. FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| HIGH | CVE-2026-54873 | libcrypto3 | 3.5.8-r0 | Issue summary: QUIC process may keep memory for QUIC packet buffer for much longer period than necessary. Impact summary: Remote peer can exploit this vulnerability by sending maliciously crafted packets, making the local QUIC stack to keep the memory for packet buffers allocated. The time for which the memory remains allocated is entirely under the control of the potentially malicious remote peer. CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: To save copy operation from the packet buffer to the stream reassemble buffer the QUIC stack leaves the stream data on the packet buffer waiting to be copied to a buffer provided by the local receiving application. The QUIC stack releases a reference to the packet buffer only after the data are copied to the application buffer. This design is more efficient for legitimate data transfers but enables an attacker to allocate a lot more memory than actually required by the data kept in the receiving stream buffer. To mitigate the vulnerability, the QUIC stack now calculates and monitors memory overhead for every stream. The memory overhead for a single stream frame is calculated as a difference between the size of the whole packet that carries the stream frame and the size of the stream frame itself. The memory overhead for a single stream frame is added to the total (cumulative) memory overhead QUIC stack keeps for each stream. Once the cumulative memory overhead exceeds 64kB, the QUIC stack moves the stream frame data from the packet buffer to the stream buffer, starting with the next packet received. FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-5704 | tar | 1.35-r5 | A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-35189 | libcrypto3 | 3.5.8-r0 | Issue summary: A certificate with many nameRelativeToCRLIssuer CRL distribution points causes disproportionate heap growth when OpenSSL caches X.509 extensions. Impact summary: Receiving a crafted certificate from a malicious peer can lead to significant memory pressure and possible Denial of Service in clients or in servers that solicit client certificates. CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: A certificate or a set of certificates that fits under the limit for size of certificates accepted from the peer (~100 KiB) can result in allocation of several hundred MiB of resident memory on the receiving side during a normal TLS handshake. This may be enough to crash the client or server, if multiple concurrent connections lead to similarly large memory allocations. The fix postpones processing of the CRL distribution points extensions in certificates to the time when the processed value is required for CRL processing. This avoids keeping large memory allocations for a long time when such certificates are received. FIPS impact: no The affected code is outside the FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-35189 | libssl3 | 3.5.8-r0 | Issue summary: A certificate with many nameRelativeToCRLIssuer CRL distribution points causes disproportionate heap growth when OpenSSL caches X.509 extensions. Impact summary: Receiving a crafted certificate from a malicious peer can lead to significant memory pressure and possible Denial of Service in clients or in servers that solicit client certificates. CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: A certificate or a set of certificates that fits under the limit for size of certificates accepted from the peer (~100 KiB) can result in allocation of several hundred MiB of resident memory on the receiving side during a normal TLS handshake. This may be enough to crash the client or server, if multiple concurrent connections lead to similarly large memory allocations. The fix postpones processing of the CRL distribution points extensions in certificates to the time when the processed value is required for CRL processing. This avoids keeping large memory allocations for a long time when such certificates are received. FIPS impact: no The affected code is outside the FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-35189 | openssl | 3.5.8-r0 | Issue summary: A certificate with many nameRelativeToCRLIssuer CRL distribution points causes disproportionate heap growth when OpenSSL caches X.509 extensions. Impact summary: Receiving a crafted certificate from a malicious peer can lead to significant memory pressure and possible Denial of Service in clients or in servers that solicit client certificates. CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: A certificate or a set of certificates that fits under the limit for size of certificates accepted from the peer (~100 KiB) can result in allocation of several hundred MiB of resident memory on the receiving side during a normal TLS handshake. This may be enough to crash the client or server, if multiple concurrent connections lead to similarly large memory allocations. The fix postpones processing of the CRL distribution points extensions in certificates to the time when the processed value is required for CRL processing. This avoids keeping large memory allocations for a long time when such certificates are received. FIPS impact: no The affected code is outside the FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-75805 | libcrypto3 | 3.5.8-r0 | Issue summary: A CMP client that requests certificate revocation on the basis of a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when processing a crafted revocation response. Impact summary: The NULL pointer dereference happens on a read which leads to a crash and a Denial of Service for the affected client application. CWE: CWE-476: NULL-pointer dereference Description: A CMP client revoking a certificate has to tell the server which certificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the certificate itself or its issuer name and serial number. This is 'openssl cmp -cmd rr -csr <file>' on the command line, or OSSL_CMP_exec_RR_ses() with the certificate supplied via OSSL_CMP_CTX_set1_p10CSR() through the API. A CSR does not contain the issuer name and serial number of the certificate, so the client does not send them. A server may optionally name the certificate it revoked in its response, and the client then compares that name against what it sent. Having sent neither an issuer name nor a serial number, it has nothing to compare against, and a server returning a specially crafted name causes the client to read from a NULL pointer and crash. The revocation response is checked for valid message protection before the affected code is reached, so an attacker must be a malicious or compromised CMP server, or a man-in-the-middle in possession of the secret used for message protection. Clients that identify the certificate to be revoked by a certificate or by issuer and serial number rather than by a PKCS#10 CSR are not affected. FIPS impact: no No FIPS modules are affected by this issue, as the CMP protocol implementation is outside the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-75805 | libssl3 | 3.5.8-r0 | Issue summary: A CMP client that requests certificate revocation on the basis of a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when processing a crafted revocation response. Impact summary: The NULL pointer dereference happens on a read which leads to a crash and a Denial of Service for the affected client application. CWE: CWE-476: NULL-pointer dereference Description: A CMP client revoking a certificate has to tell the server which certificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the certificate itself or its issuer name and serial number. This is 'openssl cmp -cmd rr -csr <file>' on the command line, or OSSL_CMP_exec_RR_ses() with the certificate supplied via OSSL_CMP_CTX_set1_p10CSR() through the API. A CSR does not contain the issuer name and serial number of the certificate, so the client does not send them. A server may optionally name the certificate it revoked in its response, and the client then compares that name against what it sent. Having sent neither an issuer name nor a serial number, it has nothing to compare against, and a server returning a specially crafted name causes the client to read from a NULL pointer and crash. The revocation response is checked for valid message protection before the affected code is reached, so an attacker must be a malicious or compromised CMP server, or a man-in-the-middle in possession of the secret used for message protection. Clients that identify the certificate to be revoked by a certificate or by issuer and serial number rather than by a PKCS#10 CSR are not affected. FIPS impact: no No FIPS modules are affected by this issue, as the CMP protocol implementation is outside the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-75805 | openssl | 3.5.8-r0 | Issue summary: A CMP client that requests certificate revocation on the basis of a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when processing a crafted revocation response. Impact summary: The NULL pointer dereference happens on a read which leads to a crash and a Denial of Service for the affected client application. CWE: CWE-476: NULL-pointer dereference Description: A CMP client revoking a certificate has to tell the server which certificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the certificate itself or its issuer name and serial number. This is 'openssl cmp -cmd rr -csr <file>' on the command line, or OSSL_CMP_exec_RR_ses() with the certificate supplied via OSSL_CMP_CTX_set1_p10CSR() through the API. A CSR does not contain the issuer name and serial number of the certificate, so the client does not send them. A server may optionally name the certificate it revoked in its response, and the client then compares that name against what it sent. Having sent neither an issuer name nor a serial number, it has nothing to compare against, and a server returning a specially crafted name causes the client to read from a NULL pointer and crash. The revocation response is checked for valid message protection before the affected code is reached, so an attacker must be a malicious or compromised CMP server, or a man-in-the-middle in possession of the secret used for message protection. Clients that identify the certificate to be revoked by a certificate or by issuer and serial number rather than by a PKCS#10 CSR are not affected. FIPS impact: no No FIPS modules are affected by this issue, as the CMP protocol implementation is outside the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-56391 | coreutils | 9.11-r0 | GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. This incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input. When running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure. This issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-56391 | coreutils-env | 9.11-r0 | GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. This incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input. When running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure. This issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-56391 | coreutils-fmt | 9.11-r0 | GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. This incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input. When running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure. This issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-56391 | coreutils-sha512sum | 9.11-r0 | GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. This incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input. When running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure. This issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-56392 | coreutils | 9.11-r0 | GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer. When processing crafted input, subsequent writes exceed the allocated memory, leading to an out‑of‑bounds heap write. When running GNU coreutils unexpand with attacker-provided large tab stop (-t) arguments, this behavior leads to a crash and potentially achieve a heap write primitive depending on memory layout. This issue has been fixed in the commit b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-56392 | coreutils-env | 9.11-r0 | GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer. When processing crafted input, subsequent writes exceed the allocated memory, leading to an out‑of‑bounds heap write. When running GNU coreutils unexpand with attacker-provided large tab stop (-t) arguments, this behavior leads to a crash and potentially achieve a heap write primitive depending on memory layout. This issue has been fixed in the commit b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-56392 | coreutils-fmt | 9.11-r0 | GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer. When processing crafted input, subsequent writes exceed the allocated memory, leading to an out‑of‑bounds heap write. When running GNU coreutils unexpand with attacker-provided large tab stop (-t) arguments, this behavior leads to a crash and potentially achieve a heap write primitive depending on memory layout. This issue has been fixed in the commit b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-56392 | coreutils-sha512sum | 9.11-r0 | GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer. When processing crafted input, subsequent writes exceed the allocated memory, leading to an out‑of‑bounds heap write. When running GNU coreutils unexpand with attacker-provided large tab stop (-t) arguments, this behavior leads to a crash and potentially achieve a heap write primitive depending on memory layout. This issue has been fixed in the commit b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-18508 | tar | 1.35-r5 | A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-18477 | tar | 1.35-r5 | A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. This could lead to unauthorized file modification or, in some cases, privilege escalation. Exploitation does not require the attacker to modify or craft the archive, and standard backup and restore workflows—including extracting into a newly created directory without using the -P option do not mitigate the issue. — /lib/apk/db/installed | |
| MEDIUM | CVE-2016-2781 | coreutils | 9.11-r0 | chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer. — /lib/apk/db/installed | |
| MEDIUM | CVE-2016-2781 | coreutils-env | 9.11-r0 | chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer. — /lib/apk/db/installed | |
| MEDIUM | CVE-2016-2781 | coreutils-fmt | 9.11-r0 | chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer. — /lib/apk/db/installed | |
| MEDIUM | CVE-2016-2781 | coreutils-sha512sum | 9.11-r0 | chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-75806 | libcrypto3 | 3.5.8-r0 | Issue summary: An established DTLS 1.2 association using an AEAD cipher suite can be terminated by a single unauthenticated datagram whose encrypted fragment is shorter than the mandatory explicit IV and authentication tag overhead. Impact summary: An attacker who can send a datagram that is routed to an existing DTLS 1.2 association can tear that association down without knowing any key material. This is a Denial of Service limited to the targeted association. There is no memory safety or confidentiality impact. CWE: CWE-1284: Improper Validation of Specified Quantity in Input Description: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher suite carries an explicit IV followed by the ciphertext and an authentication tag. When decrypting such a record the record layer passed the record length to the cipher implementation before checking that the record was long enough to contain the explicit IV and the tag. For a record shorter than that overhead the cipher implementation rejected the impossible length, and the record layer treated this as an internal failure and raised a fatal internal_error alert instead of treating the record as one that failed authentication. In TLS 1.2 the same record causes a fatal internal_error alert instead of the expected bad_record_mac alert. Since any undecryptable record already terminates a TLS connection, this is a protocol conformance issue rather than a security issue in TLS. The fix validates the record length against the explicit IV and tag length before any AEAD processing, so that TLS reports bad_record_mac and DTLS silently discards the record. FIPS impact: no The affected code is outside the FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-75806 | libssl3 | 3.5.8-r0 | Issue summary: An established DTLS 1.2 association using an AEAD cipher suite can be terminated by a single unauthenticated datagram whose encrypted fragment is shorter than the mandatory explicit IV and authentication tag overhead. Impact summary: An attacker who can send a datagram that is routed to an existing DTLS 1.2 association can tear that association down without knowing any key material. This is a Denial of Service limited to the targeted association. There is no memory safety or confidentiality impact. CWE: CWE-1284: Improper Validation of Specified Quantity in Input Description: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher suite carries an explicit IV followed by the ciphertext and an authentication tag. When decrypting such a record the record layer passed the record length to the cipher implementation before checking that the record was long enough to contain the explicit IV and the tag. For a record shorter than that overhead the cipher implementation rejected the impossible length, and the record layer treated this as an internal failure and raised a fatal internal_error alert instead of treating the record as one that failed authentication. In TLS 1.2 the same record causes a fatal internal_error alert instead of the expected bad_record_mac alert. Since any undecryptable record already terminates a TLS connection, this is a protocol conformance issue rather than a security issue in TLS. The fix validates the record length against the explicit IV and tag length before any AEAD processing, so that TLS reports bad_record_mac and DTLS silently discards the record. FIPS impact: no The affected code is outside the FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-75806 | openssl | 3.5.8-r0 | Issue summary: An established DTLS 1.2 association using an AEAD cipher suite can be terminated by a single unauthenticated datagram whose encrypted fragment is shorter than the mandatory explicit IV and authentication tag overhead. Impact summary: An attacker who can send a datagram that is routed to an existing DTLS 1.2 association can tear that association down without knowing any key material. This is a Denial of Service limited to the targeted association. There is no memory safety or confidentiality impact. CWE: CWE-1284: Improper Validation of Specified Quantity in Input Description: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher suite carries an explicit IV followed by the ciphertext and an authentication tag. When decrypting such a record the record layer passed the record length to the cipher implementation before checking that the record was long enough to contain the explicit IV and the tag. For a record shorter than that overhead the cipher implementation rejected the impossible length, and the record layer treated this as an internal failure and raised a fatal internal_error alert instead of treating the record as one that failed authentication. In TLS 1.2 the same record causes a fatal internal_error alert instead of the expected bad_record_mac alert. Since any undecryptable record already terminates a TLS connection, this is a protocol conformance issue rather than a security issue in TLS. The fix validates the record length against the explicit IV and tag length before any AEAD processing, so that TLS reports bad_record_mac and DTLS silently discards the record. FIPS impact: no The affected code is outside the FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-75804 | libcrypto3 | 3.5.8-r0 | Issue summary: OpenSSL QUIC stack does not enforce connection level flow control for streams. Remote peers may send more bytes as long as they fit within the stream flow control limits. Impact summary: A malicious remote peer may exploit the lack of connection flow control for streams to make the QUIC stack receive ~100MB of memory instead of 768 KiB (default flow control window size). CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: The local QUIC stack advertises two flow control limits to its remote peer: stream flow control limit and connection flow control limit. The remote peer must follow both limits when transmitting stream data. Whenever the local QUIC stack receives a stream frame, it validates that the size of the received stream frame stays within flow control limits. If either limit is exceeded (stream level or connection level), then the QUIC stack must close the connection with a flow control error. The vulnerable OpenSSL QUIC stack enforces the stream-level but not the connection-level limit. To exploit the issue, three conditions must be met: - the remote peer opens several streams - each stream must stay within the stream-level flow control limit - there must be no zero-offset byte sent on any of the streams (to prevent the vulnerable QUIC stack from consuming data). By meeting the conditions above, the remote peer may make the local stack allocate 2 x MAX_STREAMS x (stream flow control limit) bytes of memory. MAX_STREAMS defaults to 100, and the limit applies to both bidirectional and unidirectional streams, making it 200 in total. The default flow control window for a stream is 512kB. The remote peer may force the vulnerable QUIC stack to allocate 100MB of heap per connection. FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-75804 | libssl3 | 3.5.8-r0 | Issue summary: OpenSSL QUIC stack does not enforce connection level flow control for streams. Remote peers may send more bytes as long as they fit within the stream flow control limits. Impact summary: A malicious remote peer may exploit the lack of connection flow control for streams to make the QUIC stack receive ~100MB of memory instead of 768 KiB (default flow control window size). CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: The local QUIC stack advertises two flow control limits to its remote peer: stream flow control limit and connection flow control limit. The remote peer must follow both limits when transmitting stream data. Whenever the local QUIC stack receives a stream frame, it validates that the size of the received stream frame stays within flow control limits. If either limit is exceeded (stream level or connection level), then the QUIC stack must close the connection with a flow control error. The vulnerable OpenSSL QUIC stack enforces the stream-level but not the connection-level limit. To exploit the issue, three conditions must be met: - the remote peer opens several streams - each stream must stay within the stream-level flow control limit - there must be no zero-offset byte sent on any of the streams (to prevent the vulnerable QUIC stack from consuming data). By meeting the conditions above, the remote peer may make the local stack allocate 2 x MAX_STREAMS x (stream flow control limit) bytes of memory. MAX_STREAMS defaults to 100, and the limit applies to both bidirectional and unidirectional streams, making it 200 in total. The default flow control window for a stream is 512kB. The remote peer may force the vulnerable QUIC stack to allocate 100MB of heap per connection. FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-60876 | ssl_client | 1.37.0-r31 | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-60876 | busybox-binsh | 1.37.0-r31 | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-75804 | openssl | 3.5.8-r0 | Issue summary: OpenSSL QUIC stack does not enforce connection level flow control for streams. Remote peers may send more bytes as long as they fit within the stream flow control limits. Impact summary: A malicious remote peer may exploit the lack of connection flow control for streams to make the QUIC stack receive ~100MB of memory instead of 768 KiB (default flow control window size). CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: The local QUIC stack advertises two flow control limits to its remote peer: stream flow control limit and connection flow control limit. The remote peer must follow both limits when transmitting stream data. Whenever the local QUIC stack receives a stream frame, it validates that the size of the received stream frame stays within flow control limits. If either limit is exceeded (stream level or connection level), then the QUIC stack must close the connection with a flow control error. The vulnerable OpenSSL QUIC stack enforces the stream-level but not the connection-level limit. To exploit the issue, three conditions must be met: - the remote peer opens several streams - each stream must stay within the stream-level flow control limit - there must be no zero-offset byte sent on any of the streams (to prevent the vulnerable QUIC stack from consuming data). By meeting the conditions above, the remote peer may make the local stack allocate 2 x MAX_STREAMS x (stream flow control limit) bytes of memory. MAX_STREAMS defaults to 100, and the limit applies to both bidirectional and unidirectional streams, making it 200 in total. The default flow control window for a stream is 512kB. The remote peer may force the vulnerable QUIC stack to allocate 100MB of heap per connection. FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-42772 | libcrypto3 | 3.5.8-r0 | Issue summary: The QUIC stream reassembly algorithm performance deteriorates progressively as packets are arriving out of order. The worst case has a quadratic complexity proportional to the number of stream frames kept in the buffer for the received stream data. Impact summary: A remote QUIC peer that completes the handshake can create a connection-scoped CPU pressure and potentially a Denial of Service using compliant STREAM frames inside the advertised receive window, with low attacker bandwidth. CWE: CWE-407: Inefficient Algorithmic Complexity Description: OpenSSL manages received QUIC stream fragments using a doubly-linked list. While it optimizes for append operations (at the end of the list), it falls back to a head-to-tail linear search for any fragment that does not immediately follow the current `tail`. By manipulating the sequence of offsets, an attacker can force the server to perform O(n^2) operations, consuming excessive CPU time for the QUIC process. FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-42772 | libssl3 | 3.5.8-r0 | Issue summary: The QUIC stream reassembly algorithm performance deteriorates progressively as packets are arriving out of order. The worst case has a quadratic complexity proportional to the number of stream frames kept in the buffer for the received stream data. Impact summary: A remote QUIC peer that completes the handshake can create a connection-scoped CPU pressure and potentially a Denial of Service using compliant STREAM frames inside the advertised receive window, with low attacker bandwidth. CWE: CWE-407: Inefficient Algorithmic Complexity Description: OpenSSL manages received QUIC stream fragments using a doubly-linked list. While it optimizes for append operations (at the end of the list), it falls back to a head-to-tail linear search for any fragment that does not immediately follow the current `tail`. By manipulating the sequence of offsets, an attacker can force the server to perform O(n^2) operations, consuming excessive CPU time for the QUIC process. FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-60876 | busybox | 1.37.0-r31 | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-42772 | openssl | 3.5.8-r0 | Issue summary: The QUIC stream reassembly algorithm performance deteriorates progressively as packets are arriving out of order. The worst case has a quadratic complexity proportional to the number of stream frames kept in the buffer for the received stream data. Impact summary: A remote QUIC peer that completes the handshake can create a connection-scoped CPU pressure and potentially a Denial of Service using compliant STREAM frames inside the advertised receive window, with low attacker bandwidth. CWE: CWE-407: Inefficient Algorithmic Complexity Description: OpenSSL manages received QUIC stream fragments using a doubly-linked list. While it optimizes for append operations (at the end of the list), it falls back to a head-to-tail linear search for any fragment that does not immediately follow the current `tail`. By manipulating the sequence of offsets, an attacker can force the server to perform O(n^2) operations, consuming excessive CPU time for the QUIC process. FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| LOW | CVE-2026-77696 | openssl | 3.5.8-r0 | Issue summary: SM2 signature generation uses non-constant-time arithmetic on secret values, forming a timing side-channel. Impact summary: An attacker able to measure SM2 signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key. CWE: CWE-208: Observable Timing Discrepancy Description: SM2 signature generation computes the signature value using variable-time BIGNUM operations on the secret nonce and the private key, so the time taken to produce an SM2 signature depends on these secret values, forming a timing side-channel. Applications performing SM2 signature generation are affected on all platforms. FIPS Impact: no SM2 is not a FIPS algorithm. — /lib/apk/db/installed | |
| LOW | CVE-2026-77696 | libssl3 | 3.5.8-r0 | Issue summary: SM2 signature generation uses non-constant-time arithmetic on secret values, forming a timing side-channel. Impact summary: An attacker able to measure SM2 signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key. CWE: CWE-208: Observable Timing Discrepancy Description: SM2 signature generation computes the signature value using variable-time BIGNUM operations on the secret nonce and the private key, so the time taken to produce an SM2 signature depends on these secret values, forming a timing side-channel. Applications performing SM2 signature generation are affected on all platforms. FIPS Impact: no SM2 is not a FIPS algorithm. — /lib/apk/db/installed | |
| LOW | CVE-2026-77696 | libcrypto3 | 3.5.8-r0 | Issue summary: SM2 signature generation uses non-constant-time arithmetic on secret values, forming a timing side-channel. Impact summary: An attacker able to measure SM2 signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key. CWE: CWE-208: Observable Timing Discrepancy Description: SM2 signature generation computes the signature value using variable-time BIGNUM operations on the secret nonce and the private key, so the time taken to produce an SM2 signature depends on these secret values, forming a timing side-channel. Applications performing SM2 signature generation are affected on all platforms. FIPS Impact: no SM2 is not a FIPS algorithm. — /lib/apk/db/installed | |
| LOW | CVE-2026-35191 | libcrypto3 | 3.5.8-r0 | Issue summary: The OpenSSL QUIC server, when configured to not preform address validation, can be forced to count incoming packets multiple times in its unvalidated credit computation, leading to a violation of the RFC 9000 unvalidated connection amplification limit of 3 times the amount of data received. Impact summary: A remote attacker able to spoof packets to a server using the OpenSSL QUIC implementation might use the server for an amplification of a DDoS attack. CWE: CWE-440: Expected Behavior Violation Description: OpenSSL's QUIC stack, when operating as a server, enforces client address validation (RFC 9000, Section 8), to confirm the peer address is not used for a traffic amplification attack. If this feature is disabled on the server, the QUIC stack limits the amount of server data that can be sent to 3 times the amount of data received from the peer address, until such time as the TLS handshake is completed. The OpenSSL QUIC server, when operating in non-validation mode, adds the length of the whole datagram received to the unvalidated credit limit when processing each QUIC packet in the datagram. A remote peer may, after establishing a connection with an initial client hello frame, send a subsequent datagram containing multiple QUIC packets, leading the server to account the entire datagram length for each packet in the datagram, resulting in the server believing that the peer has sent more data than it actually has, thereby violating the 3x amplification limit mandated by the RFC. FIPS impact: no As the QUIC stack lives outside the FIPS module boundary, no FIPS modules are affected by this CVE. — /lib/apk/db/installed | |
| LOW | CVE-2026-35191 | libssl3 | 3.5.8-r0 | Issue summary: The OpenSSL QUIC server, when configured to not preform address validation, can be forced to count incoming packets multiple times in its unvalidated credit computation, leading to a violation of the RFC 9000 unvalidated connection amplification limit of 3 times the amount of data received. Impact summary: A remote attacker able to spoof packets to a server using the OpenSSL QUIC implementation might use the server for an amplification of a DDoS attack. CWE: CWE-440: Expected Behavior Violation Description: OpenSSL's QUIC stack, when operating as a server, enforces client address validation (RFC 9000, Section 8), to confirm the peer address is not used for a traffic amplification attack. If this feature is disabled on the server, the QUIC stack limits the amount of server data that can be sent to 3 times the amount of data received from the peer address, until such time as the TLS handshake is completed. The OpenSSL QUIC server, when operating in non-validation mode, adds the length of the whole datagram received to the unvalidated credit limit when processing each QUIC packet in the datagram. A remote peer may, after establishing a connection with an initial client hello frame, send a subsequent datagram containing multiple QUIC packets, leading the server to account the entire datagram length for each packet in the datagram, resulting in the server believing that the peer has sent more data than it actually has, thereby violating the 3x amplification limit mandated by the RFC. FIPS impact: no As the QUIC stack lives outside the FIPS module boundary, no FIPS modules are affected by this CVE. — /lib/apk/db/installed | |
| LOW | CVE-2026-54872 | openssl | 3.5.8-r0 | Issue summary: The generic elliptic-curve scalar multiplication used for ECDSA and SM2 signature operations with curves that do not have a dedicated implementation leaks information about the secret nonce through timing. Impact summary: An attacker able to measure signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key. CWE: CWE-208: Observable Timing Discrepancy Description: The generic elliptic-curve scalar multiplication used for curves that do not have a dedicated constant-time implementation pads the secret scalar with non-constant-time BIGNUM operations, so the time taken depends on the value of the secret scalar derived from the ECDSA and SM2 nonce. The leak is very small; observing it requires a large number of measurements. The effect is largest for curves whose group order lies on a machine-word boundary, such as brainpoolP384r1. Applications using ECDSA signing over the Brainpool and other generic prime curves, and SM2 signing on platforms that use the generic implementation, are vulnerable to this issue. The NIST curves P-256, P-384 and P-521 use dedicated constant-time implementations and are not affected. FIPS Impact: no The FIPS modules are not affected: the approved NIST curves used in the FIPS provider have dedicated constant-time implementations and do not use the affected code path. — /lib/apk/db/installed | |
| LOW | CVE-2026-54872 | libssl3 | 3.5.8-r0 | Issue summary: The generic elliptic-curve scalar multiplication used for ECDSA and SM2 signature operations with curves that do not have a dedicated implementation leaks information about the secret nonce through timing. Impact summary: An attacker able to measure signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key. CWE: CWE-208: Observable Timing Discrepancy Description: The generic elliptic-curve scalar multiplication used for curves that do not have a dedicated constant-time implementation pads the secret scalar with non-constant-time BIGNUM operations, so the time taken depends on the value of the secret scalar derived from the ECDSA and SM2 nonce. The leak is very small; observing it requires a large number of measurements. The effect is largest for curves whose group order lies on a machine-word boundary, such as brainpoolP384r1. Applications using ECDSA signing over the Brainpool and other generic prime curves, and SM2 signing on platforms that use the generic implementation, are vulnerable to this issue. The NIST curves P-256, P-384 and P-521 use dedicated constant-time implementations and are not affected. FIPS Impact: no The FIPS modules are not affected: the approved NIST curves used in the FIPS provider have dedicated constant-time implementations and do not use the affected code path. — /lib/apk/db/installed | |
| LOW | CVE-2026-54872 | libcrypto3 | 3.5.8-r0 | Issue summary: The generic elliptic-curve scalar multiplication used for ECDSA and SM2 signature operations with curves that do not have a dedicated implementation leaks information about the secret nonce through timing. Impact summary: An attacker able to measure signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key. CWE: CWE-208: Observable Timing Discrepancy Description: The generic elliptic-curve scalar multiplication used for curves that do not have a dedicated constant-time implementation pads the secret scalar with non-constant-time BIGNUM operations, so the time taken depends on the value of the secret scalar derived from the ECDSA and SM2 nonce. The leak is very small; observing it requires a large number of measurements. The effect is largest for curves whose group order lies on a machine-word boundary, such as brainpoolP384r1. Applications using ECDSA signing over the Brainpool and other generic prime curves, and SM2 signing on platforms that use the generic implementation, are vulnerable to this issue. The NIST curves P-256, P-384 and P-521 use dedicated constant-time implementations and are not affected. FIPS Impact: no The FIPS modules are not affected: the approved NIST curves used in the FIPS provider have dedicated constant-time implementations and do not use the affected code path. — /lib/apk/db/installed | |
| LOW | CVE-2026-35191 | openssl | 3.5.8-r0 | Issue summary: The OpenSSL QUIC server, when configured to not preform address validation, can be forced to count incoming packets multiple times in its unvalidated credit computation, leading to a violation of the RFC 9000 unvalidated connection amplification limit of 3 times the amount of data received. Impact summary: A remote attacker able to spoof packets to a server using the OpenSSL QUIC implementation might use the server for an amplification of a DDoS attack. CWE: CWE-440: Expected Behavior Violation Description: OpenSSL's QUIC stack, when operating as a server, enforces client address validation (RFC 9000, Section 8), to confirm the peer address is not used for a traffic amplification attack. If this feature is disabled on the server, the QUIC stack limits the amount of server data that can be sent to 3 times the amount of data received from the peer address, until such time as the TLS handshake is completed. The OpenSSL QUIC server, when operating in non-validation mode, adds the length of the whole datagram received to the unvalidated credit limit when processing each QUIC packet in the datagram. A remote peer may, after establishing a connection with an initial client hello frame, send a subsequent datagram containing multiple QUIC packets, leading the server to account the entire datagram length for each packet in the datagram, resulting in the server believing that the peer has sent more data than it actually has, thereby violating the 3x amplification limit mandated by the RFC. FIPS impact: no As the QUIC stack lives outside the FIPS module boundary, no FIPS modules are affected by this CVE. — /lib/apk/db/installed | |
| LOW | CVE-2026-54875 | openssl | 3.5.8-r0 | Issue summary: A non-constant-time optimized implementation of scalar point multiplication is used for SM2 private key operations on ARM64 and RISC-V platforms. Impact summary: An attacker able to measure the time taken by, or to observe the cache-line access pattern of SM2 signing or decryption on an affected platform can learn information about the secret scalar. CWE: CWE-208: Observable Timing Discrepancy Description: On ARM64 and RISC-V processors, the SM2 curve uses an optimized scalar multiplication implementation whose conditional branches and table look ups are chosen according to the bits of the secret scalar. The execution time and the cache-access pattern therefore depend on the long-term private key (during SM2 decryption) or the per-signature nonce (during SM2 signature generation), forming a timing and cache side-channel. FIPS Impact: no SM2 is not a FIPS algorithm and the optimized SM2 implementation is not part of the FIPS module. OpenSSL 4.0, 3.6, 3.5 and 3.4 are vulnerable to this issue on AArch64 and RISC-V. OpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue. OpenSSL 4.0 users should upgrade to OpenSSL 4.0.3. OpenSSL 3.6 users should upgrade to OpenSSL 3.6.5. OpenSSL 3.5 users should upgrade to OpenSSL 3.5.9. OpenSSL 3.4 users should upgrade to OpenSSL 3.4.8. This issue was reported on 2 May 2026 by Abhinav Agarwal. It was independently reported on 6 June 2026 by Feng Xue. The fix was developed by Igor Ustinov. -- cut (non-publishing metadata for internal use) -- Reported by: Abhinav Agarwal, Feng Xue Fixed by: Igor Ustinov — /lib/apk/db/installed | |
| LOW | CVE-2026-54875 | libssl3 | 3.5.8-r0 | Issue summary: A non-constant-time optimized implementation of scalar point multiplication is used for SM2 private key operations on ARM64 and RISC-V platforms. Impact summary: An attacker able to measure the time taken by, or to observe the cache-line access pattern of SM2 signing or decryption on an affected platform can learn information about the secret scalar. CWE: CWE-208: Observable Timing Discrepancy Description: On ARM64 and RISC-V processors, the SM2 curve uses an optimized scalar multiplication implementation whose conditional branches and table look ups are chosen according to the bits of the secret scalar. The execution time and the cache-access pattern therefore depend on the long-term private key (during SM2 decryption) or the per-signature nonce (during SM2 signature generation), forming a timing and cache side-channel. FIPS Impact: no SM2 is not a FIPS algorithm and the optimized SM2 implementation is not part of the FIPS module. OpenSSL 4.0, 3.6, 3.5 and 3.4 are vulnerable to this issue on AArch64 and RISC-V. OpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue. OpenSSL 4.0 users should upgrade to OpenSSL 4.0.3. OpenSSL 3.6 users should upgrade to OpenSSL 3.6.5. OpenSSL 3.5 users should upgrade to OpenSSL 3.5.9. OpenSSL 3.4 users should upgrade to OpenSSL 3.4.8. This issue was reported on 2 May 2026 by Abhinav Agarwal. It was independently reported on 6 June 2026 by Feng Xue. The fix was developed by Igor Ustinov. -- cut (non-publishing metadata for internal use) -- Reported by: Abhinav Agarwal, Feng Xue Fixed by: Igor Ustinov — /lib/apk/db/installed | |
| LOW | CVE-2026-54875 | libcrypto3 | 3.5.8-r0 | Issue summary: A non-constant-time optimized implementation of scalar point multiplication is used for SM2 private key operations on ARM64 and RISC-V platforms. Impact summary: An attacker able to measure the time taken by, or to observe the cache-line access pattern of SM2 signing or decryption on an affected platform can learn information about the secret scalar. CWE: CWE-208: Observable Timing Discrepancy Description: On ARM64 and RISC-V processors, the SM2 curve uses an optimized scalar multiplication implementation whose conditional branches and table look ups are chosen according to the bits of the secret scalar. The execution time and the cache-access pattern therefore depend on the long-term private key (during SM2 decryption) or the per-signature nonce (during SM2 signature generation), forming a timing and cache side-channel. FIPS Impact: no SM2 is not a FIPS algorithm and the optimized SM2 implementation is not part of the FIPS module. OpenSSL 4.0, 3.6, 3.5 and 3.4 are vulnerable to this issue on AArch64 and RISC-V. OpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue. OpenSSL 4.0 users should upgrade to OpenSSL 4.0.3. OpenSSL 3.6 users should upgrade to OpenSSL 3.6.5. OpenSSL 3.5 users should upgrade to OpenSSL 3.5.9. OpenSSL 3.4 users should upgrade to OpenSSL 3.4.8. This issue was reported on 2 May 2026 by Abhinav Agarwal. It was independently reported on 6 June 2026 by Feng Xue. The fix was developed by Igor Ustinov. -- cut (non-publishing metadata for internal use) -- Reported by: Abhinav Agarwal, Feng Xue Fixed by: Igor Ustinov — /lib/apk/db/installed |
ghcr.io/openvoxproject/openvoxserver
Downloads
ghcr.io/openvoxproject/openvoxserver:latest (2026-09-09)
Trivy
CRITICAL 4
HIGH 104
MEDIUM 3711
LOW 205
UNKNOWN 13
| Severity | ID | Package | Installed | Fixed | Title / target |
|---|---|---|---|---|---|
| CRITICAL | CVE-2026-64535 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: nvmet-tcp: Fix potential UAF when ddgst mismatch — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| CRITICAL | CVE-2026-64564 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: sctp: don't free the ASCONF's own transport in DEL-IP processing — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| CRITICAL | CVE-2026-72287 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: KVM: nVMX: Move vTPR vs. TPR Threshold consistency check into "normal" checks — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| CRITICAL | CVE-2026-74394 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: RDMA/srpt: fix integer overflow in immediate data length check — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| HIGH | CVE-2026-68284 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: Linux kernel: bpf/sockmap use-after-free vulnerability leading to denial of service — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| HIGH | CVE-2026-68323 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: tipc: serialize udp bearer replicast list updates — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| HIGH | CVE-2026-68329 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: iommu/amd: Wait for completion instead of returning early in iommu_completion_wait() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| HIGH | CVE-2026-68380 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: accel/amdxdna: Fix use-after-free of mm_struct in job scheduler — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| HIGH | CVE-2026-68393 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: Bluetooth: hci_sync: extend conn_hash lookup critical sections — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| HIGH | CVE-2026-68399 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: bpf: Fix UAF in sock clone early bailouts — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| HIGH | CVE-2026-68442 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: btrfs: don't propagate EXTENT_FLAG_LOGGING to split extent maps — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| HIGH | CVE-2026-68446 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/vmwgfx: Validate vmw_surface_metadata::array_size — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| HIGH | CVE-2026-68451 | linux-libc-dev | 7.0.0-31.31 | kernel: s390/zcrypt: Validate length for CCA ECC private key requests — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| HIGH | CVE-2026-68470 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: wifi: mac80211: validate extension-frame layout before RX — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| HIGH | CVE-2026-72003 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: wifi: brcmfmac: cyw: fix heap overflow on a short auth frame — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| HIGH | CVE-2026-72024 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: mac802154: remove interfaces with RCU list deletion — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| HIGH | CVE-2026-72110 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: bpf,fork: wipe ->bpf_storage before bailouts that access it — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| HIGH | CVE-2026-72111 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: bpf: Reset register bounds before narrowing retval range in check_mem_access() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| HIGH | CVE-2026-72123 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: can: bcm: thrtimer use-after-free during RX operation teardown — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| HIGH | CVE-2026-72124 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: can: isotp: serialize TX state transitions under so->rx_lock — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| HIGH | CVE-2026-72135 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: tpm: Make the TPM character devices non-seekable — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| HIGH | CVE-2026-72151 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: tpm: tpm2-sessions: wait for async KPP completion in tpm_buf_append_salt — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| HIGH | CVE-2026-72195 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: fs/ntfs3: bound attr_off in UpdateResidentValue against data_off — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| HIGH | CVE-2026-72288 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: KVM: arm64: vgic: Handle race between interrupt affinity change and LPI disabling — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| HIGH | CVE-2026-74510 | linux-libc-dev | 7.0.0-31.31 | kernel: Bluetooth: mgmt: fix UAF in pair command cancellation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| HIGH | CVE-2025-40190 | linux-libc-dev | 7.0.0-31.31 | kernel: ext4: guard against EA inode refcount underflow in xattr update — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| HIGH | CVE-2026-64543 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: tipc: fix use-after-free of the discoverer in tipc_disc_rcv() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| HIGH | CVE-2026-64548 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: bpf, sockmap: reject overflowing copy + len in bpf_msg_push_data() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| HIGH | CVE-2026-64554 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: netfilter: bridge: fix stale prevhdr pointer in br_ip6_fragment() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| HIGH | CVE-2026-64557 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: Bluetooth: L2CAP: Fix use-after-free in l2cap_sock_new_connection_cb() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| HIGH | CVE-2026-64558 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: s390/pkey: Check length in pkey_pckmo handler implementation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| HIGH | CVE-2026-64562 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: KVM: nVMX: Hide shadow VMCS right after VMCLEAR — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| HIGH | CVE-2026-64567 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: btrfs: reject free space cache with more entries than pages — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| HIGH | CVE-2026-68098 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ksmbd: bound DACL dedup walk to copied ACEs — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| HIGH | CVE-2026-68117 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: tipc: clear sock->sk on the failed-insert path in tipc_sk_create() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| HIGH | CVE-2026-68121 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: pppoe: reload header pointer after dev_hard_header() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| HIGH | CVE-2026-68147 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: fscrypt: Avoid dynamic allocation in fscrypt_get_devices() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| HIGH | CVE-2026-68162 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: sctp: avoid auth_enable sysctl UAF during netns teardown — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| HIGH | CVE-2026-68189 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: Bluetooth: hci_sync: Protect UUID list traversal — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| HIGH | CVE-2026-68196 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: wifi: wilc1000: validate assoc response length before subtracting header — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| HIGH | CVE-2026-68198 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: Linux kernel: Use-after-free in ath6kl Wi-Fi driver leading to denial of service — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| HIGH | CVE-2026-68199 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: wifi: ath6kl: fix OOB access from firmware ADDBA window size — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| HIGH | CVE-2026-68201 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ALSA: timer: drain a slave's callback before its master detaches it — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| HIGH | CVE-2026-68204 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: media: vivid: check for vb2_is_busy() when toggling caps — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| HIGH | CVE-2026-68236 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/amd/display: set new_stream to NULL after release — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| HIGH | CVE-2026-68257 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/amdkfd: fix 32-bit overflow in CWSR total size calculation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| HIGH | CVE-2026-74529 | linux-libc-dev | 7.0.0-31.31 | kernel: Bluetooth: hci_sync: hold conn in hci_connect_pa_sync() callback — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| HIGH | CVE-2026-74534 | linux-libc-dev | 7.0.0-31.31 | kernel: Bluetooth: ISO: fix refcounting of iso_conn — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| HIGH | CVE-2026-74535 | linux-libc-dev | 7.0.0-31.31 | kernel: Bluetooth: ISO: avoid deadlocks in iso_sock_timeout — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| HIGH | CVE-2026-80631 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: btrfs: lzo: reject compressed segment that overflows the compressed input — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| HIGH | CVE-2026-80634 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: netfilter: flowtable: avoid num_encaps underflow on bridge VLAN untag — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| HIGH | CVE-2026-80637 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: netfilter: synproxy: fix unaligned memory access in timestamp adjustment — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| HIGH | CVE-2026-80644 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ocfs2: don't BUG_ON an invalid journal dinode — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| HIGH | CVE-2026-80665 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: KVM: arm64: nv: Inject SEA if kvm_translate_vncr() can't resolve PFN — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| HIGH | CVE-2026-80668 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: netfilter: nf_conntrack_expect: use conntrack GC to reap expectations — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| HIGH | CVE-2026-80671 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: perf sched: Fix register_pid() overflow, strcpy, and BUG_ON — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| HIGH | CVE-2026-80681 | linux-libc-dev | 7.0.0-31.31 | kernel: vxlan: re-fetch eth header after route_shortcircuit() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| HIGH | CVE-2026-80683 | linux-libc-dev | 7.0.0-31.31 | kernel: Bluetooth: SCO: give the socket its own sco_conn reference — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| HIGH | CVE-2026-80691 | linux-libc-dev | 7.0.0-31.31 | kernel: scsi: target: iblock: Fix wrong PR ops NULL check for PREEMPT/RELEASE — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| HIGH | CVE-2026-80692 | linux-libc-dev | 7.0.0-31.31 | kernel: Bluetooth: hci_sync: hold conn in hci_connect_acl/le_sync() callbacks — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| HIGH | CVE-2026-80693 | linux-libc-dev | 7.0.0-31.31 | kernel: idpf: bound interrupt-vector register fill to the allocated array — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| HIGH | CVE-2026-80700 | linux-libc-dev | 7.0.0-31.31 | kernel: drm/vmwgfx: validate external BO copy bounds for both stride paths — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| HIGH | CVE-2026-80702 | linux-libc-dev | 7.0.0-31.31 | kernel: drm/vmwgfx: fix guest_memory_dirty bitfield clobbered as size — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| HIGH | CVE-2026-80710 | linux-libc-dev | 7.0.0-31.31 | kernel: s390/dasd: Fix undersized format-check buffer — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| HIGH | CVE-2026-80714 | linux-libc-dev | 7.0.0-31.31 | kernel: ipvs: do not propagate one-packet flag to synced conns — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| HIGH | CVE-2026-80716 | linux-libc-dev | 7.0.0-31.31 | kernel: ALSA: pcm: wake linked drain waiters on unlink — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| HIGH | CVE-2026-80718 | linux-libc-dev | 7.0.0-31.31 | kernel: mm/percpu-km: fix bitmap overflow and accounting in pcpu_create_chunk() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| HIGH | CVE-2026-80721 | linux-libc-dev | 7.0.0-31.31 | kernel: Bluetooth: ISO: ensure no dangling hcon references in iso_conn — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| HIGH | CVE-2026-72331 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: accel/amdxdna: Fix VMA access race — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| HIGH | CVE-2026-72338 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net/sched: act_pedit: fix TOCTOU heap OOB write in tc offload — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| HIGH | CVE-2026-72372 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: afs: Fix lack of locking around modifications of net->cells_dyn_ino — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| HIGH | CVE-2026-72390 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net/sched: sch_teql: Introduce slaves_lock to avoid race condition and UAF — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| HIGH | CVE-2026-72461 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: apparmor: fix refcount leak when updating the sk_ctx — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| HIGH | CVE-2026-72462 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: apparmor: fix race in unix socket mediation when peer_path is used — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| HIGH | CVE-2026-72472 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: nfs: use nfsi->rwsem to protect traversal of the file lock list — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| HIGH | CVE-2026-72478 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: fs/ntfs3: add bounds check to run_get_highest_vcn() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| HIGH | CVE-2026-74268 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: tcp: clear sock_ops cb flags before force-closing a child socket — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| HIGH | CVE-2026-74317 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ixgbe: do not configure xps for XDP queues — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| HIGH | CVE-2026-74334 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: RDMA/nldev: Fix locking when accessing mr->pd — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| HIGH | CVE-2026-74341 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: wifi: wcn36xx: fix heap overflow from oversized firmware HAL response — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| HIGH | CVE-2026-74350 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: ocfs2: validate fast symlink target during inode read — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| HIGH | CVE-2026-74363 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: bpf: fix UAF by restoring RCU-delayed inode freeing in bpffs — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| HIGH | CVE-2026-74378 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: RDMA/rxe: Fix TOCTOU heap overflow in get_srq_wqe — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| HIGH | CVE-2026-74390 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: RDMA/irdma: Fix out-of-bounds write in irdma_copy_user_pgaddrs — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| HIGH | CVE-2026-74411 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: wifi: rtw89: Correct data type for scan index to avoid infinite loop — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| HIGH | CVE-2026-74427 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: afs: Fix netns teardown to cancel the preallocation charger — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| HIGH | CVE-2026-74438 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: crypto: sun4i-ss - Remove insecure and unused rng_alg — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| HIGH | CVE-2026-74446 | linux-libc-dev | 7.0.0-31.31 | kernel: drm/amdkfd: hold event_mutex while checkpointing CRIU events — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| HIGH | CVE-2026-74465 | linux-libc-dev | 7.0.0-31.31 | kernel: net: openvswitch: fix potential UAF on meter attach failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| HIGH | CVE-2026-74470 | linux-libc-dev | 7.0.0-31.31 | kernel: scsi: scsi_debug: Fix REPORT ZONES alloc_len underflow OOB write — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| HIGH | CVE-2026-74506 | linux-libc-dev | 7.0.0-31.31 | kernel: afs: Fix UAF when sending a message — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| HIGH | CVE-2026-56858 | stdlib | v1.26.5 | 1.25.13, 1.26.6, 1.27.0-rc.3 | html/template: golang: Go html/template: Cross-Site Scripting via pathological input — usr/bin/pebble |
| HIGH | CVE-2026-89407 | com.fasterxml.jackson.core:jackson-core | 2.21.6 | 2.18.11, 2.21.7, 2.22.3 | com.fasterxml.jackson/jackson-core: tools.jackson.core/jackson-core: Jackson-core: Denial of Service via regular expression backtracking — Java |
| HIGH | CVE-2026-89425 | com.fasterxml.jackson.core:jackson-core | 2.21.6 | 2.21.7, 2.22.3, 2.18.11 | com.fasterxml.jackson.core/jackson-core: Jackson-core: Denial of Service via unbounded StringBuilder growth during malformed token processing — Java |
| HIGH | CVE-2026-84782 | libssl3t64 | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | openssl: compat-openssl: openssl: Information disclosure via DTLS handshake retransmission — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| HIGH | CVE-2026-91776 | com.fasterxml.jackson.core:jackson-databind | 2.21.6 | 2.18.11, 2.21.7, 2.22.3 | jackson-databind: com.fasterxml.jackson/jackson-core: jackson-databind: Denial of Service via unbounded cache growth in TypeDeserializerBase — Java |
| HIGH | CVE-2026-84782 | libssl-dev | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | openssl: compat-openssl: openssl: Information disclosure via DTLS handshake retransmission — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| HIGH | CVE-2026-91777 | com.fasterxml.jackson.core:jackson-databind | 2.21.6 | 2.21.7, 2.18.11, 2.22.3 | com.fasterxml.jackson.core/jackson-databind: Jackson-databind: Denial of Service via quadratic forward-reference completion — Java |
| HIGH | CVE-2022-41404 | org.ini4j:ini4j | 0.5.4 | org.ini4j: unspecified DoS — Java | |
| HIGH | CVE-2026-56853 | stdlib | v1.26.5 | 1.25.13, 1.26.6, 1.27.0-rc.3 | net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service — usr/bin/pebble |
| HIGH | CVE-2026-46600 | stdlib | v1.26.5 | 1.26.6, 1.27.0-rc.3 | golang.org/x/net/dns/dnsmessage: golang.org/x/net/dns/dnsmessage: Denial of Service via invalid DNS record parsing — usr/bin/pebble |
| HIGH | CVE-2026-33818 | stdlib | v1.26.5 | 1.25.13, 1.26.6, 1.27.0-rc.3 | encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal — usr/bin/pebble |
| HIGH | CVE-2026-56862 | stdlib | v1.26.5 | 1.25.13, 1.26.6, 1.27.0-rc.3 | crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages — usr/bin/pebble |
| HIGH | CVE-2026-56860 | stdlib | v1.26.5 | 1.25.13, 1.26.6, 1.27.0-rc.3 | net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution — usr/bin/pebble |
| HIGH | CVE-2026-56859 | stdlib | v1.26.5 | 1.25.13, 1.26.6, 1.27.0-rc.3 | encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue — usr/bin/pebble |
| HIGH | CVE-2026-84782 | openssl | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | openssl: compat-openssl: openssl: Information disclosure via DTLS handshake retransmission — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| HIGH | CVE-2026-84782 | openssl-provider-legacy | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | openssl: compat-openssl: openssl: Information disclosure via DTLS handshake retransmission — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| HIGH | CVE-2026-39821 | stdlib | v1.26.5 | 1.25.13, 1.26.6, 1.27.0-rc.3 | golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing — usr/bin/pebble |
| MEDIUM | CVE-2026-90152 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90151 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: N ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90153 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: k ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90154 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: k ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90155 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: k ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90156 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: k ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90179 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: a ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90178 | linux-libc-dev | 7.0.0-31.31 | kernel: hwmon: (coretemp) Fix core_data leak on CPUs without PTS — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90177 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90176 | linux-libc-dev | 7.0.0-31.31 | kernel: ksmbd: Do not skip lock checks for single-byte ranges — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90175 | linux-libc-dev | 7.0.0-31.31 | kernel: smb: server: fix leak of ksmbd_ipc_login_request_ext() returned buffer — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90174 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: k ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90170 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: k ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90169 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: k ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90167 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: k ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90166 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90165 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90164 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90163 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90162 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: k ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90161 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: e ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90160 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: l ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90159 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90158 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90157 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90115 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: x ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90116 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: A ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90119 | linux-libc-dev | 7.0.0-31.31 | kernel: ALSA: ice1712: Fix the card leak at probe error with the auto-cleanup — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90120 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90121 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90122 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: c ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90124 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90125 | linux-libc-dev | 7.0.0-31.31 | kernel: smb: client: fix request buffer leak in smb2_new_read_req() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90126 | linux-libc-dev | 7.0.0-31.31 | kernel: rtc: pcf8563: fix clock provider leak on unbind — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90127 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: v ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90128 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: v ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90129 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: v ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90130 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: v ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90135 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90136 | linux-libc-dev | 7.0.0-31.31 | kernel: platform/x86/amd/hsmp: Reject negative power cap writes in hwmon — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90137 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: p ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90138 | linux-libc-dev | 7.0.0-31.31 | kernel: vsock: don't check the listener's sk_err in vsock_accept() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90139 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90140 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: c ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90141 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90142 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: v ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90143 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90144 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90145 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: h ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90146 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90147 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: c ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90148 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: N ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90149 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: N ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90150 | linux-libc-dev | 7.0.0-31.31 | kernel: pnfs/blocklayout: Fix device leaks on parse failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90213 | linux-libc-dev | 7.0.0-31.31 | kernel: firewire: core: fix memory leak in error path of build_tree() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90214 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: A ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90215 | linux-libc-dev | 7.0.0-31.31 | kernel: mtd: ubi: Release device reference on busy detach — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90216 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: u ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90217 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90218 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: R ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90219 | linux-libc-dev | 7.0.0-31.31 | kernel: RDMA/cxgb4: Free debugfs on registration failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90220 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: A ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90221 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90222 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90223 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90224 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90225 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90226 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90227 | linux-libc-dev | 7.0.0-31.31 | kernel: nvme/ioctl: check SUBMIT_IO with nvme_cmd_allowed() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90228 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90229 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90230 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90231 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: a ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90232 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: a ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90233 | linux-libc-dev | 7.0.0-31.31 | kernel: nvme-pci: release descriptor pools on probe failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90234 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: N ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90235 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90237 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90240 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90241 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90242 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90243 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90244 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90245 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90246 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: a ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90180 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90182 | linux-libc-dev | 7.0.0-31.31 | kernel: blk-iocost: clear delay state when freeing policy data — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90183 | linux-libc-dev | 7.0.0-31.31 | kernel: blk-iolatency: clear delay state when freeing policy data — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90184 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90185 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90186 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90187 | linux-libc-dev | 7.0.0-31.31 | kernel: null_blk: free zones array on device power-off — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90188 | linux-libc-dev | 7.0.0-31.31 | kernel: null_blk: free global tag_set on init error path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90189 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90190 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90191 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90192 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90193 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90194 | linux-libc-dev | 7.0.0-31.31 | kernel: ACPI: scan: fix bus ID cleanup on device_add() failures — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90195 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: r ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90196 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: A ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90197 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: H ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90198 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: A ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90199 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90200 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90201 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90202 | linux-libc-dev | 7.0.0-31.31 | kernel: scsi: mpt3sas: Avoid freeing unallocated PCIe SGL buffers — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90203 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: S ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90204 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: o ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90205 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: o ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90206 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90207 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: A ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90208 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: c ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90209 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90211 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90212 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: a ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90055 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: u ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90054 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: t ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90053 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90051 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: t ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90049 | linux-libc-dev | 7.0.0-31.31 | kernel: net: skbuff: don't skb_tx_error() the source skb in skb_zerocopy() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90048 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90047 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90046 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90045 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: U ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90044 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: u ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90043 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: z ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90042 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: c ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90041 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: H ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90040 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: K ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90039 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: N ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90037 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: N ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90036 | linux-libc-dev | 7.0.0-31.31 | kernel: NFSD: Prevent client use-after-free during blocked-lock reaping — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90035 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90034 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: u ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90033 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: A ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90032 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90031 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: u ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90030 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: u ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90029 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: u ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90028 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: u ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90027 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: u ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90026 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: u ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90025 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: u ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90024 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: u ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90072 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90073 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90074 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90075 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90076 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90077 | linux-libc-dev | 7.0.0-31.31 | kernel: net: fix a resource leak in copy_net_ns() error handling path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90078 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90079 | linux-libc-dev | 7.0.0-31.31 | kernel: octeontx2-af: fix cn20k mailbox lifetime on repeated rvu_mbox_init() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90080 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: o ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90081 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90082 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90083 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90084 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: o ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90085 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: o ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90071 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90070 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: t ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90069 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: c ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90068 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: A ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90067 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: l ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90066 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90065 | linux-libc-dev | 7.0.0-31.31 | kernel: net/smc: release the internal TCP sock on IPPROTO_SMC socket creation failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90063 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: v ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90062 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90061 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90060 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: A ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90059 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90058 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90057 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90056 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89991 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90086 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: x ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90087 | linux-libc-dev | 7.0.0-31.31 | kernel: Bluetooth: do not leak an hci_conn when a second LE connect is rejected — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90088 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: B ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90089 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: B ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90090 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: B ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90091 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: B ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90092 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: B ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90093 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: B ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90094 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: a ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90095 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90097 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: D ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90098 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90099 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90100 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: p ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90101 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90102 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: N ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90103 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: N ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90104 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: N ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90105 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: v ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90106 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90107 | linux-libc-dev | 7.0.0-31.31 | kernel: net/smc: free pending qentry in smc_llc_flow_stop() before memset — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90108 | linux-libc-dev | 7.0.0-31.31 | kernel: net/smc: free stashed qentry before overwrite in REQ_ADD_LINK to ADD_LINK transition — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90109 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90110 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90111 | linux-libc-dev | 7.0.0-31.31 | kernel: ip6mr: do not clone dst in ip6mr_cache_report() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90112 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90113 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90114 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90023 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: u ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90022 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: u ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90021 | linux-libc-dev | 7.0.0-31.31 | kernel: usb: gadget: f_midi: initialize work in f_midi_alloc() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90020 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: U ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90019 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: u ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90018 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90017 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90016 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90015 | linux-libc-dev | 7.0.0-31.31 | kernel: xhci: fix lost bounce buffers on TDs spanning several ring segments — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90014 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: t ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90013 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: t ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90012 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90011 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90008 | linux-libc-dev | 7.0.0-31.31 | kernel: scsi: megaraid_sas: Limit NVMe request size to the PRP chain frame — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90007 | linux-libc-dev | 7.0.0-31.31 | kernel: scsi: pm8001: Use rollback index when freeing MSI-X vectors — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90006 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90005 | linux-libc-dev | 7.0.0-31.31 | kernel: samples/damon/wsse: handle damon_start() failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90003 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90002 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90001 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: H ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90000 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: H ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89999 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: H ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89998 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89997 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89996 | linux-libc-dev | 7.0.0-31.31 | kernel: dma-buf: dma-heap: don't publish fd before copy_to_user() succeeds — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89995 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89994 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89993 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89992 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: c ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90400 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90401 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90402 | linux-libc-dev | 7.0.0-31.31 | kernel: bus: mhi: host: Fix controller cleanup on EDL sysfs failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90403 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90404 | linux-libc-dev | 7.0.0-31.31 | kernel: platform/chrome: cros_ec_debugfs: Unregister panic notifier — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90406 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90407 | linux-libc-dev | 7.0.0-31.31 | kernel: wifi: ath11k: fix overreads in ath11k_wmi_process_csa_switch_count_event() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90408 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90409 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90410 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90411 | linux-libc-dev | 7.0.0-31.31 | kernel: nvme-fc: unmap cmd_iu DMA on rsp_iu mapping failure in init_request — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90412 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90413 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: I ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90414 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: I ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90415 | linux-libc-dev | 7.0.0-31.31 | kernel: RDMA/cxgb4: free STAG index when TPT entry write fails — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90416 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: R ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90417 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: R ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90418 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90419 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90420 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90421 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: P ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90422 | linux-libc-dev | 7.0.0-31.31 | kernel: clk: mediatek: pllfh: Fix IO remapping leak in register_pllfhs error path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90423 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: R ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90424 | linux-libc-dev | 7.0.0-31.31 | kernel: iommu/tegra241-cmdqv: Fix VINTF0 leak on the init-failure path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90425 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90426 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90427 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90428 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90429 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90371 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90372 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90373 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90374 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90375 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90376 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90377 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90378 | linux-libc-dev | 7.0.0-31.31 | kernel: wifi: mt76: mt792x: Fix memory leak in SDIO TX path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90379 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90380 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90381 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90382 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90383 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90384 | linux-libc-dev | 7.0.0-31.31 | kernel: iomap: release the folio batch on iomap callback failures — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90385 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90386 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90387 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90388 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90389 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90390 | linux-libc-dev | 7.0.0-31.31 | kernel: md/bitmap: resume array on backlog_store() error path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90391 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: l ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90392 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90393 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90394 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: p ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90395 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: p ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90396 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90397 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90398 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90399 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-92503 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: e ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-92504 | linux-libc-dev | 7.0.0-31.31 | kernel: thermal: intel: int3400: clean up ODVP on probe failures — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-92505 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-92506 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-92507 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: R ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-92508 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: R ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-92509 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: R ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-92510 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: R ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-92511 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: R ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-92512 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: R ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-92513 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: R ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-92514 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: R ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-92515 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-92516 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-92517 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-92518 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: r ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-92519 | linux-libc-dev | 7.0.0-31.31 | kernel: riscv, bpf: Fix memory leak in bpf_jit_free — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-92520 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-92521 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: A ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-92522 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: A ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-92523 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: R ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-92524 | linux-libc-dev | 7.0.0-31.31 | kernel: irqchip/gic-v3-its: Prevent leak in its_vpe_irq_domain_alloc() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-92525 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: R ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93037 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: R ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93039 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: A ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93040 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93041 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93042 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98045 | linux-libc-dev | 7.0.0-31.31 | kernel: bpf: Mark faultable stack helpers as sleepable — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90430 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90431 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: r ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90433 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90434 | linux-libc-dev | 7.0.0-31.31 | kernel: isofs: release zisofs block pointer buffer head — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90435 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: R ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-92476 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: c ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-92477 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-92479 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-92480 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-92481 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: p ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-92482 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: p ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-92483 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: l ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-92484 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: c ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-92485 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-92486 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-92488 | linux-libc-dev | 7.0.0-31.31 | kernel: RDMA/erdma: complete object teardown when the destroy command fails — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-92489 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: x ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-92490 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-92491 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-92493 | linux-libc-dev | 7.0.0-31.31 | kernel: cpufreq: amd-pstate-ut: Skip tests when amd-pstate driver is not active — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-92494 | linux-libc-dev | 7.0.0-31.31 | kernel: ext4: fix buffer_head leak in ext4_init_orphan_info — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-92495 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: R ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-92496 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-92497 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-92498 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-92499 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: e ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-92500 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: e ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-92501 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: e ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-92502 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | In the Linux kernel, the following vulnerability has been resolved: e ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-90278 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90279 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90280 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: p ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90281 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: p ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90282 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: p ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90283 | linux-libc-dev | 7.0.0-31.31 | kernel: hugetlbfs: release subpool on fill_super failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90284 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90285 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90286 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90287 | linux-libc-dev | 7.0.0-31.31 | kernel: phy: sunplus: fix error handling in sp_uphy_init() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90288 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: p ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90289 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90290 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: a ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90291 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90292 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: R ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90293 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: I ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90294 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: I ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90295 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: c ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90296 | linux-libc-dev | 7.0.0-31.31 | kernel: cpufreq: imx6q: fix devres accumulation across driver rebind — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90297 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90298 | linux-libc-dev | 7.0.0-31.31 | kernel: drm/sun4i: tcon: Drop TCON TOP device reference — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90300 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90301 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: o ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90302 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: o ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90303 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: A ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90306 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: A ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90307 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: R ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90308 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: R ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90309 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: R ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90247 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90248 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90249 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90250 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90251 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: B ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90252 | linux-libc-dev | 7.0.0-31.31 | kernel: Bluetooth: MGMT: free the HCI command when it is cancelled — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90253 | linux-libc-dev | 7.0.0-31.31 | kernel: Bluetooth: MGMT: free the mesh send cancel command when it is cancelled — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90254 | linux-libc-dev | 7.0.0-31.31 | kernel: Bluetooth: hci_sync: free the advertising instance on the failure and cancel paths — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90255 | linux-libc-dev | 7.0.0-31.31 | kernel: Bluetooth: hci_conn: fix the SCO setup context lifetime — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90256 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: B ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90257 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: B ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90258 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: p ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90259 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90260 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90261 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90262 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90263 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90264 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90265 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90267 | linux-libc-dev | 7.0.0-31.31 | kernel: scsi: sd: Fix special_vec mempool leak when scsi_alloc_sgtables() fails — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90269 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90270 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: a ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90271 | linux-libc-dev | 7.0.0-31.31 | kernel: arm_mpam: Fix a NULL pointer dereference on unbinding after an error interrupt — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90272 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: p ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90273 | linux-libc-dev | 7.0.0-31.31 | kernel: coresight: etm4x: missing cscfg_csdev_disable_active_config() in perf enable — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90274 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: c ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90275 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90276 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90277 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90342 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90343 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90344 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90345 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90346 | linux-libc-dev | 7.0.0-31.31 | kernel: wifi: nl80211: clean up color-change beacon data on errors — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90347 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: a ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90348 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90349 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90350 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90351 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90352 | linux-libc-dev | 7.0.0-31.31 | kernel: wifi: mt76: mt7915: release hif2 reference on probe IRQ failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90353 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90354 | linux-libc-dev | 7.0.0-31.31 | kernel: wifi: mt76: mt7915: fix double hif2 init on the non-WED path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90355 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90356 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90357 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90358 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90359 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90360 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: r ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90361 | linux-libc-dev | 7.0.0-31.31 | kernel: wifi: ath11k: fix leak in ath11k_service_ready_ext_event() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90362 | linux-libc-dev | 7.0.0-31.31 | kernel: drm/msm/dsi: Drop dev_pm_opp_set_rate(0) — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90363 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90364 | linux-libc-dev | 7.0.0-31.31 | kernel: ACPI: processor: Unregister cpufreq notifier on init failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90365 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90366 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90367 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90368 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90369 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90370 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90311 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: t ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90312 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90313 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90314 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: r ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90315 | linux-libc-dev | 7.0.0-31.31 | kernel: PCI/sysfs: Add lockdown checks to legacy I/O and memory handlers — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90316 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90317 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90318 | linux-libc-dev | 7.0.0-31.31 | kernel: fat: release buffer head after rebuilding parent — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90319 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: r ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90320 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: o ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90321 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: o ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90322 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: o ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90323 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: u ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90324 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: u ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90325 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90326 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90327 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: p ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90328 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: H ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90329 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: H ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90330 | linux-libc-dev | 7.0.0-31.31 | kernel: HID: logitech-hidpp: Fix FF device cleanup on init failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90331 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: H ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90332 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: P ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90333 | linux-libc-dev | 7.0.0-31.31 | kernel: dm-integrity: replace forgeable discard filler with a keyed sector marker — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90334 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: t ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90335 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: t ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90336 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90337 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90338 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-90341 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89662 | linux-libc-dev | 7.0.0-31.31 | kernel: NFSD: Prevent lock owner use-after-free during client teardown — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89663 | linux-libc-dev | 7.0.0-31.31 | kernel: nfsd: revoke copy-notify stateids before dropping their reference — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89664 | linux-libc-dev | 7.0.0-31.31 | kernel: nfsd: release OPEN-decoded posix ACLs via op_release — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89665 | linux-libc-dev | 7.0.0-31.31 | kernel: nfsd: reject out-of-range useconds in NFSv2 SETATTR/CREATE — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89666 | linux-libc-dev | 7.0.0-31.31 | kernel: nfsd: reject out-of-range nseconds in NFSv3 SETATTR and create ops — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89667 | linux-libc-dev | 7.0.0-31.31 | kernel: nfsd: close shrinker/GC/fsnotify vs per-net shutdown race in filecache — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89668 | linux-libc-dev | 7.0.0-31.31 | kernel: nfsd: move nfsd_debugfs_init() after nfsd4_init_slabs() in init_nfsd() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89669 | linux-libc-dev | 7.0.0-31.31 | kernel: nfsd: initialize copy-notify stateid before publishing it — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89670 | linux-libc-dev | 7.0.0-31.31 | kernel: nfsd: hold rcu across localio cmpxchg retry — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89671 | linux-libc-dev | 7.0.0-31.31 | kernel: nfsd: gate nfs3 setacl by argp->mask — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89672 | linux-libc-dev | 7.0.0-31.31 | kernel: nfsd: gate nfs2 setacl by argp->mask — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89674 | linux-libc-dev | 7.0.0-31.31 | kernel: nfsd: fix XDR length calculation in nfsd4_ff_encode_layoutget — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89675 | linux-libc-dev | 7.0.0-31.31 | kernel: nfsd: fix UAF in async copy cancel and shutdown — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89676 | linux-libc-dev | 7.0.0-31.31 | kernel: nfsd: fix stale s2s_cp_stateids IDR entry for async COPY — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89677 | linux-libc-dev | 7.0.0-31.31 | kernel: nfsd: fix possible fh_compose of wrong dentry in nfsd4_create_file() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89678 | linux-libc-dev | 7.0.0-31.31 | kernel: nfsd: fix partial-write detection in nfsd_direct_write — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89679 | linux-libc-dev | 7.0.0-31.31 | kernel: nfsd: fix null dereference in nfsd4_setattr for deleg timestamp attrs — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89680 | linux-libc-dev | 7.0.0-31.31 | kernel: nfsd: fix nfsd_file leak on inter-server COPY setup failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89682 | linux-libc-dev | 7.0.0-31.31 | kernel: nfsd: fix fcache_disposal UAF by inlining dispose state into nfsd_net — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89683 | linux-libc-dev | 7.0.0-31.31 | kernel: nfsd: fix dentry ref leak on V4ROOT export filehandle lookup — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89684 | linux-libc-dev | 7.0.0-31.31 | kernel: nfsd: fix cpntf publish race in nfs4_init_cp_state — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89685 | linux-libc-dev | 7.0.0-31.31 | kernel: nfsd: fix clock domain mismatch in clients_still_reclaiming() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89686 | linux-libc-dev | 7.0.0-31.31 | kernel: nfsd: fix BUG_ON in nfsd4_alloc_layout_stateid on racing delegation revoke — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89687 | linux-libc-dev | 7.0.0-31.31 | kernel: nfsd: ensure nfsd_file_do_acquire() does not use a non-opened file — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89688 | linux-libc-dev | 7.0.0-31.31 | kernel: nfsd: drop the stateid, not the stateowner, on seqid_op replay retry — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89689 | linux-libc-dev | 7.0.0-31.31 | kernel: nfsd: don't free session slots that are still in use — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89690 | linux-libc-dev | 7.0.0-31.31 | kernel: nfsd: defer vfree of compound ops to fix rpc_status UAF — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89691 | linux-libc-dev | 7.0.0-31.31 | kernel: nfsd: clear opcnt on compound arg release to prevent OOB read — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89692 | linux-libc-dev | 7.0.0-31.31 | kernel: nfsd: clear CALLBACK_RUNNING on failed delegation recall queue — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89630 | linux-libc-dev | 7.0.0-31.31 | kernel: smb: client: restore the data_offset bound in is_valid_oplock_break() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89631 | linux-libc-dev | 7.0.0-31.31 | kernel: smb: client: reject a tree connect response whose byte count is too small — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89633 | linux-libc-dev | 7.0.0-31.31 | kernel: smb: client: fix OOB read/write from unvalidated DataOffset in coalesce_t2() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89634 | linux-libc-dev | 7.0.0-31.31 | kernel: smb: client: fix ALIGN() overflow in symlink_data() error context loop — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89636 | linux-libc-dev | 7.0.0-31.31 | kernel: smb: client: clear ce->tgthint in free_tgts() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89637 | linux-libc-dev | 7.0.0-31.31 | kernel: smb: client: fix UAF and buffer leak in cifs_check_trans2() for malformed secondary T2 — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89638 | linux-libc-dev | 7.0.0-31.31 | kernel: smb: client: clear setuid/setgid bit on write with cifsacl/modefromsid/posix extensions — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89640 | linux-libc-dev | 7.0.0-31.31 | kernel: cifs: fix loff_t underflow in cifs_remap_file_range() when len == 0 — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89641 | linux-libc-dev | 7.0.0-31.31 | kernel: cifs: clear tcon after cifsFileInfo_put() in cifs_file_set_size() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89642 | linux-libc-dev | 7.0.0-31.31 | kernel: cifs: call pagecache_isize_extended() in cifs_setsize() when extending — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89643 | linux-libc-dev | 7.0.0-31.31 | kernel: audit: avoid dropping live tree ref on fsnotify rule autoremove — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89644 | linux-libc-dev | 7.0.0-31.31 | kernel: btrfs: fix extent map leak in NOCOW direct I/O write — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89645 | linux-libc-dev | 7.0.0-31.31 | kernel: btrfs: drop recovered reloc root refs on recovery failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89646 | linux-libc-dev | 7.0.0-31.31 | kernel: ceph: fix leaked inode reference on writeback abort at umount — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89647 | linux-libc-dev | 7.0.0-31.31 | kernel: ceph: do not repeat ceph_trim_dentries() if no progress possible — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89648 | linux-libc-dev | 7.0.0-31.31 | kernel: ceph: cap delegated inode count in ceph_parse_deleg_inos() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89649 | linux-libc-dev | 7.0.0-31.31 | kernel: ceph: bound xattr value length in __build_xattrs() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89650 | linux-libc-dev | 7.0.0-31.31 | kernel: ceph: bound num_export_targets array for mds info v2/v3 — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89651 | linux-libc-dev | 7.0.0-31.31 | kernel: ceph: bound MDSCapAuth path and fs_name decode in handle_session() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89652 | linux-libc-dev | 7.0.0-31.31 | kernel: ceph: bound copied dentry name length in NFS export get_name — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89653 | linux-libc-dev | 7.0.0-31.31 | kernel: kernel: Memory corruption via out-of-bounds write in Ceph client — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89654 | linux-libc-dev | 7.0.0-31.31 | kernel: ceph: fix UAF in check_new_map() on session freed during unlock — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89655 | linux-libc-dev | 7.0.0-31.31 | kernel: ceph: fix UAF in __kick_flushing_caps() on cf entry freed during unlock — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89656 | linux-libc-dev | 7.0.0-31.31 | kernel: libceph: reject buckets with mismatched CRUSH ids — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89657 | linux-libc-dev | 7.0.0-31.31 | kernel: libceph: validate OSD extent maps before cursor advance — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89658 | linux-libc-dev | 7.0.0-31.31 | kernel: NFSD: Prevent client use-after-free during NFSv4.0 revoked-state cleanup — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89659 | linux-libc-dev | 7.0.0-31.31 | kernel: NFSD: Prevent client use-after-free during delegation revoke — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89660 | linux-libc-dev | 7.0.0-31.31 | kernel: NFSD: Prevent client use-after-free during admin state revocation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89661 | linux-libc-dev | 7.0.0-31.31 | kernel: NFSD: Prevent post-shutdown use-after-free in unlock_filesystem — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89722 | linux-libc-dev | 7.0.0-31.31 | kernel: PCI/sysfs: Fix out-of-bounds read in pci_write_legacy_io() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89723 | linux-libc-dev | 7.0.0-31.31 | kernel: nilfs2: fix slab-out-of-bounds in nilfs_direct_propagate after truncation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89724 | linux-libc-dev | 7.0.0-31.31 | kernel: media: vicodec: fix out-of-bounds write in FWHT encoder — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89725 | linux-libc-dev | 7.0.0-31.31 | kernel: media: cec: stm32: prevent out-of-bounds write on RX overflow — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89726 | linux-libc-dev | 7.0.0-31.31 | kernel: lib/ucs2_string.c: fix out-of-bounds read in ucs2_strnlen() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89727 | linux-libc-dev | 7.0.0-31.31 | kernel: KVM: arm64: GICv2: Don't WARN on out-of-range GICV_DIR INTID — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89728 | linux-libc-dev | 7.0.0-31.31 | kernel: i3c: renesas: Fix out-of-bounds access for newdevs mask — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89729 | linux-libc-dev | 7.0.0-31.31 | kernel: HID: sensor-hub: Fix out-of-bounds write in sensor_hub_get_feature — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89730 | linux-libc-dev | 7.0.0-31.31 | kernel: fpga: altera-cvp: Avoid out-of-bounds read in trailing byte write — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89731 | linux-libc-dev | 7.0.0-31.31 | kernel: cxl/ras: Fix cxl_rch_get_aer_info() out-of-bounds AER register read — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89732 | linux-libc-dev | 7.0.0-31.31 | kernel: usb: gadget: f_fs: Prevent deadlock during ep0 read loop — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89733 | linux-libc-dev | 7.0.0-31.31 | kernel: usb: gadget: uvc: fix dangling pointers in uvc_function_bind() and uvc_function_unbind() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89734 | linux-libc-dev | 7.0.0-31.31 | kernel: usb: gadget: uvc: Fix null pointer dereference in uvcg_video_init() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89735 | linux-libc-dev | 7.0.0-31.31 | kernel: usb: gadget: midi2: remove default configfs groups on teardown — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89736 | linux-libc-dev | 7.0.0-31.31 | kernel: usb: gadget: u_audio: Fix use-after-free on sound card disconnect — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89737 | linux-libc-dev | 7.0.0-31.31 | kernel: usb: typec: thunderbolt: Disable work before freeing tbt on remove — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89738 | linux-libc-dev | 7.0.0-31.31 | kernel: usb: gadget: at91_udc: drain polled-VBUS timer/work before udc is freed — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89739 | linux-libc-dev | 7.0.0-31.31 | kernel: usb: dwc3: gadget: Fix use-after-free in dwc3_gadget_free_endpoints due to race condition — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89740 | linux-libc-dev | 7.0.0-31.31 | kernel: serial: imx: serialize imx_uart_ports[] lifetime — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89741 | linux-libc-dev | 7.0.0-31.31 | kernel: Revert "media: v4l2-dev: fix error handling in __video_register_device()" — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89742 | linux-libc-dev | 7.0.0-31.31 | kernel: rapidio: mport_cdev: fix use-after-free in dma_req_free() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89743 | linux-libc-dev | 7.0.0-31.31 | kernel: misc: nsm: bound the device-reported response length — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89744 | linux-libc-dev | 7.0.0-31.31 | kernel: device property: fix infinite loop in fwnode_for_each_child_node() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89745 | linux-libc-dev | 7.0.0-31.31 | kernel: debugfs: Fix lockdown check for mmap_prepare — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89746 | linux-libc-dev | 7.0.0-31.31 | kernel: tracing: Fix use-after-free with same-name named triggers — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89747 | linux-libc-dev | 7.0.0-31.31 | kernel: tracing: Fix use-after-free in trace_pipe read on sub-buffer order change — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89749 | linux-libc-dev | 7.0.0-31.31 | kernel: tracing: Fix crash passing ERR_PTR to kthread_stop() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89750 | linux-libc-dev | 7.0.0-31.31 | kernel: tracing/user_events: Clear copied tracing state before fork duplication — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89751 | linux-libc-dev | 7.0.0-31.31 | kernel: x86/tdx: Fix off-by-one in port I/O handling — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89693 | linux-libc-dev | 7.0.0-31.31 | kernel: nfsd: check nfsd4_acl_to_attr() return value in nfsd4_create() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89694 | linux-libc-dev | 7.0.0-31.31 | kernel: nfsd: check client ownership when cancelling a copy-notify stateid — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89695 | linux-libc-dev | 7.0.0-31.31 | kernel: nfsd: cap decoded POSIX ACL count to bound sort cost — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89696 | linux-libc-dev | 7.0.0-31.31 | kernel: nfsd: block non-SAVEFH ops after FOREIGN PUTFH to prevent NULL deref — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89697 | linux-libc-dev | 7.0.0-31.31 | kernel: nfsd: add fh_want_write() for early-verified SETATTR in nfsd_proc_setattr() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89698 | linux-libc-dev | 7.0.0-31.31 | kernel: nfsd: widen nfsd_genl_rqstp address fields to sockaddr_storage — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89699 | linux-libc-dev | 7.0.0-31.31 | kernel: nfsd: validate symlink target length in NFSv4 CREATE — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89700 | linux-libc-dev | 7.0.0-31.31 | kernel: nfsd: validate sockaddr length per family in listener_set — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89701 | linux-libc-dev | 7.0.0-31.31 | kernel: nfsd: validate nseconds in TIME_DELEG decode paths — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89702 | linux-libc-dev | 7.0.0-31.31 | kernel: nfsd: size fh_verify server sockaddr slot by xpt_locallen — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89703 | linux-libc-dev | 7.0.0-31.31 | kernel: nfsd: set SC_STATUS_FREED in nfsd4_drop_revoked_stid for delegations — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89704 | linux-libc-dev | 7.0.0-31.31 | kernel: nfsd: sample writeback error cursor before async COPY loop — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89705 | linux-libc-dev | 7.0.0-31.31 | kernel: nfsd: restore rq_status_counter to even on all nfsd_dispatch() exit paths — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89706 | linux-libc-dev | 7.0.0-31.31 | kernel: nfsd: Reset write verifier when async COPY writeback fails — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89707 | linux-libc-dev | 7.0.0-31.31 | kernel: nfsd: release path refs on follow_down() error — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89708 | linux-libc-dev | 7.0.0-31.31 | kernel: nfsd: RCU-protect cl_cb_session to fix use-after-free on session teardown — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89709 | linux-libc-dev | 7.0.0-31.31 | kernel: lockd, nfsd: RCU-protect nlmsvc_ops dispatch — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89710 | linux-libc-dev | 7.0.0-31.31 | kernel: NFSv4.1: fix layout segment leak on the pnfs_layout_process() forget path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89711 | linux-libc-dev | 7.0.0-31.31 | kernel: NFSD: remove flawed WARN_ON_ONCE from nfsd_mode_check — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89712 | linux-libc-dev | 7.0.0-31.31 | kernel: NFSD: restart ssc_expire_umount walk after dropping nfsd_ssc_lock — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89713 | linux-libc-dev | 7.0.0-31.31 | kernel: NFSD: check truncate permission under inode lock — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89714 | linux-libc-dev | 7.0.0-31.31 | kernel: NFS: fix delegation_hash_table leak when nfs4_server_common_setup() fails — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89715 | linux-libc-dev | 7.0.0-31.31 | kernel: NFS/localio: fix ref leak on nfs_uuid_add_file failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89716 | linux-libc-dev | 7.0.0-31.31 | kernel: zram: validate deflate params — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89717 | linux-libc-dev | 7.0.0-31.31 | kernel: zram: set default primary compressor in zram_destroy_comps() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89718 | linux-libc-dev | 7.0.0-31.31 | kernel: zram: fix out-of-bounds access in writeback_store() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89719 | linux-libc-dev | 7.0.0-31.31 | kernel: zram: fix out-of-bounds access in read_block_state() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89720 | linux-libc-dev | 7.0.0-31.31 | kernel: ubifs: fix out-of-bounds read in signature length check — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89721 | linux-libc-dev | 7.0.0-31.31 | kernel: phy: rockchip-samsung-dcphy: fix out-of-range max_register — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89537 | linux-libc-dev | 7.0.0-31.31 | kernel: SUNRPC: Reject short RFC 4121 MIC tokens in gss_krb5_verify_mic_v2 — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89538 | linux-libc-dev | 7.0.0-31.31 | kernel: SUNRPC: Reject krb5 v2 wrap tokens with oversized ec field — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89539 | linux-libc-dev | 7.0.0-31.31 | kernel: SUNRPC: reject duplicate CREDS_VALUE options — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89540 | linux-libc-dev | 7.0.0-31.31 | kernel: sunrpc: init gssp_lock before publishing proc entry — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89541 | linux-libc-dev | 7.0.0-31.31 | kernel: SUNRPC: harden gss_unwrap_resp_priv length checks — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89542 | linux-libc-dev | 7.0.0-31.31 | kernel: SUNRPC: harden gss_krb5_unwrap_v2 against short tokens — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89543 | linux-libc-dev | 7.0.0-31.31 | kernel: sunrpc: fix use-after-free in __rpc_clnt_handle_event and __rpc_clnt_remove_pipedir — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89544 | linux-libc-dev | 7.0.0-31.31 | kernel: SUNRPC: fix gssx_dec_option_array error path bugs — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89545 | linux-libc-dev | 7.0.0-31.31 | kernel: sunrpc: defer rq_argp and rq_resp free until after RCU grace period — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89546 | linux-libc-dev | 7.0.0-31.31 | kernel: SUNRPC: close backchannel before destroying callback service — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89547 | linux-libc-dev | 7.0.0-31.31 | kernel: SUNRPC: Check svc pool percpu counter allocation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89548 | linux-libc-dev | 7.0.0-31.31 | kernel: SUNRPC: always drain cache_cleaner before destroying a cache_detail — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89549 | linux-libc-dev | 7.0.0-31.31 | kernel: sunrpc: route to a populated pool in svc_pool_for_cpu() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89550 | linux-libc-dev | 7.0.0-31.31 | kernel: SUNRPC: svcauth_gss: enforce krb5 token minimum length — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89551 | linux-libc-dev | 7.0.0-31.31 | kernel: SUNRPC: xdr_buf_trim: clamp buf->len to avoid underflow — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89552 | linux-libc-dev | 7.0.0-31.31 | kernel: params: fix charp corruption on allocation failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89553 | linux-libc-dev | 7.0.0-31.31 | kernel: nouveau/gem: reserve the bo in the info ioctl around the vma lookup — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89554 | linux-libc-dev | 7.0.0-31.31 | kernel: mptcp: fix uninitialized local_id in syncookie MP_JOIN reconstruction — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89555 | linux-libc-dev | 7.0.0-31.31 | kernel: mpls: reload header after pskb_may_pull() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89556 | linux-libc-dev | 7.0.0-31.31 | kernel: module: validate string table section types — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89557 | linux-libc-dev | 7.0.0-31.31 | kernel: md: do overflow check for sb->bblog_shift in super_1_load() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89558 | linux-libc-dev | 7.0.0-31.31 | kernel: md/raid10: fix still_degraded being inverted in raid10_sync_request() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89559 | linux-libc-dev | 7.0.0-31.31 | kernel: libnvdimm/labels: Prevent integer overflow in __nd_label_validate() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89560 | linux-libc-dev | 7.0.0-31.31 | kernel: landlock: Require LANDLOCK_ACCESS_FS_MAKE_REG for whiteout creation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89561 | linux-libc-dev | 7.0.0-31.31 | kernel: ipv6: rpl: fix NULL dereference of idev in ipv6_rpl_srh_rcv() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89562 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89563 | linux-libc-dev | 7.0.0-31.31 | kernel: ip6_tunnel: use skb_cow_head() in ip6_tnl_xmit() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89564 | linux-libc-dev | 7.0.0-31.31 | kernel: ip: orphan prefetched skbs before multicast forwarding — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89565 | linux-libc-dev | 7.0.0-31.31 | kernel: ipip: fix skb leak in collect_md mode when metadata_dst allocation fails — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-13608 | curl | 8.18.0-1ubuntu2.5 | 8.18.0-1ubuntu2.7 | curl: curl: Authentication bypass in OpenLDAP SASL negotiation via Man-in-the-Middle (MITM) attack — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-89508 | linux-libc-dev | 7.0.0-31.31 | kernel: RDMA/ucma: Lock the handler in ucma_set_ib_path() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89509 | linux-libc-dev | 7.0.0-31.31 | kernel: RDMA/ionic: Embed counter driver data in rdma_counter allocation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89510 | linux-libc-dev | 7.0.0-31.31 | kernel: RDMA/cxgb4: Cancel reg_work before freeing device on remove — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89511 | linux-libc-dev | 7.0.0-31.31 | kernel: qede: Fix NULL pointer dereference in TPA fragment processing — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89512 | linux-libc-dev | 7.0.0-31.31 | kernel: remoteproc: scp: Fix device reference leak on failed lookup — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89513 | linux-libc-dev | 7.0.0-31.31 | kernel: RISC-V: KVM: Fix PMU event info array size overflow — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89514 | linux-libc-dev | 7.0.0-31.31 | kernel: scsi: fnic: Use GFP_ATOMIC for VLAN alloc under spinlock — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89515 | linux-libc-dev | 7.0.0-31.31 | kernel: scsi: core: Fill in DMA padding bytes in scsi_alloc_sgtables() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89517 | linux-libc-dev | 7.0.0-31.31 | kernel: sched_ext: Fix rq->core_pick corruption under core scheduling — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89518 | linux-libc-dev | 7.0.0-31.31 | kernel: sched_ext: Fix this_rq() assumptions in dispatch kfuncs — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89519 | linux-libc-dev | 7.0.0-31.31 | kernel: sched_ext: Replace SCX_RQ_BAL_KEEP with a dispatch verdict return — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89520 | linux-libc-dev | 7.0.0-31.31 | kernel: sched/core: Make core-sched flips wait for in-flight selections — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89521 | linux-libc-dev | 7.0.0-31.31 | kernel: sched/core: Handle pick_task() releasing the rq lock — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89522 | linux-libc-dev | 7.0.0-31.31 | kernel: media: staging/ipu7: fix async notifier UAF on probe error path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89523 | linux-libc-dev | 7.0.0-31.31 | kernel: wifi: mt76: mt7925: cancel pending mlo_pm_work — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89524 | linux-libc-dev | 7.0.0-31.31 | kernel: wifi: ath6kl: clamp assoc request/response lengths before subtracting IE offsets — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89525 | linux-libc-dev | 7.0.0-31.31 | kernel: udf: reject VAT indexes equal to the entry count — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89526 | linux-libc-dev | 7.0.0-31.31 | kernel: svcrdma: Validate Read chunk positions before reconstruction — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89527 | linux-libc-dev | 7.0.0-31.31 | kernel: svcrdma: Use svc_xprt_put to free listener on create failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89528 | linux-libc-dev | 7.0.0-31.31 | kernel: svcrdma: Reject Read lists that exceed the page budget — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89529 | linux-libc-dev | 7.0.0-31.31 | kernel: svcrdma: Reject oversized Read segments at decode time — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89530 | linux-libc-dev | 7.0.0-31.31 | kernel: svcrdma: Reject inline replies that overflow the pull-up buffer — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89531 | linux-libc-dev | 7.0.0-31.31 | kernel: svcrdma: Reject connection when transport allocation fails — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89532 | linux-libc-dev | 7.0.0-31.31 | kernel: svcrdma: Fix pcl_for_each_segment for empty chunks — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89533 | linux-libc-dev | 7.0.0-31.31 | kernel: svcrdma: Fix offset arithmetic in read_chunk_range — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89534 | linux-libc-dev | 7.0.0-31.31 | kernel: svcrdma: Clear sc_cm_id when ADDR_CHANGE replacement fails — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89535 | linux-libc-dev | 7.0.0-31.31 | kernel: svcrdma: Reorder rpcrdma_rn_unregister before rdma_destroy_id — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89536 | linux-libc-dev | 7.0.0-31.31 | kernel: SUNRPC: wait for in-flight client TLS handshake callback — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89595 | linux-libc-dev | 7.0.0-31.31 | kernel: fsnotify: Fix stale object mask after concurrent mark updates — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89596 | linux-libc-dev | 7.0.0-31.31 | kernel: forcedeth: fix off-by-one when saving/restoring non-PCI config space — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89597 | linux-libc-dev | 7.0.0-31.31 | kernel: fbdev: uvesafb: unregister connector callback on init failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89598 | linux-libc-dev | 7.0.0-31.31 | kernel: fbdev: ssd1307fb: defer I2C transfers from damage callbacks — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89599 | linux-libc-dev | 7.0.0-31.31 | kernel: fbdev: omapfb: panel-dsi-cm: initialize lock before registering display — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89600 | linux-libc-dev | 7.0.0-31.31 | kernel: fanotify: fix use-after-free of file range info — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89601 | linux-libc-dev | 7.0.0-31.31 | kernel: ext2: Fix lost inode updates for IS_SYNC inodes — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89602 | linux-libc-dev | 7.0.0-31.31 | kernel: erofs: skip sufficiently large global buffers when resizing — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89603 | linux-libc-dev | 7.0.0-31.31 | kernel: entry: Fix seccomp bypass after ptrace with TSYNC — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89604 | linux-libc-dev | 7.0.0-31.31 | kernel: efivarfs: Rate limit statfs() handler — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89605 | linux-libc-dev | 7.0.0-31.31 | kernel: ecryptfs: release message context on send failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89606 | linux-libc-dev | 7.0.0-31.31 | kernel: ecryptfs: reject too-small tag 70 packets — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89607 | linux-libc-dev | 7.0.0-31.31 | kernel: ecryptfs: reject oversized encrypted_key_size in parse_tag_3_packet — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89608 | linux-libc-dev | 7.0.0-31.31 | kernel: ecryptfs: pass packet set buffer size to parser — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89609 | linux-libc-dev | 7.0.0-31.31 | kernel: ecryptfs: hold msg ctx list lock when cleaning daemon queue — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89615 | linux-libc-dev | 7.0.0-31.31 | kernel: fs/ntfs3: bound page_lcns[] index by the log record — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89616 | linux-libc-dev | 7.0.0-31.31 | kernel: fs/ntfs3: fix info-leak on partial LZNT decompress in ni_read_frame() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89617 | linux-libc-dev | 7.0.0-31.31 | kernel: fs/ntfs3: validate dirty page table on log replay — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89618 | linux-libc-dev | 7.0.0-31.31 | kernel: eventfs: Initialize ei->children and ei->list in init_ei() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89619 | linux-libc-dev | 7.0.0-31.31 | kernel: HID: intel-thc-hid: intel-quickspi: bound GET_REPORT response to the caller buffer — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89620 | linux-libc-dev | 7.0.0-31.31 | kernel: HID: intel-thc-hid: intel-quickspi: validate report size before copy — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89621 | linux-libc-dev | 7.0.0-31.31 | kernel: HID: mcp2221: validate report size in mcp2221_raw_event() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89622 | linux-libc-dev | 7.0.0-31.31 | kernel: HID: mcp2221: clear rxbuf after I2C/SMBus transfer completes — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89624 | linux-libc-dev | 7.0.0-31.31 | kernel: HID: universal-pidff: stop the device when force-feedback init fails — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89625 | linux-libc-dev | 7.0.0-31.31 | kernel: HID: sony: fix UAF of ghl_poke_timer / ghl_urb at driver unbind — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89626 | linux-libc-dev | 7.0.0-31.31 | kernel: HID: sensor: custom: Fix field sysfs group cleanup on failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89627 | linux-libc-dev | 7.0.0-31.31 | kernel: HID: roccat: free buffered reports when destroying device — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89628 | linux-libc-dev | 7.0.0-31.31 | kernel: HID: picolcd: clamp eeprom debugfs read to bytes actually received — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89629 | linux-libc-dev | 7.0.0-31.31 | kernel: HID: corsair-void: Check size of status and firmware events before reading them — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89566 | linux-libc-dev | 7.0.0-31.31 | kernel: jbd2: check need_resched() when skipping busy checkpoint buffers — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89567 | linux-libc-dev | 7.0.0-31.31 | kernel: jbd2: bound shrinker scans by examined checkpoint buffers — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89568 | linux-libc-dev | 7.0.0-31.31 | kernel: kho: fix size calculation in kho_preserved_memory_reserve() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89569 | linux-libc-dev | 7.0.0-31.31 | kernel: Bluetooth: RFCOMM: serialize security confirmation handling — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89570 | linux-libc-dev | 7.0.0-31.31 | kernel: cxl/mce: Make the MCE notifier per-region — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89571 | linux-libc-dev | 7.0.0-31.31 | kernel: cxl/features: bound fwctl command payload to the input buffer — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89572 | linux-libc-dev | 7.0.0-31.31 | kernel: cpufreq: apple-soc: Fix OPP table cleanup — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89573 | linux-libc-dev | 7.0.0-31.31 | kernel: dm array: reject an array block whose value size is not the caller's — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89574 | linux-libc-dev | 7.0.0-31.31 | kernel: dm array: validate array block headers on read — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89575 | linux-libc-dev | 7.0.0-31.31 | kernel: dm raid1: reserve space for NUL-terminator in build_constructor_string() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89576 | linux-libc-dev | 7.0.0-31.31 | kernel: dm-era: fix shadowed superblock leak on take-snap failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89577 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89578 | linux-libc-dev | 7.0.0-31.31 | kernel: dm-io: clone the source bio instead of copying its biovec — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89579 | linux-libc-dev | 7.0.0-31.31 | kernel: bpf: Harden bloom filter sizing and indexing on 32-bit kernels — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89580 | linux-libc-dev | 7.0.0-31.31 | kernel: bpf: Disable preemption in __bpf_get_stack — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89581 | linux-libc-dev | 7.0.0-31.31 | kernel: bpf, x86: Fix per-CPU address resolution into an extended register — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89582 | linux-libc-dev | 7.0.0-31.31 | kernel: bnx2x: fix double free in bnx2x_init_firmware() error path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89583 | linux-libc-dev | 7.0.0-31.31 | kernel: Bluetooth: eir: Fix OOB read in eir_get_service_data() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89584 | linux-libc-dev | 7.0.0-31.31 | kernel: block: validate user space vectors during extraction — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89585 | linux-libc-dev | 7.0.0-31.31 | kernel: auxdisplay: charlcd: cancel backlight work on registration failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89586 | linux-libc-dev | 7.0.0-31.31 | kernel: ata: libata-scsi: fix DSM TRIM for sector sizes larger than 2048 bytes — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89587 | linux-libc-dev | 7.0.0-31.31 | kernel: ACPI: pfr_update: fix stack buffer overflow in query_capability() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89588 | linux-libc-dev | 7.0.0-31.31 | kernel: ACPI: APEI: GHES: fix ARM section length accounting after header — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89589 | linux-libc-dev | 7.0.0-31.31 | kernel: acpi/apei/ghes: Use raw_spinlock_t for CXL CPER work locks — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89590 | linux-libc-dev | 7.0.0-31.31 | kernel: accel/rocket: Fix error path handling in rocket_job_run() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89591 | linux-libc-dev | 7.0.0-31.31 | kernel: accel/rocket: initialize job domain before cleanup paths — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89592 | linux-libc-dev | 7.0.0-31.31 | kernel: accel/rocket: fix NULL dereference and integer overflow in rocket_job_push() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89593 | linux-libc-dev | 7.0.0-31.31 | kernel: hugetlb: only adjust reservation during unmapping if mapcount is 0 — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89594 | linux-libc-dev | 7.0.0-31.31 | kernel: hsi: omap_ssi_core: fix missing DMA mask setup for SSI controller device — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89899 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89901 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89902 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: L ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89903 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: L ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89904 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: L ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89905 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: L ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89906 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: L ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89907 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: L ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89908 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: L ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89909 | linux-libc-dev | 7.0.0-31.31 | kernel: LoongArch: KVM: Free init resources if kvm_init() fails — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89911 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: K ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89912 | linux-libc-dev | 7.0.0-31.31 | kernel: KVM: arm64: vgic-its: Don't dereference a NULL collection on ITT save — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89913 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: K ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89914 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: K ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89915 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: K ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89916 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: K ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89917 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: K ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89918 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: K ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89919 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: K ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89920 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: K ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89921 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: K ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89922 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: K ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89923 | linux-libc-dev | 7.0.0-31.31 | kernel: KVM: s390: Free guest debug data on vcpu destroy — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89924 | linux-libc-dev | 7.0.0-31.31 | kernel: KVM: s390: Fix old_data leak in guest debug error path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89925 | linux-libc-dev | 7.0.0-31.31 | kernel: KVM: s390: Fix memory leak in guest debug handling — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89926 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: K ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89927 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: K ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89928 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: K ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89929 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: K ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89870 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89871 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89872 | linux-libc-dev | 7.0.0-31.31 | kernel: media: v4l2-fwnode: Fix fwnode leak in v4l2_fwnode_parse_link — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89873 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89874 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89875 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89876 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89877 | linux-libc-dev | 7.0.0-31.31 | kernel: media: saa7164: fix cleanup on resource allocation failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89878 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89879 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89880 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89881 | linux-libc-dev | 7.0.0-31.31 | kernel: media: rtl2832_sdr: use vb2_video_unregister_device() on remove to fix DMA leak — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89882 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89883 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89884 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89885 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89886 | linux-libc-dev | 7.0.0-31.31 | kernel: media: intel/ipu6: fix async notifier cleanup leak on parse error — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89887 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89888 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89889 | linux-libc-dev | 7.0.0-31.31 | kernel: media: i2c: imx415: Release runtime PM reference on VBLANK error — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89890 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89891 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89892 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89893 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89894 | linux-libc-dev | 7.0.0-31.31 | kernel: media: cx231xx: reject geometry changes while the VBI queue is busy — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89895 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89896 | linux-libc-dev | 7.0.0-31.31 | kernel: media: cedrus: fix memory leak in cedrus_init_ctrls() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89897 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89898 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89960 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89961 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: p ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89962 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: p ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89963 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: p ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89964 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: p ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89965 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89966 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89967 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89968 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89969 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89970 | linux-libc-dev | 7.0.0-31.31 | kernel: nvmet-auth: Synchronize timeout work during SQ teardown — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89971 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89972 | linux-libc-dev | 7.0.0-31.31 | kernel: nvme: add missing SRCU grace period in error path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89973 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89974 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89975 | linux-libc-dev | 7.0.0-31.31 | kernel: nvme-fabrics: fix DHCHAP secret leak on parse failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89976 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: a ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89977 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: a ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89978 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: a ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89979 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: A ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89981 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: a ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89982 | linux-libc-dev | 7.0.0-31.31 | kernel: i2c: mux: Fix channel node leak on adapter add failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89983 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89984 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: p ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89986 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89987 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89988 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: k ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89989 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89990 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: c ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89930 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: K ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89931 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: K ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89932 | linux-libc-dev | 7.0.0-31.31 | kernel: KVM: nVMX: Always flush vpid02 on first use — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89933 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89934 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89935 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89936 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89937 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89938 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89939 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89940 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89941 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89942 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89944 | linux-libc-dev | 7.0.0-31.31 | kernel: ASoC: hdac_hda: Fix hlink refcount leak on component registration failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89945 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: A ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89946 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: A ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89947 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: c ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89948 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89949 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89950 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89951 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89952 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89953 | linux-libc-dev | 7.0.0-31.31 | kernel: mtd: mtdoops: free page bitmap when the backing MTD is removed — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89954 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89955 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89956 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89957 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89958 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89959 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89783 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: x ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89784 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: S ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89785 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89786 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: e ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89787 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: e ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89788 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: k ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89789 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: g ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89790 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89791 | linux-libc-dev | 7.0.0-31.31 | kernel: perf: Fix use-after-free when perf mmap() revival races with the last munmap() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89792 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: k ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89793 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: u ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89794 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: k ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89795 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: P ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89796 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89797 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: p ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89798 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: r ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89799 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89800 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89801 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89802 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89803 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89804 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89805 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89806 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89807 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89808 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89809 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89810 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89811 | linux-libc-dev | 7.0.0-31.31 | kernel: drm/amdkfd: Add TLB flush after MES queue eviction/suspension — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89752 | linux-libc-dev | 7.0.0-31.31 | kernel: mm: memcg: stop reclaim when a limit update is superseded — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89753 | linux-libc-dev | 7.0.0-31.31 | kernel: mm/vmscan: report RCU-tasks quiescent states in shrink_lruvec() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89754 | linux-libc-dev | 7.0.0-31.31 | kernel: mm/pagewalk: fix stale walk->action escaping walk_pmd_range() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89755 | linux-libc-dev | 7.0.0-31.31 | kernel: mm/migrate_device: clear stale mapping after freeing swapcache — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89756 | linux-libc-dev | 7.0.0-31.31 | kernel: mm/migrate: report RCU-tasks quiescent states in migrate_pages_batch() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89757 | linux-libc-dev | 7.0.0-31.31 | kernel: mm/mglru: fix and remove redundant unevictable folio handling — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89758 | linux-libc-dev | 7.0.0-31.31 | kernel: mm/mempolicy: skip non-present PMDs when queueing folios — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89759 | linux-libc-dev | 7.0.0-31.31 | kernel: mm/kmemleak: avoid soft lockup when scanning task stacks — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89761 | linux-libc-dev | 7.0.0-31.31 | kernel: apparmor: fix out-of-bounds write when null terminating a label vec — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89762 | linux-libc-dev | 7.0.0-31.31 | kernel: apparmor: fix cred UAF caused by begin_current_label_crit_section() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89763 | linux-libc-dev | 7.0.0-31.31 | kernel: KEYS: trusted: Fix TPM teardown ordering — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89764 | linux-libc-dev | 7.0.0-31.31 | kernel: rust: devres: fix race between concurrent revokers — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89765 | linux-libc-dev | 7.0.0-31.31 | kernel: timers/itimer: Zero-init old itimerval before copy to userspace — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89766 | linux-libc-dev | 7.0.0-31.31 | kernel: pidfd: hold exec_update_lock around namespace ioctl — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89767 | linux-libc-dev | 7.0.0-31.31 | kernel: ovl: fix double end_creating() on the casefold-mismatch path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89768 | linux-libc-dev | 7.0.0-31.31 | kernel: fs: fix user path of nested backing files — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89769 | linux-libc-dev | 7.0.0-31.31 | kernel: clocksource/drivers/nxp-pit: Fix IRQ leak on cpuhp_setup_state error path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89771 | linux-libc-dev | 7.0.0-31.31 | kernel: ring-buffer: Fix subbuf resize race with ring buffer readers — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89772 | linux-libc-dev | 7.0.0-31.31 | kernel: btrfs: write-protect folios during data writeback — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89773 | linux-libc-dev | 7.0.0-31.31 | kernel: drm/amd/display: Skip Update HDCP Config In Transition State — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89774 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | In the Linux kernel, the following vulnerability has been resolved: B ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-89775 | linux-libc-dev | 7.0.0-31.31 | kernel: KVM: arm64: Handle negative S1 walk levels in VNCR TLB size evaluation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89776 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: v ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89777 | linux-libc-dev | 7.0.0-31.31 | kernel: vfio/pci: clear vdev->msi_perm after freeing it on init failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89778 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89779 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89780 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89781 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89782 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89841 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89842 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89843 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89844 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89845 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89846 | linux-libc-dev | 7.0.0-31.31 | kernel: scsi: qla2xxx: Bound rsp_info_len to avoid OOB sense-data read — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89847 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89848 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89849 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89850 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89851 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89852 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89853 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89854 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89855 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89856 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89857 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89858 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89859 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89860 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89861 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89862 | linux-libc-dev | 7.0.0-31.31 | kernel: scsi: qla2xxx: Fix BSG job leak on validate flash image error path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89863 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89864 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89865 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89866 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89867 | linux-libc-dev | 7.0.0-31.31 | kernel: media: chips-media: wave5: Defer job_finish() only when a DEC_PIC was queued — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89868 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89869 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89812 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89813 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89814 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89815 | linux-libc-dev | 7.0.0-31.31 | kernel: drm/ttm: Drop tt->restore after successful restore — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89816 | linux-libc-dev | 7.0.0-31.31 | kernel: drm: Fix drm_crtc_commit leak if signaled when PAGE_FLIP_EVENT is used — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89817 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89818 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89819 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89820 | linux-libc-dev | 7.0.0-31.31 | kernel: drm/amd/display: fix dc_lock leak on GPU reset error paths — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89821 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89822 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89823 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89824 | linux-libc-dev | 7.0.0-31.31 | kernel: drm/panel-edp: fix i2c adapter leak on probe failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89825 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89826 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89827 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89828 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89829 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89830 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89831 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89832 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89833 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89834 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89835 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89836 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89837 | linux-libc-dev | 7.0.0-31.31 | kernel: f2fs: fix dentry folio leak in find_in_level — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89838 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89839 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89840 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98046 | linux-libc-dev | 7.0.0-31.31 | kernel: bpf: Mark bpf_btf_find_by_name_kind() as sleepable — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98047 | linux-libc-dev | 7.0.0-31.31 | kernel: bpf: Check ancestor frames for rbtree callbacks — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98048 | linux-libc-dev | 7.0.0-31.31 | kernel: bpf: don't rewrite bpf_fastcall patterns entered by a jump — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98049 | linux-libc-dev | 7.0.0-31.31 | kernel: bpf: zero extend the result of an arena 32-bit cmpxchg — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98050 | linux-libc-dev | 7.0.0-31.31 | kernel: mlxsw: spectrum_ptp: Fix napi_gro_receive() call from GC workqueue context — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98051 | linux-libc-dev | 7.0.0-31.31 | kernel: net: bcmasp: fix tx_spb_ring_full() checking same slot cnt times — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98052 | linux-libc-dev | 7.0.0-31.31 | kernel: net: bcmasp: clear txcb->last before writing each descriptor — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98053 | linux-libc-dev | 7.0.0-31.31 | kernel: ASoC: Intel: avs: Refactor and fix init_config access — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98054 | linux-libc-dev | 7.0.0-31.31 | kernel: ASoC: Intel: avs: Fix unbalanced module reference count — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98055 | linux-libc-dev | 7.0.0-31.31 | kernel: ASoC: Intel: avs: Clean up the bus when fetching ML caps fails — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98056 | linux-libc-dev | 7.0.0-31.31 | kernel: nvme: remove stale namespaces by NSID range during scan — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98057 | linux-libc-dev | 7.0.0-31.31 | kernel: ring-buffer: Add checking nr_subbufs to persistent ring buffer validation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98058 | linux-libc-dev | 7.0.0-31.31 | kernel: bpf: Mark syscall helpers as sleepable — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98059 | linux-libc-dev | 7.0.0-31.31 | kernel: bpf: Mark sched_process_wait argument as nullable — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98060 | linux-libc-dev | 7.0.0-31.31 | kernel: bpf: Reject resilient lock operations in rbtree callbacks — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98061 | linux-libc-dev | 7.0.0-31.31 | kernel: bpf: Reject tail calls directly from callback frames — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98062 | linux-libc-dev | 7.0.0-31.31 | kernel: bpf: Mark signal tracepoint siginfo arguments as scalar — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98063 | linux-libc-dev | 7.0.0-31.31 | kernel: bpf: Fix NULL-ptr-deref in btf_var_show() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98064 | linux-libc-dev | 7.0.0-31.31 | kernel: bpf: Fix NULL-ptr-deref when showing a void BTF type — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98065 | linux-libc-dev | 7.0.0-31.31 | kernel: bpf: Reject key-less BTF for hash maps — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98066 | linux-libc-dev | 7.0.0-31.31 | kernel: ALSA: caiaq: Fix potential double-free at error path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98067 | linux-libc-dev | 7.0.0-31.31 | kernel: erofs: disable LZ4 rolling decompression for now — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98068 | linux-libc-dev | 7.0.0-31.31 | kernel: net/rds: don't let rds_conn_shutdown() consume a concurrent drop — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98069 | linux-libc-dev | 7.0.0-31.31 | kernel: net/rds: acquire the fastpath locks in rds_conn_shutdown() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98070 | linux-libc-dev | 7.0.0-31.31 | kernel: net/rds: acquire RDS_IN_XMIT in rds_tcp_reset_callbacks() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98071 | linux-libc-dev | 7.0.0-31.31 | kernel: net/rds: clear cp_flags bits individually in rds_conn_path_reset() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98072 | linux-libc-dev | 7.0.0-31.31 | kernel: net/rds: use wq_has_sleeper() in release_in_xmit() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98073 | linux-libc-dev | 7.0.0-31.31 | kernel: net: Remove conflicting altnames for dying netns in __dev_change_net_namespace() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98012 | linux-libc-dev | 7.0.0-31.31 | kernel: net/sched: sfq: clamp quantum in change path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98013 | linux-libc-dev | 7.0.0-31.31 | kernel: net/sched: fq_pie: clamp quantum in change path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98014 | linux-libc-dev | 7.0.0-31.31 | kernel: net/mlx5: E-Switch, prevent mc_list repopulation during vport disable — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98015 | linux-libc-dev | 7.0.0-31.31 | kernel: net/mlx5: E-Switch: fix use-after-free in mlx5_eswitch_termtbl_put — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98016 | linux-libc-dev | 7.0.0-31.31 | kernel: net/mlx5e: Fix use-after-free race in sample_restore_put() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98017 | linux-libc-dev | 7.0.0-31.31 | kernel: net/sched: defer qdisc freeing after failed creation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98018 | linux-libc-dev | 7.0.0-31.31 | kernel: net: mctp: i3c: serialize probe with bus removal — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98019 | linux-libc-dev | 7.0.0-31.31 | kernel: bpf: mark a NULL call argument precise — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98020 | linux-libc-dev | 7.0.0-31.31 | kernel: pds_core: fix cmd_regs access racing BAR unmap on reset — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98021 | linux-libc-dev | 7.0.0-31.31 | kernel: net: reject oversized tx_queue_len at netlink parse time — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98022 | linux-libc-dev | 7.0.0-31.31 | kernel: net: cap tx_queue_len at S16_MAX to prevent oversized ring allocations — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98023 | linux-libc-dev | 7.0.0-31.31 | kernel: vxlan: reject dynamic fdb entries that reference a nexthop id — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98024 | linux-libc-dev | 7.0.0-31.31 | kernel: s390/ism: folio_put() after error — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98025 | linux-libc-dev | 7.0.0-31.31 | kernel: net: usb: cx82310_eth: drop URB after 0xffff reboot sentinel to prevent partial_data heap overflow — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98026 | linux-libc-dev | 7.0.0-31.31 | kernel: net: bridge: mcast: properly convert mglist to rcu — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98027 | linux-libc-dev | 7.0.0-31.31 | kernel: net: dsa: mv88e6xxx: bound the policy rule dump by the caller's buffer size — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98028 | linux-libc-dev | 7.0.0-31.31 | kernel: eth: nfp: drop the replaced rule from the list when reprogramming fails — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98029 | linux-libc-dev | 7.0.0-31.31 | kernel: eth: nfp: bound the ntuple rule dump by the caller's buffer size — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98030 | linux-libc-dev | 7.0.0-31.31 | kernel: net: dsa: bcm_sf2: bound the CFP rule dump by the caller's buffer size — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98031 | linux-libc-dev | 7.0.0-31.31 | kernel: nexthop: Initialize extack in remove_nh_grp_entry() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98032 | linux-libc-dev | 7.0.0-31.31 | kernel: tracing: Fix subbuf resize races with trace_pipe_raw readers — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98033 | linux-libc-dev | 7.0.0-31.31 | kernel: bpf: Preserve inner map identity in callback frames — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98034 | linux-libc-dev | 7.0.0-31.31 | kernel: bpf: Mark NULL kptr stores precise — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98037 | linux-libc-dev | 7.0.0-31.31 | kernel: bpf: Reject untrusted allocated-object pointers — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98038 | linux-libc-dev | 7.0.0-31.31 | kernel: bpf: Keep refcount_acquire nullable for borrowed RCU kptrs — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98039 | linux-libc-dev | 7.0.0-31.31 | kernel: bpf: Require MEM_PERCPU for percpu kptr stores — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98041 | linux-libc-dev | 7.0.0-31.31 | kernel: bpf: Don't predict JMP32 pointer vs zero comparisons — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98043 | linux-libc-dev | 7.0.0-31.31 | kernel: bpf: Don't infer non-NULL from a pointer with an unbounded offset — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98044 | linux-libc-dev | 7.0.0-31.31 | kernel: bpf: Reject legacy packet loads from callbacks — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98104 | linux-libc-dev | 7.0.0-31.31 | kernel: net/sched: cls_u32: fix duplicate handle when node ID pool is exhausted — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98105 | linux-libc-dev | 7.0.0-31.31 | kernel: net: ethernet: oa_tc6: Improve the error recovery — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98106 | linux-libc-dev | 7.0.0-31.31 | kernel: drm/pagemap: Prevent double migration of device pages — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98107 | linux-libc-dev | 7.0.0-31.31 | kernel: Bluetooth: L2CAP: fix out-of-bounds write in l2cap_ecred_connect — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98108 | linux-libc-dev | 7.0.0-31.31 | kernel: Bluetooth: L2CAP: fix chan mode for LE_CONN_REQ + EXT_FLOWCTL pchan — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98109 | linux-libc-dev | 7.0.0-31.31 | kernel: Bluetooth: hci_core: Fix race condition during device registration — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98110 | linux-libc-dev | 7.0.0-31.31 | kernel: Bluetooth: btintel: bound firmware ID by TLV length — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98111 | linux-libc-dev | 7.0.0-31.31 | kernel: Bluetooth: btintel: validate version TLV value lengths — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98112 | linux-libc-dev | 7.0.0-31.31 | kernel: ksmbd: fix listener task lifetime on netdev events — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98113 | linux-libc-dev | 7.0.0-31.31 | kernel: ksmbd: rate limit unmapped SID errors — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98114 | linux-libc-dev | 7.0.0-31.31 | kernel: ksmbd: propagate DACL parsing errors — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98115 | linux-libc-dev | 7.0.0-31.31 | kernel: ksmbd: safely drain sessions during logoff — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98116 | linux-libc-dev | 7.0.0-31.31 | kernel: ALSA: pcm: Serialize PCM mmap with buffer reallocation to fix page UAF — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98117 | linux-libc-dev | 7.0.0-31.31 | kernel: cachefiles: Fix potential UAF/KASAN warning — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98118 | linux-libc-dev | 7.0.0-31.31 | kernel: netfs: Fix readahead synchronisation issues by loading all folios upfront — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98119 | linux-libc-dev | 7.0.0-31.31 | kernel: netfs: break unbuffered write when netfs_alloc_subrequest() fails — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98120 | linux-libc-dev | 7.0.0-31.31 | kernel: netfs: Fix subreq ref leak — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98121 | linux-libc-dev | 7.0.0-31.31 | kernel: watchdog: msc313e: Fix NULL pointer dereference in PM callbacks — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98122 | linux-libc-dev | 7.0.0-31.31 | kernel: vxlan: mdb: Fix use-after-free in vxlan_mdb_remote_src_del() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98123 | linux-libc-dev | 7.0.0-31.31 | kernel: sctp: fix soft lockup from unpadded ASCONF-ACK parameter iteration — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98124 | linux-libc-dev | 7.0.0-31.31 | kernel: smb/client: invalidate fscache for fallocate range operations — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98125 | linux-libc-dev | 7.0.0-31.31 | kernel: smb/client: fix stale page cache in insert/collapse range — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98126 | linux-libc-dev | 7.0.0-31.31 | kernel: smb/client: validate new EOF for zero range — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98127 | linux-libc-dev | 7.0.0-31.31 | kernel: smb/client: validate new EOF for insert range — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98128 | linux-libc-dev | 7.0.0-31.31 | kernel: scsi: mpi3mr: Fix target device refcount leak in mpi3mr_sas_port_add() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98129 | linux-libc-dev | 7.0.0-31.31 | kernel: scsi: mpi3mr: Fix NULL pointer dereference in mpi3mr_sas_port_add() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98130 | linux-libc-dev | 7.0.0-31.31 | kernel: sctp: fix a TOCTOU race in SCTP_CMD_TIMER_START — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98131 | linux-libc-dev | 7.0.0-31.31 | kernel: net: stmmac: fix dma mapping leak in stmmac_tso_xmit() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98134 | linux-libc-dev | 7.0.0-31.31 | kernel: bpf: check_cond_jmp_op(): properly infer if register is null — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98074 | linux-libc-dev | 7.0.0-31.31 | kernel: bonding: do not clear curr_active_slave prematurely when releasing all slaves — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98075 | linux-libc-dev | 7.0.0-31.31 | kernel: bpf: reject BPF_PSEUDO_FUNC reference to the main program — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98076 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: t ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98077 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98078 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98079 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98080 | linux-libc-dev | 7.0.0-31.31 | kernel: btrfs: do not force reloc root creation during qgroup_account_snapshot() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98081 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98082 | linux-libc-dev | 7.0.0-31.31 | kernel: btrfs: fix the possible bioc_list memory leak during error — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98083 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98084 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98085 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98086 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: A ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98087 | linux-libc-dev | 7.0.0-31.31 | kernel: sched/rt,dl: Skip migrate-disabled tasks when picking a push candidate — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98088 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98089 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98090 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98091 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98092 | linux-libc-dev | 7.0.0-31.31 | kernel: ASoC: amd: yc: fix memory leak in acp6x_pdm_dma_close() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98093 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: A ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98094 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98095 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: a ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98096 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98097 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: t ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98098 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: t ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98099 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98101 | linux-libc-dev | 7.0.0-31.31 | kernel: ipv6: mcast: use copy-on-write RCU updates in ip6_mc_source() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98102 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98103 | linux-libc-dev | 7.0.0-31.31 | kernel: igmp: convert struct ip_sf_list to RCU — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97921 | linux-libc-dev | 7.0.0-31.31 | kernel: tracing: Free histogram the field rejected for a bad modifier — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97922 | linux-libc-dev | 7.0.0-31.31 | kernel: tracing: Free histogram var refs regardless of how often they are referenced — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97923 | linux-libc-dev | 7.0.0-31.31 | kernel: tracing: Free histogram the var ref when its initialization fails — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97924 | linux-libc-dev | 7.0.0-31.31 | kernel: tracing/user_events: Don't destroy fields when event removal fails — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97925 | linux-libc-dev | 7.0.0-31.31 | kernel: tick/broadcast: Plug clockevents replacement race — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97926 | linux-libc-dev | 7.0.0-31.31 | kernel: ufs: validate cylinder group metadata before caching it — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97927 | linux-libc-dev | 7.0.0-31.31 | kernel: ufs: create the root dentry after loading cylinder metadata — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97928 | linux-libc-dev | 7.0.0-31.31 | kernel: drm/amdgpu: skip the VMID 0 flush for VRAM — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97929 | linux-libc-dev | 7.0.0-31.31 | kernel: ALSA: usbusx2y: validate URB actual_length in interrupt callback — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97930 | linux-libc-dev | 7.0.0-31.31 | kernel: ALSA: usbusx2y: fix in04_last array size mismatch with in04_buf — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97931 | linux-libc-dev | 7.0.0-31.31 | kernel: ALSA: us122l: Prevent write upgrades for read mappings — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97932 | linux-libc-dev | 7.0.0-31.31 | kernel: tracing: Don't dereference trace_event_file in deferred trigger free — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97933 | linux-libc-dev | 7.0.0-31.31 | kernel: tracing: Take trace_array reference when opening a tracer options file — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97934 | linux-libc-dev | 7.0.0-31.31 | kernel: tracing: Fix memory corruption from a "STACKTRACE" histogram key — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97935 | linux-libc-dev | 7.0.0-31.31 | kernel: tracing: Set the trace clock before registering the histogram trigger — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97936 | linux-libc-dev | 7.0.0-31.31 | kernel: tracing: Fix memory corruption from the histogram stacktrace modifier — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97938 | linux-libc-dev | 7.0.0-31.31 | kernel: reboot: fix cad_pid use-after-free race — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97939 | linux-libc-dev | 7.0.0-31.31 | kernel: ipmr: account multicast table and route memory — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97940 | linux-libc-dev | 7.0.0-31.31 | kernel: ipv6: fix fib6 walker UAF on seq stop — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97942 | linux-libc-dev | 7.0.0-31.31 | kernel: x86/alternatives: Exclude text poking against change_page_attr() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97943 | linux-libc-dev | 7.0.0-31.31 | kernel: x86/mm/pat: Acquire init_mm write lock on collapse to avoid UAF — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97944 | linux-libc-dev | 7.0.0-31.31 | kernel: x86/cfi: Fix FineIBT hash offset in cfi_get_func_hash() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97945 | linux-libc-dev | 7.0.0-31.31 | kernel: x86/mm: Fix user-space data loss with MADV_FREE and THP — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97946 | linux-libc-dev | 7.0.0-31.31 | kernel: x86/amd_node: Fix PCI device reference counting in amd_smn_init() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97947 | linux-libc-dev | 7.0.0-31.31 | kernel: x86/amd_node: Fix potential NULL pointer dereference — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97948 | linux-libc-dev | 7.0.0-31.31 | kernel: powerpc/eeh: Fix recursive locking on devices without EEH sensitive driver — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97949 | linux-libc-dev | 7.0.0-31.31 | kernel: configfs: unhash the dentry before dropping the item in rmdir — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97950 | linux-libc-dev | 7.0.0-31.31 | kernel: configfs: pin the symlink target's dirent instead of chasing ->ci_dentry — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97951 | linux-libc-dev | 7.0.0-31.31 | kernel: scsi: target: iscsi: Fix hang for aborted WRITE_PENDING commands — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97614 | linux-libc-dev | 7.0.0-31.31 | kernel: net: dsa: tag_brcm: legacy FCS: request needed tailroom — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97615 | linux-libc-dev | 7.0.0-31.31 | kernel: net: bridge: use option bits for CFM/MRP frame handlers — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97616 | linux-libc-dev | 7.0.0-31.31 | kernel: net/sched: act_api: release all action references on NEWACTION failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97617 | linux-libc-dev | 7.0.0-31.31 | kernel: ring-buffer: Check resize_disabled before publishing the new subbuf order — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97618 | linux-libc-dev | 7.0.0-31.31 | kernel: io_uring/net: don't overconsume buffers when using MSG_TRUNC — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97619 | linux-libc-dev | 7.0.0-31.31 | kernel: io_uring/rw: end write accounting from ->ki_complete — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97620 | linux-libc-dev | 7.0.0-31.31 | kernel: drm/xe: Flush LSC untyped L1 dataport cache after rcs/ccs batches — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97621 | linux-libc-dev | 7.0.0-31.31 | kernel: drm/rockchip: analogix_dp: fix unchecked bound endpoint name length — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97899 | linux-libc-dev | 7.0.0-31.31 | kernel: drm/i915: Fix memory leak in query_perf_config_list() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97900 | linux-libc-dev | 7.0.0-31.31 | kernel: drm/drm_exec: fix up contended obj when num_objects is 0 — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97901 | linux-libc-dev | 7.0.0-31.31 | kernel: genetlink: pin family module during policy dump — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97902 | linux-libc-dev | 7.0.0-31.31 | kernel: fs: don't return -EINVAL for successful nested thaw — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97903 | linux-libc-dev | 7.0.0-31.31 | kernel: exit: hold a reference to thread_pid across proc_flush_pid — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97904 | linux-libc-dev | 7.0.0-31.31 | kernel: cpufreq: initialize policy rwsem before sysfs publication — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97905 | linux-libc-dev | 7.0.0-31.31 | kernel: cpufreq: zero-initialize policy cpumask before sysfs publication — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97906 | linux-libc-dev | 7.0.0-31.31 | kernel: bootconfig: Fix integer overflow in initrd size check — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97907 | linux-libc-dev | 7.0.0-31.31 | kernel: Bluetooth: btrtl: Don't leak return code when parsing firmware format v2 — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97908 | linux-libc-dev | 7.0.0-31.31 | kernel: Bluetooth: btqcomsmd: destroy RPMsg endpoints before freeing hci_dev — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97909 | linux-libc-dev | 7.0.0-31.31 | kernel: ASoC: sti: initialize IRQ lock before requesting IRQ — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97910 | linux-libc-dev | 7.0.0-31.31 | kernel: ASoC: sprd: validate compress buffer sizes against fixed allocations — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97912 | linux-libc-dev | 7.0.0-31.31 | kernel: accel: ethosu: Ensure SRAM size is 0 on mapping failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97913 | linux-libc-dev | 7.0.0-31.31 | kernel: accel: ethosu: Ensure cmd stream ends with a stop op — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97914 | linux-libc-dev | 7.0.0-31.31 | kernel: accel: ethosu: Fix ethosu_job_open() return value — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97915 | linux-libc-dev | 7.0.0-31.31 | kernel: accel/ivpu: Limit firmware log name prints to field size — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97916 | linux-libc-dev | 7.0.0-31.31 | kernel: accel/ivpu: Validate firmware log buffer metadata — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97917 | linux-libc-dev | 7.0.0-31.31 | kernel: accel/ivpu: Validate full buffer range in ivpu_to_cpu_addr — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97918 | linux-libc-dev | 7.0.0-31.31 | kernel: tracing: Undo the registration when enabling the histogram trigger fails — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97919 | linux-libc-dev | 7.0.0-31.31 | kernel: tracing: Take the reference before publishing the named histogram trigger — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97920 | linux-libc-dev | 7.0.0-31.31 | kernel: tracing: Keep the entry count when the histogram stats allocation fails — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97982 | linux-libc-dev | 7.0.0-31.31 | kernel: net: ethernet: cortina: Fix budget accounting — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97983 | linux-libc-dev | 7.0.0-31.31 | kernel: vduse: return compat ioctl results directly — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97984 | linux-libc-dev | 7.0.0-31.31 | kernel: net: ipv6: Fix UDP length overflow with PMTU discover and big MTU — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97985 | linux-libc-dev | 7.0.0-31.31 | kernel: af_unix: Update last skb marker in manage_oob() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97986 | linux-libc-dev | 7.0.0-31.31 | kernel: virtio_input: stop callbacks before unregistering input device — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97987 | linux-libc-dev | 7.0.0-31.31 | kernel: virtio_input: reset device if input_register_device() fails — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97988 | linux-libc-dev | 7.0.0-31.31 | kernel: vhost: invalidate vring access on IOTLB transitions — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97989 | linux-libc-dev | 7.0.0-31.31 | kernel: vduse: validate virtqueue alignment — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97990 | linux-libc-dev | 7.0.0-31.31 | kernel: vdpa_sim_net: check TX pull result before RX copy — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97991 | linux-libc-dev | 7.0.0-31.31 | kernel: vdpa_sim_blk: reject out-of-range sector starts — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97992 | linux-libc-dev | 7.0.0-31.31 | kernel: vhost-vdpa: protect config_ctx from being freed under the config callback — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97993 | linux-libc-dev | 7.0.0-31.31 | kernel: vhost-vdpa: don't install the eventfd_ctx_fdget() error in config_ctx — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97994 | linux-libc-dev | 7.0.0-31.31 | kernel: vhost/vdpa: reject VRING_NUM larger than device max — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97995 | linux-libc-dev | 7.0.0-31.31 | kernel: virtio_console: do not free control-out buffers on remove — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97996 | linux-libc-dev | 7.0.0-31.31 | kernel: virtio: fix use-after-free in unregister_virtio_device() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97997 | linux-libc-dev | 7.0.0-31.31 | kernel: virtio_ring: fix stale descriptor flags after a failed packed add — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97998 | linux-libc-dev | 7.0.0-31.31 | kernel: netfilter: nfnetlink_log: cope with concurrent instance destruction — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98000 | linux-libc-dev | 7.0.0-31.31 | kernel: hwmon: Fix potential UAF in pec_store — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98001 | linux-libc-dev | 7.0.0-31.31 | kernel: hwmon: (ltc4282) Make sure clk_init_data is fully initialized — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98002 | linux-libc-dev | 7.0.0-31.31 | kernel: iommu/amd: Fix ineffective error check in nested domain allocation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98003 | linux-libc-dev | 7.0.0-31.31 | kernel: iommu/amd: Do not reallocate GA log buffers on resume — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98004 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98005 | linux-libc-dev | 7.0.0-31.31 | kernel: erofs: delimit inode_share cache key components — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98006 | linux-libc-dev | 7.0.0-31.31 | kernel: ALSA: caiaq: Decoupling ep1_in_urb in caiaq dev — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98007 | linux-libc-dev | 7.0.0-31.31 | kernel: bpf: Reject non-scalar bpf_loop iteration counts — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98008 | linux-libc-dev | 7.0.0-31.31 | kernel: net: macb: fix NULL pointer dereference on unbind with fixed-link — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98009 | linux-libc-dev | 7.0.0-31.31 | kernel: net/sched: ets: clamp quantum in parse and fallback paths — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98010 | linux-libc-dev | 7.0.0-31.31 | kernel: net/sched: drr: clamp quantum in change class — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98011 | linux-libc-dev | 7.0.0-31.31 | kernel: net/sched: hhf: clamp quantum in change and init paths — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97952 | linux-libc-dev | 7.0.0-31.31 | kernel: sunvdc: unmap LDC cookies when the descriptor send fails — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97953 | linux-libc-dev | 7.0.0-31.31 | kernel: net: stmmac: fix TX descriptor availability check for TSO traffic — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97954 | linux-libc-dev | 7.0.0-31.31 | kernel: net/rds: fix tcp stream corruption with large pages — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97955 | linux-libc-dev | 7.0.0-31.31 | kernel: net: mana: restore the XDP program pointer when pre-allocation fails — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97956 | linux-libc-dev | 7.0.0-31.31 | kernel: net: net_failover: Fix the deadlock in net_failover_slave_name_change() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97957 | linux-libc-dev | 7.0.0-31.31 | kernel: net: hinic: fix mailbox segment buffer overflow — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97958 | linux-libc-dev | 7.0.0-31.31 | kernel: net/sched: cls_api: Don't replay RTM_GETCHAIN in tc_ctl_chain() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97959 | linux-libc-dev | 7.0.0-31.31 | kernel: net/sched: cls_route: free emptied bucket on filter move — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97960 | linux-libc-dev | 7.0.0-31.31 | kernel: perf/x86/intel: Prevent drain_pebs() reentry — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97961 | linux-libc-dev | 7.0.0-31.31 | kernel: perf/core: Allow list_del during perf_event_overflow() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97962 | linux-libc-dev | 7.0.0-31.31 | kernel: net/mlx5e: Move representor vnic reporter to eswitch devlink port — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97963 | linux-libc-dev | 7.0.0-31.31 | kernel: net: stmmac: initialize ptp_lock at probe time — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97964 | linux-libc-dev | 7.0.0-31.31 | kernel: ppp_synctty: ensure a writeable skb header — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97965 | linux-libc-dev | 7.0.0-31.31 | kernel: vxlan: initialize _md in vxlan_xmit_one() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97966 | linux-libc-dev | 7.0.0-31.31 | kernel: octeontx2-pf: reset HTB scheduler topology before freeing queues — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97967 | linux-libc-dev | 7.0.0-31.31 | kernel: hwmon: (corsair-cpro) Remove debugfs entries when probe fails — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97968 | linux-libc-dev | 7.0.0-31.31 | kernel: hwmon: (corsair-cpro) Create debugfs entries after hwmon registration — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97969 | linux-libc-dev | 7.0.0-31.31 | kernel: watchdog: msc313e: Fix clock leak and spurious timer in settimeout() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97970 | linux-libc-dev | 7.0.0-31.31 | kernel: watchdog: msc313e: Avoid division by zero — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97971 | linux-libc-dev | 7.0.0-31.31 | kernel: nstree: check listing permission before taking a namespace reference — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97972 | linux-libc-dev | 7.0.0-31.31 | kernel: net: macb: put the "mdio" child node reference on success — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97973 | linux-libc-dev | 7.0.0-31.31 | kernel: net: macb: destroy the phylink instance on the probe error path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97974 | linux-libc-dev | 7.0.0-31.31 | kernel: ipv6: null-check fib6_node before accessing in __ip6_del_rt_siblings() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97975 | linux-libc-dev | 7.0.0-31.31 | kernel: Bluetooth: hci_sysfs: Fix NULL pointer dereference in device_del() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97976 | linux-libc-dev | 7.0.0-31.31 | kernel: Bluetooth: btintel_pcie: validate packet_len before skb_put_data — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97977 | linux-libc-dev | 7.0.0-31.31 | kernel: Bluetooth: btusb: Fix UAF of btusb_data by rx_work — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97978 | linux-libc-dev | 7.0.0-31.31 | kernel: eth: ice: don't dereference pointers from TP_printk() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97979 | linux-libc-dev | 7.0.0-31.31 | kernel: ice: add missing xa_destroy for sched_node_ids — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97981 | linux-libc-dev | 7.0.0-31.31 | kernel: net: ethernet: cortina: Count dropped frames as NAPI work — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98297 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: B ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98298 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98299 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: t ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98300 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: t ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98301 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98302 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98303 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98304 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98306 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98307 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98308 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: A ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98309 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98311 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98312 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: A ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98313 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98314 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: A ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98316 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: A ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98317 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98318 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98319 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98320 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98321 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98322 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98323 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: R ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98324 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98325 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98326 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98327 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98328 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98268 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: p ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98269 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98270 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98271 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98272 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98273 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: x ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98274 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98275 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98276 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98277 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: e ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98278 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98279 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98280 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98281 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98282 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: p ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98283 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: K ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98284 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98285 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98286 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98287 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: p ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98288 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98289 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: a ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98290 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: B ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98291 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: B ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98292 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: B ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98293 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: B ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98294 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: B ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98295 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: B ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98296 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: B ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98359 | linux-libc-dev | 7.0.0-31.31 | kernel: RDMA/core: Reject unregistering netdevs in ib_get_eth_speed — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98360 | linux-libc-dev | 7.0.0-31.31 | kernel: RDMA/rxe: insert mcg into mcg_tree only after rxe_mcast_add() succeeds — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98361 | linux-libc-dev | 7.0.0-31.31 | kernel: RDMA/rxe: Restore HMM_PFN_WRITE check in ODP write paths — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98362 | linux-libc-dev | 7.0.0-31.31 | kernel: clk: scpi: bound-check DVFS index in scpi_dvfs_recalc_rate — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98363 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98364 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: x ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98365 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: R ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98366 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: R ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98367 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: R ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98368 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: e ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98369 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: x ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98370 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: x ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98371 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: x ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98372 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: x ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35341 | rust-coreutils | 0.8.0-0ubuntu3 | A vulnerability in uutils coreutils mkfifo allows for the unauthorized ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2025-10990 | ruby3.3-dev | 3.3.8-2ubuntu3.1 | rexml: REXML: Denial of Service via inefficient regex parsing — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2025-10990 | ruby3.3 | 3.3.8-2ubuntu3.1 | rexml: REXML: Denial of Service via inefficient regex parsing — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-57433 | perl-modules-5.40 | 5.40.1-7ubuntu0.2 | 5.40.1-7ubuntu0.3 | Storable: Storable: Denial of Service via signed integer overflow in deserialization — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-57432 | perl-modules-5.40 | 5.40.1-7ubuntu0.2 | 5.40.1-7ubuntu0.3 | perl: Perl: Information disclosure via integer overflow in pack/unpack operations — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-13221 | perl-modules-5.40 | 5.40.1-7ubuntu0.2 | 5.40.1-7ubuntu0.3 | perl: Perl: Incorrect regular expression processing via large regular expressions — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-12087 | perl-modules-5.40 | 5.40.1-7ubuntu0.2 | 5.40.1-7ubuntu0.3 | perl-Socket: perl-Socket: Information Disclosure due to Out-of-Bounds Read — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-57433 | perl-base | 5.40.1-7ubuntu0.2 | 5.40.1-7ubuntu0.3 | Storable: Storable: Denial of Service via signed integer overflow in deserialization — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-57432 | perl-base | 5.40.1-7ubuntu0.2 | 5.40.1-7ubuntu0.3 | perl: Perl: Information disclosure via integer overflow in pack/unpack operations — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-13221 | perl-base | 5.40.1-7ubuntu0.2 | 5.40.1-7ubuntu0.3 | perl: Perl: Incorrect regular expression processing via large regular expressions — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-12087 | perl-base | 5.40.1-7ubuntu0.2 | 5.40.1-7ubuntu0.3 | perl-Socket: perl-Socket: Information Disclosure due to Out-of-Bounds Read — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-57433 | perl | 5.40.1-7ubuntu0.2 | 5.40.1-7ubuntu0.3 | Storable: Storable: Denial of Service via signed integer overflow in deserialization — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-57432 | perl | 5.40.1-7ubuntu0.2 | 5.40.1-7ubuntu0.3 | perl: Perl: Information disclosure via integer overflow in pack/unpack operations — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-13221 | perl | 5.40.1-7ubuntu0.2 | 5.40.1-7ubuntu0.3 | perl: Perl: Incorrect regular expression processing via large regular expressions — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-12087 | perl | 5.40.1-7ubuntu0.2 | 5.40.1-7ubuntu0.3 | perl-Socket: perl-Socket: Information Disclosure due to Out-of-Bounds Read — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-98329 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98330 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98331 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98332 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98333 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98334 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98335 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98336 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98337 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98338 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98339 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98340 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98341 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98342 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98343 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98344 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98345 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98346 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98347 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: I ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98348 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98349 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98350 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98351 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98352 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: R ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98354 | linux-libc-dev | 7.0.0-31.31 | kernel: RDMA/mad: Fix receive buffer leak when PKey enforcement fails — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98355 | linux-libc-dev | 7.0.0-31.31 | kernel: RDMA/rtrs: guard against null kobj name — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98356 | linux-libc-dev | 7.0.0-31.31 | kernel: RDMA/bnxt_re: check create_singlethread_workqueue() in DCB setup — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98357 | linux-libc-dev | 7.0.0-31.31 | kernel: IB/isert: wait for deferred control PDU completions before releasing the connection — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98358 | linux-libc-dev | 7.0.0-31.31 | kernel: IB/iser: reject a remote invalidation of an unregistered direction — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98174 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98175 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98176 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98177 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98179 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98180 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98181 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98182 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98184 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98185 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98186 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98187 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98188 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98189 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98190 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98191 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98192 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98193 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98194 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98195 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98196 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98197 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: h ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98198 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: h ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98199 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: h ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98200 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: h ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98201 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: I ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98202 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: I ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98203 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: I ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98204 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: I ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98142 | linux-libc-dev | 7.0.0-31.31 | kernel: drm/cirrus-qemu: Validate BAR0 size during probe — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98143 | linux-libc-dev | 7.0.0-31.31 | kernel: accel: ethosu: Don't read the U65 rounding mode as a storage mode — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98146 | linux-libc-dev | 7.0.0-31.31 | kernel: accel/amdxdna: Remove __counted_by from struct amdxdna_cmd_chain — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98147 | linux-libc-dev | 7.0.0-31.31 | kernel: printk: Don't WARN on kthread_run failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98148 | linux-libc-dev | 7.0.0-31.31 | kernel: drm/gud: validate GUD_ROTATION_0 is present in supported rotations — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98149 | linux-libc-dev | 7.0.0-31.31 | kernel: bpf: Fix percpu map update indexing with sparse CPU IDs — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98150 | linux-libc-dev | 7.0.0-31.31 | kernel: bpf: Fix BPF_F_CPU validation for sparse CPU IDs — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98151 | linux-libc-dev | 7.0.0-31.31 | kernel: bpf: Fix REG INVARIANTS VIOLATION on speculative pointer arithmetic — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98152 | linux-libc-dev | 7.0.0-31.31 | kernel: nvmet-rdma: fix queue leak when connect backlog is exceeded — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98153 | linux-libc-dev | 7.0.0-31.31 | kernel: nvme: fix racy access to FDP placement id array — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98154 | linux-libc-dev | 7.0.0-31.31 | kernel: nvme-rdma: fix -EIO cleanup order in queue_rq — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98155 | linux-libc-dev | 7.0.0-31.31 | kernel: accel/qaic: Address potential out-of-bounds read in resp_worker() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98156 | linux-libc-dev | 7.0.0-31.31 | kernel: drm/virtio: use the DMA API for resource backing on Xen — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98157 | linux-libc-dev | 7.0.0-31.31 | kernel: EDAC/device_sysfs: Use kstrtouint() for poll_msec to prevent truncation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98158 | linux-libc-dev | 7.0.0-31.31 | kernel: ppp_async: drop the errored frame instead of resetting its headroom — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98159 | linux-libc-dev | 7.0.0-31.31 | kernel: wifi: mt76: mt7921: validate CLC firmware records — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98160 | linux-libc-dev | 7.0.0-31.31 | kernel: staging: rtl8723bs: fix mismatched free of HalData in rtw_sdio_if1_init() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98161 | linux-libc-dev | 7.0.0-31.31 | kernel: nvdimm: pmem: keep PREFLUSH before data writes — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98162 | linux-libc-dev | 7.0.0-31.31 | kernel: smb/server: fix tree connection leak in smb2_tree_connect() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98163 | linux-libc-dev | 7.0.0-31.31 | kernel: cgroup: Avoid iteration of dying tasks with zero refcount — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98164 | linux-libc-dev | 7.0.0-31.31 | kernel: KVM: x86/mmu: Check write tracking in all address spaces — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98166 | linux-libc-dev | 7.0.0-31.31 | kernel: drm/ttm: fix swapped-out resources never leaving their bulk_move range — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98167 | linux-libc-dev | 7.0.0-31.31 | kernel: smb: client: fix server->total_read for compound encrypted PDUs — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98168 | linux-libc-dev | 7.0.0-31.31 | kernel: smb: client: fix reparse buffer bounds in cifs_query_reparse_point() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98169 | linux-libc-dev | 7.0.0-31.31 | kernel: smb: client: fix potential OOB read in smb3_enum_snapshots() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98170 | linux-libc-dev | 7.0.0-31.31 | kernel: smb: client: fix OOB struct field reads in move_smb2_ea_to_cifs() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98171 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98172 | linux-libc-dev | 7.0.0-31.31 | kernel: smb: client: fix smbd_connection leak on cifs_get_tcp_session() error — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98173 | linux-libc-dev | 7.0.0-31.31 | kernel: smb: client: fix use-after-free of iface in cifs_try_adding_channels() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98237 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98238 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98239 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98240 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98241 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98242 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98244 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98245 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98246 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: B ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98247 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: B ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98248 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: a ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98249 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: a ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98251 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: o ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98252 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: R ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98253 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: R ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98254 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98255 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: t ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98256 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98257 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: r ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98258 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: p ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98259 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98260 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: e ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98261 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: c ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98262 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: a ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98263 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: A ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98264 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: A ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98265 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: A ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98266 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: A ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98267 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: 9 ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98205 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: I ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98206 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: I ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98207 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98208 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98209 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98210 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98211 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98212 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98213 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98214 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98215 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98216 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: I ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98217 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: I ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98218 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98221 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: K ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98222 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: K ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98223 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98224 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98226 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98227 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98228 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98229 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: x ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98230 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: x ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98231 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: x ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98232 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98233 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98234 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98235 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-98236 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93203 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93204 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93205 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93206 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: P ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93207 | linux-libc-dev | 7.0.0-31.31 | kernel: SUNRPC: Zero rpc_gss_wire_cred at svcauth_gss_decode_credbody() entry — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93208 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: k ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93209 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: B ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93210 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93211 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93212 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93213 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: o ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93214 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: u ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93215 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: c ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93216 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93217 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93218 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93219 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: c ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93220 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93221 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93222 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93223 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93224 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93225 | linux-libc-dev | 7.0.0-31.31 | kernel: phy: fsl-imx8mq-usb: fix typec switch leak on probe error path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93226 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93227 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93228 | linux-libc-dev | 7.0.0-31.31 | kernel: svcrdma: Reject Write/Reply chunks with segcount 0 — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93229 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93230 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93231 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: l ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93172 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93173 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93174 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93175 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93176 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93177 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93178 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93179 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93180 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93181 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: p ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93182 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93183 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93184 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: A ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93185 | linux-libc-dev | 7.0.0-31.31 | kernel: ASoC: rt700-sdw: always drain jack work on remove — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93186 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: c ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93188 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: H ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93189 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: H ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93190 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: p ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93191 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93192 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93193 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93194 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93195 | linux-libc-dev | 7.0.0-31.31 | kernel: drm/bridge: synopsys: dw-dp: Support unregistering the AUX channel — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93196 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93198 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93199 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93200 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93201 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93202 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93266 | linux-libc-dev | 7.0.0-31.31 | kernel: arm64: RSI: fix field-spanning write warning in attestation token init — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93267 | linux-libc-dev | 7.0.0-31.31 | kernel: RDMA/core: Fix potential use after free in uverbs_free_dmah() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93268 | linux-libc-dev | 7.0.0-31.31 | kernel: ext4: skip extra isize expansion during mount to prevent deadlock — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93269 | linux-libc-dev | 7.0.0-31.31 | kernel: ext4: fix circular lock dependency in ext4_ext_migrate — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93270 | linux-libc-dev | 7.0.0-31.31 | kernel: bpf: Disallow interpreter fallback for BPF_ADDR_PERCPU insn — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93271 | linux-libc-dev | 7.0.0-31.31 | kernel: wifi: ath11k: cap out-of-range rx MCS instead of leaving bogus rate — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93272 | linux-libc-dev | 7.0.0-31.31 | kernel: remoteproc: qcom_wcnss: Fix handling the lack of PD regulators in v3 — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93273 | linux-libc-dev | 7.0.0-31.31 | kernel: regulator: tps6594: Fix device node reference leaks in multiphase loop — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93274 | linux-libc-dev | 7.0.0-31.31 | kernel: pinctrl: bcm2835: Don't remove an unregistered GPIO chip — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93275 | linux-libc-dev | 7.0.0-31.31 | kernel: perf/x86/intel/pt: Fix stop/start with no update — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93276 | linux-libc-dev | 7.0.0-31.31 | kernel: phy: renesas: phy-rcar-gen3-usb2: Fix devm action registration for disabled VBUS regulator — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93278 | linux-libc-dev | 7.0.0-31.31 | kernel: staging: octeon: add missing napi_disable in cvm_oct_rx_shutdown — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93279 | linux-libc-dev | 7.0.0-31.31 | kernel: staging: octeon: add missing tasklet_kill in cvm_oct_tx_shutdown — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93280 | linux-libc-dev | 7.0.0-31.31 | kernel: greybus: audio: bound the topology section sizes against the fetched size — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93281 | linux-libc-dev | 7.0.0-31.31 | kernel: wifi: rtw89: fix HE extended capability length check — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93282 | linux-libc-dev | 7.0.0-31.31 | kernel: ksmbd: fix maximum allowed access checks — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93283 | linux-libc-dev | 7.0.0-31.31 | kernel: i3c: master: Fix device_register() error path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93284 | linux-libc-dev | 7.0.0-31.31 | kernel: drm/pagemap: dma-unmap pages before handling migration errors — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93285 | linux-libc-dev | 7.0.0-31.31 | kernel: f2fs: embed f2fs_gc_kthread in f2fs_sb_info — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93286 | linux-libc-dev | 7.0.0-31.31 | kernel: net: appletalk: fix NULL pointer dereference in aarp_send_ddp() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93287 | linux-libc-dev | 7.0.0-31.31 | kernel: i2c: smbus: reject oversized block transfers in the common path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93288 | linux-libc-dev | 7.0.0-31.31 | kernel: netfilter: nfnetlink_log: wait for rcu grace period before freeing pernet state — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93781 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93782 | linux-libc-dev | 7.0.0-31.31 | kernel: vhost-scsi: flush backend after device ioctls — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93783 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: B ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93784 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93785 | linux-libc-dev | 7.0.0-31.31 | kernel: cifs: validate idmap key payload length — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93786 | linux-libc-dev | 7.0.0-31.31 | kernel: ksmbd: preserve VFS inherited POSIX ACL mask — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93787 | linux-libc-dev | 7.0.0-31.31 | kernel: smb: client: bound dirent name against end of SMB response in cifs_filldir — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93233 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93234 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93235 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93236 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93237 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: L ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93238 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93239 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: a ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93240 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93241 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93242 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93243 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93244 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93245 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: a ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93247 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: B ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93248 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93249 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93250 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: v ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93251 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: A ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93252 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: o ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93253 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93255 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93256 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: a ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93258 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: o ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93259 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: p ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93260 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: p ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93261 | linux-libc-dev | 7.0.0-31.31 | kernel: locking/lockdep: Fix NULL pointer dereference in __lock_set_class() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93262 | linux-libc-dev | 7.0.0-31.31 | kernel: md/raid5-ppl: fix use-after-free in ppl_do_flush() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93264 | linux-libc-dev | 7.0.0-31.31 | kernel: RDMA/efa: Fix PBL chunk length computation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93265 | linux-libc-dev | 7.0.0-31.31 | kernel: PCI/pwrctrl: tc9563: Fix parsing the integrated Ethernet MAC Endpoint node — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93077 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: c ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93078 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: c ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93079 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: c ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93080 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93081 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93082 | linux-libc-dev | 7.0.0-31.31 | kernel: firmware: arm_scmi: Unwind P2A receiver mailbox setup failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93083 | linux-libc-dev | 7.0.0-31.31 | kernel: firmware: arm_scmi: Unwind TX receiver mailbox setup failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93084 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93085 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93086 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93089 | linux-libc-dev | 7.0.0-31.31 | kernel: firmware: arm_scmi: Free transport channel on IDR failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93090 | linux-libc-dev | 7.0.0-31.31 | kernel: firmware: arm_scmi: Clean up channels on setup failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93091 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93092 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93093 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93094 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93095 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: h ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93096 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: c ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93097 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: c ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93098 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: r ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93099 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93100 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93101 | linux-libc-dev | 7.0.0-31.31 | kernel: media: v4l2-async: Unregister sub-device if asc_list is empty — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93102 | linux-libc-dev | 7.0.0-31.31 | kernel: RDMA/hfi1: Free RX data on late probe failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93103 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: R ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93104 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: R ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93105 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: e ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93106 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: c ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93107 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: R ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93043 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93044 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93045 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93046 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93047 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93048 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93049 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93050 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93051 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93052 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93053 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93054 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: u ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93055 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: U ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93056 | linux-libc-dev | 7.0.0-31.31 | kernel: usb: gadget: f_uac1_legacy: remove broken string configfs attributes — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93058 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93059 | linux-libc-dev | 7.0.0-31.31 | kernel: drm/msm: Fix task_struct reference leak in recover_worker — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93061 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: g ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93062 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93063 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93064 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93065 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93066 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: x ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93067 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93068 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93069 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: O ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93070 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93071 | linux-libc-dev | 7.0.0-31.31 | kernel: media: bcm2835-unicam: Fix asc leaked in error/remove path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93072 | linux-libc-dev | 7.0.0-31.31 | kernel: irqchip/renesas-irqc: Fix generic interrupt chip leak on remove — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93073 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93140 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: u ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93141 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: u ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93142 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: t ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93143 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93144 | linux-libc-dev | 7.0.0-31.31 | kernel: bpf: Reject writes through untrusted BTF pointers — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93145 | linux-libc-dev | 7.0.0-31.31 | kernel: clk: qcom: gdsc: tear down per-domain genpds in gdsc_unregister() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93146 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: t ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93148 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93149 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93150 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: c ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93151 | linux-libc-dev | 7.0.0-31.31 | kernel: nvmet-rdma: fix response resource leak on queue teardown — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93152 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93153 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: R ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93154 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: R ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93155 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: c ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93156 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: c ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93157 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: h ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93158 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: c ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93159 | linux-libc-dev | 7.0.0-31.31 | kernel: crypto: atmel-sha204a - fix heap info leak on I2C transfer failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93160 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: c ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93161 | linux-libc-dev | 7.0.0-31.31 | kernel: crypto: qat - clear AES key schedule from stack — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93162 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: c ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93163 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: h ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93164 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: u ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93165 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: p ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93167 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: c ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93168 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93169 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93170 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93108 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: R ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93109 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: R ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93110 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: R ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93112 | linux-libc-dev | 7.0.0-31.31 | kernel: bpf: Require a BPF cpumask for bpf_cpumask_populate() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93113 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: c ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93114 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: p ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93115 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: p ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93116 | linux-libc-dev | 7.0.0-31.31 | kernel: platform/x86: asus-wmi: fix resource leaks on probe failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93117 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: u ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93118 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: u ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93119 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: u ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93120 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: u ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93121 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: u ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93122 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: u ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93123 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93125 | linux-libc-dev | 7.0.0-31.31 | kernel: bpf: Reject rdonly/rdwr_buf_size kfunc arguments that exceed u32 max — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93126 | linux-libc-dev | 7.0.0-31.31 | kernel: remoteproc: qcom_q6v5_adsp: Fix reference leak for device node — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93127 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93128 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: p ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93129 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: p ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93130 | linux-libc-dev | 7.0.0-31.31 | kernel: platform/x86: dell-wmi-base: Fix resource leak on module load failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93131 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: p ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93132 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: A ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93133 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: A ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93134 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: p ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93135 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93136 | linux-libc-dev | 7.0.0-31.31 | kernel: bus: mhi: ep: Fix device refcount leak in the error path of MHI device creation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93137 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93138 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97525 | linux-libc-dev | 7.0.0-31.31 | kernel: x86/mm/pat: Allocate split page tables as kernel page tables — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97526 | linux-libc-dev | 7.0.0-31.31 | kernel: s390/pai: Support CPU hotplug for PMU PAI — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97527 | linux-libc-dev | 7.0.0-31.31 | kernel: scsi: qla2xxx: Serialize NVMe unsol ctx list with a per-fcport lock — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97528 | linux-libc-dev | 7.0.0-31.31 | kernel: scsi: qla2xxx: Unlink NVMe unsol ctx before freeing on LS reject error — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97529 | linux-libc-dev | 7.0.0-31.31 | kernel: scsi: qla2xxx: Validate BSG request_len before reading vendor_cmd[] — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97530 | linux-libc-dev | 7.0.0-31.31 | kernel: scsi: qla2xxx: Fix soft lockup polling continuation IOCB signature — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97531 | linux-libc-dev | 7.0.0-31.31 | kernel: scsi: qla2xxx: Skip vport under deletion in report ID acquisition — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97532 | linux-libc-dev | 7.0.0-31.31 | kernel: scsi: qla2xxx: Null out freed pointers in qla2x00_mem_alloc() error path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97533 | linux-libc-dev | 7.0.0-31.31 | kernel: x86/mm/pat: Acquire init_mm read lock on attribute changes to avoid UAF — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97534 | linux-libc-dev | 7.0.0-31.31 | kernel: f2fs: accurately adjust free_sections during free_segment_range — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97535 | linux-libc-dev | 7.0.0-31.31 | kernel: scsi: qla2xxx: Bound VP index against VP_CTRL IOCB bitmap size — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97536 | linux-libc-dev | 7.0.0-31.31 | kernel: scsi: qla2xxx: Fix use-after-free of qpair work on queue teardown — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97537 | linux-libc-dev | 7.0.0-31.31 | kernel: scsi: qla2xxx: Fix queue teardown NULL dma_free and bitmap locking — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97538 | linux-libc-dev | 7.0.0-31.31 | kernel: hwmon: (asus_rog_ryujin) Validate HID report lengths — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97539 | linux-libc-dev | 7.0.0-31.31 | kernel: usb: xusbatm: don't rely on id table pointer arithmetic — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97540 | linux-libc-dev | 7.0.0-31.31 | kernel: net: usb: pegasus: don't rely on id table pointer arithmetic — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97541 | linux-libc-dev | 7.0.0-31.31 | kernel: wifi: ath9k_htc: don't store usb_device_id — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97542 | linux-libc-dev | 7.0.0-31.31 | kernel: xfs: bail out on bitmap errors in xrep_agfl_fill — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97543 | linux-libc-dev | 7.0.0-31.31 | kernel: xfs: destroy seen inode bitmap when we fail to add a dirpath — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97544 | linux-libc-dev | 7.0.0-31.31 | kernel: xfs: don't leak dqacct if rhashtable insertion fails — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97545 | linux-libc-dev | 7.0.0-31.31 | kernel: xfs: don't leak new_bp if xfs_btree_bload_drop_buf fails — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97546 | linux-libc-dev | 7.0.0-31.31 | kernel: xfs: don't spin forever on zero-length dirents when salvaging them — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97547 | linux-libc-dev | 7.0.0-31.31 | kernel: xfs: fix exchange-range reflink flag clearing issue with INO1_WRITTEN — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97548 | linux-libc-dev | 7.0.0-31.31 | kernel: xfs: fix the rtrmap and rtrefcount _maxlevels_ondisk functions — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97549 | linux-libc-dev | 7.0.0-31.31 | kernel: xfs: fix under-reservation of blocks when repairing sf directories — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97550 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: x ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97551 | linux-libc-dev | 7.0.0-31.31 | kernel: xfs: initialise args->total for parent pointer updates — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97552 | linux-libc-dev | 7.0.0-31.31 | kernel: xfs: initialise error in xfs_defer_finish_one() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97553 | linux-libc-dev | 7.0.0-31.31 | kernel: xfs: lock the healthmon when inserting unmount event — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97495 | linux-libc-dev | 7.0.0-31.31 | kernel: drm/amdkfd: Check bounds on allocate_doorbell — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97496 | linux-libc-dev | 7.0.0-31.31 | kernel: drm/amdkfd: Fix OOB memory exposure in get_wave_state() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97497 | linux-libc-dev | 7.0.0-31.31 | kernel: drm/amdkfd: Check bounds for allocate_sdma_queue restore_sdma_id — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97498 | linux-libc-dev | 7.0.0-31.31 | kernel: drm/amdgpu/userq: pin mqd and fw object bo to avoid eviction — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97499 | linux-libc-dev | 7.0.0-31.31 | kernel: coresight: perf: Retrieve path and source from event data — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97500 | linux-libc-dev | 7.0.0-31.31 | kernel: wifi: rtw89: phy: check length before parsing PHY status IE — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97501 | linux-libc-dev | 7.0.0-31.31 | kernel: pinctrl: mediatek: paris: bypass pinctrl GPIO layer in set GPIO direction — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97502 | linux-libc-dev | 7.0.0-31.31 | kernel: mmc: davinci: avoid NULL deref of host->data in IRQ handler — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97503 | linux-libc-dev | 7.0.0-31.31 | kernel: genirq/proc: Size interrupt directory names for 10-digit interrupt numbers — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97505 | linux-libc-dev | 7.0.0-31.31 | kernel: PCI/sysfs: Add CAP_SYS_ADMIN check to __resource_resize_store() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97506 | linux-libc-dev | 7.0.0-31.31 | kernel: crypto: ixp4xx - fix buffer chain unwind on allocation failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97507 | linux-libc-dev | 7.0.0-31.31 | kernel: media: dm1105: fix missing error check for dma_alloc_coherent — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97508 | linux-libc-dev | 7.0.0-31.31 | kernel: thunderbolt: Set tb->root_switch to NULL when domain is stopped — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97509 | linux-libc-dev | 7.0.0-31.31 | kernel: thunderbolt: Keep XDomain reference during the lifetime of a service — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97510 | linux-libc-dev | 7.0.0-31.31 | kernel: thunderbolt: Release request if tb_cfg_request() fails in __tb_xdomain_response() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97511 | linux-libc-dev | 7.0.0-31.31 | kernel: wifi: mac80211: avoid out-of-bounds access in monitor — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97512 | linux-libc-dev | 7.0.0-31.31 | kernel: spi: spi-qcom-qspi: Fix incomplete error handling in runtime PM — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97513 | linux-libc-dev | 7.0.0-31.31 | kernel: media: chips-media: wave5: Release m2m_ctx after Instance Removed from List — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97514 | linux-libc-dev | 7.0.0-31.31 | kernel: media: chips-media: wave5: Fix Reports from Kernel Lock Validator — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97515 | linux-libc-dev | 7.0.0-31.31 | kernel: i3c: master: svc: Prevent IRQ storm from false SLVSTART on NPCM845 — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97516 | linux-libc-dev | 7.0.0-31.31 | kernel: wifi: rtw88: Add NULL check for chip->edcca_th in rtw_fw_adaptivity_result() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97517 | linux-libc-dev | 7.0.0-31.31 | kernel: wifi: nl80211: reject beacons with bad HE operation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97518 | linux-libc-dev | 7.0.0-31.31 | kernel: wifi: cfg80211: reject duplicate wiphy cipher suite entries — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97519 | linux-libc-dev | 7.0.0-31.31 | kernel: drm/xe: Fix null pointer dereference in devcoredump cleanup — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97520 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: g ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97521 | linux-libc-dev | 7.0.0-31.31 | kernel: gfs2: fix quota init duplicate scan — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97522 | linux-libc-dev | 7.0.0-31.31 | kernel: mptcp: fix bad accounting in __mptcp_subflow_push_pending() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97523 | linux-libc-dev | 7.0.0-31.31 | kernel: mptcp: close race between scheduler and state change — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97524 | linux-libc-dev | 7.0.0-31.31 | kernel: mptcp: avoid unneeded actions on subflow reset — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97585 | linux-libc-dev | 7.0.0-31.31 | kernel: afs: Fix double-unmap of directory block — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97586 | linux-libc-dev | 7.0.0-31.31 | kernel: afs: Fix missing kunmap in afs_dir_search_bucket() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97587 | linux-libc-dev | 7.0.0-31.31 | kernel: perf: RISC-V: store available counter mask as bitmap — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97588 | linux-libc-dev | 7.0.0-31.31 | kernel: s390/crypto: Map EBUSY to EIO when key conversion fails repeatedly — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97589 | linux-libc-dev | 7.0.0-31.31 | kernel: s390/crypto: Fix wrong return code to engine in asynch callbacks — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97590 | linux-libc-dev | 7.0.0-31.31 | kernel: s390/crypto: Fix missing scrub of temp buffers with PAES algorithm — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97591 | linux-libc-dev | 7.0.0-31.31 | kernel: s390/crypto: Fix handling of EBUSY in PHMAC when req is pushed to crypto engine — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97592 | linux-libc-dev | 7.0.0-31.31 | kernel: s390/crypto: Fix missing scrub of temp buffers with AES ctr and gcm algorithm — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97593 | linux-libc-dev | 7.0.0-31.31 | kernel: iommu/s390: Fix NULL dereference in iova_to_phys() with ZPCI_TABLE_TYPE_RFX — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97594 | linux-libc-dev | 7.0.0-31.31 | kernel: landlock: Fix use-after-free of the source's parent directory — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97595 | linux-libc-dev | 7.0.0-31.31 | kernel: mac802154: fix use-after-free of sdata via queued RX frames — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97596 | linux-libc-dev | 7.0.0-31.31 | kernel: ipvs: reject invalid states in connection template sync records — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97597 | linux-libc-dev | 7.0.0-31.31 | kernel: ipv6: flowlabel: cap duplicate leases per socket — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97598 | linux-libc-dev | 7.0.0-31.31 | kernel: ipv4: fib: bound automatic table ID allocation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97599 | linux-libc-dev | 7.0.0-31.31 | kernel: ieee802154: hwsim: serialize pib updates to fix double-free — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97600 | linux-libc-dev | 7.0.0-31.31 | kernel: ieee802154: cc2520: fix FIFOP work use-after-free — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97601 | linux-libc-dev | 7.0.0-31.31 | kernel: ieee802154: 6lowpan: fix NULL dereference in lowpan_newlink — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97602 | linux-libc-dev | 7.0.0-31.31 | kernel: inet: frags: invalidate queues before flushing them — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97603 | linux-libc-dev | 7.0.0-31.31 | kernel: idpf: disable DIM work before freeing q_vectors — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97604 | linux-libc-dev | 7.0.0-31.31 | kernel: fbdev: vfb: defer cleanup until the last reference — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97605 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: e ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97606 | linux-libc-dev | 7.0.0-31.31 | kernel: fs: autofs: fix memory leak in autofs_fill_super() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97607 | linux-libc-dev | 7.0.0-31.31 | kernel: vdpa: ifcvf: Put device on unsupported feature error — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97608 | linux-libc-dev | 7.0.0-31.31 | kernel: netfilter: nf_log: unregister loggers before per-net teardown — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97609 | linux-libc-dev | 7.0.0-31.31 | kernel: netfilter: cttimeout: prevent UAF during module unload — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97610 | linux-libc-dev | 7.0.0-31.31 | kernel: netfs: Fix uninitialized return value in netfs_unbuffered_write() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97611 | linux-libc-dev | 7.0.0-31.31 | kernel: net: openvswitch: fix use-after-free of the flow table mask array — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97612 | linux-libc-dev | 7.0.0-31.31 | kernel: net: mpls: clear inner_protocol when the last label is popped — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97613 | linux-libc-dev | 7.0.0-31.31 | kernel: net: mana: Reserve extra CQ slot for the fence completion CQE — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97554 | linux-libc-dev | 7.0.0-31.31 | kernel: smb: client: avoid using uninitialized SIDs in cifs_posix_to_fattr() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97555 | linux-libc-dev | 7.0.0-31.31 | kernel: smb: client: fix heap overflow in DACL owner/group rewrite — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97556 | linux-libc-dev | 7.0.0-31.31 | kernel: smb: client: avoid leaking refcount when cifs_sb_tlink() fails — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97557 | linux-libc-dev | 7.0.0-31.31 | kernel: smb: client: avoid leaking refcount in cifs_queue_oplock_break() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97558 | linux-libc-dev | 7.0.0-31.31 | kernel: smb: client: fix cifsFileInfo reference leak in deferred close — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97559 | linux-libc-dev | 7.0.0-31.31 | kernel: smb: client: fail DACL rewrite when the new DACL exceeds 64K — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97560 | linux-libc-dev | 7.0.0-31.31 | kernel: smb: client: fix one-byte OOB read in smb2_parse_native_symlink() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97561 | linux-libc-dev | 7.0.0-31.31 | kernel: smb: client: honor forceuid/forcegid when mapping SIDs to uid/gid — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97562 | linux-libc-dev | 7.0.0-31.31 | kernel: smb: client: pin DFS superblock in iterator callback — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97563 | linux-libc-dev | 7.0.0-31.31 | kernel: smb: client: reject out-of-bounds DataOffset in CIFSSMBRead() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97564 | linux-libc-dev | 7.0.0-31.31 | kernel: smb: client: reject userspace cifs.idmap descriptions — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97565 | linux-libc-dev | 7.0.0-31.31 | kernel: smb: client: reject short READ responses in CIFSSMBRead() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97566 | linux-libc-dev | 7.0.0-31.31 | kernel: mptcp: pm: kernel: drop pending ADD_ADDR when removing ID0 — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97567 | linux-libc-dev | 7.0.0-31.31 | kernel: mptcp: prevent race between disconnect() and rtx — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97568 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97571 | linux-libc-dev | 7.0.0-31.31 | kernel: bnxt_en: Propagate TPA buffer allocation failures in bnxt_queue_mem_alloc() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97572 | linux-libc-dev | 7.0.0-31.31 | kernel: bnxt_en: Propagate RX ring init failures in bnxt_init_nic() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97573 | linux-libc-dev | 7.0.0-31.31 | kernel: bnxt_en: Handle buffer allocation failure in bnxt_rx_ring_reset() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97574 | linux-libc-dev | 7.0.0-31.31 | kernel: bnxt_en: Don't free the live ring's TPA state on queue restart failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97575 | linux-libc-dev | 7.0.0-31.31 | kernel: media: v4l2-ctrls: validate AV1 tile counts — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97576 | linux-libc-dev | 7.0.0-31.31 | kernel: media: v4l2-ctrls: validate HEVC tile counts — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97577 | linux-libc-dev | 7.0.0-31.31 | kernel: media: verisilicon: rockchip: reject AV1 frames exceeding the tile capacity — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97578 | linux-libc-dev | 7.0.0-31.31 | kernel: media: verisilicon: rockchip: guard VPU981 AV1 divisor and tile buffer — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97579 | linux-libc-dev | 7.0.0-31.31 | kernel: media: mediatek: vcodec: bound AV1 tile-start copy to the array capacity — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97580 | linux-libc-dev | 7.0.0-31.31 | kernel: media: rkvdec: bound HEVC tile loops and PPS id to the array capacity — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97581 | linux-libc-dev | 7.0.0-31.31 | kernel: media: verisilicon: hantro: bound G2 HEVC tile loop to the buffer capacity — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97582 | linux-libc-dev | 7.0.0-31.31 | kernel: hwmon: (gpio-fan) Fix use-after-free in alarm work — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97583 | linux-libc-dev | 7.0.0-31.31 | kernel: afs: Clear stale peer app data after address list changes — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97584 | linux-libc-dev | 7.0.0-31.31 | kernel: afs: Fix incorrect free in candidate cleanup in afs_lookup_server() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93817 | linux-libc-dev | 7.0.0-31.31 | kernel: perf: Fix addr_filter_ranges lifetime — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93818 | linux-libc-dev | 7.0.0-31.31 | kernel: PCI: plda: Protect root bus removal with rescan lock — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93819 | linux-libc-dev | 7.0.0-31.31 | kernel: PCI: mediatek: Protect root bus removal with rescan lock — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93820 | linux-libc-dev | 7.0.0-31.31 | kernel: PCI: rockchip: Protect root bus removal with rescan lock — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93821 | linux-libc-dev | 7.0.0-31.31 | kernel: PCI: altera: Protect root bus removal with rescan lock — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93822 | linux-libc-dev | 7.0.0-31.31 | kernel: PCI: iproc: Protect root bus removal with rescan lock — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93823 | linux-libc-dev | 7.0.0-31.31 | kernel: drm/amdkfd: Let driver decide buffer size at AMDKFD_IOC_GET_DMABUF_INFO ioctl — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93824 | linux-libc-dev | 7.0.0-31.31 | kernel: tls: reject the combination of TLS and sockmap — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93825 | linux-libc-dev | 7.0.0-31.31 | kernel: spi: Add NULL check for spi_get_device_id() in spi_get_device_match_data() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93826 | linux-libc-dev | 7.0.0-31.31 | kernel: HID: hidpp: fix potential UAF in hidpp_connect_event() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93827 | linux-libc-dev | 7.0.0-31.31 | kernel: virtio-fs: avoid double-free on failed queue setup — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93828 | linux-libc-dev | 7.0.0-31.31 | kernel: exfat: fix handling of damaged volume in exfat_create_upcase_table() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93829 | linux-libc-dev | 7.0.0-31.31 | kernel: smb: client: fix races in cifsd thread creation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93830 | linux-libc-dev | 7.0.0-31.31 | kernel: net: stmmac: xgmac2: disable RBUE in default RX interrupt mask — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97407 | linux-libc-dev | 7.0.0-31.31 | kernel: ASoC: rockchip: rockchip_pdm: Handle runtime PM resume failures in set_fmt — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97408 | linux-libc-dev | 7.0.0-31.31 | kernel: Bluetooth: L2CAP: validate connectionless PSM length — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97409 | linux-libc-dev | 7.0.0-31.31 | kernel: nvme-fc: Do not cancel requests in io target before it is initialized — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97410 | linux-libc-dev | 7.0.0-31.31 | kernel: netconsole: take target_cleanup_list_lock in drop_netconsole_target() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97411 | linux-libc-dev | 7.0.0-31.31 | kernel: net: ibm: emac: mal: fix potential system hang in mal_remove() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97412 | linux-libc-dev | 7.0.0-31.31 | kernel: pds_core: quiesce DMA before freeing resources — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97413 | linux-libc-dev | 7.0.0-31.31 | kernel: RDMA/rtrs-srv: Fix integer underflow in process_read and process_write — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97414 | linux-libc-dev | 7.0.0-31.31 | kernel: ASoC: mediatek: mt8365-afe-pcm: fix possible NULL-pointer dereferences in mt8365_afe_suspend() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97415 | linux-libc-dev | 7.0.0-31.31 | kernel: btrfs: tree-checker: validate names in ROOT_REF and ROOT_BACKREF — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97416 | linux-libc-dev | 7.0.0-31.31 | kernel: btrfs: balance: fix potential bg lookup failure in btrfs_may_alloc_data_chunk() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97417 | linux-libc-dev | 7.0.0-31.31 | kernel: netfilter: nf_conntrack: use get_unaligned_be32() in tcp_sack() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97418 | linux-libc-dev | 7.0.0-31.31 | kernel: ALSA: es18xx: check control allocation before private data setup — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97419 | linux-libc-dev | 7.0.0-31.31 | kernel: hsr: broadcast netlink notifications in the device's net namespace — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97420 | linux-libc-dev | 7.0.0-31.31 | kernel: bpf: NUL-terminate replaced sysctl value — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97421 | linux-libc-dev | 7.0.0-31.31 | kernel: RDMA/umem: Be careful about boundary conditions in ib_umem_find_best_pgsz() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93788 | linux-libc-dev | 7.0.0-31.31 | kernel: wifi: iwlwifi: acpi: validate WGDS table revision index — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93789 | linux-libc-dev | 7.0.0-31.31 | kernel: wifi: iwlwifi: bound aligned TLV advance in FW parser — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93790 | linux-libc-dev | 7.0.0-31.31 | kernel: wifi: iwlwifi: mvm: fix out-of-bounds tid_data access in BA notif — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93791 | linux-libc-dev | 7.0.0-31.31 | kernel: wifi: iwlwifi: mvm: add a check on the tid coming from the firmware — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93792 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93793 | linux-libc-dev | 7.0.0-31.31 | kernel: wifi: iwlwifi: mvm: validate TX_CMD response layout — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93794 | linux-libc-dev | 7.0.0-31.31 | kernel: smb/client: flush dirty data before punching a hole — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93795 | linux-libc-dev | 7.0.0-31.31 | kernel: blk-cgroup: fix leaks and online flag on radix_tree_insert failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93796 | linux-libc-dev | 7.0.0-31.31 | kernel: wifi: iwlwifi: pcie: null RX pointers after free — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93797 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93798 | linux-libc-dev | 7.0.0-31.31 | kernel: btrfs: fix reloc root cleanup in merge_reloc_roots() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93799 | linux-libc-dev | 7.0.0-31.31 | kernel: wifi: iwlwifi: mvm: validate sta_id in BA window status notif — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93800 | linux-libc-dev | 7.0.0-31.31 | kernel: btrfs: fix use-after-free on reloc root after error in insert_dirty_subvol() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93801 | linux-libc-dev | 7.0.0-31.31 | kernel: smb/client: zero-initialize stack-allocated cifs_open_info_data — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93802 | linux-libc-dev | 7.0.0-31.31 | kernel: wifi: rsi: validate beacon length before fixed buffer copy — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93803 | linux-libc-dev | 7.0.0-31.31 | kernel: wifi: libipw: fix key index receive bound checks — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93804 | linux-libc-dev | 7.0.0-31.31 | kernel: wifi: mac80211: ibss: wait for in-flight TX on disconnect — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93805 | linux-libc-dev | 7.0.0-31.31 | kernel: wifi: cfg80211: validate rx/tx MLME callback frame lengths before access — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93806 | linux-libc-dev | 7.0.0-31.31 | kernel: wifi: cfg80211: validate assoc response length before status and IE access — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93807 | linux-libc-dev | 7.0.0-31.31 | kernel: wifi: rsi: avoid reading TKIP MIC keys for non-TKIP ciphers — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93808 | linux-libc-dev | 7.0.0-31.31 | kernel: ALSA: usb-audio: caiaq: validate EP1 reply lengths — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93809 | linux-libc-dev | 7.0.0-31.31 | kernel: drm/amdgpu: flush pending RCU callbacks on module unload — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93810 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: c ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93811 | linux-libc-dev | 7.0.0-31.31 | kernel: ksmbd: Fix acl.sd_buf memory leak and invalid sd_size error handling — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93812 | linux-libc-dev | 7.0.0-31.31 | kernel: ksmbd: fix sd_ndr.data memory leak in ksmbd_vfs_set_sd_xattr — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93813 | linux-libc-dev | 7.0.0-31.31 | kernel: btrfs: tree-checker: validate INODE_REF's namelen — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93814 | linux-libc-dev | 7.0.0-31.31 | kernel: spi: core: Abort active target transfer on controller suspend — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93815 | linux-libc-dev | 7.0.0-31.31 | kernel: net: au1000: move free_irq out of the close-time spinlocked section — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-93816 | linux-libc-dev | 7.0.0-31.31 | kernel: f2fs: validate inline dentry name lengths before conversion — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97451 | linux-libc-dev | 7.0.0-31.31 | kernel: ACPICA: Fix integer overflow in acpi_ex_opcode_3A_1T_1R() (mid_op) — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97452 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: A ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97453 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: A ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97454 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: A ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97455 | linux-libc-dev | 7.0.0-31.31 | kernel: ACPICA: Fix use-after-free in acpi_ds_terminate_control_method() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97456 | linux-libc-dev | 7.0.0-31.31 | kernel: ACPICA: Fix condition check in acpi_ps_parse_loop() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97472 | linux-libc-dev | 7.0.0-31.31 | kernel: ipv6: addrconf: fix temp address generation after prefix deprecation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97473 | linux-libc-dev | 7.0.0-31.31 | kernel: powercap: intel_rapl: Fix memory leak in rapl_add_package_cpuslocked() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97474 | linux-libc-dev | 7.0.0-31.31 | kernel: wifi: iwlwifi: mld: purge async notifications upon nic error — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97475 | linux-libc-dev | 7.0.0-31.31 | kernel: thermal/drivers/tegra/soctherma: Switch to devm cooling device registration — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97476 | linux-libc-dev | 7.0.0-31.31 | kernel: rds: filter RDS_INFO_* getsockopt by caller's netns — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97477 | linux-libc-dev | 7.0.0-31.31 | kernel: RDMA/counter: Fix num_counters leak on bind_qp failure in alloc_and_bind() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97478 | linux-libc-dev | 7.0.0-31.31 | kernel: virt: acrn: Fix irqfd use-after-free during eventfd shutdown — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97479 | linux-libc-dev | 7.0.0-31.31 | kernel: driver core: Avoid warning when removing a device while its supplier is unbinding — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97480 | linux-libc-dev | 7.0.0-31.31 | kernel: tty: serial: 8250: protect against NULL uart->port.dev in register — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97481 | linux-libc-dev | 7.0.0-31.31 | kernel: serial: 8250: fix possible ISR soft lockup — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97482 | linux-libc-dev | 7.0.0-31.31 | kernel: usb: gadget: goku_udc: avoid NULL deref of dev->driver in INT_USBRESET log — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97483 | linux-libc-dev | 7.0.0-31.31 | kernel: usb: core: hcd: fix possible deadlock in rh control transfers — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97484 | linux-libc-dev | 7.0.0-31.31 | kernel: usbip: vhci_hcd: fix NULL deref in status_show_vhci — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97485 | linux-libc-dev | 7.0.0-31.31 | kernel: omfs: handle set_blocksize failures — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97486 | linux-libc-dev | 7.0.0-31.31 | kernel: hpfs: handle set_blocksize failures — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97487 | linux-libc-dev | 7.0.0-31.31 | kernel: jfs: handle set_blocksize failures — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97488 | linux-libc-dev | 7.0.0-31.31 | kernel: qnx4: handle set_blocksize failures — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97489 | linux-libc-dev | 7.0.0-31.31 | kernel: bfs: handle set_blocksize failures — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97490 | linux-libc-dev | 7.0.0-31.31 | kernel: affs: handle set_blocksize failures — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97491 | linux-libc-dev | 7.0.0-31.31 | kernel: net/rds: Don't sleep inside rds_ib_conn_path_shutdown — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97492 | linux-libc-dev | 7.0.0-31.31 | kernel: wifi: mac80211: don't call ieee80211_handle_reconfig_failure when not needed — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97493 | linux-libc-dev | 7.0.0-31.31 | kernel: drm/amdgpu: Bound GPIO I2C table entry count from VBIOS — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97494 | linux-libc-dev | 7.0.0-31.31 | kernel: drm/amdgpu: validate and share PSP fw_pri_buf copies via psp_copy_fw — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97422 | linux-libc-dev | 7.0.0-31.31 | kernel: drm/amdkfd: fix SMI event cross-process information leak — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97423 | linux-libc-dev | 7.0.0-31.31 | kernel: cxl/region: Validate partition index before array access — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97424 | linux-libc-dev | 7.0.0-31.31 | kernel: drm/amdgpu/ras: add ras_suspend callback and use it for cp_ecc_error_irq — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97425 | linux-libc-dev | 7.0.0-31.31 | kernel: drm/amdgpu: fix buffer overflow during vBIOS update — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97426 | linux-libc-dev | 7.0.0-31.31 | kernel: drm/amdgpu/pm: fix SmartShift bias sysfs store PM refcount on parse error — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97427 | linux-libc-dev | 7.0.0-31.31 | kernel: drm/amd/pm: bound pp_dpm_set_pp_table() memcpy — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97428 | linux-libc-dev | 7.0.0-31.31 | kernel: drm/amdgpu: harden FRU PIA parsing with bounded helpers — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97429 | linux-libc-dev | 7.0.0-31.31 | kernel: drm/amdkfd: fix UAF race in destroy_queue_cpsch — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97430 | linux-libc-dev | 7.0.0-31.31 | kernel: xhci: Prevent queuing new commands if xhci is inaccessible — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97431 | linux-libc-dev | 7.0.0-31.31 | kernel: drm/amd/display: Avoid DPMS-on for phantom stream — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97432 | linux-libc-dev | 7.0.0-31.31 | kernel: wifi: iwlwifi: mvm: fix P2P-Device binding handling — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97433 | linux-libc-dev | 7.0.0-31.31 | kernel: nvme: validate FDP configuration descriptor sizes — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97434 | linux-libc-dev | 7.0.0-31.31 | kernel: dpaa2-switch: fix handling of NAPI on the remove path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97435 | linux-libc-dev | 7.0.0-31.31 | kernel: net: dsa: sja1105: flower: reject cross-chip redirect — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97436 | linux-libc-dev | 7.0.0-31.31 | kernel: dpaa2-switch: rework FDB management on the bridge leave path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97437 | linux-libc-dev | 7.0.0-31.31 | kernel: ntfs3: fix out-of-bounds read in ntfs_dir_emit() and hdr_find_e() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97438 | linux-libc-dev | 7.0.0-31.31 | kernel: fs/ntfs3: validate index entry key bounds — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97439 | linux-libc-dev | 7.0.0-31.31 | kernel: fs/ntfs3: preserve non-DOS attribute bits in system.dos_attrib — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97440 | linux-libc-dev | 7.0.0-31.31 | kernel: net: qrtr: fix node refcount leak on ctrl packet alloc failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97441 | linux-libc-dev | 7.0.0-31.31 | kernel: ata: ahci: fail probe if BAR too small for claimed ports — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97442 | linux-libc-dev | 7.0.0-31.31 | kernel: wifi: ath11k: fix invalid data access in ath11k_dp_rx_h_undecap_nwifi — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97443 | linux-libc-dev | 7.0.0-31.31 | kernel: perf/ftrace: Fix WARNING in __unregister_ftrace_function — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97444 | linux-libc-dev | 7.0.0-31.31 | kernel: ACPICA: add boundary checks in two places — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97445 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: A ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97446 | linux-libc-dev | 7.0.0-31.31 | kernel: ACPICA: Fix NULL pointer dereference in acpi_ns_custom_package() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97447 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: A ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97448 | linux-libc-dev | 7.0.0-31.31 | kernel: ACPICA: Add validation for node in acpi_ns_build_normalized_path() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97449 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: A ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-97450 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: A ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-72107 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: dm era: fix out-of-bounds memory access for non-zero start sector — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72109 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net: sparx5: unregister blocking notifier on init failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72113 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: can: bcm: add missing device refcount for CAN filter removal — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72114 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: can: bcm: validate frame length in bcm_rx_setup() for RTR replies — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72115 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: can: bcm: track a single source interface for ANYDEV timeout/throttle ops — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72116 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: can: bcm: fix stale rx/tx ops after device removal — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72117 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: can: bcm: fix data race on rx_stamp/rx_ifindex in bcm_rx_handler() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72118 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: can: bcm: fix CAN frame rx/tx statistics — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72119 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: can: bcm: extend bcm_tx_lock usage for data and timer updates — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72120 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: can: bcm: add missing rcu list annotations and operations — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72121 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: can: bcm: add locking when updating filter and timer values — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72122 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: can: bcm: fix lockless bound/ifindex race and silent RX_SETUP failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72125 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: can: isotp: fix use-after-free race with concurrent NETDEV_UNREGISTER — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72126 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: can: isotp: use unconditional synchronize_rcu() in isotp_release() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72127 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: netdev-genl: report NAPI thread PID in the caller's pid namespace — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72128 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: nvmet: fix refcount leak in nvmet_sq_create() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72129 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: nvmet-rdma: handle inline data with a nonzero offset — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72130 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: nvmet-auth: reject short AUTH_RECEIVE buffers — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72131 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: nvme-apple: Prevent shared tags across queues on Apple A11 — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72132 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: NFS: Charge unstable writes by request size, not folio size — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72133 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: spi: uniphier: Fix completion initialization order before devm_request_irq() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72136 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: xfrm: xfrm_interface: require CAP_NET_ADMIN in the device netns for changelink — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72137 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: xfrm: nat_keepalive: avoid double free on send error — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72138 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: xen/gntdev: fix error handling in ioctl — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72139 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: tcp: defer md5sig_info kfree past RCU grace period in tcp_connect — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72140 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72141 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: i2c: imx: fix locked bus on SMBus block-read of 0 (IRQ) — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72142 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: i2c: imx: fix locked bus on SMBus block-read of 0 (atomic) — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72143 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: platform/x86: ISST: Restore SST-PP control to all domains — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72076 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: Input: ims-pcu - fix out-of-bounds read in ims_pcu_irq() debug logging — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72077 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: Input: ims-pcu - fix firmware leak in async update — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72078 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: Input: ims-pcu - validate control endpoint type — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72079 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: Input: ims-pcu - fix use-after-free and double-free in disconnect — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72080 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: fs/resctrl: Fix use-after-free during unmount — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72081 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: scsi: elx: efct: Fix I/O leak on unsupported additional CDB — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72082 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: scsi: elx: efct: Fix refcount leak in efct_hw_io_abort() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72083 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: scsi: target: core: Fix iSCSI ISID use-after-free in REGISTER AND MOVE — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72084 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: scsi: target: Bound PR-OUT TransportID parsing to the received buffer — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72085 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: scsi: xen: scsiback: Free unsubmitted command instead of double-putting it — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72086 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: scsi: xen: scsiback: Free the command tag on the TMR submit-failure path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72087 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: scsi: lpfc: Fix memory leak in lpfc_sli4_driver_resource_setup() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72088 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: scsi: hpsa: Fix DMA mapping leak on IOACCEL2 reset path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72089 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: accel/ivpu: Reject firmware log with size smaller than header — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72091 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: accel/amdxdna: reject user command submission without a command BO — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72092 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | In the Linux kernel, the following vulnerability has been resolved: a ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72093 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: accel/amdxdna: Fix use-after-free in amdxdna_gem_dmabuf_mmap() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72094 | linux-libc-dev | 7.0.0-31.31 | kernel: dma-buf: dma-fence: Fix potential NULL pointer dereference — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-72095 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: dma-fence: Make dma_fence_dedup_array() robust against 0-count input — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72096 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: dm-verity: make error counter atomic — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72097 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: dm-verity: fix a possible NULL pointer dereference — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72098 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: dm-verity: fix buffer overflow in FEC calculation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72099 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: dm-integrity: don't increment hash_offset twice — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72101 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: dm-integrity: fix leaking uninitialized kernel memory — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72102 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: dm_early_create: fix freeing used table on dm_resume failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72103 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: dm: avoid leaking the caller's thread keyring via the table device file — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72104 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: dm-pcache: reject option groups without values — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72105 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: dm-log: fix a bitset_size overflow on 32bit machines — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72106 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: dm-ioctl: fix a possible overflow in list_version_get_info — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72176 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: mm/damon/sysfs-schemes: put stats for scheme_add_dirs() internal error — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72177 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: mm/damon/sysfs-schemes: fix dir put orders in access_pattern_add_dirs() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72178 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: mm/damon/core: always put unsuccessfully committed target pids — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72179 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: riscv: cacheinfo: Fix node reference leak in populate_cache_leaves — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72180 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: mm/huge_memory: preserve pmd_swp_uffd_wp on device-private PMD downgrade — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72181 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: mips: sched: Fix CPUMASK_OFFSTACK memory corruption — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72182 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: power: supply: charger-manager: fix refcount leak in is_full_charged() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72183 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: landlock: Fix LANDLOCK_SCOPE_SIGNAL bypass on the SIGIO path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72191 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: ntfs3: validate split-point offset in indx_insert_into_buffer — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72192 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: ntfs3: bound to_move in indx_insert_into_root before hdr_insert_head — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72193 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ntfs3: cap RESTART_TABLE free-chain walker at rt->used — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72194 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: fs/ntfs3: add depth limit to indx_find_buffer to prevent stack overflow — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72196 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: fs/ntfs3: bound copy_lcns dp->page_lcns[] index in analysis pass — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72197 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: fs/ntfs3: bound DeleteIndexEntryAllocation memmove length — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72198 | linux-libc-dev | 7.0.0-31.31 | kernel: ntfs: reject non-resident records for resident-only attributes — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-72200 | linux-libc-dev | 7.0.0-31.31 | kernel: ntfs: detect mapping-pairs LCN accumulator overflow — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-72202 | linux-libc-dev | 7.0.0-31.31 | kernel: ntfs: avoid heap allocation for free-cluster readahead state — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-72203 | linux-libc-dev | 7.0.0-31.31 | kernel: ntfs: skip extent mft records in writeback to prevent deadlock — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-72205 | linux-libc-dev | 7.0.0-31.31 | kernel: ntfs: free volume-wide resources on fill_super failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-72212 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: mm/memory_hotplug: fix incorrect altmap passing in error path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72213 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: mm/hugetlb: fix hugetlb cgroup rsvd charge/uncharge mismatch — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72214 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: power: supply: cpcap-battery: Fix missing nvmem_device_put() causing reference leak — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72215 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: MIPS: DEC: Ensure 32-bit stack location for o32 prom_printf() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72216 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: remoteproc: qcom: Fix leak when custom dump_segments addition fails — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72217 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: SUNRPC: Bound-check xdr_buf_to_bvec() stores before writing — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72218 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: lockd: Plug nlm_file refcount leak on cached nlm_do_fopen() failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72219 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: lockd: Plug nlm_file leak when nlm_do_fopen() fails — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72220 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: sunrpc: harden rq_procinfo lifecycle to prevent double-free — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72221 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: sunrpc: wait for in-flight TLS handshake callback when cancel loses race — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72144 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: platform/x86: dell-laptop: fix missing cleanups in init error path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72146 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: dmaengine: sh: rz-dmac: Move interrupt request after everything is set up — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72147 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: dmaengine: dw-edma-pcie: Reject devices without driver data — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72148 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: dmaengine: dw-edma: Add spinlock to protect DONE_INT_MASK and ABORT_INT_MASK — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72149 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: dmaengine: tegra: Fix burst size calculation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72150 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: sunrpc: fix uninitialized xprt_create_args structure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72152 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: tpm: tpm_tis_spi: Use wait_woken() in wait_for_tmp_stat() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72153 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: irqchip/crossbar: Use correct index in crossbar_domain_free() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72155 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: mtd: spi-nor: swp: Improve locking user experience — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72156 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: fpga: microchip-spi: fix zero header_size OOB read in mpf_ops_parse_header() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72157 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net: thunderbolt: Fix frags[] overflow by bounding frame_count — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72158 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: fpga: dfl: add bounds check in dfh_get_param_size() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72159 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ocfs2: reject non-inline dinodes with i_size and zero i_clusters — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72160 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ocfs2: reject dinodes with non-canonical i_mode type — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72161 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ocfs2: add journal NULL check in ocfs2_checkpoint_inode() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72162 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ocfs2: fix UBSAN array-index-out-of-bounds in ocfs2_sum_rightmost_rec — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72163 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ocfs2: fix NULL h_transaction deref in ocfs2_assure_trans_credits — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72164 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ocfs2: avoid moving extents to occupied clusters — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72165 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: mtd: rawnand: fix condition in 'nand_select_target()' — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72166 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net/9p: fix infinite loop in p9_client_rpc on fatal signal — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72167 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: mtd: rawnand: pl353: fix probe resource allocation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72168 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: mtd: maps: vmu-flash: fix fault in unaligned fixup — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72169 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: kho: make sure scratch size is always aligned by CMA_MIN_ALIGNMENT_BYTES — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72170 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: 9p: skip nlink update in cacheless mode to fix WARN_ON — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72171 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: mtd: slram: remove failed entries from the device list — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72172 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: mm/mm_init: fix uninitialized struct pages for ZONE_DEVICE — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72173 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: fs/proc/task_mmu: do not warn on seeing non-migration pmd entry — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72174 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: fs/proc/task_mmu: fix hugetlb self-deadlock in pagemap_scan_pte_hole() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72175 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: fs/proc/task_mmu: fix make_uffd_wp_huge_pte() prot-update race — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68452 | linux-libc-dev | 7.0.0-31.31 | kernel: s390/zcrypt: Validate length for CCA AES cipher key requests — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-68453 | linux-libc-dev | 7.0.0-31.31 | kernel: s390/zcrypt: Fix buffer over-read in cca_cipher2protkey — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-68455 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: liveupdate: validate session type before performing operation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68456 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: usb: atm: ueagle-atm: wait for pre-firmware load in .disconnect() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68457 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: ksmbd: use opener credentials for FSCTL mutations — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68458 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: binder: cache secctx size before release zeroes it — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68463 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: mmc: sdhci-esdhc-imx: use pm_runtime_resume_and_get() in suspend — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68464 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: mmc: sdhci-esdhc-imx: disable irq during suspend to fix unhandled interrupt — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68465 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: mmc: sdhci-esdhc-imx: fix esdhc_change_pinstate() to allow default state restore — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68467 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: mtd: mchp23k256: use SPI match data for chip caps — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68469 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: wifi: mwifiex: fix permanently busy scans after multiple roam iterations — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68471 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: wifi: ieee80211: validate MLE common info length — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68472 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: wifi: cfg80211: validate EHT MLE before MLD ID read — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68473 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: powerpc/uaccess: correct check for CONFIG_PPC_E500 in mask_user_address() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68474 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: powerpc/spufs: fix out-of-bounds access in spufs_mem_mmap_access() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68475 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: reset: sunxi: fix memory region leak on ioremap failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68476 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68477 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: ipvs: fix more places with wrong ipv6 transport offsets — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68478 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: memstick: ms_block: reject a card that reports too many blocks — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68479 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: Bluetooth: btrtl: validate firmware patch bounds — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68480 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: AMD-SN-7061: Safe RET Interrupt Vulnerability — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72004 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: wifi: mac80211: fix memory leak in ieee80211_register_hw() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72005 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: wifi: rt2x00: avoid full teardown before work setup in probe — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72006 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net/mlx5: free mlx5_st_idx_data on final dealloc — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72007 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: pmdomain: imx: Fix i.MX8MP VC8000E power up sequence — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72008 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: pmdomain: mediatek: Fix possible nullptr KP in HWV cleanup/on-check — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72009 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: pmdomain: imx93-blk-ctrl: Extract PHY as shared domain for DSI/CSI — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72010 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: cgroup/cpuset: rebind mm mempolicy to effective_mems, not mems_allowed — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72011 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: s390/diag: Add missing array_index_nospec() call to memtop_get_page_count() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68415 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: xfrm: clear mode callbacks after failed mode setup — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68416 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: mtd: fix double free and WARN_ON in add_mtd_device() error paths — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68417 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: RDMA/siw: publish QP after initialization — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68418 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: RDMA/irdma: Prevent user-triggered null deref on QP create — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68419 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: RDMA/irdma: Prevent rereg_mr for non-mem regions — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68420 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: xfrm: reject optional IPTFS templates in outbound policies — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68421 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: sched_ext: Don't warn on core-sched forced idle in put_prev_task_scx() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68422 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: btrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68425 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: IB/mad: Drop unmatched RMPP responses before reassembly — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68426 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: xfrm: fix stale skb->prev after async crypto steals a GSO segment — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68427 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: gpu: host1x: Fix use-after-free in host1x_bo_clear_cached_mappings — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68428 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: KVM: x86/mmu: Fix use-after-free on vendor module reload — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68429 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/dp_mst: Handle torn-down topology gracefully in drm_dp_mst_topology_queue_probe() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68430 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/amdgpu/gfx8: drop unecessary BUG_ON() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68431 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ksmbd: validate minimum PDU size for transform requests — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68433 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: libceph: bound get_version reply decode to front len — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68434 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: serial: 8250_mid: Fix NULL function pointer dereference on DNV/ICX-D/SNR platforms — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68436 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/amd/display: use kvzalloc to allocate struct dc — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68437 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/imagination: Fit paired fragment job in the correct CCCB — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68439 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: wifi: mt76: mt7925: fix possible NULL-pointer deref in mt7925_mcu_bss_he_tlv() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68440 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net: txgbe: fix heap overflow when reading module EEPROM — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68441 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net/sched: Handle TC_ACT_REDIRECT from qdisc filter chains — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68443 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: hwmon: (gigabyte_waterforce) Stop device IO before calling hid_hw_stop — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68444 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: firmware: arm_ffa: Fix NULL dereference in ffa_partition_info_get() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68445 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/vc4: Prevent shader BO mappings from becoming writable — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68447 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/amdkfd: clamp v9 CRIU control stack checkpoint copy to BO size — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68448 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ovl: check access to copy_file_range source with src mounter creds — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68449 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ata: sata_dwc_460ex: fix infinite loop in NCQ tag completion bit-scanning — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68450 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: btrfs: free mapping node on duplicate reloc root insert — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72042 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ipmi: Fix user refcount underflow in event delivery — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72045 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: octeontx2-af: cn10k: restrict VF LMTLINE sharing to its own PF — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72046 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: gve: fix header buffer corruption with header-split and HW-GRO — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72047 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ieee802154: ca8210: fix pointer truncation in kfifo on 64-bit — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72048 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ieee802154: ca8210: fix cas_ctl leak on spi_async failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72049 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ieee802154: admin-gate legacy LLSEC dump operations — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72050 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: octeontx2-af: Free BPID bitmap on setup failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72052 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net: ip6_gre: require CAP_NET_ADMIN in the device netns for changelink — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72053 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net: ipip: require CAP_NET_ADMIN in the device netns for changelink — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72055 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net: ip6_vti: require CAP_NET_ADMIN in the device netns for changelink — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72056 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net: ena: clean up XDP TX queues when regular TX setup fails — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72057 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net/sched: act_ct: preserve tc_skb_cb across defragmentation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72058 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net: ixp4xx_hss: fix duplicate HDLC netdev allocation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72059 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net: wwan: t7xx: destroy DMA pool on CLDMA late init failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72060 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net: ethernet: ti: icssg: guard PA stat lookups — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72061 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net: sit: require CAP_NET_ADMIN in the device netns for changelink — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72062 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: gpio: mt7621: avoid corruption of shared interrupt trigger state — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72063 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: gpio: tegra: do not call pinctrl for GPIO direction — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72064 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: net: mana: Sync page pool RX frags for CPU — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72065 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: net: mana: Validate the packet length reported by the NIC — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72066 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: cpu: hotplug: Bound hotplug states sysfs output — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72067 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: cpu: hotplug: Preserve per instance callback errors — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72068 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: posix-cpu-timers: Use u64 multiplication in update_rlimit_cpu() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72069 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: locking/rt: Fix the incorrect RCU protection in rt_spin_unlock() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72070 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: wifi: libertas_tf: fix use-after-free in lbtf_free_adapter() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72072 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net/mlx5e: macsec: fix use-after-free of metadata_dst on RX SC delete — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72073 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: mmc: vub300: fix use-after-free on probe failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72074 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: Input: ims-pcu - fix type confusion in CDC union descriptor parsing — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72075 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: Input: ims-pcu - fix race condition in reset_device sysfs callback — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72012 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: tracing/osnoise: Call synchronize_rcu() when unregistering — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72013 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: riscv: Prevent NULL pointer dereference in machine_kexec_prepare() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72014 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: drbd: reject data replies with an out-of-range payload size — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72015 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: fs/resctrl: Fix double-add of pseudo-locked region's RMID to free list — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72016 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: cpu/hotplug: Fix NULL kobject warning in cpuhp_smt_enable() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72017 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net: macb: drop in-flight Tx SKBs on close — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72018 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: dibs: loopback: validate offset and size in move_data() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72019 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: macsec: don't read an unset MAC header in macsec_encrypt() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72020 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: ipvs: reset full ip_vs_seq structs in ip_vs_conn_new — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72021 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ipvs: use parsed transport offset in SCTP state lookup — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72022 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: llc: fix SAP refcount leak in llc_ui_autobind() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72023 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: octeontx2-pf: fix SQB pointer leak on init failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72025 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: s390/monwriter: Reject buffer reuse with different data length — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72026 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: irqchip/irq-riscv-imsic-early: Fix fwnode leak on state setup failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72027 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: mm/compaction: handle free_pages_prepare() properly in compaction_free() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72028 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: riscv: probes: save original sp in rethook trampoline — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72029 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net: wwan: iosm: bound device offsets in the MUX downlink decoder — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72030 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ata: libata-core: Reject an invalid concurrent positioning ranges count — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72031 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ata: libata-core: Add NOLPM quirk for PNY CS900 1TB SSD — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72032 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net/mlx5: HWS, fix matcher leak on resize target setup failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72033 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: orangefs: keep the readdir entry size 64-bit in fill_from_part() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72034 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: fhandle: reject detached mounts in capable_wrt_mount() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72035 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net/sched: sch_taprio: Replace direct dequeue call with peek and qdisc_dequeue_peeked — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72036 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net/sched: sch_multiq: Replace direct dequeue call with peek and qdisc_dequeue_peeked — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72037 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net: lan743x: Initialize eth_syslock spinlock before use — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72038 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net: liquidio: fix BAR resource leak on PF number failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72039 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: bnx2x: fix potential memory leak in bnx2x_alloc_mem_bp() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72040 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ipmi: fix refcount leak in i_ipmi_request() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72041 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: espintcp: use sk_msg_free_partial to fix partial send — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72394 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: hwmon: (aspeed-g6-pwm-tach) Guard fan RPM calculation against divide-by-zero — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72395 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: hwmon: (pmbus) Fix passing events to regulator core — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72396 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: hwmon: adm1275: Prevent reading uninitialized stack — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72397 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: hwmon: (pmbus/core) honor vrm_version in pmbus_data2reg_vid() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72398 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: sctp: add INIT verification after cookie unpacking — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72399 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: net: enetc: check the number of BDs needed for xdp_frame — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72400 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: seg6: validate SRH length before reading fixed fields — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72401 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: bpf: Fix insn_aux_data leak on verifier err_free_env path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72402 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: bpf: Mask pseudo pointer values in verifier logs — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72403 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ALSA: FCP: Fix NULL pointer dereference in interface lookup — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72404 | linux-libc-dev | 7.0.0-31.31 | kernel: tipc: fix UAF in cleanup_bearer() due to premature dst_cache_destroy() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-72405 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net: udp_tunnel: prevent double queueing in udp_tunnel_nic_device_sync — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72406 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net: sungem: fix probe error cleanup — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72407 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: geneve: validate inner network offset in geneve_gro_complete() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72408 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: geneve: gate GRO hint in geneve_gro_complete() on gs->gro_hint — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72409 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net: mvneta: re-enable percpu interrupt on resume — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72412 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: s390/mm: Fix handling of _PAGE_UNUSED pte bit — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72413 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: sctp: fix err_chunk memory leaks in INIT handling — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72414 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net: dsa: sja1105: round up PTP perout pin duration — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72415 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ASoC: SDCA: Validate written enum value in ge_put_enum_double() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72416 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: netfilter: nft_compat: ebtables emulation must reject non-bridge targets — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72417 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: netfilter: flowtable: Validate iph->ihl in nf_flow_ip4_tunnel_proto() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72418 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: netfilter: nf_conncount: prevent connlimit drops for early confirmed ct — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72419 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: netfilter: nf_nat: avoid invalid nat_net pointer use on failed nf_nat_init() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72420 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: md/raid5: avoid R5_Overlap races while breaking stripe batches — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72421 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ipv4: fib: Don't ignore error route in local/main tables — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72422 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: ksmbd: fix use-after-free of conn->preauth_info in concurrent SMB2 NEGOTIATE — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72423 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: bpf: Guard conntrack opts error writes — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72424 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: rtc: msc313: fix NULL deref in shared IRQ handler at probe — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72363 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: netfs: Fix folio state after ENOMEM whilst under writeback iteration — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72364 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: netfs: Fix writeback error handling — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72365 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: netfs: Fix writethrough to use collection offload — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72366 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: netfs: Fix netfs_create_write_req() to handle async cache object creation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72367 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: iomap: guard io_size EOF trim against concurrent truncate underflow — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72368 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: cachefiles: Fix double unlock in nomem_d_alloc error path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72369 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: minix: avoid overflow in bitmap block count calculation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72370 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: iomap: release pages on atomic dio size mismatch — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72371 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: afs: Fix the volume AFS_VOLUME_RM_TREE is set on — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72373 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: afs: Fix missing NULL pointer check in afs_break_some_callbacks() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72374 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: afs: Fix callback service message parsers to pass through -EAGAIN — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72375 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: afs: Fix reinitialisation of the inode, in particular ->lock_work — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72376 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: afs: Fix misplaced inc of net->cells_outstanding — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72377 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: afs: Remove setting of AS_RELEASE_ALWAYS for symlinks and mountpoints — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72378 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | In the Linux kernel, the following vulnerability has been resolved: a ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72379 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: fs: refuse O_TMPFILE creation with an unmapped fsuid or fsgid — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72380 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: xen/pvcalls: bound backend response req_id before indexing rsp[] — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72381 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: ksmbd: fix use-after-free of fp->owner.name in durable handle owner check — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72382 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ksmbd: reject undersized DACLs before parsing ACEs — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72383 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: sctp: fix addr_wq_timer race in sctp_free_addr_wq() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72384 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: irqchip/ts4800: Fix missing chained handler cleanup on remove — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72385 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: tracing/fprobe: Fix NULL pointer dereference in fprobe_fgraph_entry() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72386 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/panthor: Fix a leak when a group is evicted before the tiler OOM is serviced — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72387 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/panthor: Fix potential invalid pointer deref in group_process_tiler_oom() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72388 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/panthor: Always use the IRQ-safe variant when acquiring the fence lock — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72389 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: bridge: stp: Fix a potential use-after-free when deleting a bridge — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72391 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net: phy: sfp: free mii_bus in sfp_i2c_mdiobus_destroy — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72392 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ipv6: fib6: fix NULL deref in fib6_walk_continue() on multi-batch dump — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72393 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: eth: fbnic: don't cache shinfo across skb realloc — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72457 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: apparmor: fail policy unpack on accept2 allocation failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72458 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: apparmor: fix NULL pointer dereference in unpack_pdb — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72459 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: apparmor: aa_label_alloc use aa_label_free on alloc failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72460 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: apparmor: check label build before no_new_privs test — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72463 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: xfrm: Fix dev use-after-free in xfrm async resumption — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72464 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: xprtrdma: Repost Receive buffers for malformed replies — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72465 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: xprtrdma: Sanitize the reply credit grant after parsing — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72466 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: xprtrdma: Fix bcall rep leak and unbounded peek — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72467 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: xprtrdma: Check frwr_wp_create() during connect — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72468 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: xprtrdma: Initialize re_id before removal registration — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72469 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: xprtrdma: Fix ep kref imbalance on ADDR_CHANGE — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72470 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: fs/ntfs3: resize log->one_page_buf when adopting on-disk page size — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72471 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: fs/ntfs3: prevent potential lcn remains uninitialized — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72473 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: xprtrdma: Decouple req recycling from RPC completion — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72474 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: dmaengine: dma-axi-dmac: use DMA pool to manange DMA descriptor — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72475 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: dmaengine: dma-axi-dmac: Properly free struct axi_dmac_desc — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72477 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: fs/ntfs3: call _ntfs_bad_inode() when failing to rename — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72479 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: iio: accel: mma8452: handle I2C read error(s) in mma8452_read() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72480 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: iio: adc: xilinx-ams: fix out-of-bounds channel lookup in event handling — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72481 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: iio: magnetometer: ak8975: fix potential kernel stack memory leak — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72483 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: usb: host: max3421: Fix shift-out-of-bounds in max3421_hub_control() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72484 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: staging: most: video: avoid double free on video register failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72485 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: coresight: platform: defer connection counter increment until alloc succeeds — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72486 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: mailbox: mtk-adsp: fix UAF during device teardown — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72487 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: PCI: Check ROM header and data structure addr before accessing — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72488 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: soundwire: fix bug in sdw_add_element_group_count found by syzkaller — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72489 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: staging: nvec: fix use-after-free in nvec_rx_completed() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72491 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: net/9p: fix race condition on rdma->state in trans_rdma.c — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72492 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ksmbd: fix use-after-free in same_client_has_lease() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72425 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ice: fix FDIR CTRL VSI resource leak in ice_reset_all_vfs() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72427 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: bpf: Fix effective prog array index with BPF_F_PREORDER — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72428 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: bpf: Fix stack slot index in nospec checks — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72429 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: ipv6: ioam: fix type confusion of dst_entry — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72430 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net/sched: act_ct: fix nf_connlabels leak on two error paths — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72431 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: alloc_tag: fix use-after-free in /proc/allocinfo after module unload — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72433 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: netfilter: nft_meta_bridge: fix NFT_META_BRI_IIFPVID stack leak — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72434 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: netfilter: ipset: make sure gc is properly stopped — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72435 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: netfilter: ipset: fix order of kfree_rcu() and rcu_assign_pointer() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72436 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: netfilter: ipset: Don't use test_bit() in lockless RCU readers in hash types — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72437 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: md/raid1: free r1_bio when REQ_NOWAIT is set and read would block on retry — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72438 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: md/raid10: fix writes_pending and barrier reference leaks on discard failures — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72439 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: md/raid10: fix writes_pending leak on write request failures — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72440 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: md/raid1: fix writes_pending and barrier reference leaks on write failures — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72441 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ieee802154: fix kernel-infoleak in dgram_recvmsg() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72442 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: netfilter: flowtable: fix and simplify IP6IP6 tunnel handling — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72443 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ALSA: usb-audio: Kill MIDI 2.0 URBs before freeing endpoints — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72444 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: flow_dissector: check device type before reading ETH_ADDRS — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72445 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ALSA: usb-audio: qcom: clear opened when stream enable fails — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72446 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ALSA: usb-audio: qcom: reject stream disable with no active interface — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72447 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: sctp: hold socket lock when dumping endpoints in sctp_diag — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72448 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: octeontx2-pf: Fix leak of SQ timestamp buffer on teardown — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72449 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/amdkfd: fix list_del corruption in kfd_criu_resume_svm — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72450 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: xfrm: validate selector family and prefixlen during match — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72451 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: xfrm: Fix xfrm state cache insertion race — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72452 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/i915: clear CRTC color blob pointers after dropping refs — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72453 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: regcache: Do not overwrite error code when finalizing cache after error — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72455 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: apparmor: fix uninitialised pointer passed to audit_log_untrustedstring() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72456 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: apparmor: release exe file resources on path failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72253 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: netfilter: nf_conntrack_sip: validate skb_dst() before accessing it — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72254 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: netfilter: nft_fib: reject fib expression on the netdev egress hook — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72255 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: netfilter: nf_queue: pin bridge device while NFQUEUE holds fake dst — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72256 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: netfilter: xt_cluster: reject template conntracks in hash match — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72257 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ASoC: qcom: q6apm: fix NULL pointer dereference in graph_callback — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72258 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ASoC: mediatek: mt8183: Release reserved memory on cleanup — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72259 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ASoC: mediatek: mt8192: Release reserved memory on cleanup — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72260 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ASoC: mediatek: mt8192: Check runtime resume during probe — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72261 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72262 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72263 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ASoC: SOF: topology: fix memory leak in snd_sof_load_topology — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72264 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: fbdev: tridentfb: fix potential memory leak in trident_pci_probe() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72265 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: fbdev: nvidia: fix potential memory leak in nvidiafb_probe() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72266 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: fbdev: vesafb: fix memory leak in vesafb_probe() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72267 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: fbdev: carminefb: fix potential memory leak in alloc_carmine_fb() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72268 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: fbdev: tdfxfb: fix potential memory leak in tdfxfb_probe() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72269 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: fbdev: uvesafb: fix potential memory leak in uvesafb_probe() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72270 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: fbdev: s3fb: fix potential memory leak in s3_pci_probe() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72271 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: fbdev: i740fb: fix potential memory leak in i740fb_probe() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72272 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: fbdev: radeon: fix potential memory leak in radeonfb_pci_register() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72273 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: fbdev: efifb: fix memory leak in efifb_probe() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72274 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: fbdev: hecubafb: fix potential memory leak in hecubafb_probe() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72275 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: fbdev: broadsheetfb: fix potential memory leak in broadsheetfb_probe() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72276 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: fbdev: metronomefb: fix potential memory leak in metronomefb_probe() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72277 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: KVM: arm64: nv: Inject SEA if guest VNCR isn't normal memory — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72278 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: KVM: arm64: nv: Re-translate VNCR before injecting abort — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72279 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: KVM: arm64: nv: Respect read-only PFN when mapping L1 VNCR — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72280 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: KVM: arm64: nv: Drop bogus WARN for write to ZCR_EL2 — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72282 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: KVM: Move kvm_io_bus_get_dev() locking responsibilities to callers — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72222 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: sunrpc: pin svc_xprt across the asynchronous TLS handshake callback — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72223 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: nvdimm/btt: Free arena sub-allocations on discover_arenas() error path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72224 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: nvdimm/btt: Free arenas on btt_init() error paths — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72225 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: jbd2: fix integer underflow in jbd2_journal_initialize_fast_commit() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72226 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: batman-adv: tt: prevent TVLV OOB check overflow — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72227 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: batman-adv: mcast: avoid OOB read of num_dests header — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72228 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: batman-adv: frag: fix primary_if leak on failed linearization — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72229 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: batman-adv: clean untagged VLAN on netdev registration failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72230 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: batman-adv: frag: free unfragmentable packet — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72231 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: batman-adv: tt: avoid request storms during pending request — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72232 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: batman-adv: ensure minimal ethernet header on TX — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72233 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: batman-adv: bla: reacquire gw address after skb realloc — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72234 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: batman-adv: access unicast_ttvn skb->data only after skb realloc — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72235 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: batman-adv: retrieve ethhdr after potential skb realloc on RX — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72236 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: s390/perf_cpum_cf: Add missing array_index_nospec() to __hw_perf_event_init() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72237 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: perf/x86/amd/brs: Fix kernel address leakage — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72238 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: x86/boot: Validate console=uart8250 baud rate to fix early boot hang — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72240 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: mfd: sm501: Fix reference leak on failed device registration — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72241 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: leds: uleds: Fix potential buffer overread — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72242 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: selinux: avoid sk_socket dereference in selinux_sctp_bind_connect() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72243 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: selinux: check connect-related permissions on TCP Fast Open — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72244 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: gpu/buddy: bail out of try_harder when alignment cannot be honoured — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72245 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: gpu: host1x: Fix device reference leak in host1x_device_parse_dt() error path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72247 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: netfilter: nf_conncount: fix zone comparison in tuple dedup — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72248 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: netfilter: flowtable: support IPIP tunnel with direct xmit — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72249 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: netfilter: flowtable: use dst in this direction when pushing IPIP header — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72250 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: netfilter: nf_conntrack_reasm: guard mac_header adjustment after IPv6 defrag — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72251 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: netfilter: nf_nat_sip: reload possible stale data pointer — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72252 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: netfilter: nft_set_pipapo: don't leak bad clone into future transaction — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72324 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: gpio: mvebu: free generic chips on unbind — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72325 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: perf/x86/amd/core: Avoid enabling BRS from the SVM reload path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72326 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net/sched: cake: reject overhead values that underflow length — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72327 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/v3d: Reject invalid indirect BO handle in indirect CSD setup — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72328 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: accel/amdxdna: Fix potential amdxdna_umap lifetime race — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72330 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net/tls: Consume empty data records in tls_sw_read_sock() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72332 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: accel/amdxdna: Prevent PM resume deadlock in hwctx_sync_debug_bo() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72333 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: Bluetooth: L2CAP: fix tx ident leak for commands without a response — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72334 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: Bluetooth: ISO: fix malformed ISO_END/CONT handling — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72335 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: Bluetooth: MGMT: Fix adv monitor add failure cleanup — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72336 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: Bluetooth: 6lowpan: hold L2CAP conn across debugfs control — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72337 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: Bluetooth: 6lowpan: avoid untracked enable work — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72339 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: qede: fix off-by-one in BD ring consumption on build_skb failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72340 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net: microchip: vcap: fix races on the shared Super VCAP block — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72341 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net/mlx5e: Fix publication race for priv->channel_stats[] — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72343 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net/mlx5e: Fix HV VHCA stats zero-sized buffer allocation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72344 | linux-libc-dev | 7.0.0-31.31 | kernel: net/mlx5e: TC, skip peer flow cleanup when LAG seq is unavailable — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-72345 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net/mlx5: LAG, Fix off-by-one in single-FDB error rollback — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72347 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: netfilter: xt_connmark: reject invalid shift parameters — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72348 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: netfilter: ip6tables: mark malformed IPv6 extension headers for hotdrop — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72349 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: netfilter: xt_rateest: fix u64 truncation in xt_rateest_mt() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72350 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: netfilter: xt_u32: reject invalid shift counts — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72351 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: gue: validate REMCSUM private option length — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72355 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: netfs: Fix barriering when walking subrequest list — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72356 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: cifs: Fix missing credit release on failure in cifs_issue_read() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72357 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: uprobes/x86: Use proper mm_struct in __in_uprobe_trampoline — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72360 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/xe/pf: Don't attempt to process FAST_REQ or EVENT relays — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72361 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/xe/hw_engine: Fix double-free of managed BO in error path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72362 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/xe/pt: Fix NULL pointer dereference in xe_pt_zap_ptes_entry() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72283 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: KVM: x86: Nullify irqfd->producer if updating IRTE for bypass fails — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72284 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: KVM: x86: Ignore pending PV EOI if the vCPU has since disabled PV EOIs — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72285 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: KVM: TDX: Reject concurrent change to CPUID entry count — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72289 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: KVM: arm64: vgic: Check the interrupt is still ours before migrating it — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72290 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: KVM: s390: pci: Fix GISC refcount leak on AIF enable failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72292 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: KVM: s390: Initialize KVM_S390_GET_CMMA_BITS memory — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72293 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: KVM: s390: vsie: Add missing radix_tree_preload() in _gaccess_shadow_fault() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72296 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: net: ife: require ETH_HLEN to be pullable in ife_decode() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72297 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net: atm: reject out-of-range traffic classes in QoS validation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72298 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net: qrtr: fix 32-bit integer overflow in qrtr_endpoint_post() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72299 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: tipc: restrict socket queue dumps in enqueue tracepoints — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72300 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ASoC: SOF: topology: validate vendor array size before parsing — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72301 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ASoC: SOF: ipc3-control: Fix TOCTOU in bytes_put and bytes_get — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72302 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ASoC: SOF: ipc3-control: Use overflow checks in control_update size calc — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72304 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ASoC: SOF: ipc4-control: Fix TOCTOU in sof_ipc4_bytes_put — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72305 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: VDUSE: avoid leaking information to userspace — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72306 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | In the Linux kernel, the following vulnerability has been resolved: v ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72307 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: mlxsw: fix refcount leak in mlxsw_sp_vrs_lpm_tree_replace() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72308 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: mlxsw: fix refcount leak in mlxsw_sp_port_lag_join() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72313 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/fb-helper: Only consider active CRTCs for vblank sync — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72315 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: smb: client: fix busy dentry warning on unmount after DIO — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72316 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: dm era: fix NULL pointer dereference in metadata_open() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72317 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: SUNRPC: pin upper rpc_clnt across the TLS connect_worker — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72318 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: cifs: validate DFS referral string offsets — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72319 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: ipvs: ensure inner headers in ICMP errors are in headroom — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72320 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: netfilter: nft_lookup: fix catchall element handling with inverted lookups — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72321 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ipv4: igmp: Fix potential memory leaks in igmp_mod_timer() and igmp_stop_timer() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72322 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: ipv6: mcast: Fix potential UAF in MLD delayed work — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72323 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: ipv4: igmp: Fix potential UAF in igmp_gq_start_timer() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-64544 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-64545 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net, bpf: check master for NULL in xdp_master_redirect() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-64546 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/edid: fix OOB read in drm_parse_tiled_block() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-64547 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net: usb: net1080: validate packet_len before pad-byte access in rx_fixup — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-64549 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: Bluetooth: bpa10x: avoid OOB read of revision string in bpa10x_setup() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-64550 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net: qualcomm: rmnet: validate MAP frame length before ingress parsing — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-64551 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: sctp: validate STALE_COOKIE cause length before reading staleness — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-64552 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: virtio-net: fix len check in receive_big() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-64553 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net: psample: fix info leak in PSAMPLE_ATTR_DATA — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-64555 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: KVM: arm64: nv: Fix SPSR_EL2 restore in kvm_hyp_handle_mops() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-64559 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: s390/pkey: Check length in PKEY_VERIFYPROTK ioctl — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-64560 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: posix-cpu-timers: Prevent UAF caused by non-leader exec() race — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-64561 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: KVM: x86: Check for invalid/obsolete root *after* making MMU pages available — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-64563 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: rhashtable: clear stale iter->p on table restart — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-64565 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: Input: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-64566 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: xfrm: iptfs: propagate SKBFL_SHARED_FRAG in iptfs_skb_add_frags() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-64568 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-64569 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-64570 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: wifi: mac80211: fix fils_discovery double free on alloc failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-64571 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: wifi: p54: validate RX frame length in p54_rx_eeprom_readback() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-64572 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ipv4: fib: free fib_alias with kfree_rcu() on insert error path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-64573 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: Bluetooth: qca: fix NVM tag length underflow in TLV parser — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-64575 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: bpf: tcp: fix double sock release on batch realloc — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-64576 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: nexthop: initialize extack in nh_res_bucket_migrate() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-64577 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: gtp: check skb_pull_data() return in gtp1u_send_echo_resp() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-64578 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ksmbd: validate compound request size before reading StructureSize2 — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-64579 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-64580 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | In the Linux kernel, the following vulnerability has been resolved: x ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-64581 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | In the Linux kernel, the following vulnerability has been resolved: x ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2023-53642 | linux-libc-dev | 7.0.0-31.31 | kernel: x86: fix clear_user_rep_good() exception handling annotation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2023-54105 | linux-libc-dev | 7.0.0-31.31 | kernel: can: isotp: check CAN address family in isotp_bind() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2023-54187 | linux-libc-dev | 7.0.0-31.31 | kernel: Linux kernel (F2FS): Data corruption and denial of service when moving a directory — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2023-54190 | linux-libc-dev | 7.0.0-31.31 | kernel: Kernel: Denial of Service via reference count leak in LED core — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2024-35895 | linux-libc-dev | 7.0.0-31.31 | kernel: bpf, sockmap: Prevent lock inversion deadlock in map delete elem — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2024-53216 | linux-libc-dev | 7.0.0-31.31 | kernel: nfsd: release svc_expkey/svc_export with rcu_work — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-100070 | linux-libc-dev | 7.0.0-31.31 | kernel: netfilter: nf_nat_sip: rewind offset when NAT shrinks the packet — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-100071 | linux-libc-dev | 7.0.0-31.31 | kernel: net: hsr: free learned nodes on device setup failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-100072 | linux-libc-dev | 7.0.0-31.31 | kernel: ACPI: platform: Use acpi_bus_get_primary_device() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-100073 | linux-libc-dev | 7.0.0-31.31 | kernel: ext4: fix transaction overflow during writeback — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-100074 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-100075 | linux-libc-dev | 7.0.0-31.31 | kernel: RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-100076 | linux-libc-dev | 7.0.0-31.31 | kernel: staging: rtl8723bs: fix xmit_frame/xmit_buf leaks on mgnt-frame error paths — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-100077 | linux-libc-dev | 7.0.0-31.31 | kernel: drm/msm: Recover HW before retire hung submit — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-100078 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-100079 | linux-libc-dev | 7.0.0-31.31 | kernel: usb: typec: ucsi: unregister debugfs entries on teardown — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-46055 | linux-libc-dev | 7.0.0-31.31 | kernel: apparmor: Fix string overrun due to missing termination — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64190 | linux-libc-dev | 7.0.0-31.31 | kernel: net: team: fix NULL pointer dereference in team_xmit during mode change — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-64349 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: usb: dwc3: fix dwc3_readl() and dwc3_writel() calls in dwc3_ulpi_setup() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-64530 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: net: sched: UAF via missing handler for TC_ACT_CONSUMED in tcf_qevent_handle — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-64532 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: fs/ntfs3: bound NTFS_DE view.data_off in UpdateRecordData{Root,Allocation} — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-64533 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: fs/ntfs3: validate lcns_follow in log_replay conversion — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-64534 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-64537 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: bridge: cfm: reject invalid CCM interval at configuration time — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-64538 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ipv6: Fix null-ptr-deref in fib6_nh_mtu_change() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-64539 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: Bluetooth: eir: Fix stack OOB write when prepending the Flags AD — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-64540 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: usbnet: gl620a: fix out-of-bounds read in genelink_rx_fixup() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-64541 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-64542 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ipv6: ndisc: fix NULL deref in accept_untracked_na() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68122 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ovpn: fix peer refcount leak in TCP error paths — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68123 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: openvswitch: fix GSO userspace truncation underflow — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68125 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: mac802154: llsec: reject frames shorter than the authentication tag — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68126 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: mac802154: hold an interface reference across the scan worker — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68127 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ila: reload IPv6 header after pskb_may_pull in checksum adjust — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68128 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: Linux kernel (ice): Denial of Service via out-of-range ptype in VIRTCHNL — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68129 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: gve: fix Rx queue stall on alloc failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68130 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ksmbd: defer destroy_previous_session() until after NTLM authentication — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68131 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: rbd: Reset positive result codes to zero in object map update path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68132 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: super: fix emergency thaw deadlock on frozen block devices — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68133 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ice: fix PTP Call Trace during PTP release — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68134 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ptp: ptp_s390: Add missing facility check — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68135 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net: hip04: fix RX buffer leak on build_skb failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68136 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net: gro: fix double aggregation of flush-marked skbs — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68137 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net/x25: fix use-after-free in x25_kill_by_neigh() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68138 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net/sched: serialize qdisc_rtab_list against concurrent get/put — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68139 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net/mlx5e: Use sender devcom for MPV master-up — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68140 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net/iucv: fix use-after-free of a severed iucv_path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68141 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net/af_iucv: fix NULL deref in afiucv_hs_callback_syn() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68143 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: Linux kernel SLIP: Out-of-bounds write due to race condition during MTU change — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68144 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: phonet: pep: fix use-after-free in pep_get_sb() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68145 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: iomap: fix out-of-bounds bitmap_set() with zero-length range — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68146 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ftrace: Add global mutex to serialize trace_parser access — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68148 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: fscrypt: Add missing superblock check in find_or_insert_direct_key() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68149 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: fs: preserve ACL_DONT_CACHE state in forget_cached_acl() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68150 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: fs/super: fix emergency thaw double-unlock of s_umount — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68151 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: binfmt_elf_fdpic: only honour the first PT_INTERP — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68152 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: amt: fix use-after-free in AMT delayed works — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68154 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: libceph: reject zero bucket types in crush_decode — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-64582 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: RDMA/rxe: Fix a use-after-free problem in rxe_mmap — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-64584 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | In the Linux kernel, the following vulnerability has been resolved: u ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-64585 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | In the Linux kernel, the following vulnerability has been resolved: c ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-64586 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68081 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | In the Linux kernel, the following vulnerability has been resolved: K ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68082 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | In the Linux kernel, the following vulnerability has been resolved: l ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68083 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: ksmbd: fix path resolution in ksmbd_vfs_kern_path_create — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68086 | linux-libc-dev | 7.0.0-31.31 | kernel: mm/khugepaged: write all dirty file folios when collapsing — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-68093 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: KVM: SVM: Bump asid_generation on CPU online to avoid ASID collision after hotplug — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68095 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: fuse-uring: fix race between registration and connection abortion — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68096 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: audit: fix recursive locking deadlock in audit_dupe_exe() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68097 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | In the Linux kernel, the following vulnerability has been resolved: k ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68099 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ksmbd: restore DACL size on check_add_overflow() to avoid malformed ACL — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68100 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ksmbd: validate num_subauth when copying ACE in set_ntacl_dacl — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68102 | linux-libc-dev | 7.0.0-31.31 | kernel: drm/amdgpu: fix aperture mapping leak — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-68103 | linux-libc-dev | 7.0.0-31.31 | kernel: drm/amdgpu: reject mapping a reserved doorbell to a new queue — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-68105 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/amdgpu: Fix kernel panic during driver load failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68106 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/amdgpu: fix division by zero with invalid uvd dimensions — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68108 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/amdgpu/vce: fix integer overflow in image size — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68109 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/amdgpu/sdma7.1: replace BUG_ON() with WARN_ON() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68110 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/amdgpu/sdma4.4.2: replace BUG_ON() with WARN_ON() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68111 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/amdgpu/gfx9: replace BUG_ON() with WARN_ON() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68112 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/amdgpu/gfx9.4.3: replace BUG_ON() with WARN_ON() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68113 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/amdgpu/gfx12: replace BUG_ON() with WARN_ON() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68114 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/amdgpu/gfx12.1: replace BUG_ON() with WARN_ON() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68115 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/amdgpu/gfx10: replace BUG_ON() with WARN_ON() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68118 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: tcp: challenge ACK for non-exact RST in SYN-RECEIVED — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68119 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: tcp: initialize standalone TCP-AO response padding — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68120 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: rtase: Workaround for TX hang caused by hardware packet parsing — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-82209 | libcurl4t64 | 8.18.0-1ubuntu2.5 | 8.18.0-1ubuntu2.7 | curl: libcurl: Information disclosure via improper Public Suffix List boundary check — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2025-66382 | libexpat1 | 2.7.4-1 | libexpat: libexpat: Denial of service via crafted file processing — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-32776 | libexpat1 | 2.7.4-1 | 2.7.4-1ubuntu0.1 | libexpat: libexpat: Denial of Service due to NULL pointer dereference — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-32777 | libexpat1 | 2.7.4-1 | 2.7.4-1ubuntu0.1 | libexpat: libexpat: Denial of Service via infinite loop in DTD content parsing — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-32778 | libexpat1 | 2.7.4-1 | 2.7.4-1ubuntu0.1 | libexpat: libexpat: Denial of Service via NULL pointer dereference after out-of-memory condition — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-41080 | libexpat1 | 2.7.4-1 | 2.7.4-1ubuntu0.1 | libexpat: expat: libexpat: Denial of Service via hash flooding with crafted XML — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-45186 | libexpat1 | 2.7.4-1 | 2.7.4-1ubuntu0.1 | libexpat: denial of service via crafted XML input — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-50219 | libexpat1 | 2.7.4-1 | 2.7.4-1ubuntu0.1 | expat: libexpat: Use-after-free vulnerability due to improper handler call depth tracking — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-56131 | libexpat1 | 2.7.4-1 | 2.7.4-1ubuntu0.2 | libexpat: libexpat: Use-after-free vulnerability due to insufficient handler call depth tracking — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-56132 | libexpat1 | 2.7.4-1 | 2.7.4-1ubuntu0.2 | expat: libexpat: Arbitrary Code Execution via Heap-based Buffer Overflow — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-56403 | libexpat1 | 2.7.4-1 | 2.7.4-1ubuntu0.1 | libexpat: libexpat: Arbitrary code execution due to integer overflow in storeAtts — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-56404 | libexpat1 | 2.7.4-1 | 2.7.4-1ubuntu0.1 | libexpat: libexpat: Arbitrary Code Execution via integer overflow in addBinding — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-56405 | libexpat1 | 2.7.4-1 | 2.7.4-1ubuntu0.1 | libexpat: libexpat: Information disclosure and arbitrary code execution via integer overflow — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-56406 | libexpat1 | 2.7.4-1 | 2.7.4-1ubuntu0.2 | libexpat: libexpat: Arbitrary code execution via integer overflow in XML_ParseBuffer — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-56407 | libexpat1 | 2.7.4-1 | 2.7.4-1ubuntu0.2 | libexpat: libexpat: Arbitrary code execution due to integer overflow — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-56408 | libexpat1 | 2.7.4-1 | 2.7.4-1ubuntu0.1 | libexpat before 2.8.2 has an integer overflow in copyString. — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-56409 | libexpat1 | 2.7.4-1 | 2.7.4-1ubuntu0.2 | xmlwf in libexpat before 2.8.2 has an integer overflow for the output ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-56410 | libexpat1 | 2.7.4-1 | 2.7.4-1ubuntu0.2 | libexpat: libexpat: Integer overflow in xmlwf can lead to information disclosure and arbitrary code execution. — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-56411 | libexpat1 | 2.7.4-1 | 2.7.4-1ubuntu0.2 | expat: libexpat: Integer Overflow Vulnerability Leading to Information Disclosure or Code Execution — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-56412 | libexpat1 | 2.7.4-1 | 2.7.4-1ubuntu0.1 | libexpat: libexpat: Use-after-free vulnerability due to improper handling of XML CDATA sections — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-66046 | libexpat1 | 2.7.4-1 | 2.7.4-1ubuntu0.2 | expat: Expat: Denial of Service via quadratic complexity in attribute processing — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72522 | libexpat1 | 2.7.4-1 | 2.7.4-1ubuntu0.2 | expat: libexpat: Denial of Service due to incorrect Unicode surrogate handling — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-76641 | libexpat1 | 2.7.4-1 | 2.7.4-1ubuntu0.2 | expat: Expat: Denial of Service via XML external entity parsing — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-76957 | libexpat1 | 2.7.4-1 | 2.7.4-1ubuntu0.2 | libexpat: libexpat: Memory corruption vulnerability allows arbitrary code execution or denial of service — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-53583 | libgit2-1.9 | 1.9.1+ds-1ubuntu1.1 | 1.9.1+ds-1ubuntu1.3 | libgit2: libgit2: Network attacker can intercept HTTPS connections via inverted IP SubjectAltName comparison — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-5917 | libgit2-1.9 | 1.9.1+ds-1ubuntu1.1 | 1.9.1+ds-1ubuntu1.2 | libgit2: libgit2: Arbitrary code execution via shell command injection in SSH backend — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-13757 | libp11-kit0 | 0.26.2-2 | p11-kit: Stack exhaustion via unbounded recursion in RPC attribute parsing — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-86145 | libpcre2-8-0 | 10.46-1build1 | pcre2: PCRE2: Out-of-bounds write allows arbitrary code execution via crafted regular expressions — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89161 | libpcre2-8-0 | 10.46-1build1 | pcre2: PCRE2: Memory corruption vulnerability in pcre2_jit_match — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-18924 | curl | 8.18.0-1ubuntu2.5 | 8.18.0-1ubuntu2.7 | curl: libcurl: Use-after-free in HTTP/2 Server Push with shared connections — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80229 | curl | 8.18.0-1ubuntu2.5 | 8.18.0-1ubuntu2.7 | When performing transfers via libcurl\u2019s multi interface, pooled T ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80230 | curl | 8.18.0-1ubuntu2.5 | 8.18.0-1ubuntu2.7 | curl: curl: Public key pinning bypass allows unauthenticated connections — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80255 | curl | 8.18.0-1ubuntu2.5 | 8.18.0-1ubuntu2.7 | curl: curl: Information disclosure due to secure cookie attribute bypass — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-82209 | curl | 8.18.0-1ubuntu2.5 | 8.18.0-1ubuntu2.7 | curl: libcurl: Information disclosure via improper Public Suffix List boundary check — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2024-52005 | git | 1:2.53.0-1ubuntu1 | git: The sideband payload is passed unfiltered to the terminal in git — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2024-52005 | git-man | 1:2.53.0-1ubuntu1 | git: The sideband payload is passed unfiltered to the terminal in git — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-16517 | libarchive13t64 | 3.8.5-1ubuntu2.2 | 3.8.5-1ubuntu2.3 | libarchive: libarchive: Signed Integer Overflow in archive_write_zip_header — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-18374 | libc-bin | 2.43-2ubuntu2.4 | glibc: glibc: Heap buffer overflow via attacker-controlled fopen mode string — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89092 | libc-bin | 2.43-2ubuntu2.4 | glibc: nscd stack overflow leads to degraded DNS resolution — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-18374 | libc-dev-bin | 2.43-2ubuntu2.4 | glibc: glibc: Heap buffer overflow via attacker-controlled fopen mode string — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89092 | libc-dev-bin | 2.43-2ubuntu2.4 | glibc: nscd stack overflow leads to degraded DNS resolution — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-18374 | libc-gconv-modules-extra | 2.43-2ubuntu2.4 | glibc: glibc: Heap buffer overflow via attacker-controlled fopen mode string — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89092 | libc-gconv-modules-extra | 2.43-2ubuntu2.4 | glibc: nscd stack overflow leads to degraded DNS resolution — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-18374 | libc6 | 2.43-2ubuntu2.4 | glibc: glibc: Heap buffer overflow via attacker-controlled fopen mode string — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89092 | libc6 | 2.43-2ubuntu2.4 | glibc: nscd stack overflow leads to degraded DNS resolution — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-18374 | libc6-dev | 2.43-2ubuntu2.4 | glibc: glibc: Heap buffer overflow via attacker-controlled fopen mode string — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89092 | libc6-dev | 2.43-2ubuntu2.4 | glibc: nscd stack overflow leads to degraded DNS resolution — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-13608 | libcurl3t64-gnutls | 8.18.0-1ubuntu2.5 | 8.18.0-1ubuntu2.7 | curl: curl: Authentication bypass in OpenLDAP SASL negotiation via Man-in-the-Middle (MITM) attack — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-18924 | libcurl3t64-gnutls | 8.18.0-1ubuntu2.5 | 8.18.0-1ubuntu2.7 | curl: libcurl: Use-after-free in HTTP/2 Server Push with shared connections — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80229 | libcurl3t64-gnutls | 8.18.0-1ubuntu2.5 | 8.18.0-1ubuntu2.7 | When performing transfers via libcurl\u2019s multi interface, pooled T ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80230 | libcurl3t64-gnutls | 8.18.0-1ubuntu2.5 | 8.18.0-1ubuntu2.7 | curl: curl: Public key pinning bypass allows unauthenticated connections — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80255 | libcurl3t64-gnutls | 8.18.0-1ubuntu2.5 | 8.18.0-1ubuntu2.7 | curl: curl: Information disclosure due to secure cookie attribute bypass — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-82209 | libcurl3t64-gnutls | 8.18.0-1ubuntu2.5 | 8.18.0-1ubuntu2.7 | curl: libcurl: Information disclosure via improper Public Suffix List boundary check — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-13608 | libcurl4t64 | 8.18.0-1ubuntu2.5 | 8.18.0-1ubuntu2.7 | curl: curl: Authentication bypass in OpenLDAP SASL negotiation via Man-in-the-Middle (MITM) attack — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-18924 | libcurl4t64 | 8.18.0-1ubuntu2.5 | 8.18.0-1ubuntu2.7 | curl: libcurl: Use-after-free in HTTP/2 Server Push with shared connections — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80229 | libcurl4t64 | 8.18.0-1ubuntu2.5 | 8.18.0-1ubuntu2.7 | When performing transfers via libcurl\u2019s multi interface, pooled T ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80230 | libcurl4t64 | 8.18.0-1ubuntu2.5 | 8.18.0-1ubuntu2.7 | curl: curl: Public key pinning bypass allows unauthenticated connections — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80255 | libcurl4t64 | 8.18.0-1ubuntu2.5 | 8.18.0-1ubuntu2.7 | curl: curl: Information disclosure due to secure cookie attribute bypass — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74860 | libxml2-16 | 2.15.2+dfsg-0.1ubuntu0.1 | 2.15.2+dfsg-0.1ubuntu0.2 | libxml2: double-free/UAF in libxml2 Python bindings — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-86140 | libxml2-16 | 2.15.2+dfsg-0.1ubuntu0.1 | 2.15.2+dfsg-0.1ubuntu0.2 | libxml2: libxml2: Arbitrary code execution via stack-based buffer overflow in xmlSnprintfElements — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2013-7445 | linux-libc-dev | 7.0.0-31.31 | kernel: memory exhaustion via crafted Graphics Execution Manager (GEM) objects — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2015-7837 | linux-libc-dev | 7.0.0-31.31 | kernel: securelevel disabled after kexec — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2016-8660 | linux-libc-dev | 7.0.0-31.31 | kernel: xfs: local DoS due to a page lock order bug in the XFS seek hole/data implementation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2018-17977 | linux-libc-dev | 7.0.0-31.31 | kernel: Mishandled interactions among XFRM Netlink messages, IPPROTO_AH packets, and IPPROTO_IP packets resulting in a denial of service — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2019-15794 | linux-libc-dev | 7.0.0-31.31 | kernel: Overlayfs in the Linux kernel and shiftfs not restoring original value on error leading to a refcount underflow — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2021-3714 | linux-libc-dev | 7.0.0-31.31 | kernel: Remote Page Deduplication Attacks — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2021-3864 | linux-libc-dev | 7.0.0-31.31 | kernel: descendant's dumpable setting with certain SUID binaries — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2022-0400 | linux-libc-dev | 7.0.0-31.31 | kernel: Out of bounds read in the smc protocol stack — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2022-0480 | linux-libc-dev | 7.0.0-31.31 | kernel: memcg does not limit the number of POSIX file locks allowing memory exhaustion — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2022-1247 | linux-libc-dev | 7.0.0-31.31 | kernel: A race condition bug in rose_connect() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2022-25836 | linux-libc-dev | 7.0.0-31.31 | Bluetooth® Low Energy Pairing in Bluetooth Core Specification v4. ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2022-2961 | linux-libc-dev | 7.0.0-31.31 | kernel: race condition in rose_bind() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2022-3238 | linux-libc-dev | 7.0.0-31.31 | kernel: ntfs3 local privledge escalation if NTFS character set and remount and umount called simultaneously — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2022-4543 | linux-libc-dev | 7.0.0-31.31 | kernel: KASLR Prefetch Bypass Breaks KPTI — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2022-49940 | linux-libc-dev | 7.0.0-31.31 | kernel: tty: n_gsm: add sanity check for gsm->receive in gsm_receive_buf() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2022-50090 | linux-libc-dev | 7.0.0-31.31 | kernel: btrfs: replace BTRFS_MAX_EXTENT_SIZE with fs_info->max_extent_size — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2022-50230 | linux-libc-dev | 7.0.0-31.31 | kernel: arm64: set UXN on swapper page tables — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2022-50232 | linux-libc-dev | 7.0.0-31.31 | kernel: arm64: set UXN on swapper page tables — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2022-50240 | linux-libc-dev | 7.0.0-31.31 | kernel: binder: fix UAF of alloc->vma in race with munmap() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2022-50332 | linux-libc-dev | 7.0.0-31.31 | kernel: Linux kernel: Denial of Service due to improper PCI device handling in aperture driver — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2022-50380 | linux-libc-dev | 7.0.0-31.31 | kernel: mm: /proc/pid/smaps_rollup: fix no vma's null-deref — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2022-50551 | linux-libc-dev | 7.0.0-31.31 | kernel: wifi: brcmfmac: Fix potential shift-out-of-bounds in brcmf_fw_alloc_request() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2023-0030 | linux-libc-dev | 7.0.0-31.31 | kernel: Use after Free in nvkm_vmm_pfn_map — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2023-0160 | linux-libc-dev | 7.0.0-31.31 | kernel: possibility of deadlock in libbpf function sock_hash_delete_elem — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2023-1193 | linux-libc-dev | 7.0.0-31.31 | kernel: use-after-free in setup_async_work() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2023-26242 | linux-libc-dev | 7.0.0-31.31 | kernel: kernel: fpga: dfl-afu: integer overflow in afu_mmio_region_get_by_offset() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2023-31082 | linux-libc-dev | 7.0.0-31.31 | kernel: sleeping function called from an invalid context in gsmld_write — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-12087 | libperl5.40 | 5.40.1-7ubuntu0.2 | 5.40.1-7ubuntu0.3 | perl-Socket: perl-Socket: Information Disclosure due to Out-of-Bounds Read — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-13221 | libperl5.40 | 5.40.1-7ubuntu0.2 | 5.40.1-7ubuntu0.3 | perl: Perl: Incorrect regular expression processing via large regular expressions — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-57432 | libperl5.40 | 5.40.1-7ubuntu0.2 | 5.40.1-7ubuntu0.3 | perl: Perl: Information disclosure via integer overflow in pack/unpack operations — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-57433 | libperl5.40 | 5.40.1-7ubuntu0.2 | 5.40.1-7ubuntu0.3 | Storable: Storable: Denial of Service via signed integer overflow in deserialization — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2025-10990 | libruby3.3 | 3.3.8-2ubuntu3.1 | rexml: REXML: Denial of Service via inefficient regex parsing — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-39113 | libsqlite3-0 | 3.46.1-9ubuntu0.2 | 3.46.1-9ubuntu0.3 | Buffer Overflow vulnerability in SQLite affected version source s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-85091 | zlib1g-dev | 1:1.3.dfsg+really1.3.1-1ubuntu3.1 | zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vul ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-85091 | zlib1g | 1:1.3.dfsg+really1.3.1-1ubuntu3.1 | zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vul ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-18508 | tar | 1.35+dfsg-4ubuntu0.4 | tar: tar: --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-18477 | tar | 1.35+dfsg-4ubuntu0.4 | tar: tar: TOCTOU in incremental dumpdir 'X' rename handling allows restore path escape — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35377 | rust-coreutils | 0.8.0-0ubuntu3 | A logic error in the env utility of uutils coreutils causes a failure ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35374 | rust-coreutils | 0.8.0-0ubuntu3 | A Time-of-Check to Time-of-Use (TOCTOU) vulnerability exists in the sp ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35373 | rust-coreutils | 0.8.0-0ubuntu3 | A logic error in the ln utility of uutils coreutils causes the program ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35371 | rust-coreutils | 0.8.0-0ubuntu3 | The id utility in uutils coreutils exhibits incorrect behavior in its ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35370 | rust-coreutils | 0.8.0-0ubuntu3 | The id utility in uutils coreutils miscalculates the groups= section o ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35368 | rust-coreutils | 0.8.0-0ubuntu3 | A vulnerability exists in the chroot utility of uutils coreutils when ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35367 | rust-coreutils | 0.8.0-0ubuntu3 | The nohup utility in uutils coreutils creates its default output file, ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35364 | rust-coreutils | 0.8.0-0ubuntu3 | A Time-of-Check to Time-of-Use (TOCTOU) race condition exists in the m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35363 | rust-coreutils | 0.8.0-0ubuntu3 | A vulnerability in the rm utility of uutils coreutils allows the bypas ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35360 | rust-coreutils | 0.8.0-0ubuntu3 | The touch utility in uutils coreutils is vulnerable to a Time-of-Check ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35359 | rust-coreutils | 0.8.0-0ubuntu3 | A Time-of-Check to Time-of-Use (TOCTOU) vulnerability in the cp utilit ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35357 | rust-coreutils | 0.8.0-0ubuntu3 | The cp utility in uutils coreutils is vulnerable to an information dis ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35354 | rust-coreutils | 0.8.0-0ubuntu3 | A Time-of-Check to Time-of-Use (TOCTOU) vulnerability exists in the mv ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35352 | rust-coreutils | 0.8.0-0ubuntu3 | A Time-of-Check to Time-of-Use (TOCTOU) race condition exists in the m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35351 | rust-coreutils | 0.8.0-0ubuntu3 | The mv utility in uutils coreutils fails to preserve file ownership du ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35350 | rust-coreutils | 0.8.0-0ubuntu3 | The cp utility in uutils coreutils fails to properly handle setuid and ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35348 | rust-coreutils | 0.8.0-0ubuntu3 | The sort utility in uutils coreutils is vulnerable to a process panic ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35345 | rust-coreutils | 0.8.0-0ubuntu3 | A vulnerability in the tail utility of uutils coreutils allows for the ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-35344 | rust-coreutils | 0.8.0-0ubuntu3 | The dd utility in uutils coreutils suppresses errors during file trunc ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-68319 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: pds_core: fix deadlock between reset thread and remove — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68320 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68321 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net: txgbe: fix FDIR filter leak on remove — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68322 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: rds: Fix inet6_addr_lst NULL dereference when IPv6 is disabled — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68324 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: iommu/intel: Fix out-of-bounds memset in dmar_latency_disable() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68325 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: iommu/amd: Bound the early ACPI HID map — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68326 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: wifi: mwifiex: bound uAP association event IEs to the event buffer — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68327 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: wan: wanxl: Only reset hardware after BAR mapping — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68328 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: nfp: Check resource mutex allocation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68331 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: dpaa2-eth: put MAC endpoint device on disconnect — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68332 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net: airoha: Fix potential use-after-free in airoha_ppe_deinit() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68333 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: dpaa2-switch: put MAC endpoint device on disconnect — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68334 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: Linux kernel: `rxrpc` race condition causes Denial of Service — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68335 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: rds: drop incoming messages that cross network namespace boundaries — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68336 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: bonding: fix devconf_all NULL dereference when IPv6 is disabled — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68337 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: Linux kernel: Denial of Service in BPF redirect helpers — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68338 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net/packet: avoid fanout hook re-registration after unregister — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68339 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: Bluetooth: btusb: validate Realtek vendor event length — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68340 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: hwmon: occ: validate poll response sensor blocks — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68341 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ovpn: fix use after free in unlock_ovpn() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68342 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ovpn: avoid putting unrelated P2P peer on socket release — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68343 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: smb: client: validate DFS referral PathConsumed — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68345 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: arm_mpam: guard MBWU state before adding it to garbage — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68346 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ALSA: hda: cs35l41: validate and free ACPI mute object — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68347 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: iommu/amd: Fix IRQ unsafe locking in gdom allocation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68348 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ASoC: tas2781: bound firmware description string parsing — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68349 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: wifi: carl9170: fix buffer overflow in rx_stream failover path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68350 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: Linux kernel carl9170 Wi-Fi driver: Out-of-bounds read vulnerability — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68351 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: wifi: carl9170: bound memcpy length in cmd callback to prevent OOB read — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68287 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drop_monitor: fix size calculations for 64-bit attributes — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68288 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net: drop_monitor: fix info leak in NET_DM_ATTR_PAYLOAD — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68289 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: tipc: fix integer overflow in tipc_recvmsg() and tipc_recvstream() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68290 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: Kernel: Use-after-free vulnerability in RDS TCP can lead to system instability — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68291 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: Linux kernel: idpf driver null pointer dereference leads to Denial of Service — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68292 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ice: prevent tstamp ring allocation for non-PF VSI types — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68293 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net/mlx5: Fix MCIA register buffer overflow on 32 dword reads — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68294 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net: qrtr: restrict socket creation to the initial network namespace — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68296 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net: gre: fix lltx regression for GRE tunnels with SEQ/CSUM — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68297 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: tipc: fix u16 MTU truncation in media and bearer MTU validation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68298 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/xe/vm: Fix SVM leak on resv obj alloc failure in xe_vm_create() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68299 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68300 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: sctp: auth: verify auth requirement when auth_chunk is NULL — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68301 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net: hsr: fix memory leak on slave unregistration by removing synced VLANs — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68302 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: amt: re-read skb header pointers after every pull — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68303 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/vc4: hvs/v3d: Fix null dereference in unbind — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68304 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: wifi: brcmfmac: fix 802.1X-SHA256 call trace warning — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68306 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: wifi: mt76: mt7996: fix possible NULL-pointer deref in mt7996_mcu_sta_bfer_eht() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68307 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: wifi: mt76: mt7925: fix crash in reset link replay — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68308 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: wifi: mt76: mt7996: check pointer returned by mt76_connac_get_he_phy_cap() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68309 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: wifi: mt76: connac: fix possible NULL-pointer deref in mt76_connac_mcu_uni_bss_he_tlv() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68310 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: wifi: mt76: mt7915: guard HE capability lookups — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68311 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: wifi: mt76: mt7925: guard link STA in decap offload — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68312 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: cifs: fix cifsFileInfo leak on kmalloc failure in deferred close drain paths — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68313 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: tipc: fix infinite loop in __tipc_nl_compat_dumpit — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68315 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: sctp: validate stream count in sctp_process_strreset_inreq() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68316 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: accel: ethosu: Fix element size accounting for cmd stream validation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68317 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: pds_core: fix auxiliary device add/del races — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68318 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: pds_core: fix use-after-free on workqueue during remove — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68384 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/xe/vf: Fix VF CCS attach/detach race with in-flight BO moves — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68385 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: s390/checksum: Fix csum_partial() without vector facility — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68386 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: bpf, sockmap: Reject unhashed UDP sockets on sockmap update — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68387 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: can: raw: add locking for raw flags bitfield — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68388 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: smb/client: handle overlapping allocated ranges in fallocate — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68389 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: Bluetooth: hci_qca: Clear memdump state on invalid dump size — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68390 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: Bluetooth: hci_sync: hold hdev->lock for hci_conn_params lookups — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68391 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68392 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: Bluetooth: mgmt: fix locking in unpair_device/disconnect_sync — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68394 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: Bluetooth: MGMT: revalidate LOAD_CONN_PARAM queued update — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68395 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ata: sata_dwc_460ex: enable SATA interrupts only after IRQ handler is registered — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68396 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: scsi: core: wake eh reliably when using scsi_schedule_eh — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68397 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net/iucv: take a reference on the socket found in afiucv_hs_rcv() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68398 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: Linux kernel: PPP over L2TP Use-After-Free vulnerability — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68400 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: firmware: arm_ffa: Fix Endpoint Memory Access Descriptor offset calculation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68401 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: firmware: arm_ffa: Fix out-of-bound writes in ffa_setup_and_transmit() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68402 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: Linux kernel: Wi-Fi subsystem out-of-bounds read via crafted frames — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68403 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: wifi: brcmfmac: initialize SDIO data work before cleanup — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68404 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: wifi: cfg80211: use wiphy work for socket owner autodisconnect — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68405 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: wifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68406 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: wifi: cfg80211: validate PMSR FTM preamble range — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68407 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: wifi: nl80211: free RNR data on MBSSID mismatch — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68408 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: wifi: cfg80211: convert pmsr_free_wk to wiphy_work to fix deadlock — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68409 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: wifi: mac80211: defer link RX stats percpu free to RCU — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68410 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: wifi: libertas: fix memory leak in helper_firmware_cb() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68411 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: wifi: mac80211_hwsim: clamp virtio RX length before skb_put — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68412 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: wifi: cfg80211: Fix an error handling path in cfg80211_wext_siwscan() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68413 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: memory leak in ipw2100_pci_init_one() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68414 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: wifi: cfg80211: cancel sched scan results work on unregister — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68352 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: wifi: ath6kl: fix OOB read from firmware IE lengths in connect event — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68354 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: firewire: net: Fix fragmented datagram reassembly — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68355 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: wifi: ath11k: fix potential buffer underflow in ath11k_hal_rx_msdu_list_get() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68356 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: watchdog: airoha: Prevent division by zero when clock frequency is zero — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68357 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: watchdog: pretimeout: Fix UAF in watchdog_unregister_governor() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68358 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: hwmon: (nzxt-kraken3) Stop device IO before calling hid_hw_stop — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68359 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: hwmon: (nzxt-smart2) Stop device IO before calling hid_hw_stop — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68360 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: hwmon: (corsair-cpro) Stop device IO before calling hid_hw_stop — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68361 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: hwmon: (corsair-psu) Stop device IO before calling hid_hw_stop — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68362 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: wifi: ath11k: fix NULL pointer dereference in ath11k_hal_srng_access_begin — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68363 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: Linux kernel: ath9k Wi-Fi driver use-after-free vulnerability leading to system crash — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68364 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/amd/display: Fix ISM dc_lock deadlock during suspend — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68365 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: USB: serial: io_edgeport: cap received transmit credits — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68366 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: usb: gadget: uvc: clamp SEND_RESPONSE length to the response buffer — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68367 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: usb: gadget: f_tcm: synchronize delayed set_alt with teardown — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68368 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: usb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68369 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: usb: gadget: printer: fix infinite loop in printer_read() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68371 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: usb: musb: omap2430: Do not put borrowed of_node in probe — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68372 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: usb: core: port: Deattach Type-C connector on component unbind — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68373 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: Linux kernel: Out-of-bounds read in wifi driver due to length underflow — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68374 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: usb: core: sysfs: add lock to bos_descriptors_read() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68375 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: bnxt_en: Handle partially initialized auxiliary devices — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68376 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: sctp: fix auth_hmacs array size in struct sctp_cookie — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68377 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: Linux kernel: Denial of Service due to use-after-free in act_tunnel_key — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68378 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: dpll: fix NULL pointer dereference in dpll_msg_add_pin_ref_sync() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68379 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: tcp: fix TIME_WAIT socket reference leak on PSP policy failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68381 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ksmbd: Use-after-free vulnerability due to race condition in connection handling — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68382 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/xe/guc: Hold device ref until queue teardown completes — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68383 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/xe/guc: Keep scheduler timeline name alive — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68190 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: staging: rtl8723bs: fix OOB reads in rtw_get_wps_ie() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68191 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: wifi: ath12k: fix NULL pointer dereference in rhash table destroy — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68192 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68193 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: wifi: mt76: mt7925: drop TXRX_NOTIFY on non-mmio buses — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68194 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: wifi: mt76: mt7921: drop TXRX_NOTIFY on non-mmio buses — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68195 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: wifi: mt76: mt7615: drop TXRX_NOTIFY on non-mmio buses — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68197 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68200 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: Linux kernel: ALSA timer use-after-free vulnerability allows privilege escalation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68202 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ALSA: seq: close a re-opened queue timer in the destructor — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68203 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: media: vivid: fix cleanup bugs in vivid_init() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68205 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: media: v4l2-fwnode: Fix subdev owner overwritten in v4l2_async_register_subdev_sensor() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68206 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: media: v4l2-ctrls: validate HEVC active reference counts — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68207 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: media: ti: vpe: unwind v4l2 device registration on probe error — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68208 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: media: ti: vpe: Fix the error code of devm_kzalloc() in vip_probe_slice() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68209 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: media: sun4i-csi: Return queued buffers on start_streaming() failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68210 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: media: stm32: dcmi: unregister notifier on probe failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68211 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: media: stm32-dcmipp: Return queued buffers on start_streaming() failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68212 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: media: saa7134: Fix a possible memory leak in saa7134_video_init1 — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68213 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: media: rtl2832_sdr: Return queued buffers on start_streaming() failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68214 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: media: rtl2832: fix use-after-free in rtl2832_remove() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68215 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: media: radio-si476x: Unregister v4l2_device on probe failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68216 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: media: pwc: Return queued buffers on start_streaming() failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68217 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: media: pwc: Drain fill_buf on start_streaming() failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68218 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: media: pci: dm1105: Free allocated workqueue — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68219 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: media: nxp: imx8-isi: Fix potential out-of-bounds issues — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68220 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: media: nxp: imx8-isi: Add missing v4l2_subdev_cleanup() in crossbar and pipe — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68221 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: media: nuvoton: npcm-video: fix memory leaks in probe and remove — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68222 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: media: msi2500: Return queued buffers on start_streaming() failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68223 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: media: meson: vdec: Fix memory leak in error path of vdec_open — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68155 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: Linux kernel (libceph): Denial of Service due to malformed monitor maps — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68157 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: Linux kernel: libceph null pointer dereference leads to denial of service — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68158 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: libceph: Fix multiplication overflow in decode_new_up_state_weight() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68159 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: Linux kernel: libceph stack out-of-bounds write via crafted OSDMap — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68160 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68161 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: sctp: close UDP tunnel sockets during netns teardown — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68163 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: mm/page_vma_mapped: fix device-private PMD handling — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68164 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: mm/damon/core: disallow overlapping input ranges for damon_set_regions() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68165 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: mm/damon/core: validate ranges in damon_set_regions() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68166 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: Linux kernel: Arbitrary code execution via userfaultfd shadow stack manipulation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68168 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: afs: Fix afs_edit_dir_remove() to get, not find, block 0 — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68169 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: mptcp: pm: userspace: fix use-after-free in get_local_id — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68170 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: mptcp: fix stale skb->sk reference on subflow close — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68172 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: arm64: make huge_ptep_get handled unaligned addresses — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68173 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ublk: wait on ublk_dev_ready() instead of ub->completion — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68174 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: tracing: Fix union collision of module and refcnt for dynamic events — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68175 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: tracing: Fix resource leak on mmiotrace trace_pipe close — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68176 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: tracing: Fix mmiotrace possible NULL dereferencing of hiter->dev — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68177 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: tracing: Delay module ref count for "enable_event" trigger — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68178 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: misc: nsm: pin the module while the device is open — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68179 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: misc: nsm: only unlock nsm_dev on post-lock error paths — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68180 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: intel_th: fix MSC output device reference leak — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68181 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: mei: bus: access mei_device under device_lock on cleanup — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68182 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: comedi: comedi_parport: deal with premature interrupt — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68183 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: firmware: stratix10-svc: fix memory leaks and list corruption bugs — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68184 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: cdrom: fix stack out-of-bounds read in CDROMVOLCTRL — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68186 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: binfmt_misc: set have_execfd only once the interpreter is opened — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68187 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: exec: fix unsigned loop counter wrap in transfer_args_to_stack() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68188 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: Linux kernel Bluetooth RFCOMM: Denial of Service via use-after-free in set_termios — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68255 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/virtio: bound EDID block reads to the response buffer — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68256 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/amd/display: detect_link_and_local_sink: DP alt mode timeout path leaks prev_sink reference — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68258 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/amdkfd: Check bounds on CRIU restore queue type and mqd size — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68259 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/amdkfd: Check bounds in allocate_event_notification_slot — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68260 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/imagination: acquire vm_ctx->lock before mapping memory to GPU VM — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68261 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/imagination: fix error checking of pvr_vm_context_lookup() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68262 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/imagination: Fix user array stride in pvr_set_uobj_array() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68263 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: Linux kernel: drm/imagination use-after-free vulnerability — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68264 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/xe/pt: Reset current_op in xe_pt_update_ops_init() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68265 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/xe/vm: Fix BO prefetch with CONSULT_MEM_ADVISE_PREF_LOC — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68266 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/xe: Hold a dma-buf reference for imported BOs — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68267 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/xe/rtp: Add RING_FORCE_TO_NONPRIV_DENY to OA whitelists — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68268 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/xe: Return error on non-migratable faults requiring devmem — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68269 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/i915/gem: Add missing nospec on parallel submit slot — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68270 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/sysfb: Avoid possible truncation with calculating visible size — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68271 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/nouveau: fix reversed error cleanup order in ucopy functions — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68272 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1 — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68273 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/amdgpu: Fix context pstate override handling — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68274 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/xe/guc: Fix buffer overflow in steered register list allocation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68275 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/amdgpu: check amdgpu_vm_bo_find() result in GET_MAPPING_INFO — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68276 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/amdgpu/gfx: fix cleaner shader IB buffer overflow — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68277 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68278 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/dp/mst: fix buffer overflows in sideband chunk accumulation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68279 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68280 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68281 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/imagination: Count paired job fence as dependency in prepare_job() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68282 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/rockchip: analogix_dp: Add missing error check for platform_get_resource() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68283 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: tracing: Fix use-after-free freeing trigger private data — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68286 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drop_monitor: perform u64_stats updates under IRQ-disabled section — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68224 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: media: mali-c55: Fix possible ERR_PTR in enable_streams — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68225 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: media: i2c: alvium: fix critical pointer access in alvium_ctrl_init — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68226 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: media: cx23885: add ioremap return check and cleanup — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68227 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: media: cx231xx: fix devres lifetime — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68228 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: media: chips-media: wave5: Move src_buf Removal to finish_encode — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68229 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: media: cedrus: skip invalid H.264 reference list entries — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68230 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: media: amlogic-c3: Add validations for ae and awb config — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68231 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: media: airspy: Return queued buffers on start_streaming() failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68232 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/gpusvm: Fix MM reference leak in drm_gpusvm_range_evict — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68233 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/vc4: Shut down BO cache timer before teardown — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68234 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/amdgpu: fix bo->pin leaking in amdgpu_bo_create_reserved — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68235 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/amd/display: dce100: skip non-DP stream encoders for DP MST — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68237 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/amdgpu/userq: fix indefinite fence wait during GPU reset — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68238 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/amdgpu: Release VFCT ACPI table reference — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68239 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/ttm: Account for NULL and handle pages in ttm_pool_backup — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68241 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/i915/mst: limit DP MST ESI service loop — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68242 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/i915/gt: Fix NULL deref on sched_engine alloc failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68243 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEU — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68244 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/i915/gem: Do not leak siblings[] on proto context error — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68245 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/amdgpu: fix lifetime issue of amdgpu_vm_get_task_info_pasid() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68246 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/amdgpu/gfx11: replace BUG_ON() with WARN_ON() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68247 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/i915/bios: range check LFP Data Block panel_type2 — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68248 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/i915: Return NULL on error in active_instance — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68249 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/amdgpu/sdma5.0: replace BUG_ON() with WARN_ON() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68250 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/amdgpu/sdma5.2: replace BUG_ON() with WARN_ON() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68251 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/amdgpu/sdma6.0: replace BUG_ON() with WARN_ON() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68252 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/amdgpu/sdma7.0: replace BUG_ON() with WARN_ON() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68253 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/i915/hdcp: check streams[] bounds before overflow — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-68254 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/i915/vrr: require valid min/max vfreq for VRR — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80762 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: B ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80763 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: B ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80764 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: B ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80765 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: H ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80766 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: H ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80767 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: H ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80768 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: H ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80769 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: H ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80770 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: H ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80771 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: H ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80772 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: H ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80774 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: H ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80775 | linux-libc-dev | 7.0.0-31.31 | kernel: futex: Fix race on the initial mm->futex.phash.ref allocation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80776 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80777 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80778 | linux-libc-dev | 7.0.0-31.31 | kernel: futex/pi: Reject cross-mm private futex owners — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80779 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80780 | linux-libc-dev | 7.0.0-31.31 | kernel: HID: pidff: fix OOB write when hid->inputs is empty — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80781 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: H ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80782 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: H ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80783 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: H ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80784 | linux-libc-dev | 7.0.0-31.31 | kernel: mptcp: pm: fix memory leak from alloc-during-teardown race — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80785 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80786 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80787 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80788 | linux-libc-dev | 7.0.0-31.31 | kernel: nvmet-tcp: Do not WARN on remotely-controlled oversized SGL allocations — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80789 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80790 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80791 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80732 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: a ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80733 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80734 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80735 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: o ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80736 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: t ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80737 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80738 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80739 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80740 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80741 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80742 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: a ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80743 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: A ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80744 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80745 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: r ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80747 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80748 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80749 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80750 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: p ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80751 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: p ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80752 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: I ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80753 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: o ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80754 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: I ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80755 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80756 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80757 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80758 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80759 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: B ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80760 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: B ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80761 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: B ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80821 | linux-libc-dev | 7.0.0-31.31 | kernel: nvmet: pci-epf: put CQ ref on create_cq mapping failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80822 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80823 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80824 | linux-libc-dev | 7.0.0-31.31 | kernel: usb: usbfs: fix use-after-free of usb_device in usbdev_release() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80825 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80826 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: U ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80827 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: U ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80828 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: A ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80829 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: A ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80830 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: u ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80831 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: c ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80832 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: c ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80833 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: c ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80834 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: c ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80835 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: c ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80836 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: c ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80837 | linux-libc-dev | 7.0.0-31.31 | kernel: netfilter: nf_tables: don't queue packet path object notifications — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80838 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: v ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80839 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80840 | linux-libc-dev | 7.0.0-31.31 | kernel: ipv6: seg6: clear IPv4 control block on IPIP decapsulation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80841 | linux-libc-dev | 7.0.0-31.31 | kernel: net/packet: defer vmalloc TX_RING free until skbs finish — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80842 | linux-libc-dev | 7.0.0-31.31 | kernel: net: bridge: mcast: fix use-after-free of a master VLAN's multicast context — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80843 | linux-libc-dev | 7.0.0-31.31 | kernel: xfrm: fix xfrm_state_construct() auth-trunc leak — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80844 | linux-libc-dev | 7.0.0-31.31 | kernel: xfrm: ah6: validate routing header segments_left — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80845 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: x ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80846 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: x ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80847 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: t ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80848 | linux-libc-dev | 7.0.0-31.31 | kernel: xfrm: espintcp: fix UAF during close — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80849 | linux-libc-dev | 7.0.0-31.31 | kernel: net/tcp-ao: fix use-after-free of current_key on reconnect to another peer — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80792 | linux-libc-dev | 7.0.0-31.31 | kernel: ipv6: fix use-after-free in ip6_finish_output2() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80793 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80794 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80795 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80796 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80797 | linux-libc-dev | 7.0.0-31.31 | kernel: nfc: pn533: purge fragmented skbs during cleanup — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80798 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80799 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80800 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80801 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80802 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80803 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80804 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: x ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80805 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: x ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80806 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: e ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80807 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80808 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: e ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80809 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: o ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80810 | linux-libc-dev | 7.0.0-31.31 | kernel: io_uring/rsrc: fix folio size overflow in io_vec_fill_bvec() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80811 | linux-libc-dev | 7.0.0-31.31 | kernel: io_uring/cmd: fix iovec leak when the async cmd is not recycled — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80812 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: A ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80813 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80814 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: r ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80815 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: A ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80816 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: A ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80817 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80818 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80819 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: B ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80820 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: x ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80567 | linux-libc-dev | 7.0.0-31.31 | kernel: Input: synaptics-rmi4 - propagate F54 worker errors to V4L2 queue — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80568 | linux-libc-dev | 7.0.0-31.31 | kernel: Input: synaptics-rmi4 - block s_input when F54 queue is busy — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80569 | linux-libc-dev | 7.0.0-31.31 | kernel: Input: synaptics-rmi4 - bound the F54 report size to the allocated buffer — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80570 | linux-libc-dev | 7.0.0-31.31 | kernel: Input: synaptics-rmi4 - zero report size on F54 work error — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80571 | linux-libc-dev | 7.0.0-31.31 | kernel: powerpc/pseries: papr-phy-attest - validate cmd.length, plug mem leak — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80572 | linux-libc-dev | 7.0.0-31.31 | kernel: Input: byd - synchronize timer deletion before freeing private data — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80573 | linux-libc-dev | 7.0.0-31.31 | kernel: Input: iforce - validate input packet lengths — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80574 | linux-libc-dev | 7.0.0-31.31 | kernel: Input: focaltech - fix array out-of-bounds in focaltech_process_rel_packet — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80575 | linux-libc-dev | 7.0.0-31.31 | kernel: Input: cs40l50-vibra - validate custom data from user space — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80576 | linux-libc-dev | 7.0.0-31.31 | kernel: drm/amdgpu: reject oversized IBs with per-ring packet limits — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80577 | linux-libc-dev | 7.0.0-31.31 | kernel: drm/panthor: skip zero-sized firmware sections — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80578 | linux-libc-dev | 7.0.0-31.31 | kernel: fbdev: core: Fix pointer desynchronization in fb_io_read() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80579 | linux-libc-dev | 7.0.0-31.31 | kernel: fbdev: clear fb_info->mode before deleting a videomode — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80580 | linux-libc-dev | 7.0.0-31.31 | kernel: fbdev: bound mode sysfs output to the sysfs buffer — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80581 | linux-libc-dev | 7.0.0-31.31 | kernel: ASoC: SOF: ipc4-pcm: Continue the pipeline trigger in case of IPC timeout — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80582 | linux-libc-dev | 7.0.0-31.31 | kernel: drm/shmem_helper: Check VMA boundaries for PMD mappings — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80583 | linux-libc-dev | 7.0.0-31.31 | kernel: ASoC: codecs: lpass-tx-macro: Fix enum kcontrol accesses — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80584 | linux-libc-dev | 7.0.0-31.31 | kernel: s390/qeth: validate user buffer length in SNMP and ARP query ioctls — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80585 | linux-libc-dev | 7.0.0-31.31 | kernel: mptcp: fastopen: only mark MPTFO subflows with SYN data — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80586 | linux-libc-dev | 7.0.0-31.31 | kernel: mptcp: options: reset DSS fields in case of unexpected size — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80587 | linux-libc-dev | 7.0.0-31.31 | kernel: mptcp: avoid combining some incoming suboptions — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80588 | linux-libc-dev | 7.0.0-31.31 | kernel: mptcp: reclaim forward-allocated memory on RX path errors — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80589 | linux-libc-dev | 7.0.0-31.31 | kernel: block: stop the timeout timer when releasing a never added disk — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80590 | linux-libc-dev | 7.0.0-31.31 | kernel: inet: frags: strip GSO state from fragments before reassembly — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80592 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: samples/damon/mtier: fail early if address range parameters are invalid — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80593 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: hwmon: (asus_atk0110) Check package count before accessing element — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80594 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: Input: ims-pcu - fix potential infinite loop in CDC union descriptor parsing — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80595 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: Input: ims-pcu - add response length checks — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80596 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: Input: ims-pcu - only expose sysfs attributes on control interface — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80534 | linux-libc-dev | 7.0.0-31.31 | kernel: xfs: fix ilock leak on error in xfs_dq_get_next_id — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80535 | linux-libc-dev | 7.0.0-31.31 | kernel: xfs: don't double-lock when deleting a self-referential directory — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80536 | linux-libc-dev | 7.0.0-31.31 | kernel: xfs: bounds-check buffer log item's dirty bitmap — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80537 | linux-libc-dev | 7.0.0-31.31 | kernel: xfs: fix off-by-one in rtrefcount btree root level validation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80538 | linux-libc-dev | 7.0.0-31.31 | kernel: xfs: propagate errors from xfs_rtginode_load — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80539 | linux-libc-dev | 7.0.0-31.31 | kernel: drm/amdgpu: disallow multiple FENCE chunks in one submit — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80540 | linux-libc-dev | 7.0.0-31.31 | kernel: drm/amdgpu: Fix UVD decode image min size calculation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80541 | linux-libc-dev | 7.0.0-31.31 | kernel: drm/amdgpu: validate GEM_CREATE domain combinations — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80542 | linux-libc-dev | 7.0.0-31.31 | kernel: drm/amd/display: Fix NULL pointer dereference in amdgpu_dm_crtc_set_vblank() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80547 | linux-libc-dev | 7.0.0-31.31 | kernel: s390/vfio_ccw: Implement a crw lock — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80548 | linux-libc-dev | 7.0.0-31.31 | kernel: s390/vfio_ccw: Selectively expand io_mutex — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80549 | linux-libc-dev | 7.0.0-31.31 | kernel: s390/vfio_ccw: Move cp cleanup out of not operational — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80550 | linux-libc-dev | 7.0.0-31.31 | kernel: s390/vfio_ccw: Fix out of bounds check on CCW array — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80551 | linux-libc-dev | 7.0.0-31.31 | kernel: s390/vfio_ccw: Ensure first IDAW remains constant — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80552 | linux-libc-dev | 7.0.0-31.31 | kernel: s390/vfio_ccw: Ensure index for read/write regions are within range — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80553 | linux-libc-dev | 7.0.0-31.31 | kernel: s390/vfio_ccw: Cancel existing workqueues — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80554 | linux-libc-dev | 7.0.0-31.31 | kernel: s390/vfio_ccw: Limit the number of channel program segments — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80555 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80556 | linux-libc-dev | 7.0.0-31.31 | kernel: mmc: atmel-mci: Fix use-after-free in atmci_remove due to race condition — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80557 | linux-libc-dev | 7.0.0-31.31 | kernel: libceph: fix OOB read in decode_watchers() via missing bounds check — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80558 | linux-libc-dev | 7.0.0-31.31 | kernel: libceph: Avoid using invalid osd indices from primary_temp — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80559 | linux-libc-dev | 7.0.0-31.31 | kernel: Input: sur40 - fix input device registration ordering — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80560 | linux-libc-dev | 7.0.0-31.31 | kernel: openrisc: signal: do not restore privileged SR bits on sigreturn — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80561 | linux-libc-dev | 7.0.0-31.31 | kernel: libceph: fix multiple unsafe decodes in decode_locker() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80562 | linux-libc-dev | 7.0.0-31.31 | kernel: gpio: ml-ioh: use raw_spinlock_t for the register lock — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80563 | linux-libc-dev | 7.0.0-31.31 | kernel: gpio: sloppy-logic-analyzer: fix use-after-free via debugfs trigger on unbind — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80564 | linux-libc-dev | 7.0.0-31.31 | kernel: gve: fix NULL dereference due to missing ptp adjfine — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80565 | linux-libc-dev | 7.0.0-31.31 | kernel: crypto: qce - fix error path in devm_qce_register_algs — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80566 | linux-libc-dev | 7.0.0-31.31 | kernel: Input: hynitron_cstxxx - validate touch count and finger IDs — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80646 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ipv6: guard against possible NULL deref in __in6_dev_stats_get() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80659 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: mmc: vub300: defer reset until cmd_mutex is unlocked — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80663 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: tools/power/x86/intel-speed-select: Harden daemon pidfile open — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80664 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: netfilter: xt_nat: reject unsupported target families — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80666 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: Bluetooth: sco: Fix a race condition in sco_sock_timeout() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80667 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net/mlx5: LAG, MPESW, Fix missing complete() on devcom error — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80669 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: bpf: Disable xfrm_decode_session hook attachment — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80670 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: perf tools: Use perf_env__get_cpu_topology() in machine__resolve() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80675 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: libbpf: Reject non-exclusive metadata maps in the signed loader — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80684 | linux-libc-dev | 7.0.0-31.31 | kernel: KVM: s390: pci: Fix NULL dereference on AIBV allocation failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80686 | linux-libc-dev | 7.0.0-31.31 | kernel: mm: migrate_device: fix pte_pfn/pte_dirty called on non-present PTE — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80694 | linux-libc-dev | 7.0.0-31.31 | kernel: net: ethernet: mtk_eth_soc: pass eth to mtk_handle_irq_rx in poll_controller — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80695 | linux-libc-dev | 7.0.0-31.31 | kernel: hwmon: (sht3x) Fix unaligned accesses — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80697 | linux-libc-dev | 7.0.0-31.31 | kernel: erofs: ensure valid f_path for page cache sharing — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80699 | linux-libc-dev | 7.0.0-31.31 | kernel: KVM: arm64: vgic: Avoid double-deactivate of IRQs in the nested context — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80701 | linux-libc-dev | 7.0.0-31.31 | kernel: drm/vmwgfx: enforce cursor size limits for MOB cursors — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80703 | linux-libc-dev | 7.0.0-31.31 | kernel: drm/amdkfd: Fix missing authorization check in KFD_IOC_DBG_TRAP_DISABLE — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80705 | linux-libc-dev | 7.0.0-31.31 | kernel: drm/amd/display: check if dml21_add_phantom_plane() is successful — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80707 | linux-libc-dev | 7.0.0-31.31 | kernel: can: j1939: transport: j1939_session_fresh_new(): initialize receive buffer — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80713 | linux-libc-dev | 7.0.0-31.31 | kernel: io_uring: preserve task restrictions across exec — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80715 | linux-libc-dev | 7.0.0-31.31 | kernel: igc: remove napi_synchronize() in igc_down() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80717 | linux-libc-dev | 7.0.0-31.31 | kernel: sctp: validate Adaptation Indication parameter length — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80720 | linux-libc-dev | 7.0.0-31.31 | kernel: iomap: add a separate bio_set for iomap_split_ioend — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80722 | linux-libc-dev | 7.0.0-31.31 | kernel: wifi: mac80211: validate individual TWT params before driver setup — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80726 | linux-libc-dev | 7.0.0-31.31 | kernel: KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80727 | linux-libc-dev | 7.0.0-31.31 | kernel: x86/mce: Set up the polling timer before CMCI discovery — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80729 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80730 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: r ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80731 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80597 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: mtd: maps: vmu-flash: fix NULL pointer dereference in initialization — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80598 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ntfs3: fix out-of-bounds read in decompress_lznt — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80599 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: batman-adv: dat: ensure accessible eth_hdr proto field — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80600 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: batman-adv: dat: acquire ARP hw source only after skb realloc — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80601 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: batman-adv: gw: acquire ethernet header only after skb realloc — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80602 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: perf/x86/amd/lbr: Fix kernel address leakage — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80603 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: netfilter: nf_conntrack_irc: fix parse_dcc() off-by-one OOB read — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80604 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: HID: core: Fix OOB read in hid_get_report for numbered reports — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80605 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: HID: picolcd: prevent NULL pointer dereference in picolcd_send_and_wait() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80606 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/xe/userptr: Hold notifier_lock for write on inject test path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80607 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: tracing/probes: Remove WARN_ON_ONCE from parse_btf_arg — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80608 | linux-libc-dev | 7.0.0-31.31 | kernel: accel/amdxdna: Fix iommu domain lifetime race during device removal — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80609 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: qede: fix out-of-bounds check for cqe->len_list[] — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80610 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net: enetc: fix potential divide-by-zero when num_vsi is zero — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80611 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ACPI: processor_idle: Mark LPI enter functions as __cpuidle — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80612 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net: lwtunnel: Drop skb metadata before LWT encapsulation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80613 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: veth: fix NAPI leak in XDP enable error path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80614 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net: emac: Fix NULL pointer dereference in emac_probe — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80615 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net: dst_metadata: fix false-positive memcpy overflow in tun_dst_unclone — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80616 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ieee802154: Avoid calling WARN_ON() on -ENOMEM in cfg802154_switch_netns() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80617 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net: airoha: fix foe_check_time allocation size — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80618 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/amdkfd: Avoid double-unpin of DOORBELL/MMIO BOs on free — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80619 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: apparmor: fix potential UAF in aa_replace_profiles — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80620 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: Revert "PCI/MSI: Unmap MSI-X region on error" — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80621 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: PCI: dwc: Avoid dwc_pcie_rasdes_debugfs_deinit() NULL dereference when no RAS DES capability — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80626 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: powerpc/perf: fix preempt count underflow in fsl_emb_pmu_del — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80630 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net/sched: sch_fq_codel: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80638 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ocfs2: fix out-of-bounds write in ocfs2_remove_refcount_extent — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80641 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: wifi: wlcore: enable the right set of ciphers — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-81000 | linux-libc-dev | 7.0.0-31.31 | kernel: net: tun: bound receive headroom — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-81001 | linux-libc-dev | 7.0.0-31.31 | kernel: slip: fix use-after-free in sl_sync() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-81002 | linux-libc-dev | 7.0.0-31.31 | kernel: xdp: fix zero-copy frame layout — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-81003 | linux-libc-dev | 7.0.0-31.31 | kernel: net/iucv: filter frames in afiucv_hs_rcv() by ingress device — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-81004 | linux-libc-dev | 7.0.0-31.31 | kernel: ipmi:msghandler: Cancel work cleanly on an error — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-81005 | linux-libc-dev | 7.0.0-31.31 | kernel: ipmi: si: Fix NULL pointer dereference after failed registration — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-81006 | linux-libc-dev | 7.0.0-31.31 | kernel: ipmi: Remove all sysfs files on registration failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-81007 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-81008 | linux-libc-dev | 7.0.0-31.31 | kernel: interconnect: Fix use after free in icc_get() and of_icc_get_by_index() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-81009 | linux-libc-dev | 7.0.0-31.31 | kernel: io_uring/query: cap user size passed to copy_struct_to_user — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-81010 | linux-libc-dev | 7.0.0-31.31 | kernel: io_uring/waitid: honor task_work cancellation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-81011 | linux-libc-dev | 7.0.0-31.31 | kernel: platform/x86: hp-bioscfg: pass validated element count to package parsers — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-81012 | linux-libc-dev | 7.0.0-31.31 | kernel: platform/x86: hp-bioscfg: fix off-by-one write in hp_get_string_from_buffer() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-81013 | linux-libc-dev | 7.0.0-31.31 | kernel: platform/x86: hp-bioscfg: fix heap OOB read on empty password write — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-81014 | linux-libc-dev | 7.0.0-31.31 | kernel: platform/x86: hp-bioscfg: fix heap OOB read in sk_store() and kek_store() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-81015 | linux-libc-dev | 7.0.0-31.31 | kernel: platform/x86/amd/pmc: Fix LPS0 and debugfs leaks when STB init fails — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-81016 | linux-libc-dev | 7.0.0-31.31 | kernel: platform/x86/amd/pmc: Propagate SMU errors and validate S2D address — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-81017 | linux-libc-dev | 7.0.0-31.31 | kernel: platform/chrome: sensorhub: Bound the EC-reported sensor number — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-81018 | linux-libc-dev | 7.0.0-31.31 | kernel: platform/x86: think-lmi: Free system certificate signatures — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89437 | linux-libc-dev | 7.0.0-31.31 | kernel: platform/x86: int1092: Fix potential memory leak in sar_probe() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89438 | linux-libc-dev | 7.0.0-31.31 | kernel: platform/x86: ISST: Validate logical CPU id and clos id — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89439 | linux-libc-dev | 7.0.0-31.31 | kernel: platform/x86: ISST: Add a NULL check for sst_inst[] — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89440 | linux-libc-dev | 7.0.0-31.31 | kernel: mmc: via-sdmmc: stop card-detect handling on probe failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89441 | linux-libc-dev | 7.0.0-31.31 | kernel: mmc: via-sdmmc: cancel card-detect work on remove — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89442 | linux-libc-dev | 7.0.0-31.31 | kernel: platform/x86: ISST: Validate socket ID in clos_assoc ioctl — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89443 | linux-libc-dev | 7.0.0-31.31 | kernel: platform/x86: ISST: Validate level in perf mask ioctls — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89444 | linux-libc-dev | 7.0.0-31.31 | kernel: platform/x86: dell-wmi-sysman: Don't hex dump attribute security buffer — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89445 | linux-libc-dev | 7.0.0-31.31 | kernel: iommufd: Fix UAF in selftest IOPF reporting — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89446 | linux-libc-dev | 7.0.0-31.31 | kernel: iommufd: Release current IOAS on xa_store() failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80969 | linux-libc-dev | 7.0.0-31.31 | kernel: ALSA: mpu401: Check card index validity at probe — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80970 | linux-libc-dev | 7.0.0-31.31 | kernel: ALSA: FCP: do not copy out an uninitialised init response — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80971 | linux-libc-dev | 7.0.0-31.31 | kernel: ALSA: bcd2000: clear the URB pointers on disconnect — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80972 | linux-libc-dev | 7.0.0-31.31 | kernel: ALSA: aloop: Check card index validity at probe — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80973 | linux-libc-dev | 7.0.0-31.31 | kernel: ALSA: 6fire: bound the MIDI event length from the device — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80974 | linux-libc-dev | 7.0.0-31.31 | kernel: mfd: sm501: Fix potential memory leaks during remove — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80975 | linux-libc-dev | 7.0.0-31.31 | kernel: mfd: qnap-mcu: keep the reply buffer alive past a command timeout — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80976 | linux-libc-dev | 7.0.0-31.31 | kernel: seg6: reset IP6CB after IPv6 decapsulation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80977 | linux-libc-dev | 7.0.0-31.31 | kernel: net: skbuff: don't touch shared zerocopy state in skb_tx_error() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80978 | linux-libc-dev | 7.0.0-31.31 | kernel: net: cap advertised IP tunnel headroom — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80979 | linux-libc-dev | 7.0.0-31.31 | kernel: net/smc: unregister the connection before draining the rx tasklet — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80980 | linux-libc-dev | 7.0.0-31.31 | kernel: net/smc: stop killed, freed and out_of_sync sharing a byte — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80981 | linux-libc-dev | 7.0.0-31.31 | kernel: net/smc: fix use-after-free of the LLC qentry in smc_llc_srv_add_link() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80982 | linux-libc-dev | 7.0.0-31.31 | kernel: net/smc: fix use-after-free in smc_rx_pipe_buf_release() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80983 | linux-libc-dev | 7.0.0-31.31 | kernel: net/smc: fix socket refcount leak in smc_switch_conns() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80984 | linux-libc-dev | 7.0.0-31.31 | kernel: net/smc: do not dereference an unset send buffer on the SMC-D teardown path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80985 | linux-libc-dev | 7.0.0-31.31 | kernel: net/smc: carry oversized SMC-Rv2 LLC messages in the queue entry — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80986 | linux-libc-dev | 7.0.0-31.31 | kernel: net/smc: bound the peer rkey counts in SMC-Rv2 LLC messages — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80987 | linux-libc-dev | 7.0.0-31.31 | kernel: NTB: ntb_transport: Reject oversized TX buffers — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80988 | linux-libc-dev | 7.0.0-31.31 | kernel: NTB: ntb_transport: Fail TX enqueue when the QP link is down — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80989 | linux-libc-dev | 7.0.0-31.31 | kernel: net: thunderbolt: Mark the connection down when bringing it up fails — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80990 | linux-libc-dev | 7.0.0-31.31 | kernel: net: thunderbolt: Release the Rx HopID that was handed out on mismatch — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80991 | linux-libc-dev | 7.0.0-31.31 | kernel: net: ravb: serialize PTP clock teardown — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80992 | linux-libc-dev | 7.0.0-31.31 | kernel: net: ravb: avoid dereferencing an invalid PTP clock — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80993 | linux-libc-dev | 7.0.0-31.31 | kernel: net: phylink: correctly validate returned PCS in phylink_inband_caps — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80994 | linux-libc-dev | 7.0.0-31.31 | kernel: net: openvswitch: fix flow mask use-after-free on flow deletion — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80996 | linux-libc-dev | 7.0.0-31.31 | kernel: net: l2tp: do not propagate multicast notification errors — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80997 | linux-libc-dev | 7.0.0-31.31 | kernel: net: ipa: fix stalled modem TX queue after runtime resume — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80999 | linux-libc-dev | 7.0.0-31.31 | kernel: net: dsa: realtek: use gpiod_set_value_cansleep for reset GPIO — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89477 | linux-libc-dev | 7.0.0-31.31 | kernel: sctp: fix NULL deref on untransmitted RECONF completion — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89478 | linux-libc-dev | 7.0.0-31.31 | kernel: sctp: drop a chunk if its transport was removed — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89479 | linux-libc-dev | 7.0.0-31.31 | kernel: sctp: stop processing a packet once its association is deleted — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89480 | linux-libc-dev | 7.0.0-31.31 | kernel: nvme-tcp: reject a read that transferred too few bytes — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89481 | linux-libc-dev | 7.0.0-31.31 | kernel: nvme-tcp: fix host memory disclosure on R2T for a read command — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89482 | linux-libc-dev | 7.0.0-31.31 | kernel: nvme-tcp: do not accept C2HData based on blk_rq_payload_bytes() alone — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89483 | linux-libc-dev | 7.0.0-31.31 | kernel: nvme: zero the discard fallback page — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89484 | linux-libc-dev | 7.0.0-31.31 | kernel: lockd: fix NULL dereference on lockowner allocation failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89485 | linux-libc-dev | 7.0.0-31.31 | kernel: lockd: pin next file across nlm_inspect_file lock-drop — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89486 | linux-libc-dev | 7.0.0-31.31 | kernel: ipmi: Fix use-after-free of cmd_rcvr in _ipmi_destroy_user() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89487 | linux-libc-dev | 7.0.0-31.31 | kernel: openvswitch: only skb_tx_error() a packet we are about to drop — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89488 | linux-libc-dev | 7.0.0-31.31 | kernel: openvswitch: Fix CT limit teardown use-after-free — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89489 | linux-libc-dev | 7.0.0-31.31 | kernel: openrisc: fix arbitrary kernel memory access via or1k_atomic syscall — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89490 | linux-libc-dev | 7.0.0-31.31 | kernel: ocfs2: ocfs2: Denial of Service via readdir position truncation on 32-bit kernels — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89491 | linux-libc-dev | 7.0.0-31.31 | kernel: ocfs2: cluster: don't sleep while holding o2hb_live_lock in o2hb_region_pin() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89492 | linux-libc-dev | 7.0.0-31.31 | kernel: ocfs2: validate directory-index entry counts when reading metadata — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89493 | linux-libc-dev | 7.0.0-31.31 | kernel: ocfs2: validate rl_used against rl_count in refcount block validator — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89494 | linux-libc-dev | 7.0.0-31.31 | kernel: ocfs2: validate lengths in dlm_mig_lockres_handler — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89495 | linux-libc-dev | 7.0.0-31.31 | kernel: ocfs2: bound namelen in dlm_migrate_request_handler — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89496 | linux-libc-dev | 7.0.0-31.31 | kernel: ocfs2: always run deallocs on copy-on-write completion — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89497 | linux-libc-dev | 7.0.0-31.31 | kernel: orangefs: skip leading spaces before parsing client debug masks — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89498 | linux-libc-dev | 7.0.0-31.31 | kernel: orangefs: fix double-free of trailer_buf on readdir copy failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89500 | linux-libc-dev | 7.0.0-31.31 | kernel: ring-buffer: Make cpu_buffer::free_page a buffer_data_read_page — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89501 | linux-libc-dev | 7.0.0-31.31 | kernel: ring-buffer: Hold cpu_buffer::lock when resizing a subbuf — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89502 | linux-libc-dev | 7.0.0-31.31 | kernel: ring-buffer: Free cpu_buffer::free_page with subbuf_order — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89503 | linux-libc-dev | 7.0.0-31.31 | kernel: ring-buffer: Fix subbuf resize race with ring_buffer_alloc_read_page() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89504 | linux-libc-dev | 7.0.0-31.31 | kernel: regulator: as3722_get_regulator_dt_data: fix premature of_node_put leaving dangling of_node pointer — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89506 | linux-libc-dev | 7.0.0-31.31 | kernel: RDMA/uverbs: Add UVERBS_ATTR_UHW to UVERBS_METHOD_REG_MR — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89507 | linux-libc-dev | 7.0.0-31.31 | kernel: RDMA/ucma: Lock the handler in ucma_write_cm_event() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89447 | linux-libc-dev | 7.0.0-31.31 | kernel: iommufd: Avoid locking internal accesses during unmap — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89448 | linux-libc-dev | 7.0.0-31.31 | kernel: iommu/vt-d: Force requesting ACS when tboot is enabled — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89449 | linux-libc-dev | 7.0.0-31.31 | kernel: iommu: Fix dev_iommu memory leak when device_add fails in iommu_mock_device_add — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89450 | linux-libc-dev | 7.0.0-31.31 | kernel: iommu/tegra241-cmdqv: Reject a vSID wider than the SID_MATCH field — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89451 | linux-libc-dev | 7.0.0-31.31 | kernel: iommu/sva: Set handle->dev before the SVA handle is visible — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89452 | linux-libc-dev | 7.0.0-31.31 | kernel: iommu/msm: Unwind probe state on registration failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89453 | linux-libc-dev | 7.0.0-31.31 | kernel: iommu/amd: Put PCI device after handling PPR faults — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89454 | linux-libc-dev | 7.0.0-31.31 | kernel: PCI: plda: Fix IRQ domain leaks in the error paths of plda_init_interrupts() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89455 | linux-libc-dev | 7.0.0-31.31 | kernel: PCI: plda: Fix use-after-free of event IRQs during teardown — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89456 | linux-libc-dev | 7.0.0-31.31 | kernel: s390/dasd: Propagate partial completion length across ERP recovery — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89457 | linux-libc-dev | 7.0.0-31.31 | kernel: s390/dasd: Guard sysfs discipline callbacks against unallocated private data — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89458 | linux-libc-dev | 7.0.0-31.31 | kernel: s390/dasd: Do not complete a failed ESE read as successful — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89460 | linux-libc-dev | 7.0.0-31.31 | kernel: s390/cpum_cf: Handle CPU hotplug via prepare/dead callbacks — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89461 | linux-libc-dev | 7.0.0-31.31 | kernel: power: supply: max17040: synchronize work cancellation on suspend — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89462 | linux-libc-dev | 7.0.0-31.31 | kernel: power: supply: max17040: propagate register read errors — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89463 | linux-libc-dev | 7.0.0-31.31 | kernel: power: supply: ucs1002: fix use-after-free on remove — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89464 | linux-libc-dev | 7.0.0-31.31 | kernel: power: supply: twl4030_charger: cancel workers via devm — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89465 | linux-libc-dev | 7.0.0-31.31 | kernel: power: supply: rt9455: quiesce delayed work before teardown — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89466 | linux-libc-dev | 7.0.0-31.31 | kernel: power: supply: qcom_battmgr: terminate the strings from firmware — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89467 | linux-libc-dev | 7.0.0-31.31 | kernel: power: supply: qcom_battmgr: fix use-after-free — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89468 | linux-libc-dev | 7.0.0-31.31 | kernel: power: supply: lp8788-charger: fix use-after-free on remove — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89469 | linux-libc-dev | 7.0.0-31.31 | kernel: power: supply: lp8727: fix use-after-free in lp8727_release_irq() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89470 | linux-libc-dev | 7.0.0-31.31 | kernel: power: supply: cros_usbpd: Limit port counts to EC_USB_PD_MAX_PORTS — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89471 | linux-libc-dev | 7.0.0-31.31 | kernel: power: supply: cros_usbpd-charger: bound the EC-reported port count — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89472 | linux-libc-dev | 7.0.0-31.31 | kernel: power: supply: charger-manager: register regulators before exposing sysfs — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89473 | linux-libc-dev | 7.0.0-31.31 | kernel: power: supply: bq25890: Fix power_supply reference leak — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89474 | linux-libc-dev | 7.0.0-31.31 | kernel: power: supply: bq256xx: drain usb_work before freeing the charger — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89475 | linux-libc-dev | 7.0.0-31.31 | kernel: power: supply: bq24257: fix use-after-free on remove — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-89476 | linux-libc-dev | 7.0.0-31.31 | kernel: sctp: fix stream->outcnt underflow on duplicate RECONF responses — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80881 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | In the Linux kernel, the following vulnerability has been resolved: o ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80882 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | In the Linux kernel, the following vulnerability has been resolved: c ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80883 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80884 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80885 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: afs: Fix uncancelled rxrpc OOB message handler — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80886 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80887 | linux-libc-dev | 7.0.0-31.31 | kernel: drm/vmwgfx: use check_add_overflow for shader size+offset bound — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80888 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80889 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: c ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80890 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80891 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: K ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80892 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: e ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80893 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80894 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80895 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80896 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80897 | linux-libc-dev | 7.0.0-31.31 | kernel: netfs: release readahead folios on iterator preparation failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80898 | linux-libc-dev | 7.0.0-31.31 | kernel: netfs: clear PG_private_2 on copy-to-cache append failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80899 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: e ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80900 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: A ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80901 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80902 | linux-libc-dev | 7.0.0-31.31 | kernel: dmaengine: sun6i-dma: Fix reclaim descriptors while terminating DMA — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80903 | linux-libc-dev | 7.0.0-31.31 | kernel: drm/xe/oa: Fix sync entry leak on OA config emit failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80904 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80905 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80906 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80907 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80908 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80909 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80850 | linux-libc-dev | 7.0.0-31.31 | kernel: tcp: fix AO info use-after-free in tcp_ao_connect_init() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80851 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: g ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80852 | linux-libc-dev | 7.0.0-31.31 | kernel: tls: device: fix out-of-bounds write in tls_append_frag() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80854 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: u ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80855 | linux-libc-dev | 7.0.0-31.31 | kernel: fuse: fix invalidate lock leak on open O_TRUNC DAX failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80856 | linux-libc-dev | 7.0.0-31.31 | kernel: fuse: fix invalidate lock leak on setattr writeback failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80857 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80858 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80859 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80860 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80861 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: u ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80862 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80863 | linux-libc-dev | 7.0.0-31.31 | kernel: RDMA/rxe: Fix OOB in free_rd_atomic_resources() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80864 | linux-libc-dev | 7.0.0-31.31 | kernel: RDMA/rxe: Fix responder UAF on IB_QP_MAX_DEST_RD_ATOMIC modify_qp — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80865 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80866 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | In the Linux kernel, the following vulnerability has been resolved: t ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80867 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | In the Linux kernel, the following vulnerability has been resolved: a ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80868 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80870 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80871 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | In the Linux kernel, the following vulnerability has been resolved: c ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80872 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | In the Linux kernel, the following vulnerability has been resolved: A ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80873 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | In the Linux kernel, the following vulnerability has been resolved: K ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80874 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | In the Linux kernel, the following vulnerability has been resolved: a ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80875 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80876 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | In the Linux kernel, the following vulnerability has been resolved: r ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80877 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: afs: Fix vllist leak — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80878 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: afs: Fix leak of ungot volume — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80879 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | In the Linux kernel, the following vulnerability has been resolved: o ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80880 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | In the Linux kernel, the following vulnerability has been resolved: I ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-80940 | linux-libc-dev | 7.0.0-31.31 | kernel: wifi: rtw88: pci: fix resource leak on failed NAPI setup — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80941 | linux-libc-dev | 7.0.0-31.31 | kernel: wifi: rtw88: Fix potential memory leak in rtw_txq_push_skb() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80942 | linux-libc-dev | 7.0.0-31.31 | kernel: wifi: rtlwifi: rtl8192du: Fix possible memory leak in rtl92du_init_sw_vars() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80943 | linux-libc-dev | 7.0.0-31.31 | kernel: wifi: rtlwifi: rtl8192du: check QoS TID before indexing tids — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80944 | linux-libc-dev | 7.0.0-31.31 | kernel: wifi: mwifiex: Detach sync cmd buffer on interrupted wait — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80945 | linux-libc-dev | 7.0.0-31.31 | kernel: crypto: iaa - unmap dst before software fallback on decompress — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80946 | linux-libc-dev | 7.0.0-31.31 | kernel: fuse: copy request headers via a stack buffer for io-uring — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80947 | linux-libc-dev | 7.0.0-31.31 | kernel: wifi: rtl8xxxu: fix use-after-free from rx_urb_wq on stop — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80948 | linux-libc-dev | 7.0.0-31.31 | kernel: wifi: iwlwifi: dvm: fix memory leak in iwl_op_mode_dvm_start() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80949 | linux-libc-dev | 7.0.0-31.31 | kernel: wifi: brcmfmac: Fix memory leak in brcmf_sdio_read_control() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80950 | linux-libc-dev | 7.0.0-31.31 | kernel: i3c: renesas: Check that the transfer is valid before accessing it — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80951 | linux-libc-dev | 7.0.0-31.31 | kernel: i3c: master: svc: bound IBI payload to the requested max_payload_len — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80952 | linux-libc-dev | 7.0.0-31.31 | kernel: i3c: master: Fix info leak and UAF in device unregister path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80953 | linux-libc-dev | 7.0.0-31.31 | kernel: i3c: master: adi: initialize the lock before enabling interrupts — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80954 | linux-libc-dev | 7.0.0-31.31 | kernel: i3c: Fix unlocked dereference of dev->desc in i3c_device_get_supported_xfer_mode() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80955 | linux-libc-dev | 7.0.0-31.31 | kernel: dm-pcache: fix use-after-free and invalid seg operations in kset_replay() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80956 | linux-libc-dev | 7.0.0-31.31 | kernel: dm-pcache: only hand out initialized cache segments — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80957 | linux-libc-dev | 7.0.0-31.31 | kernel: dm-pcache: detect a cycle in the last-kset chain during replay — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80958 | linux-libc-dev | 7.0.0-31.31 | kernel: dm-pcache: clamp the tail kset read to the segment data region — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80959 | linux-libc-dev | 7.0.0-31.31 | kernel: dm-pcache: bound the persisted tail-position offset — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80960 | linux-libc-dev | 7.0.0-31.31 | kernel: dm-pcache: validate on-media seg_num against the cache device size — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80961 | linux-libc-dev | 7.0.0-31.31 | kernel: dm-pcache: validate kset key_num and intra-segment bounds — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80962 | linux-libc-dev | 7.0.0-31.31 | kernel: dm-pcache: validate geometry fields from on-disk cache_info — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80963 | linux-libc-dev | 7.0.0-31.31 | kernel: dm-stats: fix a crash if allocation of per-cpu data fails — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80964 | linux-libc-dev | 7.0.0-31.31 | kernel: ALSA: virmidi: Check card index validity at probe — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80965 | linux-libc-dev | 7.0.0-31.31 | kernel: ALSA: serial-u16550: Check card index validity at probe — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80966 | linux-libc-dev | 7.0.0-31.31 | kernel: ALSA: portman2x4: Check card index validity at probe — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80967 | linux-libc-dev | 7.0.0-31.31 | kernel: ALSA: pcxhr: initialize mutexes before requesting threaded IRQ — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80968 | linux-libc-dev | 7.0.0-31.31 | kernel: ALSA: mts64: Check card index validity at probe — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80910 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: A ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80911 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: A ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80912 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80913 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80914 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: B ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80915 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80916 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: k ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80917 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: P ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80918 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: H ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80920 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80921 | linux-libc-dev | 7.0.0-31.31 | kernel: KVM: s390: vsie: zero stale crypto bits — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80922 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: c ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80923 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: x ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80924 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: c ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80925 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: v ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80926 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: k ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80927 | linux-libc-dev | 7.0.0-31.31 | kernel: timekeeping: Check the return value of tk_get_aux_ts64 in __do_adjtimex() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80928 | linux-libc-dev | 7.0.0-31.31 | kernel: smack: fix cred UAF in smack_file_send_sigiotask() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80929 | linux-libc-dev | 7.0.0-31.31 | kernel: sysctl: move the "cad_pid" entry from pid_table[] to kern_reboot_table[] — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80930 | linux-libc-dev | 7.0.0-31.31 | kernel: tpm: tpm_i2c_nuvoton: disable IRQ on wait timeout — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80931 | linux-libc-dev | 7.0.0-31.31 | kernel: w1: ds28e17: reject an oversize length on an I2C block read — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80932 | linux-libc-dev | 7.0.0-31.31 | kernel: vsock/virtio: flush works in dependency order — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80933 | linux-libc-dev | 7.0.0-31.31 | kernel: wifi: mt76: mt7996: validate default EEPROM firmware size — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80934 | linux-libc-dev | 7.0.0-31.31 | kernel: wifi: mt76: mt7996: fix TX DMA mapping leak for AddBA req frames — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80935 | linux-libc-dev | 7.0.0-31.31 | kernel: wifi: mt76: mt7996: bound the device EEPROM address before the EFUSE copy — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80936 | linux-libc-dev | 7.0.0-31.31 | kernel: wifi: mt76: mt7925: cancel mlo_pm_work on stop — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80937 | linux-libc-dev | 7.0.0-31.31 | kernel: wifi: mt76: mt7915: bound the device EEPROM address before the EFUSE copy — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80938 | linux-libc-dev | 7.0.0-31.31 | kernel: wifi: mt76: mt7615: avoid waiting for mac work under the mt76 mutex — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80939 | linux-libc-dev | 7.0.0-31.31 | kernel: wifi: rtw89: pci: add .shutdown callback to stop rfkill polling on reboot — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74424 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: fbcon: fix NULL pointer dereference for a console without vc_data — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74425 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: afs: handle CB.InitCallBackState3 requests without a server record — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74426 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: afs: fix NULL pointer dereference in afs_get_tree() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74428 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: rxrpc: Fix double unlock in rxrpc_recvmsg() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74429 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: rxrpc: Fix the reception of a reply packet before data transmission — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74430 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: rxrpc: Fix ACKALL packet handling — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74431 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: rxrpc: Fix potential infinite loop in rxrpc_recvmsg() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74432 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: rxrpc: Fix leak of released call in recvmsg(MSG_PEEK) — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74433 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | In the Linux kernel, the following vulnerability has been resolved: r ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74434 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: rxrpc: Don't move a peeked OOB message onto the pending queue — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74435 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: rxrpc: rxrpc_verify_data ensure rx_dec_buffer alloc — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74436 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: rxrpc: serialize kernel accept preallocation with socket teardown — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74437 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: media: uvcvideo: Fix deadlock if uvc_status_stop is called from async_ctrl.work — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74439 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: iommu/vt-d: Clear Present bit before tearing down scalable-mode context entry — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74440 | linux-libc-dev | 7.0.0-31.31 | kernel: drm/xe: Wait on external BO kernel fences in exec IOCTL — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74441 | linux-libc-dev | 7.0.0-31.31 | kernel: usb: typec: ucsi: Fix race condition and ordering in port unregistration — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74442 | linux-libc-dev | 7.0.0-31.31 | kernel: drm/vmwgfx: avoid destroy_workqueue(NULL) on vkms init failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74443 | linux-libc-dev | 7.0.0-31.31 | kernel: drm/vmwgfx: bound DMA command body size against suffix pointer — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74444 | linux-libc-dev | 7.0.0-31.31 | kernel: drm/vmwgfx: validate DRAW_PRIMITIVES header size before division — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74445 | linux-libc-dev | 7.0.0-31.31 | kernel: drm/vmwgfx: reject DX_BIND_QUERY without a DX context — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74447 | linux-libc-dev | 7.0.0-31.31 | kernel: drm/amdkfd: fix uint32_t overflow in EOP ring buffer size alignment — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74448 | linux-libc-dev | 7.0.0-31.31 | kernel: drm/amdkfd: fix QID bit leak in pqm_create_queue() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74449 | linux-libc-dev | 7.0.0-31.31 | kernel: drm/amd/display: Fix divide-by-zero in calculate_mcache_setting on zero viewport — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74451 | linux-libc-dev | 7.0.0-31.31 | kernel: drm/panthor: validate firmware interface structure sizes — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74452 | linux-libc-dev | 7.0.0-31.31 | kernel: drm/panthor: reject firmware sections with oversized data — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74453 | linux-libc-dev | 7.0.0-31.31 | kernel: drm/vc4: Zero the tile state data array before each BIN job — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74454 | linux-libc-dev | 7.0.0-31.31 | kernel: drm/vc4: Supply the overflow slot size in BPOS, not the whole bin BO size — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74455 | linux-libc-dev | 7.0.0-31.31 | kernel: can: peak_usb: validate uCAN receive record lengths — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74456 | linux-libc-dev | 7.0.0-31.31 | kernel: can: peak_usb: peak_usb_start(): fix double free of transfer buffer on URB submit error — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74385 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: nvmet-tcp: check return value of nvmet_tcp_set_queue_sock — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74386 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: nvmet-tcp: fix page fragment cache leak in error path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74387 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ALSA: seq: midi: Serialize output teardown with event_input — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74388 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ALSA: seq: oss: Fix UAF at handling events with embedded SysEx data — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74389 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: RDMA/hns: Fix log flood after cmd_mbox failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74391 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: tracing: Bound synthetic-field strings with seq_buf — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74392 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: dm: limit target bio polling to one shot — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74393 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/syncobj: Fix memory leak in drm_syncobj_find_fence() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74395 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: RDMA/mlx5: Fix devx subscribe-event unwind NULL dereference — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74396 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: RDMA/mlx5: Fix UMR XLT cleanup on ODP populate failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74398 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: ipv6: addrconf: bail out of dad_failure when state is no longer POSTDAD — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74399 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: evm: terminate and bound the evm_xattrs read buffer — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74400 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: bpf: fix crash in bpf_[set|remove]_dentry_xattr for negative dentries — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74402 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: crypto: atmel-sha204a - fix blocking and non-blocking rng logic — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74404 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: crypto: ccp - Fix snp_filter_reserved_mem_regions() off-by-one — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74406 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: vxlan: Fix potential null-ptr-deref in vxlan_gro_prepare_receive() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74407 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: wifi: ath11k: cancel SSR work items during PCI shutdown — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74408 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: wifi: ath9k: fix OOB access from firmware tx status queue ID — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74409 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: wifi: rtw89: add bounds check on firmware mac_id in link lookup — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74410 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: wifi: rtw88: fix OOB read from firmware RX descriptor exceeding DMA buffer — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74413 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: wifi: rtw89: fix wrong pci_get_drvdata type in AER handlers — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74415 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: spi: atcspi200: fix use-after-free when driver unbind — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74416 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/radeon: fix memory leak in radeon_ring_restore() on lock failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74417 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/radeon: fix integer overflow in radeon_align_pitch() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74419 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: accel/amdxdna: Adjust size for copy_to_user() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74420 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/gpusvm: Reject VMAs with VM_IO or VM_PFNMAP when creating SVM ranges — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74421 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/rockchip: dw_dp: Switch to drmm_kzalloc() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74422 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/rockchip: inno-hdmi: Switch to drmm_kzalloc() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74423 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: accel/amdxdna: Fix leak when pinning ubuf pages — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74491 | linux-libc-dev | 7.0.0-31.31 | kernel: of/address: Fix NULL bus dereference in of_pci_range_parser_one() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74492 | linux-libc-dev | 7.0.0-31.31 | kernel: netfilter: ipset: do not update comments from kernel-side hash adds — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74493 | linux-libc-dev | 7.0.0-31.31 | kernel: net/smc: fix socket use-after-free during link group termination — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74494 | linux-libc-dev | 7.0.0-31.31 | kernel: ksmbd: reject repeated SMB2 NEGOTIATE requests — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74495 | linux-libc-dev | 7.0.0-31.31 | kernel: igbvf: Fix leak in TX DMA error cleanup — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74496 | linux-libc-dev | 7.0.0-31.31 | kernel: fou: Fix use-after-free in fou_create() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74497 | linux-libc-dev | 7.0.0-31.31 | kernel: ALSA: usb-audio: Clamp frame size in implicit-feedback mode — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74498 | linux-libc-dev | 7.0.0-31.31 | kernel: ALSA: usb-audio: Fix DMA buffer out-of-bounds write when fill_max is set — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74499 | linux-libc-dev | 7.0.0-31.31 | kernel: ALSA: usb-audio: fix OOB write in snd_usbmidi_akai_output() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74500 | linux-libc-dev | 7.0.0-31.31 | kernel: ALSA: usb-audio: fix stack info leak in RME Digiface status — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74501 | linux-libc-dev | 7.0.0-31.31 | kernel: ALSA: usb-audio: fix use-after-free in ump_to_endpoint() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74502 | linux-libc-dev | 7.0.0-31.31 | kernel: ALSA: ump: fix double free of out_cvts on rawmidi error — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74503 | linux-libc-dev | 7.0.0-31.31 | kernel: ALSA: timer: Clear SNDRV_TIMER_IFLG_DEAD once the close completes — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74504 | linux-libc-dev | 7.0.0-31.31 | kernel: ALSA: seq: Fix division by zero in initialize_timer() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74505 | linux-libc-dev | 7.0.0-31.31 | kernel: ALSA: 6fire: Fix UAF at error handling during probe — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74507 | linux-libc-dev | 7.0.0-31.31 | kernel: Bluetooth: HIDP: validate numbered report payloads — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74508 | linux-libc-dev | 7.0.0-31.31 | kernel: Bluetooth: HIDP: reject frames without a transaction header — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74509 | linux-libc-dev | 7.0.0-31.31 | kernel: Bluetooth: hci_sync: Fix advertising data UAFs — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74513 | linux-libc-dev | 7.0.0-31.31 | kernel: dibs: fix use-after-free of dmb_node in loopback attach/detach/unregister — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74514 | linux-libc-dev | 7.0.0-31.31 | kernel: KVM: s390: pci: Fix memory accounting for pinned/unpinned pages — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74515 | linux-libc-dev | 7.0.0-31.31 | kernel: KVM: s390: pci: Reject adapter interrupt forwarding if already enabled — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74516 | linux-libc-dev | 7.0.0-31.31 | kernel: KVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74517 | linux-libc-dev | 7.0.0-31.31 | kernel: KVM: x86: Cancel delayed I/O APIC EOI handling before destroying vCPUs — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74518 | linux-libc-dev | 7.0.0-31.31 | kernel: mm/hugetlb: fix list corruption in allocate_file_region_entries() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74520 | linux-libc-dev | 7.0.0-31.31 | kernel: iommu/iommufd: Fix IOPF group ownership UAF — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74521 | linux-libc-dev | 7.0.0-31.31 | kernel: ksmbd: use memcmp() to compare ClientGUIDs — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74522 | linux-libc-dev | 7.0.0-31.31 | kernel: ksmbd: fix use-after-free in __close_file_table_ids() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74523 | linux-libc-dev | 7.0.0-31.31 | kernel: qede: sync udp_tunnel ports outside qede_lock in the recovery path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74524 | linux-libc-dev | 7.0.0-31.31 | kernel: riscv: mm: Fix out-of-bounds page-table walk during memory hot-remove — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74457 | linux-libc-dev | 7.0.0-31.31 | kernel: can: peak_usb: add bounds check for USB channel index — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74458 | linux-libc-dev | 7.0.0-31.31 | kernel: can: kvaser_usb_leaf: kvaser_usb_leaf_wait_cmd(): validate received command extents — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74459 | linux-libc-dev | 7.0.0-31.31 | kernel: can: etas_es58x: es58x_read_bulk_callback(): fix RX buffer leak on URB resubmit failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74460 | linux-libc-dev | 7.0.0-31.31 | kernel: can: ems_usb: validate CPC message lengths — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74461 | linux-libc-dev | 7.0.0-31.31 | kernel: i2c: imx: Cancel hrtimer before clearing slave pointer — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74462 | linux-libc-dev | 7.0.0-31.31 | kernel: i2c: imx: mark I2C adapter when hardware is powered down — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74463 | linux-libc-dev | 7.0.0-31.31 | kernel: i2c: jz4780: Cache host clock rate at probe to prevent CCF prepare_lock deadlock — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74464 | linux-libc-dev | 7.0.0-31.31 | kernel: net: openvswitch: fix skb leak on flow key update failure during ct — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74466 | linux-libc-dev | 7.0.0-31.31 | kernel: s390/zcrypt: Close speculative mem read possibility — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74467 | linux-libc-dev | 7.0.0-31.31 | kernel: s390/qeth: Check CAP_NET_ADMIN for private ioctls — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74468 | linux-libc-dev | 7.0.0-31.31 | kernel: gpio: pch: use raw_spinlock_t for the register lock — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74469 | linux-libc-dev | 7.0.0-31.31 | kernel: sctp: prevent peer transport count overflow — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74471 | linux-libc-dev | 7.0.0-31.31 | kernel: tracing: Check return value of __register_event() in trace_module_add_events() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74472 | linux-libc-dev | 7.0.0-31.31 | kernel: ublk: reset kernel-owned dev_info fields in ublk_ctrl_add_dev() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74473 | linux-libc-dev | 7.0.0-31.31 | kernel: vxlan: use pskb_network_may_pull() in route_shortcircuit() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74474 | linux-libc-dev | 7.0.0-31.31 | kernel: vxlan: use pskb_network_may_pull() for transmit path header pulls — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74475 | linux-libc-dev | 7.0.0-31.31 | kernel: vxlan: use neigh_ha_snapshot() in route_shortcircuit() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74476 | linux-libc-dev | 7.0.0-31.31 | kernel: veth: convert frag_list skbs before running XDP — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74477 | linux-libc-dev | 7.0.0-31.31 | kernel: uprobes: Fix NULL pointer dereference in hprobe_expire() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74478 | linux-libc-dev | 7.0.0-31.31 | kernel: um: vector: fix use-after-free in vector_mmsg_rx() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74479 | linux-libc-dev | 7.0.0-31.31 | kernel: net: pktgen: fix proc entry use-after-free — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74480 | linux-libc-dev | 7.0.0-31.31 | kernel: net: bridge: stop fast-leave after deleting a port group — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74482 | linux-libc-dev | 7.0.0-31.31 | kernel: mm/huge_memory: unlock i_mmap_rwsem before releasing after-split folios — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74483 | linux-libc-dev | 7.0.0-31.31 | kernel: binfmt_misc: don't leak the user namespace when the mount fails — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74484 | linux-libc-dev | 7.0.0-31.31 | kernel: binfmt_misc: don't let an 'F' entry pin its own instance — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74485 | linux-libc-dev | 7.0.0-31.31 | kernel: binfmt_misc: reject a flag character as the field delimiter — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74486 | linux-libc-dev | 7.0.0-31.31 | kernel: binfmt_misc: use exe_file_deny_write_access() for the interpreter clone — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74487 | linux-libc-dev | 7.0.0-31.31 | kernel: binfmt_misc: restore write access when removing an entry — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74488 | linux-libc-dev | 7.0.0-31.31 | kernel: wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74278 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ALSA: seq: Fix kernel heap address leak in bounce_error_event() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74279 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: crypto: cavium/cpt - fix DMA cleanup using wrong loop index — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74280 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: crypto: marvell/octeontx - fix DMA cleanup using wrong loop index — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74281 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: tipc: reject inverted service ranges from peer bindings — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74282 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: tipc: prevent snt_unacked underflow on CONN_ACK — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74283 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: tipc: require net admin for TIPCv2 netlink mutators — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74284 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net/sched: sch_hfsc: Don't make class passive twice — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74286 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net: pfcp: allocate per-cpu tstats for PFCP netdevs — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74287 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: sctp: validate embedded address parameter length — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74288 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net: fib_rules: Don't dump dying fib_rule in fib_rules_dump() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74289 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ipv4: fib: Don't dump dying fib_info in fib_leaf_notify() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74290 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net/sched: cls_flow: Dont expose folded kernel pointers — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74291 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ASoC: topology: Check PCM and DAI name strings before use — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74292 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ASoC: tegra: tegra210_ahub: Validate written enum value — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74293 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ASoC: fsl: fsl_audmix: Validate written enum values — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74294 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ASoC: meson: aiu: Validate written enum values — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74295 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ASoC: codecs: hdac_hdmi: Validate written enum value — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74296 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: RDMA/mlx5: Release the HW‑provided UAR index rather than the SW one — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74297 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: RDMA/mlx5: Fix undefined shift of user RQ WQE size — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74300 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: Bluetooth: hci: validate codec capability element length — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74301 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: Bluetooth: btmtk: fix URB leak in alloc_mtk_intr_urb error path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74302 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: Bluetooth: hci_core: Fix UAF in hci_unregister_dev() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74303 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: Bluetooth: hci_qca: fix NULL pointer dereference in qca_dmp_hdr() for non-serdev device — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74304 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: Bluetooth: hci_qca: fix NULL pointer dereference in qca_setup() for non-serdev device — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74305 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: bpf: Tighten cgroup storage cookie checks for prog arrays — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74306 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: vfio/qat: fix f_pos race in qat_vf_resume_write() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74307 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ext4: validate donor file superblock early in EXT4_IOC_MOVE_EXT — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74308 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ext4: fix kernel BUG in ext4_write_inline_data_end — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74309 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: vdpa/octeon_ep: fix IRQ-to-ring mapping in interrupt handler — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72493 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: net: serialize netif_running() check in enqueue_to_backlog() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72494 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: RDMA/irdma: Replace waitqueue and flag with completion — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72495 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: RDMA/bnxt_re: Avoid repeated requests to allocate WC pages — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72496 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: RDMA/bnxt_re: Proper rollback if the ioremap fails — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72497 | linux-libc-dev | 7.0.0-31.31 | kernel: RDMA/bnxt_re: Add a max slot check for SQ — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-72498 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: RDMA/bnxt_re: Avoid displaying the kernel pointer — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72499 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: RDMA/bnxt_re: Free CQ toggle page after firmware teardown — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72500 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: RDMA/bnxt_re: Free SRQ toggle page after firmware teardown — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72501 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | In the Linux kernel, the following vulnerability has been resolved: R ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-72502 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: tcp: ipv6: clamp default adverting MSS to avoid GSO_BY_FRAGS (0xFFFF) — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74255 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: tipc: fix UAF in tipc_l2_send_msg() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74256 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: bpf, sockmap: fix integer overflow in bpf_msg_pop_data() bounds check — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74257 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: sockmap: Fix use-after-free in udp_bpf_recvmsg() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74258 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: bpf: Guard __get_user acesss with access_ok for uprobe_multi data — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74260 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: netfilter: nf_dup_netdev: add nf_dev_xmit_recursion*() helpers and use them — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74261 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ALSA: seq: avoid stale FIFO cells during resize — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74263 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net: wwan: t7xx: check skb_clone in control TX — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74264 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net: watchdog: fix refcount tracking races — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74265 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net: mana: initialize gdma queue id to INVALID_QUEUE_ID — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74266 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net/sched: sch_dualpi2: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74267 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: net/sched: sch_codel: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74269 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: bnxt: fix head underflow on XDP head-grow — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74270 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: handshake: Require admin permission for DONE command — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74271 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: power: supply: core: fix supplied_from allocations — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74272 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: cxl/region: Resolve region deletion races — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74273 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: cxl/region: Block region delete during region creation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74274 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: cxl/region: Fill first free targets[] slot during auto-discovery — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74276 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: spi: xilinx: use FIFO occupancy register to determine buffer size — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74277 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: iommu/dma-iommu: Fix wrong scatterlist length assignment in P2PDMA path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74348 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ocfs2/dlm: require a ref for locking_state debugfs open — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74349 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ocfs2: reject FITRIM ranges shorter than a cluster — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74351 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ocfs2: rebase copied fsdlm LVB pointers in locking_state — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74352 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: of: reserved_mem: avoid post-init UAF when alloc_reserved_mem_array() fails — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74353 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/amdkfd: always resume_all after suspend_all — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74354 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: bpf: Take mmap_lock in zap_pages() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74355 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: iommu/vt-d: Fix RB-tree corruption in probe error path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74356 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: vhost: fix vhost_get_avail_idx for a non empty ring — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74358 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ext4: fix fast commit wait/wake bit mapping on 64-bit — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74359 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: configfs_lookup(): don't leave ->s_dentry dangling on failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74360 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: bpf: Reject exclusive maps for bpf_map_elem iterators — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74362 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ext2: fix ignored return value of generic_write_sync() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74364 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: bpf: Reject exclusive maps as inner maps in map-in-map — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74365 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: nvdimm/btt: Handle preemption in BTT lane acquisition — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74366 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: wifi: ath12k: fix NULL deref in change_sta_links for unready link — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74367 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: wifi: ath12k: fix inconsistent arvif state in vdev_create error paths — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74368 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: wifi: ath12k: fix memory leak in ath12k_wifi7_dp_rx_h_verify_tkip_mic() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74370 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: liveupdate: fix TOCTOU race in luo_session_retrieve() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74372 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: raid1: fix nr_pending leak in REQ_ATOMIC bad-block error path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74373 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: md/raid1,raid10: fix bio accounting for split md cloned bios — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74374 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: md/raid1,raid10: fix error-path detection with md_cloned_bio() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74375 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: md/raid1,raid10: fix deadlock in read error recovery path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74376 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: md/raid10: reset read_slot when reusing r10bio for discard — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74377 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: RDMA/rxe: Copy WQE to local buffer in non-SRQ receive path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74379 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: dax/kmem: account for partial discontiguous resource upon removal — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74380 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: gpu: host1x: Fix iommu_map_sgtable() return value check — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74381 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: gpu: host1x: Allow entries in BO caches to be freed — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74382 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net/sched: cls_bpf: prevent unbounded recursion in offload rollback — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74384 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: nvme-multipath: fix flex array size in struct nvme_ns_head — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74310 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: vhost/net: complete zerocopy ubufs only once — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74311 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: virtio: rtc: tear down old virtqueues before restore — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74314 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: bpf: Cancel special fields on map value recycle — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74316 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: NFSD: Handle layout stid in nfsd4_drop_revoked_stid() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74318 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: btrfs: fix deadlock cloning inline extent when using flushoncommit — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74320 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: fbdev: sm501fb: Fix buffer errors in OF binding code — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74321 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: btrfs: fix invalid pointer dereference in __btrfs_run_delayed_refs() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74322 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: wifi: mt76: mt7996: Fix possible NULL pointer dereference in mt7996_mac_write_txwi_80211() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74323 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: wifi: mt76: mt7996: Fix possible token leak in mt7996_tx_prepare_skb() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74324 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: wifi: mt76: mt7925: validate skb length in testmode query — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74325 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: wifi: mt76: use kfree_rcu for offchannel link in mt76_put_vif_phy_link — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74327 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: vmalloc: fix NULL pointer dereference in is_vm_area_hugepages() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74328 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: iommufd: Destroy the pages content after detaching from dmabuf — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74329 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: watchdog: unregister PM notifier on watchdog unregister — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74330 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: configfs: fix lockless traversals of ->s_children — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74331 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: firmware_loader: Fix recursive lock in device_cache_fw_images() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74332 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ASoC: amd: acp-sdw-sof: Bound DAI link iteration — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74333 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ASoC: amd: acp-sdw-legacy: Bound DAI link iteration — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74335 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: bpf: Fix NULL pointer dereference in bpf_task_from_vpid() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74336 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: wifi: mac80211: bound S1G TIM PVB walk to the TIM element — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74337 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: bpf: Fix NMI/tracepoint re-entry deadlock on lru locks — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74338 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: bpf: Reject sleepable BPF_LSM_CGROUP programs at load time — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74339 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ALSA: seq: Clear variable event pointer on read — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74340 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: wifi: wcn36xx: fix OOB read from firmware count in PRINT_REG_INFO indication — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74342 | linux-libc-dev | 7.0.0-31.31 | kernel: kernfs: link kn to its parent before the LSM init hook — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74344 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: bpf: Clear rb node linkage when freeing bpf_rb_root — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74345 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: RDMA/siw: Fix endpoint/socket association handling — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74346 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: RDMA/irdma: Fix OOB read during CQ MR registration — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74347 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: netfilter: cttimeout: detach dataplane timeout policy and repurpose refcount — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| MEDIUM | CVE-2026-74679 | linux-libc-dev | 7.0.0-31.31 | kernel: usb: gadget: f_ncm: Use unsigned int for ndp_index — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74680 | linux-libc-dev | 7.0.0-31.31 | kernel: usb: atm: cxacru: properly kill rcv_urb on error in cxacru_cm() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74681 | linux-libc-dev | 7.0.0-31.31 | kernel: usb: misc: usbio: check ibuf_len against rxbuf_len in bulk msg — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74682 | linux-libc-dev | 7.0.0-31.31 | kernel: ALSA: usb-audio: fix OOB write on Type II inbound URBs — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74683 | linux-libc-dev | 7.0.0-31.31 | kernel: Input: evdev - sanitize event type index when fetching event masks — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74684 | linux-libc-dev | 7.0.0-31.31 | kernel: net: tap: set skb->dev before parsing virtio net header in tap_get_user_xdp() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74685 | linux-libc-dev | 7.0.0-31.31 | kernel: hwmon: (ltc4282) Clamp negative current limits — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74686 | linux-libc-dev | 7.0.0-31.31 | kernel: rqspinlock: Reset tail when preserving queue on deadlock — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74687 | linux-libc-dev | 7.0.0-31.31 | kernel: watchdog: at91sam9_wdt: prevent timer rearm during teardown — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74688 | linux-libc-dev | 7.0.0-31.31 | kernel: sctp: clear control chunk transport if it is being removed — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74689 | linux-libc-dev | 7.0.0-31.31 | kernel: net/atm: fix slab-out-of-bounds read in vcc_setsockopt() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74690 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74691 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74692 | linux-libc-dev | 7.0.0-31.31 | kernel: net/smc: fix TOCTOU race between smc_listen_out() and listener close — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74693 | linux-libc-dev | 7.0.0-31.31 | kernel: net: prestera: validate firmware header length — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74694 | linux-libc-dev | 7.0.0-31.31 | kernel: net/ncsi: fix heap OOB read in NCSI_CMD_SEND_CMD payload length — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74695 | linux-libc-dev | 7.0.0-31.31 | kernel: netfilter: nf_flow_table: drop existing skb dst before skb_dst_set_noref() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74696 | linux-libc-dev | 7.0.0-31.31 | kernel: tcp: fix TFO max_qlen accounting across reuseport migration — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74697 | linux-libc-dev | 7.0.0-31.31 | kernel: bnxt_en: Disable EOP for TPA on all chips to prevent data corruption — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74698 | linux-libc-dev | 7.0.0-31.31 | kernel: net/mlx5e: fix BQL reset on SQ re-activation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74699 | linux-libc-dev | 7.0.0-31.31 | kernel: drm/xe: Fix memory leak in exec_queue_set_hang_replay_state() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74700 | linux-libc-dev | 7.0.0-31.31 | kernel: net/sched: cls_api: Always acquire rtnl_lock when destroying locked classifiers — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74701 | linux-libc-dev | 7.0.0-31.31 | kernel: net/openvswitch: check Ethernet header length in key_extract() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74702 | linux-libc-dev | 7.0.0-31.31 | kernel: vhost-scsi: reject feature changes after endpoint — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74703 | linux-libc-dev | 7.0.0-31.31 | kernel: vhost-scsi: Validate T10 PI scatterlist counts — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74704 | linux-libc-dev | 7.0.0-31.31 | kernel: net/sched: sch_cake: drop WARN_ON(1) for malformed packets in ACK filter — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74705 | linux-libc-dev | 7.0.0-31.31 | kernel: udp: fix potential use-after-free in tunnel segmentation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74706 | linux-libc-dev | 7.0.0-31.31 | kernel: bnge: Fix NULL pointer dereference in aux device release — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74707 | linux-libc-dev | 7.0.0-31.31 | kernel: xsk: validate metadata when processing requests — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74650 | linux-libc-dev | 7.0.0-31.31 | kernel: staging: rtl8723bs: fix OOB read in WMM_param_handler() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74651 | linux-libc-dev | 7.0.0-31.31 | kernel: staging: rtl8723bs: fix OOB read in rtw_get_wpa_ie() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74652 | linux-libc-dev | 7.0.0-31.31 | kernel: serial: amba-pl011: cancel RS485 hrtimers after freeing IRQ — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74653 | linux-libc-dev | 7.0.0-31.31 | kernel: serial: 8250_of: clear stuck empty-FIFO RX-timeout on LPC32xx — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74654 | linux-libc-dev | 7.0.0-31.31 | kernel: serial: 8250_dma: Clear stale RX state on shutdown — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74655 | linux-libc-dev | 7.0.0-31.31 | kernel: serial: qcom-geni: fix TX DMA buffer flush — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74656 | linux-libc-dev | 7.0.0-31.31 | kernel: ipv4: fix use-after-free in fib_nhc_update_mtu() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74657 | linux-libc-dev | 7.0.0-31.31 | kernel: ipv4: Fix fib_nlmsg_size() for RTA_VIA nexthops — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74658 | linux-libc-dev | 7.0.0-31.31 | kernel: futex: Prevent robust futex exit race some more — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74659 | linux-libc-dev | 7.0.0-31.31 | kernel: net: bridge: mrp: fix uninitialised bytes on the wire — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74660 | linux-libc-dev | 7.0.0-31.31 | kernel: netfilter: ebt_nflog: pin the NFLOG backend — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74661 | linux-libc-dev | 7.0.0-31.31 | kernel: mac802154: fix netdev use-after-free in beacon worker — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74662 | linux-libc-dev | 7.0.0-31.31 | kernel: inet: frags: publish queues before arming timer — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74663 | linux-libc-dev | 7.0.0-31.31 | kernel: net/sched: reject overly deep qdisc hierarchies — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74664 | linux-libc-dev | 7.0.0-31.31 | kernel: net: openvswitch: reallocate update replies for mismatched IDs — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74665 | linux-libc-dev | 7.0.0-31.31 | kernel: net: fix skb length accounting after generic XDP frag adjustment — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74666 | linux-libc-dev | 7.0.0-31.31 | kernel: packet: synchronize pressure clearing with ring reconfiguration — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74667 | linux-libc-dev | 7.0.0-31.31 | kernel: net/packet: reset the MAC header on the packet-socket transmit path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74668 | linux-libc-dev | 7.0.0-31.31 | kernel: packet: use consistent hard_header_len in TX_RING send path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74669 | linux-libc-dev | 7.0.0-31.31 | kernel: ipvs: clear IPv4 options after rebasing tunnel ICMP errors — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74670 | linux-libc-dev | 7.0.0-31.31 | kernel: ipvs: stop estimator after disabled calc phase — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74671 | linux-libc-dev | 7.0.0-31.31 | kernel: ima: fix out-of-bounds read in xattr_verify() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74672 | linux-libc-dev | 7.0.0-31.31 | kernel: mm/vmalloc: acquire init_mm lock on huge vmap to avoid ptdump UAF — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74673 | linux-libc-dev | 7.0.0-31.31 | kernel: Input: evdev - fix information leak in evdev_pass_values() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74674 | linux-libc-dev | 7.0.0-31.31 | kernel: mm: fix incorrect flush address in direct page table reclaim — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74675 | linux-libc-dev | 7.0.0-31.31 | kernel: vt: stabilize tty reference in kbd_keycode with tty_port_tty_get — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74676 | linux-libc-dev | 7.0.0-31.31 | kernel: vt: add permission check for KDSKBMETA ioctl — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74677 | linux-libc-dev | 7.0.0-31.31 | kernel: net: usb: ipheth: fix carrier_work UAF on disconnect — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74678 | linux-libc-dev | 7.0.0-31.31 | kernel: net: usb: ax88179_178a: fix skb leak in ax88179_tx_fixup() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74739 | linux-libc-dev | 7.0.0-31.31 | kernel: net/sched: cls_u32: skip hash tables in u32_bind_class() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74740 | linux-libc-dev | 7.0.0-31.31 | kernel: net/sched: act_api: fix TOCTOU NULL deref on a->goto_chain — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74741 | linux-libc-dev | 7.0.0-31.31 | kernel: net: ngbe: fix NULL pointer dereference in non-MSI-X interrupt enabling — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74742 | linux-libc-dev | 7.0.0-31.31 | kernel: veth: fix queue index used to wake the peer txq in veth_poll — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74743 | linux-libc-dev | 7.0.0-31.31 | kernel: macvlan: inherit needed_headroom and needed_tailroom from lowerdev — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74744 | linux-libc-dev | 7.0.0-31.31 | kernel: ipvlan: inherit needed_headroom and needed_tailroom from phy_dev — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74745 | linux-libc-dev | 7.0.0-31.31 | kernel: eth: bnxt: avoid deadlock when canceling IRQ affinity notifier — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74746 | linux-libc-dev | 7.0.0-31.31 | kernel: netfilter: flowtable: publish GC-visible tuple last — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74747 | linux-libc-dev | 7.0.0-31.31 | kernel: ipvs: revalidate ihl to prevent out-of-bounds access — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74748 | linux-libc-dev | 7.0.0-31.31 | kernel: netfilter: ipset: fix refcount race between list:set GC and swap — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74750 | linux-libc-dev | 7.0.0-31.31 | kernel: ovpn: defer key slot crypto freeing to workqueue — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74752 | linux-libc-dev | 7.0.0-31.31 | kernel: sctp: validate cookie AUTH state before use — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74753 | linux-libc-dev | 7.0.0-31.31 | kernel: perf: Reject exited events as group leaders — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74754 | linux-libc-dev | 7.0.0-31.31 | kernel: scsi: core: pair EH runtime PM get and put — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80519 | linux-libc-dev | 7.0.0-31.31 | kernel: ovpn: finish crypto callback cleanup before peer release — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80520 | linux-libc-dev | 7.0.0-31.31 | kernel: ovpn: fix NULL dereference when killing missing key — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80521 | linux-libc-dev | 7.0.0-31.31 | kernel: af_unix: Unlink scc_entry in unix_del_edge() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80522 | linux-libc-dev | 7.0.0-31.31 | kernel: crypto: tegra - fix rctx->cryptlen calculation in tegra_gcm_do_one_req() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80523 | linux-libc-dev | 7.0.0-31.31 | kernel: clk: spacemit: k3: set hdma clock as critical — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80524 | linux-libc-dev | 7.0.0-31.31 | kernel: optee: ffa: Add NULL check in optee_ffa_lend_protmem — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80525 | linux-libc-dev | 7.0.0-31.31 | kernel: ASoC: SOF: ipc4-topology: Refresh copier IPC payload before widget setup — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80526 | linux-libc-dev | 7.0.0-31.31 | kernel: ASoC: tas2562: Validate values for volume writes — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80527 | linux-libc-dev | 7.0.0-31.31 | kernel: ceph: fix hanging __ceph_get_caps() with stale mds_wanted — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80528 | linux-libc-dev | 7.0.0-31.31 | kernel: ceph: avoid fs reclaim while using current->journal_info — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80529 | linux-libc-dev | 7.0.0-31.31 | kernel: xfs: don't swallow dquot recovery verification errors — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80530 | linux-libc-dev | 7.0.0-31.31 | kernel: xfs: fix exchange-range reflink flag clearing issue with INO1_WRITTEN — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80531 | linux-libc-dev | 7.0.0-31.31 | kernel: xfs: avoid UAF on sc->tempip in xrep_tempfile_create — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80532 | linux-libc-dev | 7.0.0-31.31 | kernel: xfs: fix another iunlink infinite loop bug in online fsck — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-80533 | linux-libc-dev | 7.0.0-31.31 | kernel: xfs: don't walk off the end of a null sc->sa.agi_bp in AGI repair — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74708 | linux-libc-dev | 7.0.0-31.31 | kernel: xsk: validate launch-time metadata size — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74709 | linux-libc-dev | 7.0.0-31.31 | kernel: xsk: clear metadata pointer when no timestamp is requested — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74710 | linux-libc-dev | 7.0.0-31.31 | kernel: xsk: require at least 16 bytes of TX metadata — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74711 | linux-libc-dev | 7.0.0-31.31 | kernel: hwmon: (pmbus) Fix type confusion in notification logic — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74712 | linux-libc-dev | 7.0.0-31.31 | kernel: vdpa/mlx5: Fix buffer length in create_direct_keys() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74713 | linux-libc-dev | 7.0.0-31.31 | kernel: vhost_iotlb: bound map allocation in add_range — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74714 | linux-libc-dev | 7.0.0-31.31 | kernel: bpf: tcp: Fix use-after-free in bpf_iter_tcp_established_batch() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74715 | linux-libc-dev | 7.0.0-31.31 | kernel: bpf: Fix netns reference imbalance in conntrack kfuncs — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74716 | linux-libc-dev | 7.0.0-31.31 | kernel: accel/amdxdna: Fix locally exploitable BUG_ON in amdxdna_insert_pages() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74717 | linux-libc-dev | 7.0.0-31.31 | kernel: net/mlx5: fw_tracer, return NULL on create error — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74718 | linux-libc-dev | 7.0.0-31.31 | kernel: devlink: fix net namespace reference leak in reload — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74719 | linux-libc-dev | 7.0.0-31.31 | kernel: net/smc: fix qentry overwrite for CONFIRM_LINK and ADD_LINK_CONT in smc_llc_event_handler() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74720 | linux-libc-dev | 7.0.0-31.31 | kernel: bpf: Preserve pointer state for commuted arithmetic — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74721 | linux-libc-dev | 7.0.0-31.31 | kernel: accel/amxdna: Fix page-insertion errors in amdxdna_insert_pages() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74722 | linux-libc-dev | 7.0.0-31.31 | kernel: btrfs: fix memory leak in btrfs_do_encoded_write() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74723 | linux-libc-dev | 7.0.0-31.31 | kernel: btrfs: lzo: reject inline extents without valid headers — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74724 | linux-libc-dev | 7.0.0-31.31 | kernel: ipvs: avoid out-of-bounds write in ip_vs_nat_icmp — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74725 | linux-libc-dev | 7.0.0-31.31 | kernel: enic: fix tx_hang_reset use-after-free on device removal — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74726 | linux-libc-dev | 7.0.0-31.31 | kernel: bonding: alb: re-check primary_is_promisc under RTNL in bond_alb_monitor — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74727 | linux-libc-dev | 7.0.0-31.31 | kernel: ovpn: skip rehash for peers already removed from by_id — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74728 | linux-libc-dev | 7.0.0-31.31 | kernel: xfs: handle NULL b_addr in xfs_buf_free — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74729 | linux-libc-dev | 7.0.0-31.31 | kernel: soc: aspeed: lpc-snoop: Fix usercopy overflow in snoop_file_read — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74730 | linux-libc-dev | 7.0.0-31.31 | kernel: NFS: Pin the 'struct nfs_server' during a FREE_STATEID call — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74733 | linux-libc-dev | 7.0.0-31.31 | kernel: gpio: pca953x: fix pca953x_irq_bus_sync_unlock regmap lock — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74734 | linux-libc-dev | 7.0.0-31.31 | kernel: firewire: ohci: fix NULL pointer dereference in ar_context_release — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74735 | linux-libc-dev | 7.0.0-31.31 | kernel: l2tp: fix tunnel and session refcount leak on seq_file release — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74736 | linux-libc-dev | 7.0.0-31.31 | kernel: net/sched: cls_bpf: reject dev-bound programs bound to a different device — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74737 | linux-libc-dev | 7.0.0-31.31 | kernel: net: ethernet: ti: am65-cpsw-nuss: Fix port_id extraction from SRC TAG — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74738 | linux-libc-dev | 7.0.0-31.31 | kernel: regmap: sdw-mbq: don't call an unset readable_reg callback — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74559 | linux-libc-dev | 7.0.0-31.31 | kernel: xsk: drain continuation descs after overflow in xsk_build_skb() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74560 | linux-libc-dev | 7.0.0-31.31 | kernel: xsk: fix buffer leak in xsk_drop_skb() for AF_XDP multi-buffer Tx — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74561 | linux-libc-dev | 7.0.0-31.31 | kernel: nexthop: avoid unlocked f6i_list walk in nh_rt_cache_flush — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74562 | linux-libc-dev | 7.0.0-31.31 | kernel: nexthop: take nh->lock for f6i_list walks in replace check and notify — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74563 | linux-libc-dev | 7.0.0-31.31 | kernel: rds: tcp: hold the RCU lock across ipv6_chk_addr() in rds_tcp_laddr_check() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74564 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74565 | linux-libc-dev | 7.0.0-31.31 | kernel: netfilter: nf_tables: make nft_object rhltable per table — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74566 | linux-libc-dev | 7.0.0-31.31 | kernel: keys: make keyring key-chunk byte order agree with keyring_diff_objects() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74567 | linux-libc-dev | 7.0.0-31.31 | kernel: keys: fix out-of-bounds read in keyring_get_key_chunk() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74569 | linux-libc-dev | 7.0.0-31.31 | kernel: netfilter: nf_conntrack_sip: widen NAT rewrite delta to s32 in sip_help_tcp() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74571 | linux-libc-dev | 7.0.0-31.31 | kernel: btrfs: skip global block reserve accounting for rescue mounts — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74572 | linux-libc-dev | 7.0.0-31.31 | kernel: btrfs: zoned: fix deadlock between metadata writeback and transaction commit — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74573 | linux-libc-dev | 7.0.0-31.31 | kernel: iommu/arm-smmu-v3-iommufd: Require exactly one Stream ID for a vDEVICE — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74574 | linux-libc-dev | 7.0.0-31.31 | kernel: dmaengine: idxd: fix fdev setup failure cleanup in idxd_cdev_open() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74575 | linux-libc-dev | 7.0.0-31.31 | kernel: thunderbolt: Prevent XDomain delayed work use-after-free on disconnect — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74576 | linux-libc-dev | 7.0.0-31.31 | kernel: mm/slab: prevent unbounded recursion in free path with new kmalloc type — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74577 | linux-libc-dev | 7.0.0-31.31 | kernel: net: mpls: initialize rtm_tos in mpls_getroute() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74578 | linux-libc-dev | 7.0.0-31.31 | kernel: crypto: algif_skcipher - force synchronous processing on trees without ctx->state — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74579 | linux-libc-dev | 7.0.0-31.31 | kernel: netfilter: nft_payload: fix mask build for partial field offload — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74580 | linux-libc-dev | 7.0.0-31.31 | kernel: vhost: reset the vring metadata cache on vring reconfiguration — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74581 | linux-libc-dev | 7.0.0-31.31 | kernel: net: ipv6: use-after-free in fib6_rule_suppress due to stale res->rt6 pointer — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74582 | linux-libc-dev | 7.0.0-31.31 | kernel: packet: use consistent hard_header_len in non-ring send paths — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74583 | linux-libc-dev | 7.0.0-31.31 | kernel: net/sched: cls_route: fix fastmap use-after-free on filter — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74585 | linux-libc-dev | 7.0.0-31.31 | kernel: thunderbolt: Bound the DROM dual link port number before indexing sw->ports — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74586 | linux-libc-dev | 7.0.0-31.31 | kernel: sctp: clear new_transport when removing a peer — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74587 | linux-libc-dev | 7.0.0-31.31 | kernel: sctp: fix use-after-free of cached ASCONF chunk — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74588 | linux-libc-dev | 7.0.0-31.31 | kernel: sctp: keep chunk->transport in step with the list it is queued on — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74589 | linux-libc-dev | 7.0.0-31.31 | kernel: bpf, sockmap: Fix sk_redir use-after-free in send verdict — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74591 | linux-libc-dev | 7.0.0-31.31 | kernel: mm/filemap: __filemap_add_folio() restore index before retrying — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74525 | linux-libc-dev | 7.0.0-31.31 | kernel: net: sxgbe: free TX rings on RX allocation failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74526 | linux-libc-dev | 7.0.0-31.31 | kernel: scsi: mpi3mr: Fix potential deadlock in mpi3mr_fault_uevent_emit — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74528 | linux-libc-dev | 7.0.0-31.31 | kernel: Bluetooth: hci_sync: hold conn in hci_past_sync() callback — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74530 | linux-libc-dev | 7.0.0-31.31 | kernel: Bluetooth: hci_sync: hold conn in hci_connect_big_sync() callback — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74531 | linux-libc-dev | 7.0.0-31.31 | kernel: Bluetooth: hci_conn: hold conn reference in abort_conn_sync() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74532 | linux-libc-dev | 7.0.0-31.31 | kernel: Bluetooth: btintel: Validate length before parsing diagnostics TLV — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74533 | linux-libc-dev | 7.0.0-31.31 | kernel: Bluetooth: ISO: fix race of kfree vs kref_get_unless_zero — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74536 | linux-libc-dev | 7.0.0-31.31 | kernel: Bluetooth: ISO: fix leaking sk after socket release — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74537 | linux-libc-dev | 7.0.0-31.31 | kernel: Bluetooth: ISO: hold sk properly in iso_conn_ready — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74538 | linux-libc-dev | 7.0.0-31.31 | kernel: Bluetooth: ISO: lock sk in iso_connect_ind — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74539 | linux-libc-dev | 7.0.0-31.31 | kernel: Bluetooth: ISO: lock sk in iso_sock_getname — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74540 | linux-libc-dev | 7.0.0-31.31 | kernel: Bluetooth: L2CAP: fix UAF in l2cap_le_connect_rsp — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74541 | linux-libc-dev | 7.0.0-31.31 | kernel: Bluetooth: ISO: clear iso_data always when detaching conn from hcon — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74542 | linux-libc-dev | 7.0.0-31.31 | kernel: netfs: Fix folio_queue ENOMEM in writeback by adding a mempool — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74543 | linux-libc-dev | 7.0.0-31.31 | kernel: net: udp_tunnel: fix memory leak in udp_tunnel_nic_unregister() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74544 | linux-libc-dev | 7.0.0-31.31 | kernel: net/sched: cls_u32: validate offshift to prevent shift-out-of-bounds — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74545 | linux-libc-dev | 7.0.0-31.31 | In the Linux kernel, the following vulnerability has been resolved: r ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74546 | linux-libc-dev | 7.0.0-31.31 | kernel: hwmon: (adt7470) Fix divide-by-zero TOCTOU crash in fan speed read — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74547 | linux-libc-dev | 7.0.0-31.31 | kernel: hwmon: (adt7470) Fix busy-loop and I2C flooding in update thread — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74548 | linux-libc-dev | 7.0.0-31.31 | kernel: forcedeth: fix UAF of txrx_stats in nv_remove — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74549 | linux-libc-dev | 7.0.0-31.31 | kernel: hwmon: (nct6775-core) Prevent access to unsupported weight registers — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74550 | linux-libc-dev | 7.0.0-31.31 | kernel: net: do not send ICMP/NDISC Redirects when peer allocation fails — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74551 | linux-libc-dev | 7.0.0-31.31 | kernel: hwmon: (nzxt-smart2) DMA-align output buffer — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74552 | linux-libc-dev | 7.0.0-31.31 | kernel: hwmon: (lm90) Only report alarms if driver is ready — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74553 | linux-libc-dev | 7.0.0-31.31 | kernel: hwmon: (nct6775-core) Fix number of temperature registers for NCT6116 — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74555 | linux-libc-dev | 7.0.0-31.31 | kernel: scsi: libsas: Fix HA resume deadlock and hisi_sas disk-wake race — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74556 | linux-libc-dev | 7.0.0-31.31 | kernel: scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74557 | linux-libc-dev | 7.0.0-31.31 | kernel: scsi: libiscsi: Fix stale-data leak into the SCSI sense buffer — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74558 | linux-libc-dev | 7.0.0-31.31 | kernel: xsk: reclaim invalid Tx descriptors in ZC batch path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74620 | linux-libc-dev | 7.0.0-31.31 | kernel: net/sched: act_gact, act_police: range check the fallback control action — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74621 | linux-libc-dev | 7.0.0-31.31 | kernel: net/sched: act_ct: fix sk_buff leak when the header checks reject a packet — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74622 | linux-libc-dev | 7.0.0-31.31 | kernel: net: atlantic: free RX pages of consumed but not refilled buffers — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74623 | linux-libc-dev | 7.0.0-31.31 | kernel: net: atlantic: free stranded TX buffers on ring deinit — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74624 | linux-libc-dev | 7.0.0-31.31 | kernel: netfilter: nf_conntrack: defer invalid log until after unlock — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74625 | linux-libc-dev | 7.0.0-31.31 | kernel: netfilter: bridge: release template ct on non-IP path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74626 | linux-libc-dev | 7.0.0-31.31 | kernel: NTB: ntb_netdev: Preserve RX queue depth on allocation failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74627 | linux-libc-dev | 7.0.0-31.31 | kernel: net: devmem: prevent net-iov / page mixing — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74628 | linux-libc-dev | 7.0.0-31.31 | kernel: net/x25: fix use-after-free of the socket by its timers — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74629 | linux-libc-dev | 7.0.0-31.31 | kernel: net/dibs: Correct freeing of dmb_clientid_arr — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74630 | linux-libc-dev | 7.0.0-31.31 | kernel: ipv6: prevent in6_dev_get() from resurrecting inet6_dev — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74631 | linux-libc-dev | 7.0.0-31.31 | kernel: net: smc: fix splice entry lifetime imbalance in smc_rx_splice — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74632 | linux-libc-dev | 7.0.0-31.31 | kernel: mm/huge_memory: fix huge_zero_pfn race — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74633 | linux-libc-dev | 7.0.0-31.31 | kernel: tracing: Fix NULL pointer dereference in module event cache removal — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74634 | linux-libc-dev | 7.0.0-31.31 | kernel: ring-buffer: Prevent subbuf order change when resizing is disabled — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74635 | linux-libc-dev | 7.0.0-31.31 | kernel: fbdev: bitblit: bound-check glyph index in bit_cursor() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74636 | linux-libc-dev | 7.0.0-31.31 | kernel: tracing: Fix race between update_event_fields and, event_define_fields — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74637 | linux-libc-dev | 7.0.0-31.31 | kernel: perf/core: Fix group leader use-after-free after sibling detach — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74638 | linux-libc-dev | 7.0.0-31.31 | kernel: drm/v3d: Serialize the scheduler timeout handlers — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74639 | linux-libc-dev | 7.0.0-31.31 | kernel: ALSA: us144mkii: re-anchor capture URBs on resubmission — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74640 | linux-libc-dev | 7.0.0-31.31 | kernel: ALSA: FCP: fix OOB write in fcp_meter_ctl_get() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74641 | linux-libc-dev | 7.0.0-31.31 | kernel: ALSA: usx2y: bound the hwdep mmap fault offset — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74643 | linux-libc-dev | 7.0.0-31.31 | kernel: samples/damon/mtier: error out for zero quota goal target values — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74644 | linux-libc-dev | 7.0.0-31.31 | kernel: mm/damon/ops-common: putback folios on invalid migrate nid — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74645 | linux-libc-dev | 7.0.0-31.31 | kernel: mm/damon/lru_sort: error out for >10000 active_mem_bp — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74646 | linux-libc-dev | 7.0.0-31.31 | kernel: misc: fastrpc: take fl->lock when moving mmaps on interrupted invoke — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74647 | linux-libc-dev | 7.0.0-31.31 | kernel: misc: fastrpc: Remove buffer from list prior to unmap operation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74648 | linux-libc-dev | 7.0.0-31.31 | kernel: staging: rtl8723bs: validate monitor transmit frame lengths — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74649 | linux-libc-dev | 7.0.0-31.31 | kernel: staging: rtl8723bs: fix missing shared-key auth challenge length check — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74590 | linux-libc-dev | 7.0.0-31.31 | kernel: fsverity: Fix bpf_get_fsverity_digest() dynptr assumptions — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74592 | linux-libc-dev | 7.0.0-31.31 | kernel: ima: Instantiate file_truncate and path_truncate hooks — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74593 | linux-libc-dev | 7.0.0-31.31 | kernel: sched_ext: Take cgroup_lock() first in scx_cgroup_lock() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74594 | linux-libc-dev | 7.0.0-31.31 | kernel: sched/psi: Shut down rtpoll_timer in psi_cgroup_free() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74595 | linux-libc-dev | 7.0.0-31.31 | kernel: fscrypt: use the mount idmap for the owner check in fscrypt_ioctl_set_policy() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74596 | linux-libc-dev | 7.0.0-31.31 | kernel: fs,fsverity: remove check for fsverity being enabled in setattr_prepare() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74597 | linux-libc-dev | 7.0.0-31.31 | kernel: ip6_tunnel: clear skb2->cb[] in ip6ip6_err() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74598 | linux-libc-dev | 7.0.0-31.31 | kernel: ipv6: fix Route Information option length validation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74599 | linux-libc-dev | 7.0.0-31.31 | kernel: mm/ptdump: always stabilise against page table freeing using init_mm — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74600 | linux-libc-dev | 7.0.0-31.31 | kernel: mm/page_table_check: skip special zero mappings — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74601 | linux-libc-dev | 7.0.0-31.31 | kernel: ring-buffer: Use current_context for safe per-CPU buffer swap — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74602 | linux-libc-dev | 7.0.0-31.31 | kernel: ring-buffer: Initialise reader page order in rb_allocate_cpu_buffer() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74603 | linux-libc-dev | 7.0.0-31.31 | kernel: ptp: ocp: Fix board ID over-read — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74604 | linux-libc-dev | 7.0.0-31.31 | kernel: Revert "thermal/drivers/hwmon: Cleanup coding style a bit" — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74605 | linux-libc-dev | 7.0.0-31.31 | kernel: eventfs: Use children field for rcu head and add memory barriers — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74619 | linux-libc-dev | 7.0.0-31.31 | kernel: ovl: don't warn when the mount is completed from another user namespace — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74618 | linux-libc-dev | 7.0.0-31.31 | kernel: binfmt_misc: don't warn when the mount is completed from another user namespace — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74606 | linux-libc-dev | 7.0.0-31.31 | kernel: eventfs: Fix use-after-free in eventfs_remove_rec() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74607 | linux-libc-dev | 7.0.0-31.31 | kernel: KVM: SVM: Serialize accesses to the owner and mirror list with separate lock — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74608 | linux-libc-dev | 7.0.0-31.31 | kernel: smb: client: Fix use-after-free in cifs_try_adding_channels() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74609 | linux-libc-dev | 7.0.0-31.31 | kernel: tipc: read le->link under the node lock in tipc_node_link_down() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74610 | linux-libc-dev | 7.0.0-31.31 | kernel: tls: don't leave a full plaintext sk_msg ring unpushed — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74611 | linux-libc-dev | 7.0.0-31.31 | kernel: tls: rx: restore msg_iter before TLS 1.3 optimistic retry — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74612 | linux-libc-dev | 7.0.0-31.31 | kernel: veth: fix skb length accounting after XDP frag adjustment — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74613 | linux-libc-dev | 7.0.0-31.31 | kernel: vsock/virtio: avoid refilling the RX queue after teardown — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74614 | linux-libc-dev | 7.0.0-31.31 | kernel: vsock/virtio: read virtqueues under worker locks — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74615 | linux-libc-dev | 7.0.0-31.31 | kernel: vxlan: do not arm the ageing timer on a device that is down — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74616 | linux-libc-dev | 7.0.0-31.31 | kernel: xdp: reject clones that overrun skb_shared_info tailroom — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| MEDIUM | CVE-2026-74617 | linux-libc-dev | 7.0.0-31.31 | kernel: dibs: initialise dibs->lock in dibs_dev_alloc() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-80679 | linux-libc-dev | 7.0.0-31.31 | kernel: s390/dasd: Fix potential NULL pointer dereference — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-80680 | linux-libc-dev | 7.0.0-31.31 | kernel: i2c: amd-mp2: Unregister callback on adapter add failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-80685 | linux-libc-dev | 7.0.0-31.31 | kernel: mm/util: don't read __page_2 for order-1 folios in snapshot_page() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-80687 | linux-libc-dev | 7.0.0-31.31 | kernel: iommufd/viommu: Release the igroup lock on the vdevice_size error path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-80688 | linux-libc-dev | 7.0.0-31.31 | kernel: riscv: drop __init from vec_check_unaligned_access_speed_all_cpus — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-80678 | linux-libc-dev | 7.0.0-31.31 | kernel: i2c: imx: Fix slave registration race and error handling — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-80677 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: driver core: use READ_ONCE() for dev->driver in dev_has_sync_state() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-80676 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: Drivers: hv: vmbus: use generic driver_override infrastructure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-80662 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: cxl: Fix CXL_HEADERLOG_SIZE to match RAS Capability size — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-80689 | linux-libc-dev | 7.0.0-31.31 | kernel: tracing/mmiotrace: Add NULL check for mmio_trace_array in logging functions — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-80690 | linux-libc-dev | 7.0.0-31.31 | kernel: scsi: ufs: core: Initialize hba->rpmbs list in ufshcd — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-80696 | linux-libc-dev | 7.0.0-31.31 | kernel: hwmon: (ltc4282) Fix reading the minimum alarm voltage — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-80698 | linux-libc-dev | 7.0.0-31.31 | kernel: dmaengine: idxd: fix double free of wq, engine, and group structs — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-80704 | linux-libc-dev | 7.0.0-31.31 | kernel: drm/amd/display: use proper context for logging — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-80711 | linux-libc-dev | 7.0.0-31.31 | kernel: power: supply: max17040: handle missing status supplier — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-80706 | linux-libc-dev | 7.0.0-31.31 | kernel: can: softing: fw_parse(): validate firmware record spans — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-80708 | linux-libc-dev | 7.0.0-31.31 | kernel: s390/zcrypt: Fix missing mem scrub at clear key import in cca_clr2cipherkey() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-80709 | linux-libc-dev | 7.0.0-31.31 | kernel: s390/zcrypt: Fix wrong domain value verification with EP11 CPRBs — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-80635 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: wifi: wcn36xx: fix OOB read from short trigger BA firmware response — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-80636 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: netfilter: conntrack: revert ct extension genid infrastructure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-80639 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: cxl/test: Fix __fortify_panic — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-80640 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: cxl/fwctl: Fix __fortify_panic — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-80642 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: liveupdate: Reference count incoming FLB data — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-80643 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: EDAC/igen6: Fix call trace due to missing release() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-80645 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: rapidio/tsi721: prevent a bad dereference in tsi721_db_dpc() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-80647 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: RDMA/hns: Fix warning in poll cq direct mode — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-80648 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: pinctrl: spacemit: fix NULL check in spacemit_pin_set_config — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-80649 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: firmware: arm_scmi: Fix OOB in scmi_power_name_get() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-80650 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: media: atomisp: gc2235: fix UAF and memory leak — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-80651 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: crypto: ccp/sev-dev-tsm - bail out early when pdev->bus is NULL — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-80652 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: crypto: ccp - Treat zero-length cert chain as query for blob lengths — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-80653 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: scsi: hisi_sas: Add slave_destroy interface for v3 hw — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-80654 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: soc: xilinx: Shutdown and free rx mailbox channel — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-80655 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: soc: xilinx: Fix race condition in event registration — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-80657 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: accel/amdxdna: Guard management mailbox channel cleanup against NULL pointer — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-80658 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/rockchip: dw_dp: Fix null-ptr-deref in dw_dp_remove() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-80660 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: hwmon: (occ) unregister sysfs devices outside occ lock — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-80661 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ufs: core: tracing: Do not dereference pointers in TP_printk() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-54872 | openssl-provider-legacy | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | openssl: OpenSSL: Private key recovery via timing side-channel in generic elliptic curve operations — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-54873 | openssl-provider-legacy | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.7 | openssl: openssl: Denial of Service via excessive QUIC packet buffer retention — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-54875 | openssl-provider-legacy | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | openssl: openssl: information disclosure via non-constant-time SM2 scalar multiplication on ARM64 and RISC-V — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-72897 | openssl-provider-legacy | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | openssl: openssl: Denial of Service via out-of-bounds write during TLS context switch — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-75804 | openssl-provider-legacy | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | openssl: OpenSSL: Denial of Service via unenforced QUIC connection flow control — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-75805 | openssl-provider-legacy | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | openssl: openssl: Denial of Service via crafted CMP certificate revocation response — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-75806 | openssl-provider-legacy | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | openssl: OpenSSL: Denial of Service via undersized DTLS record — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-77696 | openssl-provider-legacy | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | openssl: OpenSSL: Private key recovery via SM2 timing side-channel — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-84784 | openssl-provider-legacy | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | openssl: OpenSSL: Denial of Service via unbounded QUIC connection identifier backlog — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2024-56433 | passwd | 1:4.17.4-2ubuntu3 | shadow-utils: Default subordinate ID configuration in /etc/login.defs could lead to compromise — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2018-6952 | patch | 2.8-2build1 | patch: Double free of memory in pch.c:another_hunk() causes a crash — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2019-20633 | patch | 2.8-2build1 | patch: double free in another_hunk function in pch.c — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2021-45261 | patch | 2.8-2build1 | patch: Invalid Pointer via another_hunk function — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-56288 | patch | 2.8-2build1 | patch: GNU patch: Denial of Service via specially crafted patch file — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-56289 | patch | 2.8-2build1 | patch: GNU patch: Denial of Service via crafted unified-diff input — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2025-58767 | ruby3.3 | 3.3.8-2ubuntu3.1 | rexml: REXML denial of service — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2025-61594 | ruby3.3 | 3.3.8-2ubuntu3.1 | uri: URI module: Credential exposure via URI + operator — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2025-58767 | ruby3.3-dev | 3.3.8-2ubuntu3.1 | rexml: REXML denial of service — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2025-61594 | ruby3.3-dev | 3.3.8-2ubuntu3.1 | uri: URI module: Credential exposure via URI + operator — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-80712 | linux-libc-dev | 7.0.0-31.31 | kernel: spi: spi-qpic-snand: write the feature value before executing SET_FEATURE — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-80723 | linux-libc-dev | 7.0.0-31.31 | kernel: of: reserved_mem: prevent OOB when too many dynamic regions are defined — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-80724 | linux-libc-dev | 7.0.0-31.31 | kernel: ptp: vmclock: prevent read-only mappings from becoming writable — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2024-56433 | login.defs | 1:4.17.4-2ubuntu3 | shadow-utils: Default subordinate ID configuration in /etc/login.defs could lead to compromise — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-35189 | openssl | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | openssl: openssl: Denial of Service via excessive memory allocation in CRL distribution point processing — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-35191 | openssl | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | openssl: openssl: Traffic amplification Denial of Service via QUIC packet over-accounting — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-42772 | openssl | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.7 | openssl: openssl: Denial of Service via inefficient QUIC stream reassembly — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-54872 | openssl | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | openssl: OpenSSL: Private key recovery via timing side-channel in generic elliptic curve operations — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-54873 | openssl | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.7 | openssl: openssl: Denial of Service via excessive QUIC packet buffer retention — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-54875 | openssl | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | openssl: openssl: information disclosure via non-constant-time SM2 scalar multiplication on ARM64 and RISC-V — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-72897 | openssl | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | openssl: openssl: Denial of Service via out-of-bounds write during TLS context switch — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-75804 | openssl | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | openssl: OpenSSL: Denial of Service via unenforced QUIC connection flow control — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-75805 | openssl | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | openssl: openssl: Denial of Service via crafted CMP certificate revocation response — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-75806 | openssl | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | openssl: OpenSSL: Denial of Service via undersized DTLS record — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-77696 | openssl | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | openssl: OpenSSL: Private key recovery via SM2 timing side-channel — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-84784 | openssl | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | openssl: OpenSSL: Denial of Service via unbounded QUIC connection identifier backlog — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-35189 | openssl-provider-legacy | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | openssl: openssl: Denial of Service via excessive memory allocation in CRL distribution point processing — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-35191 | openssl-provider-legacy | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | openssl: openssl: Traffic amplification Denial of Service via QUIC packet over-accounting — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-42772 | openssl-provider-legacy | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.7 | openssl: openssl: Denial of Service via inefficient QUIC stream reassembly — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-80629 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: octeontx2-af: npc: Fix size of entry2cntr_map — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2019-19814 | linux-libc-dev | 7.0.0-31.31 | kernel: out-of-bounds write in __remove_dirty_segment in fs/f2fs/segment.c — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2019-19378 | linux-libc-dev | 7.0.0-31.31 | kernel: out-of-bounds write in index_rbio_pages in fs/btrfs/raid56.c — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2019-15213 | linux-libc-dev | 7.0.0-31.31 | kernel: use-after-free caused by malicious USB device in drivers/media/usb/dvb-usb/dvb-usb-init.c — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2019-14899 | linux-libc-dev | 7.0.0-31.31 | VPN: an attacker can inject data into the TCP stream which allows a hijack of active connections inside the VPN tunnel — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2018-12931 | linux-libc-dev | 7.0.0-31.31 | kernel: stack-based out-of-bounds write in ntfs_attr_find in the ntfs.ko — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2018-12930 | linux-libc-dev | 7.0.0-31.31 | kernel: stack-based out-of-bounds write in ntfs_end_buffer_async_read in the ntfs.ko — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2018-12929 | linux-libc-dev | 7.0.0-31.31 | kernel: use-after-free in ntfs_read_locked_inode in the ntfs.ko — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2018-12928 | linux-libc-dev | 7.0.0-31.31 | kernel: NULL pointer dereference in hfs_ext_read_extent in hfs.ko — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2018-1121 | linux-libc-dev | 7.0.0-31.31 | procps: process hiding through race condition enumerating /proc — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2017-13693 | linux-libc-dev | 7.0.0-31.31 | kernel: ACPI operand cache leak in dsutils.c — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2017-13165 | linux-libc-dev | 7.0.0-31.31 | ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2017-0537 | linux-libc-dev | 7.0.0-31.31 | ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-40228 | libudev1 | 259.5-0ubuntu3.4 | systemd: systemd-journald: Unintended output to user terminals via logger command — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-40228 | libsystemd0 | 259.5-0ubuntu3.4 | systemd: systemd-journald: Unintended output to user terminals via logger command — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-84784 | libssl3t64 | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | openssl: OpenSSL: Denial of Service via unbounded QUIC connection identifier backlog — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-77696 | libssl3t64 | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | openssl: OpenSSL: Private key recovery via SM2 timing side-channel — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2024-56568 | linux-libc-dev | 7.0.0-31.31 | kernel: iommu/arm-smmu: Defer probe of clients after smmu device bound — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2024-35995 | linux-libc-dev | 7.0.0-31.31 | kernel: ACPI: CPPC: Use access_width over bit_width for system memory accesses — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2024-0564 | linux-libc-dev | 7.0.0-31.31 | kernel: max page sharing of Kernel Samepage Merging (KSM) may cause memory deduplication — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2023-6238 | linux-libc-dev | 7.0.0-31.31 | kernel: nvme: memory corruption via unprivileged user passthrough — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2023-52879 | linux-libc-dev | 7.0.0-31.31 | kernel: tracing: Have trace_event_file have ref counters — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2023-33053 | linux-libc-dev | 7.0.0-31.31 | ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2023-20585 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel-core: hw: amd: AMD-SN-3016: IOMMU Write Buffer Vulnerability — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2022-48929 | linux-libc-dev | 7.0.0-31.31 | kernel: bpf: Fix crash due to out of bounds access into reg2btf_ids. — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2022-48846 | linux-libc-dev | 7.0.0-31.31 | kernel: block: release rq qos structures for queue without disk — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2022-45885 | linux-libc-dev | 7.0.0-31.31 | kernel: use-after-free due to race condition occurring in dvb_frontend.c — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2022-44034 | linux-libc-dev | 7.0.0-31.31 | Kernel: A use-after-free due to race between scr24x_open() and scr24x_remove() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2022-41848 | linux-libc-dev | 7.0.0-31.31 | kernel: Race condition between mgslpc_ioctl and mgslpc_detach — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2021-26934 | linux-libc-dev | 7.0.0-31.31 | An issue was discovered in the Linux kernel 4.18 through 5.10.16, as u ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2020-35501 | linux-libc-dev | 7.0.0-31.31 | kernel: audit not logging access to syscall open_by_handle_at for users with CAP_DAC_READ_SEARCH capability — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2020-14304 | linux-libc-dev | 7.0.0-31.31 | kernel: ethtool when reading eeprom of device could lead to memory leak — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2019-20426 | linux-libc-dev | 7.0.0-31.31 | ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-54875 | libssl-dev | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | openssl: openssl: information disclosure via non-constant-time SM2 scalar multiplication on ARM64 and RISC-V — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-54873 | libssl-dev | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.7 | openssl: openssl: Denial of Service via excessive QUIC packet buffer retention — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-54872 | libssl-dev | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | openssl: OpenSSL: Private key recovery via timing side-channel in generic elliptic curve operations — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-42772 | libssl-dev | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.7 | openssl: openssl: Denial of Service via inefficient QUIC stream reassembly — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-35191 | libssl-dev | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | openssl: openssl: Traffic amplification Denial of Service via QUIC packet over-accounting — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-35189 | libssl-dev | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | openssl: openssl: Denial of Service via excessive memory allocation in CRL distribution point processing — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2017-13716 | libsframe3 | 2.46-3ubuntu2 | binutils: Memory leak with the C++ symbol demangler routine in libiberty — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2025-61594 | libruby3.3 | 3.3.8-2ubuntu3.1 | uri: URI module: Credential exposure via URI + operator — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2025-58767 | libruby3.3 | 3.3.8-2ubuntu3.1 | rexml: REXML denial of service — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2017-13716 | libgprofng0 | 2.46-3ubuntu2 | binutils: Memory leak with the C++ symbol demangler routine in libiberty — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2017-13716 | libctf0 | 2.46-3ubuntu2 | binutils: Memory leak with the C++ symbol demangler routine in libiberty — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2017-13716 | libctf-nobfd0 | 2.46-3ubuntu2 | binutils: Memory leak with the C++ symbol demangler routine in libiberty — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2017-13716 | libbinutils | 2.46-3ubuntu2 | binutils: Memory leak with the C++ symbol demangler routine in libiberty — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2017-13716 | binutils-x86-64-linux-gnu | 2.46-3ubuntu2 | binutils: Memory leak with the C++ symbol demangler routine in libiberty — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2017-13716 | binutils-common | 2.46-3ubuntu2 | binutils: Memory leak with the C++ symbol demangler routine in libiberty — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2017-13716 | binutils | 2.46-3ubuntu2 | binutils: Memory leak with the C++ symbol demangler routine in libiberty — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-75806 | libssl3t64 | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | openssl: OpenSSL: Denial of Service via undersized DTLS record — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-75805 | libssl3t64 | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | openssl: openssl: Denial of Service via crafted CMP certificate revocation response — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-75804 | libssl3t64 | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | openssl: OpenSSL: Denial of Service via unenforced QUIC connection flow control — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-72897 | libssl3t64 | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | openssl: openssl: Denial of Service via out-of-bounds write during TLS context switch — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-54875 | libssl3t64 | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | openssl: openssl: information disclosure via non-constant-time SM2 scalar multiplication on ARM64 and RISC-V — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-54873 | libssl3t64 | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.7 | openssl: openssl: Denial of Service via excessive QUIC packet buffer retention — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-54872 | libssl3t64 | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | openssl: OpenSSL: Private key recovery via timing side-channel in generic elliptic curve operations — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-42772 | libssl3t64 | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.7 | openssl: openssl: Denial of Service via inefficient QUIC stream reassembly — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-35191 | libssl3t64 | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | openssl: openssl: Traffic amplification Denial of Service via QUIC packet over-accounting — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-35189 | libssl3t64 | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | openssl: openssl: Denial of Service via excessive memory allocation in CRL distribution point processing — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-84784 | libssl-dev | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | openssl: OpenSSL: Denial of Service via unbounded QUIC connection identifier backlog — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-77696 | libssl-dev | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | openssl: OpenSSL: Private key recovery via SM2 timing side-channel — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-75806 | libssl-dev | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | openssl: OpenSSL: Denial of Service via undersized DTLS record — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-75805 | libssl-dev | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | openssl: openssl: Denial of Service via crafted CMP certificate revocation response — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-75804 | libssl-dev | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | openssl: OpenSSL: Denial of Service via unenforced QUIC connection flow control — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-72897 | libssl-dev | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | openssl: openssl: Denial of Service via out-of-bounds write during TLS context switch — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-74403 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: crypto: ccp - Check for page allocation failure correctly in TIO — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-74401 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: dlm: fix add msg handle in send_queue ordered — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-74397 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: IB/mlx5: Fix transport-domain rollback and initialize lb mutex earlier — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-74383 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: nvme-pci: fix out-of-bounds access in nvme_setup_descriptor_pools — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-74371 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: bpf: fix BPF_PROG_QUERY OOB write and cgroup backward compat — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-74361 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: nvme: fix FDP fdpcidx bounds check — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-74313 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: vduse: hold vduse_lock across IDR lookup in open path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-74312 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: vhost/vdpa: validate virtqueue index in mmap and fault paths — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-74262 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: kcm: use WRITE_ONCE() when changing lower socket callbacks — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-72482 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: gpib: fix double decrement of descriptor_busy in command_ioctl() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-72476 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: dmaengine: Fix possible use after free — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-72454 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: i3c: mipi-i3c-hci: Fix race in i3c_hci_addr_to_dev() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-72410 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: octeontx2-af: Validate NIX maximum LFs correctly — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-72352 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: HID: bpf: Fix hid_bpf_get_data() range check — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-72342 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net/mlx5e: Fix HV VHCA stats agent registration race — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-72329 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-34.34 | kernel: net/liquidio: drop cached VF pci_dev LUT — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-80628 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ALSA: seq: oss: Serialize readq reset state with q->lock — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-80627 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: MIPS: mm: Fix out-of-bounds write in maar_res_walk() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-80625 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: RDMA/hns: Fix memory leak of bonding resources — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-80624 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: mfd: cs42l43: Sanity check firmware size — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-80623 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: coresight: ete: Always save state on power down — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-80622 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: char: tlclk: fix use-after-free in tlclk_cleanup() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-74568 | linux-libc-dev | 7.0.0-31.31 | kernel: KVM: arm64: vgic: Fix race between LPI release and re-registration — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-74554 | linux-libc-dev | 7.0.0-31.31 | kernel: wifi: ath12k: fix out-of-bounds clear_bit in ath12k_mac_dp_peer_cleanup() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-74527 | linux-libc-dev | 7.0.0-31.31 | kernel: octeontx2-af: Block VFs from clobbering special CGX PKIND state — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-74519 | linux-libc-dev | 7.0.0-31.31 | kernel: pinctrl: devicetree: don't free uninitialized dev_name on error path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-74512 | linux-libc-dev | 7.0.0-31.31 | kernel: audit: fix potential use-after-free in audit_del_rule() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-74490 | linux-libc-dev | 7.0.0-31.31 | kernel: tipc: avoid use-after-free in poll trace queue dumps — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-74481 | linux-libc-dev | 7.0.0-31.31 | kernel: mm/page_reporting: use system_freezable_wq to fix UAF during suspend — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-74450 | linux-libc-dev | 7.0.0-31.31 | kernel: drm/amd/pm: fix pptable use-after-free — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-74412 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: wifi: rtw88: fix wrong pci_get_drvdata type in AER handlers — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-74405 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: OPP: Fix race between OPP addition and lookup — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-68370 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: usb: gadget: dummy_hcd: prevent fifo_req reuse during giveback — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-68353 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-68330 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net: airoha: Fix DMA direction for NPU mailbox buffer — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-68314 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net: mctp i3c: clean up notifier and buses if driver register fails — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-68305 | linux-libc-dev | 7.0.0-31.31 | kernel: drm/xe/vf: Add drm_dev guards when detaching CCS read/write buffers — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-68240 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/gpusvm: publish dpagemap early to avoid device mapping leak on error — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-68156 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: libceph: refresh auth->authorizer_buf{,_len} after authorizer update — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-68153 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: libceph: remove debugfs files before client teardown — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-68142 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: geneve: require CAP_NET_ADMIN in the device netns for changelink — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-68124 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: mctp: serial: handle zero-length frames to prevent rx buffer overflow — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-68116 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: vxlan: mdb: Fix source list corruption on a failed replace — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-68107 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/amdgpu/vcn4: avoid rereading IB param length — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-68104 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: drm/amdgpu: invoke pm_genpd_remove() before freeing genpd — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-64583 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | In the Linux kernel, the following vulnerability has been resolved: u ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-64574 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: wifi: mac80211: tear down new links on vif update error path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2025-22077 | linux-libc-dev | 7.0.0-31.31 | kernel: smb: client: Fix netns refcount imbalance causing leaks and use-after-free — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) | |
| LOW | CVE-2026-72314 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: regulator: core: regulator_lock_two() should test for EDEADLK not EDEADLOCK — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-72312 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: octeontx2-af: fix VF bringup affecting PF promiscuous state — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-72310 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: smb: client: fix overflow in passthrough ioctl bounds check — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-72303 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: ASoC: SOF: ipc4-control: Validate notification payload size — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-72286 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: KVM: SEV: Do not allow intra-host migration/mirroring of SNP VMs — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-72154 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: openrisc: Fix jump_label smp syncing — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-72134 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: spi: imx: reconfigure for PIO when DMA cannot be started — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-72108 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: dm thin metadata: fix metadata snapshot consistency on commit failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-72100 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: dm-integrity: fix a bug if the bio is out of limits — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-72090 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: accel/amdxdna: Use caller client for debug BO sync — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-72071 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: tracing/user_events: Fix use-after-free in user_event_mm_dup() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-72054 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net: ip_vti: require CAP_NET_ADMIN in the device netns for changelink — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-72051 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: net: ip6_tunnel: require CAP_NET_ADMIN in the device netns for changelink — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-68466 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: mtd: rawnand: lpc32xx_slc: fail DMA transfer on completion timeout — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-68454 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: KVM: s390: pci: Fix handling of AIF enable without AISB — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| LOW | CVE-2026-68432 | linux-libc-dev | 7.0.0-31.31 | 7.0.0-38.38 | kernel: vxlan: require CAP_NET_ADMIN in the device netns for changelink — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04) |
| UNKNOWN | CVE-2026-97032 | stdlib | v1.26.5 | 1.26.9, 1.27.2 | HTTP/2 server crash due to HPACK encoder race in net/http — usr/bin/pebble |
| UNKNOWN | CVE-2026-97031 | stdlib | v1.26.5 | 1.26.9, 1.27.2 | Reject malformed ECH outer extension references in crypto/tls — usr/bin/pebble |
| UNKNOWN | CVE-2026-97030 | stdlib | v1.26.5 | 1.26.9, 1.27.2 | Recognize yield as regexp preceder keyword in html/template — usr/bin/pebble |
| UNKNOWN | CVE-2026-94448 | stdlib | v1.26.5 | 1.26.9, 1.27.2 | Reset context tracking on consecutive template expressions in html/template — usr/bin/pebble |
| UNKNOWN | CVE-2026-94440 | stdlib | v1.26.5 | 1.26.9, 1.27.2 | Memory limit bypass when parsing MIME headers in net/textproto, mime/multipart — usr/bin/pebble |
| UNKNOWN | CVE-2026-94439 | stdlib | v1.26.5 | 1.26.9, 1.27.2 | HTTP/1 server connection desynchronization after 2xx CONNECT response in net/http — usr/bin/pebble |
| UNKNOWN | CVE-2026-78669 | stdlib | v1.26.5 | 1.26.9, 1.27.2 | Excessive CPU consumption from repeated initial window changes in net/http — usr/bin/pebble |
| UNKNOWN | CVE-2026-78667 | stdlib | v1.26.5 | 1.26.9, 1.27.2 | Lack of limit on size of parsed Range headers in net/http — usr/bin/pebble |
| UNKNOWN | CVE-2026-78663 | stdlib | v1.26.5 | 1.26.9, 1.27.2 | Double flow control refund on HTTP/2 server streams in net/http — usr/bin/pebble |
| UNKNOWN | CVE-2026-78660 | stdlib | v1.26.5 | 1.26.9, 1.27.2 | HTTP/2 transport accepts malformed framing-related headers in net/http — usr/bin/pebble |
| UNKNOWN | CVE-2026-78659 | stdlib | v1.26.5 | 1.26.9, 1.27.2 | HTTP/2 server memory exhaustion due to Trailer headers in net/http — usr/bin/pebble |
| UNKNOWN | CVE-2026-56866 | stdlib | v1.26.5 | 1.26.9, 1.27.2 | HTTP/1 client connection desynchronization after CONNECT rejection in net/http — usr/bin/pebble |
| UNKNOWN | CVE-2026-56857 | stdlib | v1.26.5 | 1.26.9, 1.27.2 | Root.Mkdir(All) can follow junctions out of the root on Windows in os — usr/bin/pebble |
Grype
HIGH 14
MEDIUM 424
LOW 141
UNKNOWN 6
| Severity | ID | Package | Installed | Fixed | Title / target |
|---|---|---|---|---|---|
| HIGH | GHSA-p6pp-m3f8-5c89 | jackson-core | 2.21.6 | 2.21.7 | jackson-core: ReDoS: quadratic backtracking in NumberInput.PATTERN_FLOAT via looksLikeValidNumber() — /opt/puppetlabs/server/apps/puppetserver/puppet-server-release.jar |
| HIGH | CVE-2026-84782 | openssl-provider-legacy | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| HIGH | GO-2026-6089 | stdlib | go1.26.5 | 1.25.13, 1.26.6, 1.27.0-rc.3 | When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this. — /usr/bin/pebble |
| HIGH | GO-2026-5972 | stdlib | go1.26.5 | 1.25.13, 1.26.6, 1.27.0-rc.3 | Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures. — /usr/bin/pebble |
| HIGH | GO-2026-6090 | stdlib | go1.26.5 | 1.25.13, 1.26.6, 1.27.0-rc.3 | Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely. — /usr/bin/pebble |
| HIGH | CVE-2026-84782 | openssl | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| HIGH | GHSA-7hhh-6rmp-j9qf | jackson-core | 2.21.6 | 2.21.7 | jackson-core: UTF8DataInputJsonParser._reportInvalidToken() missing maxErrorTokenLength limit -> unbounded StringBuilder growth (DoS) — /opt/puppetlabs/server/apps/puppetserver/puppet-server-release.jar |
| HIGH | GO-2026-5026 | stdlib | go1.26.5 | 1.25.13, 1.26.6, 1.27.0-rc.3 | The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com". — /usr/bin/pebble |
| HIGH | GHSA-cxp5-3px4-pw24 | jackson-databind | 2.21.6 | 2.21.7 | jackson-databind quadratic forward-reference completion — /opt/puppetlabs/server/apps/puppetserver/puppet-server-release.jar |
| HIGH | GHSA-wv8q-qhhj-9h54 | jackson-databind | 2.21.6 | 2.21.7 | jackson-databind retains every unknown raw type ID — /opt/puppetlabs/server/apps/puppetserver/puppet-server-release.jar |
| HIGH | CVE-2026-84782 | libssl3t64 | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| HIGH | CVE-2026-84782 | libssl-dev | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| HIGH | GHSA-q339-8rmv-2mhv | erb | 4.0.3 | 4.0.3.1 | ERB has an @_init deserialization guard bypass via def_module / def_method / def_class — /usr/lib/ruby/gems/3.3.0/specifications/default/erb-4.0.3.gemspec |
| HIGH | GHSA-jr6h-r7vg-f9mc | ini4j | 0.5.4 | org.ini4j allows attackers to cause a Denial of Service (DoS) — /opt/puppetlabs/server/apps/puppetserver/puppet-server-release.jar | |
| MEDIUM | CVE-2026-90829 | binutils-common | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-90829 | binutils-x86-64-linux-gnu | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-90829 | libbinutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-90829 | libctf-nobfd0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-91779 | libctf-nobfd0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-90829 | binutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-56407 | libexpat1 | 2.7.4-1 | 2.7.4-1ubuntu0.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-56406 | libexpat1 | 2.7.4-1 | 2.7.4-1ubuntu0.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-32777 | libexpat1 | 2.7.4-1 | 2.7.4-1ubuntu0.1 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-91782 | libsframe3 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-91781 | libsframe3 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-90802 | libsframe3 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-50219 | libexpat1 | 2.7.4-1 | 2.7.4-1ubuntu0.1 | /var/lib/dpkg/status |
| MEDIUM | CVE-2025-64031 | libarchive13t64 | 3.8.5-1ubuntu2.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-56412 | libexpat1 | 2.7.4-1 | 2.7.4-1ubuntu0.1 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-56131 | libexpat1 | 2.7.4-1 | 2.7.4-1ubuntu0.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-91781 | binutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-91782 | binutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-91781 | binutils-common | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-91782 | binutils-common | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-91781 | binutils-x86-64-linux-gnu | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-91782 | binutils-x86-64-linux-gnu | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-91781 | libbinutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-91782 | libbinutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-91781 | libctf-nobfd0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-91782 | libctf-nobfd0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-91781 | libctf0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-91782 | libctf0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-91781 | libgprofng0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-91782 | libgprofng0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-91779 | libctf0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-91779 | libgprofng0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-91779 | libsframe3 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-90831 | binutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-90831 | binutils-common | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-90831 | binutils-x86-64-linux-gnu | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-90831 | libbinutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-90831 | libctf-nobfd0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-90831 | libctf0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-90831 | libgprofng0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-90831 | libsframe3 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-4647 | binutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-4647 | binutils-common | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-4647 | binutils-x86-64-linux-gnu | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-4647 | libbinutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-4647 | libctf-nobfd0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-90829 | libctf0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-90829 | libgprofng0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-90829 | libsframe3 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35363 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-56391 | coreutils | 9.5-1ubuntu2+0.0.0~ubuntu25 | 9.7-3ubuntu2.1 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-91780 | binutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-91780 | binutils-common | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-91780 | binutils-x86-64-linux-gnu | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-91780 | libbinutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-91780 | libctf-nobfd0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-91780 | libctf0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-91780 | libgprofng0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-91780 | libsframe3 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-91779 | binutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-91779 | binutils-common | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-91779 | binutils-x86-64-linux-gnu | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-91779 | libbinutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-90802 | libgprofng0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-3441 | libctf0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-3442 | libctf-nobfd0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-3441 | libctf-nobfd0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-3442 | libbinutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-3441 | libbinutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-3442 | binutils-x86-64-linux-gnu | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-3441 | binutils-x86-64-linux-gnu | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-3442 | binutils-common | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-3441 | binutils-common | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-3442 | binutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-3441 | binutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-72522 | libexpat1 | 2.7.4-1 | 2.7.4-1ubuntu0.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-39113 | libsqlite3-0 | 3.46.1-9ubuntu0.2 | 3.46.1-9ubuntu0.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-86143 | libxml2-16 | 2.15.2+dfsg-0.1ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-86137 | libxml2-16 | 2.15.2+dfsg-0.1ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-6846 | libsframe3 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-6846 | libgprofng0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-6846 | libctf0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-6846 | libctf-nobfd0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-6846 | libbinutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-6846 | binutils-x86-64-linux-gnu | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-6846 | binutils-common | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-6846 | binutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-90804 | libsframe3 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-90804 | libgprofng0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-90804 | libctf0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-90804 | libctf-nobfd0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-90804 | libbinutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-90804 | binutils-x86-64-linux-gnu | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-90804 | binutils-common | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-90804 | binutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-90802 | libctf0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-90802 | libctf-nobfd0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-90802 | libbinutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-90802 | binutils-x86-64-linux-gnu | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-90802 | binutils-common | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-90802 | binutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-47242 | ruby3.3-dev | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-47242 | ruby3.3 | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-47242 | libruby3.3 | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-78408 | util-linux | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-78408 | mount | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-78408 | login | 1:4.16.0-2+really2.41.3-3ubuntu2.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-78408 | libuuid1 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-78408 | libsmartcols1 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-78408 | libmount1 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-78408 | libblkid1 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-78408 | bsdutils | 1:2.41.3-3ubuntu2.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-86144 | libxml2-16 | 2.15.2+dfsg-0.1ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-90828 | libsframe3 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-90828 | libgprofng0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-90828 | libctf0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-90828 | libctf-nobfd0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-90828 | libbinutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-90828 | binutils-x86-64-linux-gnu | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-90828 | binutils-common | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-90828 | binutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-3442 | libsframe3 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-3441 | libsframe3 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-3442 | libgprofng0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-3441 | libgprofng0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-3442 | libctf0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-77214 | libexpat1 | 2.7.4-1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-95818 | libc6 | 2.43-2ubuntu2.4 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-95818 | libc-gconv-modules-extra | 2.43-2ubuntu2.4 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-95818 | libc-dev-bin | 2.43-2ubuntu2.4 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-95818 | libc-bin | 2.43-2ubuntu2.4 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-56404 | libexpat1 | 2.7.4-1 | 2.7.4-1ubuntu0.1 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-35367 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-102473 | dash | 0.5.12-12ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-86138 | libxml2-16 | 2.15.2+dfsg-0.1ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35344 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35350 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35348 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35373 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35371 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-93658 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35351 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-18508 | tar | 1.35+dfsg-4ubuntu0.4 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35341 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-18374 | libc6-dev | 2.43-2ubuntu2.4 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-18374 | libc6 | 2.43-2ubuntu2.4 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-18374 | libc-gconv-modules-extra | 2.43-2ubuntu2.4 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-18374 | libc-dev-bin | 2.43-2ubuntu2.4 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-18374 | libc-bin | 2.43-2ubuntu2.4 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-102474 | dash | 0.5.12-12ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-6845 | libsframe3 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-6845 | libgprofng0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-6845 | libctf0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-6845 | libctf-nobfd0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-6845 | libbinutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-6845 | binutils-x86-64-linux-gnu | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-6845 | binutils-common | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-6845 | binutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-16517 | libarchive13t64 | 3.8.5-1ubuntu2.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-18477 | tar | 1.35+dfsg-4ubuntu0.4 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35374 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35354 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35357 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35364 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35345 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35360 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-56132 | libexpat1 | 2.7.4-1 | 2.7.4-1ubuntu0.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-35359 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-76957 | libexpat1 | 2.7.4-1 | 2.7.4-1ubuntu0.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-54370 | libacl1 | 2.3.2-2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-56409 | libexpat1 | 2.7.4-1 | 2.7.4-1ubuntu0.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-35352 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-86805 | libc6-dev | 2.43-2ubuntu2.4 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-86805 | libc6 | 2.43-2ubuntu2.4 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-86805 | libc-gconv-modules-extra | 2.43-2ubuntu2.4 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-86805 | libc-dev-bin | 2.43-2ubuntu2.4 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-86805 | libc-bin | 2.43-2ubuntu2.4 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-56405 | libexpat1 | 2.7.4-1 | 2.7.4-1ubuntu0.1 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-56408 | libexpat1 | 2.7.4-1 | 2.7.4-1ubuntu0.1 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-35377 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-89161 | libpcre2-8-0 | 10.46-1build1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35370 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2025-15649 | perl-modules-5.40 | 5.40.1-7ubuntu0.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2025-15649 | perl-base | 5.40.1-7ubuntu0.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2025-15649 | perl | 5.40.1-7ubuntu0.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2025-15649 | libperl5.40 | 5.40.1-7ubuntu0.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-56411 | libexpat1 | 2.7.4-1 | 2.7.4-1ubuntu0.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-56410 | libexpat1 | 2.7.4-1 | 2.7.4-1ubuntu0.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-95818 | libc6-dev | 2.43-2ubuntu2.4 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-6844 | libsframe3 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-19548 | binutils-x86-64-linux-gnu | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-19548 | binutils-common | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-19548 | binutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-78410 | util-linux | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-78410 | mount | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-78410 | login | 1:4.16.0-2+really2.41.3-3ubuntu2.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-78410 | libuuid1 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-78410 | libsmartcols1 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-78410 | libmount1 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-78410 | libblkid1 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-78410 | bsdutils | 1:2.41.3-3ubuntu2.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-89162 | libpcre2-8-0 | 10.46-1build1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-86142 | libxml2-16 | 2.15.2+dfsg-0.1ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-32778 | libexpat1 | 2.7.4-1 | 2.7.4-1ubuntu0.1 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-86140 | libxml2-16 | 2.15.2+dfsg-0.1ubuntu0.1 | 2.15.2+dfsg-0.1ubuntu0.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-32776 | libexpat1 | 2.7.4-1 | 2.7.4-1ubuntu0.1 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-90830 | libsframe3 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-90830 | libgprofng0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-90830 | libctf0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-90830 | libctf-nobfd0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-90830 | libbinutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-90830 | binutils-x86-64-linux-gnu | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-90830 | binutils-common | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-90830 | binutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-86141 | libxml2-16 | 2.15.2+dfsg-0.1ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-86139 | libxml2-16 | 2.15.2+dfsg-0.1ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-76781 | libxml2-16 | 2.15.2+dfsg-0.1ubuntu0.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-56403 | libexpat1 | 2.7.4-1 | 2.7.4-1ubuntu0.1 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-4647 | libsframe3 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-4647 | libgprofng0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-4647 | libctf0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-6844 | libgprofng0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-6844 | libctf0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-6844 | libctf-nobfd0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-6844 | libbinutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-6844 | binutils-x86-64-linux-gnu | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-6844 | binutils-common | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-6844 | binutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-35368 | rust-coreutils | 0.8.0-0ubuntu3 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-15003 | libsframe3 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-15003 | libgprofng0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-15003 | libctf0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-15003 | libctf-nobfd0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-15003 | libbinutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-15003 | binutils-x86-64-linux-gnu | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-15003 | binutils-common | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-15003 | binutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-18938 | libp11-kit0 | 0.26.2-2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-54369 | libacl1 | 2.3.2-2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-78409 | util-linux | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-78409 | mount | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-78409 | login | 1:4.16.0-2+really2.41.3-3ubuntu2.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-78409 | libuuid1 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-78409 | libsmartcols1 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-78409 | libmount1 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-78409 | libblkid1 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-78409 | bsdutils | 1:2.41.3-3ubuntu2.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-19548 | libsframe3 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-19548 | libgprofng0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-19548 | libctf0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-19548 | libctf-nobfd0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-19548 | libbinutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-61308 | openjdk-21-jre-headless | 21.0.12+8-1~26.04 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-48962 | perl-modules-5.40 | 5.40.1-7ubuntu0.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-46727 | libruby3.3 | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-46727 | ruby3.3 | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-8674 | libc6-dev | 2.43-2ubuntu2.4 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-8674 | libc6 | 2.43-2ubuntu2.4 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-8674 | libc-gconv-modules-extra | 2.43-2ubuntu2.4 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-8674 | libc-dev-bin | 2.43-2ubuntu2.4 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-8674 | libc-bin | 2.43-2ubuntu2.4 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-102633 | libexpat1 | 2.7.4-1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-76641 | libexpat1 | 2.7.4-1 | 2.7.4-1ubuntu0.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-75466 | libjpeg-turbo8 | 2.1.5-4ubuntu4 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-57433 | perl-modules-5.40 | 5.40.1-7ubuntu0.2 | 5.40.1-7ubuntu0.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-57433 | perl-base | 5.40.1-7ubuntu0.2 | 5.40.1-7ubuntu0.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-57433 | perl | 5.40.1-7ubuntu0.2 | 5.40.1-7ubuntu0.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-57433 | libperl5.40 | 5.40.1-7ubuntu0.2 | 5.40.1-7ubuntu0.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-95619 | gcc-x86-64-linux-gnu | 4:15.2.0-5ubuntu1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-95619 | gcc | 4:15.2.0-5ubuntu1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-95619 | cpp-x86-64-linux-gnu | 4:15.2.0-5ubuntu1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-95619 | cpp | 4:15.2.0-5ubuntu1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-46727 | ruby3.3-dev | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2025-10990 | libruby3.3 | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2025-10990 | ruby3.3 | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2025-10990 | ruby3.3-dev | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-47241 | ruby3.3-dev | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-57432 | perl-modules-5.40 | 5.40.1-7ubuntu0.2 | 5.40.1-7ubuntu0.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-60589 | openjdk-21-jre-headless | 21.0.12+8-1~26.04 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-89092 | libc6-dev | 2.43-2ubuntu2.4 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-80229 | libcurl3t64-gnutls | 8.18.0-1ubuntu2.5 | 8.18.0-1ubuntu2.7 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-89092 | libc6 | 2.43-2ubuntu2.4 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-89092 | libc-gconv-modules-extra | 2.43-2ubuntu2.4 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-89092 | libc-dev-bin | 2.43-2ubuntu2.4 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-89092 | libc-bin | 2.43-2ubuntu2.4 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-89160 | libpcre2-8-0 | 10.46-1build1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-83368 | openjdk-21-jre-headless | 21.0.12+8-1~26.04 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-80229 | libcurl4t64 | 8.18.0-1ubuntu2.5 | 8.18.0-1ubuntu2.7 | /var/lib/dpkg/status |
| MEDIUM | GHSA-j3g3-5qv5-52mj | net-imap | 0.4.19 | 0.4.20 | net-imap rubygem vulnerable to possible DoS by memory exhaustion — /usr/lib/ruby/gems/3.3.0/specifications/net-imap-0.4.19.gemspec |
| MEDIUM | CVE-2024-52005 | git | 1:2.53.0-1ubuntu1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2024-52005 | git-man | 1:2.53.0-1ubuntu1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-70907 | openjdk-21-jre-headless | 21.0.12+8-1~26.04 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-89157 | libpcre2-8-0 | 10.46-1build1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-97399 | libc6-dev | 2.43-2ubuntu2.4 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-97399 | libc6 | 2.43-2ubuntu2.4 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-97399 | libc-gconv-modules-extra | 2.43-2ubuntu2.4 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-97399 | libc-dev-bin | 2.43-2ubuntu2.4 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-97399 | libc-bin | 2.43-2ubuntu2.4 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-48962 | libperl5.40 | 5.40.1-7ubuntu0.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-48962 | perl | 5.40.1-7ubuntu0.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-48962 | perl-base | 5.40.1-7ubuntu0.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-89156 | libpcre2-8-0 | 10.46-1build1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-47241 | ruby3.3 | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-47241 | libruby3.3 | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-47058 | openjdk-21-jre-headless | 21.0.12+8-1~26.04 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-86145 | libpcre2-8-0 | 10.46-1build1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-41080 | libexpat1 | 2.7.4-1 | 2.7.4-1ubuntu0.1 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-93990 | libexpat1 | 2.7.4-1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-48961 | perl-modules-5.40 | 5.40.1-7ubuntu0.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-48961 | perl-base | 5.40.1-7ubuntu0.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-48961 | perl | 5.40.1-7ubuntu0.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-48961 | libperl5.40 | 5.40.1-7ubuntu0.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-83408 | openjdk-21-jre-headless | 21.0.12+8-1~26.04 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-13221 | perl-modules-5.40 | 5.40.1-7ubuntu0.2 | 5.40.1-7ubuntu0.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-13221 | perl-base | 5.40.1-7ubuntu0.2 | 5.40.1-7ubuntu0.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-13221 | perl | 5.40.1-7ubuntu0.2 | 5.40.1-7ubuntu0.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-13221 | libperl5.40 | 5.40.1-7ubuntu0.2 | 5.40.1-7ubuntu0.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-74860 | libxml2-16 | 2.15.2+dfsg-0.1ubuntu0.1 | 2.15.2+dfsg-0.1ubuntu0.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-63435 | ruby3.3-dev | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-63435 | ruby3.3 | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-63435 | libruby3.3 | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-9538 | perl-modules-5.40 | 5.40.1-7ubuntu0.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-9538 | perl-base | 5.40.1-7ubuntu0.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-9538 | perl | 5.40.1-7ubuntu0.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-83357 | openjdk-21-jre-headless | 21.0.12+8-1~26.04 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-9538 | libperl5.40 | 5.40.1-7ubuntu0.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-45186 | libexpat1 | 2.7.4-1 | 2.7.4-1ubuntu0.1 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-13608 | curl | 8.18.0-1ubuntu2.5 | 8.18.0-1ubuntu2.7 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-13608 | libcurl3t64-gnutls | 8.18.0-1ubuntu2.5 | 8.18.0-1ubuntu2.7 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-13608 | libcurl4t64 | 8.18.0-1ubuntu2.5 | 8.18.0-1ubuntu2.7 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-80255 | curl | 8.18.0-1ubuntu2.5 | 8.18.0-1ubuntu2.7 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-80255 | libcurl3t64-gnutls | 8.18.0-1ubuntu2.5 | 8.18.0-1ubuntu2.7 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-80255 | libcurl4t64 | 8.18.0-1ubuntu2.5 | 8.18.0-1ubuntu2.7 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-42497 | libperl5.40 | 5.40.1-7ubuntu0.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-42497 | perl | 5.40.1-7ubuntu0.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-42497 | perl-base | 5.40.1-7ubuntu0.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-42497 | perl-modules-5.40 | 5.40.1-7ubuntu0.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-47057 | openjdk-21-jre-headless | 21.0.12+8-1~26.04 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-80230 | libcurl4t64 | 8.18.0-1ubuntu2.5 | 8.18.0-1ubuntu2.7 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-80230 | libcurl3t64-gnutls | 8.18.0-1ubuntu2.5 | 8.18.0-1ubuntu2.7 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-80230 | curl | 8.18.0-1ubuntu2.5 | 8.18.0-1ubuntu2.7 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-82209 | libcurl4t64 | 8.18.0-1ubuntu2.5 | 8.18.0-1ubuntu2.7 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-82209 | libcurl3t64-gnutls | 8.18.0-1ubuntu2.5 | 8.18.0-1ubuntu2.7 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-82209 | curl | 8.18.0-1ubuntu2.5 | 8.18.0-1ubuntu2.7 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-12087 | perl-modules-5.40 | 5.40.1-7ubuntu0.2 | 5.40.1-7ubuntu0.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-12087 | perl-base | 5.40.1-7ubuntu0.2 | 5.40.1-7ubuntu0.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-12087 | perl | 5.40.1-7ubuntu0.2 | 5.40.1-7ubuntu0.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-12087 | libperl5.40 | 5.40.1-7ubuntu0.2 | 5.40.1-7ubuntu0.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-54696 | ruby3.3-dev | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-54696 | ruby3.3 | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-54696 | libruby3.3 | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-57432 | perl-base | 5.40.1-7ubuntu0.2 | 5.40.1-7ubuntu0.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-57432 | perl | 5.40.1-7ubuntu0.2 | 5.40.1-7ubuntu0.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-57432 | libperl5.40 | 5.40.1-7ubuntu0.2 | 5.40.1-7ubuntu0.3 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-41316 | libruby3.3 | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-103111 | libpcre2-8-0 | 10.46-1build1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-76642 | util-linux | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-76642 | mount | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-76642 | login | 1:4.16.0-2+really2.41.3-3ubuntu2.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-76642 | libuuid1 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-76642 | libsmartcols1 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-76642 | libmount1 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-76642 | libblkid1 | 2.41.3-3ubuntu2.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-76642 | bsdutils | 1:2.41.3-3ubuntu2.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-41316 | ruby3.3 | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-41316 | ruby3.3-dev | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-42258 | libruby3.3 | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-42258 | ruby3.3 | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-42258 | ruby3.3-dev | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| MEDIUM | GHSA-g857-hhfv-j68w | zlib | 3.1.1 | 3.1.2 | Buffer Overflow in Zlib::GzipReader ungetc via large input leads to memory corruption — /usr/lib/ruby/gems/3.3.0/specifications/default/zlib-3.1.1.gemspec |
| MEDIUM | GHSA-8p34-64r3-mwg8 | net-imap | 0.4.19 | 0.5.15 | Net::IMAP: Command Injection via non-synchronizing literal in "raw" argument — /usr/lib/ruby/gems/3.3.0/specifications/net-imap-0.4.19.gemspec |
| MEDIUM | CVE-2026-5917 | libgit2-1.9 | 1.9.1+ds-1ubuntu1.1 | 1.9.1+ds-1ubuntu1.2 | /var/lib/dpkg/status |
| MEDIUM | GHSA-46q3-7gv7-qmgg | net-imap | 0.4.19 | 0.5.15 | Net::IMAP: Command Injection via ID command argument — /usr/lib/ruby/gems/3.3.0/specifications/net-imap-0.4.19.gemspec |
| MEDIUM | CVE-2026-90803 | libsframe3 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-90803 | libgprofng0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-90803 | libctf0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-90803 | libctf-nobfd0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-90803 | libbinutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-90803 | binutils-x86-64-linux-gnu | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-90803 | binutils-common | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-90803 | binutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-13757 | libp11-kit0 | 0.26.2-2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2025-66382 | libexpat1 | 2.7.4-1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-90801 | libsframe3 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-90801 | libgprofng0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-90801 | libctf0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-90801 | libctf-nobfd0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-90801 | libbinutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | GHSA-75xq-5h9v-w6px | net-imap | 0.4.19 | 0.4.24 | net-imap vulnerable to command Injection via unvalidated Symbol inputs — /usr/lib/ruby/gems/3.3.0/specifications/net-imap-0.4.19.gemspec |
| MEDIUM | CVE-2026-90801 | binutils-x86-64-linux-gnu | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-90801 | binutils-common | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-90801 | binutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-18924 | libcurl4t64 | 8.18.0-1ubuntu2.5 | 8.18.0-1ubuntu2.7 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-53583 | libgit2-1.9 | 1.9.1+ds-1ubuntu1.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-18924 | libcurl3t64-gnutls | 8.18.0-1ubuntu2.5 | 8.18.0-1ubuntu2.7 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-18924 | curl | 8.18.0-1ubuntu2.5 | 8.18.0-1ubuntu2.7 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-85091 | zlib1g-dev | 1:1.3.dfsg+really1.3.1-1ubuntu3.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-85091 | zlib1g | 1:1.3.dfsg+really1.3.1-1ubuntu3.1 | /var/lib/dpkg/status | |
| MEDIUM | GO-2026-6218 | stdlib | go1.26.5 | 1.25.13, 1.26.6, 1.27.0-rc.3 | Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations. — /usr/bin/pebble |
| MEDIUM | CVE-2026-47240 | ruby3.3-dev | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-27820 | libruby3.3 | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-27820 | ruby3.3 | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-27820 | ruby3.3-dev | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-66046 | libexpat1 | 2.7.4-1 | 2.7.4-1ubuntu0.2 | /var/lib/dpkg/status |
| MEDIUM | CVE-2026-82560 | libperl5.40 | 5.40.1-7ubuntu0.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-82560 | perl | 5.40.1-7ubuntu0.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-48959 | perl-modules-5.40 | 5.40.1-7ubuntu0.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-48959 | perl-base | 5.40.1-7ubuntu0.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-48959 | perl | 5.40.1-7ubuntu0.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-48959 | libperl5.40 | 5.40.1-7ubuntu0.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-82560 | perl-base | 5.40.1-7ubuntu0.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-82560 | perl-modules-5.40 | 5.40.1-7ubuntu0.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-102010 | cpp | 4:15.2.0-5ubuntu1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-102010 | cpp-x86-64-linux-gnu | 4:15.2.0-5ubuntu1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-102010 | gcc | 4:15.2.0-5ubuntu1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-102010 | gcc-x86-64-linux-gnu | 4:15.2.0-5ubuntu1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-47240 | libruby3.3 | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-7017 | libperl5.40 | 5.40.1-7ubuntu0.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-7017 | perl | 5.40.1-7ubuntu0.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-7017 | perl-base | 5.40.1-7ubuntu0.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-47240 | ruby3.3 | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-7017 | perl-modules-5.40 | 5.40.1-7ubuntu0.2 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-89158 | libpcre2-8-0 | 10.46-1build1 | /var/lib/dpkg/status | |
| MEDIUM | CVE-2026-80229 | curl | 8.18.0-1ubuntu2.5 | 8.18.0-1ubuntu2.7 | /var/lib/dpkg/status |
| LOW | CVE-2026-75805 | openssl | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-75805 | openssl-provider-legacy | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-75805 | libssl-dev | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-75805 | libssl3t64 | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-105712 | gpgv | 2.4.8-4ubuntu3.1 | /var/lib/dpkg/status | |
| LOW | CVE-2026-56288 | patch | 2.8-2build1 | /var/lib/dpkg/status | |
| LOW | GHSA-j4pr-3wm6-xx2r | uri | 0.13.2 | 0.13.3 | URI Credential Leakage Bypass over CVE-2025-27221 — /usr/lib/ruby/gems/3.3.0/specifications/default/uri-0.13.2.gemspec |
| LOW | CVE-2026-56289 | patch | 2.8-2build1 | /var/lib/dpkg/status | |
| LOW | CVE-2026-40228 | libudev1 | 259.5-0ubuntu3.4 | /var/lib/dpkg/status | |
| LOW | CVE-2017-13716 | binutils-common | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2017-13716 | binutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2017-13716 | binutils-x86-64-linux-gnu | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | GHSA-c2f4-jgmc-q2r5 | rexml | 3.3.9 | 3.4.2 | REXML has DoS condition when parsing malformed XML file — /usr/lib/ruby/gems/3.3.0/specifications/rexml-3.3.9.gemspec |
| LOW | CVE-2017-13716 | libbinutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2018-10126 | libjpeg-turbo8 | 2.1.5-4ubuntu4 | /var/lib/dpkg/status | |
| LOW | CVE-2017-13716 | libctf-nobfd0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2017-13716 | libctf0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2017-13716 | libgprofng0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2017-13716 | libsframe3 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66861 | binutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66861 | binutils-common | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66861 | binutils-x86-64-linux-gnu | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2026-77696 | openssl-provider-legacy | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-77696 | openssl | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-77696 | libssl3t64 | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-77696 | libssl-dev | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2025-66864 | libsframe3 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66864 | libgprofng0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66864 | libctf0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66864 | libctf-nobfd0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66864 | libbinutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66864 | binutils-x86-64-linux-gnu | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66864 | binutils-common | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66864 | binutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66861 | libbinutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66861 | libctf-nobfd0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66861 | libctf0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66861 | libgprofng0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66861 | libsframe3 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2026-40228 | libsystemd0 | 259.5-0ubuntu3.4 | /var/lib/dpkg/status | |
| LOW | CVE-2026-42772 | libssl3t64 | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.7 | /var/lib/dpkg/status |
| LOW | CVE-2025-66862 | binutils-x86-64-linux-gnu | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66862 | binutils-common | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66862 | binutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66865 | libsframe3 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66863 | libsframe3 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66865 | libgprofng0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66863 | libgprofng0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66865 | libctf0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66863 | libctf0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66865 | libctf-nobfd0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66863 | libctf-nobfd0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66865 | libbinutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66863 | libbinutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66865 | binutils-x86-64-linux-gnu | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66863 | binutils-x86-64-linux-gnu | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66865 | binutils-common | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66863 | binutils-common | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66865 | binutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66863 | binutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2026-75806 | openssl-provider-legacy | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-75806 | openssl | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-54875 | libssl-dev | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-54875 | libssl3t64 | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-54875 | openssl | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2025-1151 | binutils-x86-64-linux-gnu | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2026-42772 | openssl | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.7 | /var/lib/dpkg/status |
| LOW | CVE-2026-42772 | openssl-provider-legacy | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.7 | /var/lib/dpkg/status |
| LOW | CVE-2026-42772 | libssl-dev | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.7 | /var/lib/dpkg/status |
| LOW | GHSA-c4fp-cxrr-mj66 | net-imap | 0.4.19 | 0.5.15 | Net::IMAP: Denial of Service via incomplete raw argument validation — /usr/lib/ruby/gems/3.3.0/specifications/net-imap-0.4.19.gemspec |
| LOW | CVE-2026-75804 | openssl-provider-legacy | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-75804 | openssl | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-75804 | libssl3t64 | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-75804 | libssl-dev | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-35191 | openssl-provider-legacy | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-35191 | openssl | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-35191 | libssl3t64 | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-35191 | libssl-dev | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2025-66862 | libsframe3 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66862 | libgprofng0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66862 | libctf0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66866 | binutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66866 | binutils-common | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66866 | binutils-x86-64-linux-gnu | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66866 | libbinutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66866 | libctf-nobfd0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66866 | libctf0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66866 | libgprofng0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66866 | libsframe3 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66862 | libctf-nobfd0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-66862 | libbinutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-1151 | binutils-common | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-1151 | binutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-1150 | libsframe3 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-1150 | libgprofng0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-1150 | libctf0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-1150 | libctf-nobfd0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-1150 | libbinutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2026-35189 | libssl-dev | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-35189 | libssl3t64 | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-35189 | openssl | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-35189 | openssl-provider-legacy | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-72897 | libssl-dev | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-72897 | libssl3t64 | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-72897 | openssl | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-72897 | openssl-provider-legacy | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2025-1150 | binutils-x86-64-linux-gnu | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2026-54872 | libssl-dev | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-54872 | libssl3t64 | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-54872 | openssl | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-54872 | openssl-provider-legacy | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2025-1150 | binutils-common | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-1150 | binutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-58767 | libruby3.3 | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| LOW | CVE-2025-58767 | ruby3.3 | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| LOW | CVE-2025-58767 | ruby3.3-dev | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| LOW | CVE-2026-54875 | openssl-provider-legacy | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-75806 | libssl3t64 | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-75806 | libssl-dev | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-84784 | openssl-provider-legacy | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-84784 | openssl | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-84784 | libssl3t64 | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2026-84784 | libssl-dev | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.6 | /var/lib/dpkg/status |
| LOW | CVE-2024-56433 | passwd | 1:4.17.4-2ubuntu3 | /var/lib/dpkg/status | |
| LOW | CVE-2024-56433 | login.defs | 1:4.17.4-2ubuntu3 | /var/lib/dpkg/status | |
| LOW | CVE-2025-5278 | coreutils | 9.5-1ubuntu2+0.0.0~ubuntu25 | 9.7-3ubuntu2.1 | /var/lib/dpkg/status |
| LOW | CVE-2026-54873 | openssl-provider-legacy | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.7 | /var/lib/dpkg/status |
| LOW | CVE-2026-54873 | openssl | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.7 | /var/lib/dpkg/status |
| LOW | CVE-2026-54873 | libssl3t64 | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.7 | /var/lib/dpkg/status |
| LOW | CVE-2025-1151 | libbinutils | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-1151 | libctf-nobfd0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-1151 | libctf0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-1151 | libgprofng0 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-1151 | libsframe3 | 2.46-3ubuntu2 | /var/lib/dpkg/status | |
| LOW | CVE-2025-61594 | libruby3.3 | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| LOW | CVE-2025-61594 | ruby3.3 | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| LOW | CVE-2025-61594 | ruby3.3-dev | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| LOW | CVE-2025-43857 | libruby3.3 | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| LOW | CVE-2025-43857 | ruby3.3 | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| LOW | CVE-2025-43857 | ruby3.3-dev | 3.3.8-2ubuntu3.1 | /var/lib/dpkg/status | |
| LOW | CVE-2026-54873 | libssl-dev | 3.5.5-1ubuntu3.5 | 3.5.5-1ubuntu3.7 | /var/lib/dpkg/status |
| UNKNOWN | CVE-2019-20633 | patch | 2.8-2build1 | /var/lib/dpkg/status | |
| UNKNOWN | CVE-2021-45261 | patch | 2.8-2build1 | /var/lib/dpkg/status | |
| UNKNOWN | CVE-2018-6952 | patch | 2.8-2build1 | /var/lib/dpkg/status | |
| UNKNOWN | CVE-2025-9301 | cmake | 4.2.3-2ubuntu2 | /var/lib/dpkg/status | |
| UNKNOWN | CVE-2025-9301 | cmake-data | 4.2.3-2ubuntu2 | /var/lib/dpkg/status | |
| UNKNOWN | CVE-2026-11979 | libxml2-16 | 2.15.2+dfsg-0.1ubuntu0.1 | /var/lib/dpkg/status |
ghcr.io/openvoxproject/openvoxserver:latest-alpine (2026-09-09)
Trivy
HIGH 7
MEDIUM 3
| Severity | ID | Package | Installed | Fixed | Title / target |
|---|---|---|---|---|---|
| HIGH | CVE-2026-93990 | libexpat | 2.8.4-r0 | 2.8.5-r0 | expat: Expat: XML Injection via Malformed UTF-16 Input — ghcr.io/openvoxproject/openvoxserver:latest-alpine (alpine 3.24.1) |
| HIGH | CVE-2026-103111 | pcre2 | 10.48-r0 | 10.49-r0 | pcre2: pcre2: Out-of-bounds write via crafted regular expression — ghcr.io/openvoxproject/openvoxserver:latest-alpine (alpine 3.24.1) |
| HIGH | CVE-2026-89407 | com.fasterxml.jackson.core:jackson-core | 2.21.6 | 2.18.11, 2.21.7, 2.22.3 | com.fasterxml.jackson/jackson-core: tools.jackson.core/jackson-core: Jackson-core: Denial of Service via regular expression backtracking — Java |
| HIGH | CVE-2026-89425 | com.fasterxml.jackson.core:jackson-core | 2.21.6 | 2.21.7, 2.22.3, 2.18.11 | com.fasterxml.jackson.core/jackson-core: Jackson-core: Denial of Service via unbounded StringBuilder growth during malformed token processing — Java |
| HIGH | CVE-2026-91776 | com.fasterxml.jackson.core:jackson-databind | 2.21.6 | 2.18.11, 2.21.7, 2.22.3 | jackson-databind: com.fasterxml.jackson/jackson-core: jackson-databind: Denial of Service via unbounded cache growth in TypeDeserializerBase — Java |
| HIGH | CVE-2026-91777 | com.fasterxml.jackson.core:jackson-databind | 2.21.6 | 2.21.7, 2.18.11, 2.22.3 | com.fasterxml.jackson.core/jackson-databind: Jackson-databind: Denial of Service via quadratic forward-reference completion — Java |
| HIGH | CVE-2022-41404 | org.ini4j:ini4j | 0.5.4 | org.ini4j: unspecified DoS — Java | |
| MEDIUM | CVE-2026-58055 | nghttp2-libs | 1.69.0-r0 | 1.70.0-r0 | nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests — ghcr.io/openvoxproject/openvoxserver:latest-alpine (alpine 3.24.1) |
| MEDIUM | CVE-2026-85091 | zlib | 1.3.2-r0 | 1.3.2-r1 | zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vul ... — ghcr.io/openvoxproject/openvoxserver:latest-alpine (alpine 3.24.1) |
| MEDIUM | CVE-2026-85091 | zlib-dev | 1.3.2-r0 | 1.3.2-r1 | zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vul ... — ghcr.io/openvoxproject/openvoxserver:latest-alpine (alpine 3.24.1) |
Grype
HIGH 10
MEDIUM 1
LOW 1
NVD/CPE filtered 93
| Severity | ID | Package | Installed | Fixed | Title / target |
|---|---|---|---|---|---|
| HIGH | GHSA-jr6h-r7vg-f9mc | ini4j | 0.5.4 | org.ini4j allows attackers to cause a Denial of Service (DoS) — /opt/puppetlabs/server/apps/puppetserver/puppet-server-release.jar | |
| HIGH | GHSA-q339-8rmv-2mhv | erb | 4.0.4 | 4.0.4.1 | ERB has an @_init deserialization guard bypass via def_module / def_method / def_class — /usr/lib/ruby/gems/3.4.0/specifications/default/erb-4.0.4.gemspec |
| HIGH | CVE-2026-85091 | zlib | 1.3.2-r0 | 1.3.2-r1 | /lib/apk/db/installed |
| HIGH | CVE-2026-85091 | zlib-dev | 1.3.2-r0 | 1.3.2-r1 | /lib/apk/db/installed |
| HIGH | GHSA-p6pp-m3f8-5c89 | jackson-core | 2.21.6 | 2.21.7 | jackson-core: ReDoS: quadratic backtracking in NumberInput.PATTERN_FLOAT via looksLikeValidNumber() — /opt/puppetlabs/server/apps/puppetserver/puppet-server-release.jar |
| HIGH | GHSA-7hhh-6rmp-j9qf | jackson-core | 2.21.6 | 2.21.7 | jackson-core: UTF8DataInputJsonParser._reportInvalidToken() missing maxErrorTokenLength limit -> unbounded StringBuilder growth (DoS) — /opt/puppetlabs/server/apps/puppetserver/puppet-server-release.jar |
| HIGH | GHSA-cxp5-3px4-pw24 | jackson-databind | 2.21.6 | 2.21.7 | jackson-databind quadratic forward-reference completion — /opt/puppetlabs/server/apps/puppetserver/puppet-server-release.jar |
| HIGH | GHSA-wv8q-qhhj-9h54 | jackson-databind | 2.21.6 | 2.21.7 | jackson-databind retains every unknown raw type ID — /opt/puppetlabs/server/apps/puppetserver/puppet-server-release.jar |
| HIGH | CVE-2026-93990 | libexpat | 2.8.4-r0 | 2.8.5-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-103111 | pcre2 | 10.48-r0 | 10.49-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-58055 | nghttp2-libs | 1.69.0-r0 | 1.70.0-r0 | /lib/apk/db/installed |
| LOW | GHSA-x2f5-4prf-w687 | json | 2.9.1 | 2.19.9 | Ruby json: JSON generator heap buffer overflow when streaming to an IO — /usr/lib/ruby/gems/3.4.0/specifications/default/json-2.9.1.gemspec |
Filtered NVD/CPE matches (93)
These broad CPE matches are unconfirmed for the distribution package and excluded from scanner totals.
| Severity | ID | Package | Installed | Fixed | Title / target |
|---|---|---|---|---|---|
| HIGH | CVE-2026-72897 | libcrypto3 | 3.5.8-r0 | Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a connection to a different SSL_CTX part way through a handshake may access memory beyond the end of an internal array if the replacement context knows about more provider signature algorithms than the context the connection was created from. Applications which never call SSL_set_SSL_CTX() are not affected. Impact summary: A remote peer may be able to cause a small out-of-bounds read, and in some circumstances a fixed-value out-of-bounds write, on the server heap. This may lead to a Denial of Service. CWE: CWE-787: Out-of-bounds Write Description: A TLS connection records how many certificate slots it has when it is created, taken from the SSL_CTX that created it: the built-in certificate types plus one slot for each provider TLS-SIGALG entry that context was aware of. That count sizes an internal array of per-slot certificate validity flags. An application may replace a connection's SSL_CTX part way through the handshake by calling SSL_set_SSL_CTX(), most commonly from a servername callback in order to serve a different virtual host. Doing so did not refresh the recorded count. A provider signature algorithm's slot index is its position in the list of whichever context resolves it, so if the replacement context is aware of more of them than the original, an algorithm offered by the peer can resolve to an index beyond the end of the array. Processing the peer's signature algorithms then reads one four byte word past the end for each such algorithm and, where the word read is zero, writes a fixed value over it. A peer offering many of them can corrupt heap metadata and abort the process. Only provider signature algorithms which occupy one of the excess slots, and which the server also has configured, have this effect. Codepoints the replacement context does not recognise are discarded without being resolved to a slot, and provider signature algorithms are usable only from TLS 1.3. The two contexts must therefore be aware of different numbers of provider signature algorithms, which requires separate library contexts, a provider loaded between the two being created, or providers which differ in what they advertise - in 4.0, for example, the default provider advertises SM2 where the FIPS provider does not. A deployment meeting the condition is also unable to negotiate the affected algorithms with legitimate clients, since the same stale count hides the corresponding certificates, so the misconfiguration is likely to be noticed. For that reason, and because the configuration is not the default, this issue has been assessed as Low severity. FIPS impact: no No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| HIGH | CVE-2026-58051 | libssh2-dev | 1.11.1-r3 | libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsing populates them, so a parse failure reaching the cleanup path leaves libssh2_publickey_list_free operating on an uninitialized entry. A malicious SSH server offering the publickey subsystem can use a malformed response to make cleanup free an uninitialized, attacker-influenceable attrs pointer in a connecting libssh2 client. — /lib/apk/db/installed | |
| HIGH | CVE-2026-58051 | libssh2 | 1.11.1-r3 | libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsing populates them, so a parse failure reaching the cleanup path leaves libssh2_publickey_list_free operating on an uninitialized entry. A malicious SSH server offering the publickey subsystem can use a malformed response to make cleanup free an uninitialized, attacker-influenceable attrs pointer in a connecting libssh2 client. — /lib/apk/db/installed | |
| HIGH | CVE-2026-59850 | libssh2 | 1.11.1-r3 | A flaw was found in libssh. If data packets are processed after a channel is closed, channel data callbacks can be invoked after the associated data has already been freed, leading to crashes or possible use-after-free conditions. — /lib/apk/db/installed | |
| HIGH | CVE-2026-84784 | openssl-dev | 3.5.8-r0 | Issue summary: A malicious remote peer may flood the local QUIC stack with NEW_CONNECTION_ID frames by avoiding a limit check on how many connection IDs the remote QUIC stack can use. Impact summary: The local QUIC stack sends a RETIRE_CONN_ID frame for every NEW_CONNECTION_ID frame it receives. The RETIRE_CONN_ID frame is dispatched via the Control Frame Queue (CFQ). If the remote peer also withholds ACKs, then it can force the local stack to allocate ~400MB (depending on ACK delay). CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: RFC 9000 sections 5.1.1 and 5.1.2 [1] describe the mechanism by which a remote peer can notify the local QUIC stack to change the destination connection ID (a.k.a. CID) the local stack uses to identify the connection at the remote peer. Each CID is associated with a sequence number. The sequence number is transmitted in NEW_CONNECTION_ID and RETIRE_CONNECTION_ID frames to identify the CID which is being either associated with a connection or retired. The remote peer sends a NEW_CONNECTION_ID frame to let the local stack know a new CID is being associated with an existing connection. The NEW_CONNECTION_ID frame carries the new CID, its sequence number, and the retire-prior-to number. The retire-prior-to identifies existing CIDs that are to be retired. The local QUIC stack must send a RETIRE_CONNECTION_ID for every destination CID whose sequence number is less than retire-prior-to. The CID becomes retired after the local stack receives an ACK for its RETIRE_CONNECTION_ID frame. Although the OpenSSL QUIC stack supports at most one destination CID for every connection, it can be tricked into processing more than one RETIRE_CONNECTION_ID frame per connection. The OpenSSL QUIC stack currently retires the destination CID as soon as it receives the NEW_CONNECTION_ID, while in fact the destination CID must be retired after an ACK for the RETIRE_CONNECTION_ID frame is received. Correcting the flawed logic also fixes the backlog growth. [1] https://datatracker.ietf.org/doc/html/rfc9000#name-issuing-connection-ids FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| HIGH | CVE-2026-84784 | openssl | 3.5.8-r0 | Issue summary: A malicious remote peer may flood the local QUIC stack with NEW_CONNECTION_ID frames by avoiding a limit check on how many connection IDs the remote QUIC stack can use. Impact summary: The local QUIC stack sends a RETIRE_CONN_ID frame for every NEW_CONNECTION_ID frame it receives. The RETIRE_CONN_ID frame is dispatched via the Control Frame Queue (CFQ). If the remote peer also withholds ACKs, then it can force the local stack to allocate ~400MB (depending on ACK delay). CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: RFC 9000 sections 5.1.1 and 5.1.2 [1] describe the mechanism by which a remote peer can notify the local QUIC stack to change the destination connection ID (a.k.a. CID) the local stack uses to identify the connection at the remote peer. Each CID is associated with a sequence number. The sequence number is transmitted in NEW_CONNECTION_ID and RETIRE_CONNECTION_ID frames to identify the CID which is being either associated with a connection or retired. The remote peer sends a NEW_CONNECTION_ID frame to let the local stack know a new CID is being associated with an existing connection. The NEW_CONNECTION_ID frame carries the new CID, its sequence number, and the retire-prior-to number. The retire-prior-to identifies existing CIDs that are to be retired. The local QUIC stack must send a RETIRE_CONNECTION_ID for every destination CID whose sequence number is less than retire-prior-to. The CID becomes retired after the local stack receives an ACK for its RETIRE_CONNECTION_ID frame. Although the OpenSSL QUIC stack supports at most one destination CID for every connection, it can be tricked into processing more than one RETIRE_CONNECTION_ID frame per connection. The OpenSSL QUIC stack currently retires the destination CID as soon as it receives the NEW_CONNECTION_ID, while in fact the destination CID must be retired after an ACK for the RETIRE_CONNECTION_ID frame is received. Correcting the flawed logic also fixes the backlog growth. [1] https://datatracker.ietf.org/doc/html/rfc9000#name-issuing-connection-ids FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| HIGH | CVE-2026-84784 | libssl3 | 3.5.8-r0 | Issue summary: A malicious remote peer may flood the local QUIC stack with NEW_CONNECTION_ID frames by avoiding a limit check on how many connection IDs the remote QUIC stack can use. Impact summary: The local QUIC stack sends a RETIRE_CONN_ID frame for every NEW_CONNECTION_ID frame it receives. The RETIRE_CONN_ID frame is dispatched via the Control Frame Queue (CFQ). If the remote peer also withholds ACKs, then it can force the local stack to allocate ~400MB (depending on ACK delay). CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: RFC 9000 sections 5.1.1 and 5.1.2 [1] describe the mechanism by which a remote peer can notify the local QUIC stack to change the destination connection ID (a.k.a. CID) the local stack uses to identify the connection at the remote peer. Each CID is associated with a sequence number. The sequence number is transmitted in NEW_CONNECTION_ID and RETIRE_CONNECTION_ID frames to identify the CID which is being either associated with a connection or retired. The remote peer sends a NEW_CONNECTION_ID frame to let the local stack know a new CID is being associated with an existing connection. The NEW_CONNECTION_ID frame carries the new CID, its sequence number, and the retire-prior-to number. The retire-prior-to identifies existing CIDs that are to be retired. The local QUIC stack must send a RETIRE_CONNECTION_ID for every destination CID whose sequence number is less than retire-prior-to. The CID becomes retired after the local stack receives an ACK for its RETIRE_CONNECTION_ID frame. Although the OpenSSL QUIC stack supports at most one destination CID for every connection, it can be tricked into processing more than one RETIRE_CONNECTION_ID frame per connection. The OpenSSL QUIC stack currently retires the destination CID as soon as it receives the NEW_CONNECTION_ID, while in fact the destination CID must be retired after an ACK for the RETIRE_CONNECTION_ID frame is received. Correcting the flawed logic also fixes the backlog growth. [1] https://datatracker.ietf.org/doc/html/rfc9000#name-issuing-connection-ids FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| HIGH | CVE-2026-84784 | libcrypto3 | 3.5.8-r0 | Issue summary: A malicious remote peer may flood the local QUIC stack with NEW_CONNECTION_ID frames by avoiding a limit check on how many connection IDs the remote QUIC stack can use. Impact summary: The local QUIC stack sends a RETIRE_CONN_ID frame for every NEW_CONNECTION_ID frame it receives. The RETIRE_CONN_ID frame is dispatched via the Control Frame Queue (CFQ). If the remote peer also withholds ACKs, then it can force the local stack to allocate ~400MB (depending on ACK delay). CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: RFC 9000 sections 5.1.1 and 5.1.2 [1] describe the mechanism by which a remote peer can notify the local QUIC stack to change the destination connection ID (a.k.a. CID) the local stack uses to identify the connection at the remote peer. Each CID is associated with a sequence number. The sequence number is transmitted in NEW_CONNECTION_ID and RETIRE_CONNECTION_ID frames to identify the CID which is being either associated with a connection or retired. The remote peer sends a NEW_CONNECTION_ID frame to let the local stack know a new CID is being associated with an existing connection. The NEW_CONNECTION_ID frame carries the new CID, its sequence number, and the retire-prior-to number. The retire-prior-to identifies existing CIDs that are to be retired. The local QUIC stack must send a RETIRE_CONNECTION_ID for every destination CID whose sequence number is less than retire-prior-to. The CID becomes retired after the local stack receives an ACK for its RETIRE_CONNECTION_ID frame. Although the OpenSSL QUIC stack supports at most one destination CID for every connection, it can be tricked into processing more than one RETIRE_CONNECTION_ID frame per connection. The OpenSSL QUIC stack currently retires the destination CID as soon as it receives the NEW_CONNECTION_ID, while in fact the destination CID must be retired after an ACK for the RETIRE_CONNECTION_ID frame is received. Correcting the flawed logic also fixes the backlog growth. [1] https://datatracker.ietf.org/doc/html/rfc9000#name-issuing-connection-ids FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| HIGH | CVE-2026-66034 | libssh2-dev | 1.11.1-r3 | libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitrary-length heap out-of-bounds read and a free of an uninitialized pointer via the publickey subsystem. In libssh2_publickey_list_fetch(), the version 1 response parser reads a server-controlled comment_len value and advances the parse pointer without verifying sufficient bytes remain in the buffer, causing the out-of-bounds read to leak heap pointers from adjacent allocations defeating ASLR, followed by heap allocator state corruption when the error cleanup path frees an uninitialized pointer from a non-zeroed realloc() region. — /lib/apk/db/installed | |
| HIGH | CVE-2026-66034 | libssh2 | 1.11.1-r3 | libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitrary-length heap out-of-bounds read and a free of an uninitialized pointer via the publickey subsystem. In libssh2_publickey_list_fetch(), the version 1 response parser reads a server-controlled comment_len value and advances the parse pointer without verifying sufficient bytes remain in the buffer, causing the out-of-bounds read to leak heap pointers from adjacent allocations defeating ASLR, followed by heap allocator state corruption when the error cleanup path frees an uninitialized pointer from a non-zeroed realloc() region. — /lib/apk/db/installed | |
| HIGH | CVE-2026-84782 | openssl-dev | 3.5.8-r0 | Issue summary: The DTLS retransmission logic does not correctly handle a handshake message write that is suspended part-way through. The retransmitted message can be read past the message buffer and the retransmission overwrites the internal state the suspended write needs to resume correctly. Impact summary: The retransmitted message can disclose a heap memory to the peer as plaintext handshake data or cause a crash and a Denial of Service when the read reaches an unmapped memory region. CWE: CWE-125: Out-of-bounds Read Description: DTLS handshake messages can be written out in multiple fragments, and a write can suspend mid-message (returning WANT_WRITE) if the underlying transport temporarily cannot accept more data. While such a write is suspended, the DTLS retransmission timer may independently fire and ask the retransmission logic to resend an earlier, already-acknowledged-as-sent message from its retransmit queue. The retransmission logic reused the same internal buffer and position tracking as the message that was still being written, without resetting the position back to the start of the message being retransmitted. As a result the retransmission was read starting from wherever the suspended write had left off, producing a mislabelled message whose body was leftover bytes from the other, larger message still in flight - content that was never meant to be sent at that point, and which could run past the end of the allocated buffer. Separately, even when the retransmission is positioned correctly, allowing it to run to completion while another write is suspended overwrites the same shared bookkeeping that the suspended write depends on to resume. When the application later resumes the suspended write (via a subsequent SSL_read(), SSL_write(), SSL_accept(), or SSL_connect() call), it finds that bookkeeping in a state inconsistent with the message and aborts the process in a debugging build. The fix resets the retransmission's read position to the start of the message before resending, and skips retransmission entirely whenever a handshake write is still suspended, deferring to the next call that resumes it instead. FIPS impact: no The affected code is outside the FIPS module boundary. — /lib/apk/db/installed | |
| HIGH | CVE-2026-84782 | openssl | 3.5.8-r0 | Issue summary: The DTLS retransmission logic does not correctly handle a handshake message write that is suspended part-way through. The retransmitted message can be read past the message buffer and the retransmission overwrites the internal state the suspended write needs to resume correctly. Impact summary: The retransmitted message can disclose a heap memory to the peer as plaintext handshake data or cause a crash and a Denial of Service when the read reaches an unmapped memory region. CWE: CWE-125: Out-of-bounds Read Description: DTLS handshake messages can be written out in multiple fragments, and a write can suspend mid-message (returning WANT_WRITE) if the underlying transport temporarily cannot accept more data. While such a write is suspended, the DTLS retransmission timer may independently fire and ask the retransmission logic to resend an earlier, already-acknowledged-as-sent message from its retransmit queue. The retransmission logic reused the same internal buffer and position tracking as the message that was still being written, without resetting the position back to the start of the message being retransmitted. As a result the retransmission was read starting from wherever the suspended write had left off, producing a mislabelled message whose body was leftover bytes from the other, larger message still in flight - content that was never meant to be sent at that point, and which could run past the end of the allocated buffer. Separately, even when the retransmission is positioned correctly, allowing it to run to completion while another write is suspended overwrites the same shared bookkeeping that the suspended write depends on to resume. When the application later resumes the suspended write (via a subsequent SSL_read(), SSL_write(), SSL_accept(), or SSL_connect() call), it finds that bookkeeping in a state inconsistent with the message and aborts the process in a debugging build. The fix resets the retransmission's read position to the start of the message before resending, and skips retransmission entirely whenever a handshake write is still suspended, deferring to the next call that resumes it instead. FIPS impact: no The affected code is outside the FIPS module boundary. — /lib/apk/db/installed | |
| HIGH | CVE-2026-84782 | libssl3 | 3.5.8-r0 | Issue summary: The DTLS retransmission logic does not correctly handle a handshake message write that is suspended part-way through. The retransmitted message can be read past the message buffer and the retransmission overwrites the internal state the suspended write needs to resume correctly. Impact summary: The retransmitted message can disclose a heap memory to the peer as plaintext handshake data or cause a crash and a Denial of Service when the read reaches an unmapped memory region. CWE: CWE-125: Out-of-bounds Read Description: DTLS handshake messages can be written out in multiple fragments, and a write can suspend mid-message (returning WANT_WRITE) if the underlying transport temporarily cannot accept more data. While such a write is suspended, the DTLS retransmission timer may independently fire and ask the retransmission logic to resend an earlier, already-acknowledged-as-sent message from its retransmit queue. The retransmission logic reused the same internal buffer and position tracking as the message that was still being written, without resetting the position back to the start of the message being retransmitted. As a result the retransmission was read starting from wherever the suspended write had left off, producing a mislabelled message whose body was leftover bytes from the other, larger message still in flight - content that was never meant to be sent at that point, and which could run past the end of the allocated buffer. Separately, even when the retransmission is positioned correctly, allowing it to run to completion while another write is suspended overwrites the same shared bookkeeping that the suspended write depends on to resume. When the application later resumes the suspended write (via a subsequent SSL_read(), SSL_write(), SSL_accept(), or SSL_connect() call), it finds that bookkeeping in a state inconsistent with the message and aborts the process in a debugging build. The fix resets the retransmission's read position to the start of the message before resending, and skips retransmission entirely whenever a handshake write is still suspended, deferring to the next call that resumes it instead. FIPS impact: no The affected code is outside the FIPS module boundary. — /lib/apk/db/installed | |
| HIGH | CVE-2026-84782 | libcrypto3 | 3.5.8-r0 | Issue summary: The DTLS retransmission logic does not correctly handle a handshake message write that is suspended part-way through. The retransmitted message can be read past the message buffer and the retransmission overwrites the internal state the suspended write needs to resume correctly. Impact summary: The retransmitted message can disclose a heap memory to the peer as plaintext handshake data or cause a crash and a Denial of Service when the read reaches an unmapped memory region. CWE: CWE-125: Out-of-bounds Read Description: DTLS handshake messages can be written out in multiple fragments, and a write can suspend mid-message (returning WANT_WRITE) if the underlying transport temporarily cannot accept more data. While such a write is suspended, the DTLS retransmission timer may independently fire and ask the retransmission logic to resend an earlier, already-acknowledged-as-sent message from its retransmit queue. The retransmission logic reused the same internal buffer and position tracking as the message that was still being written, without resetting the position back to the start of the message being retransmitted. As a result the retransmission was read starting from wherever the suspended write had left off, producing a mislabelled message whose body was leftover bytes from the other, larger message still in flight - content that was never meant to be sent at that point, and which could run past the end of the allocated buffer. Separately, even when the retransmission is positioned correctly, allowing it to run to completion while another write is suspended overwrites the same shared bookkeeping that the suspended write depends on to resume. When the application later resumes the suspended write (via a subsequent SSL_read(), SSL_write(), SSL_accept(), or SSL_connect() call), it finds that bookkeeping in a state inconsistent with the message and aborts the process in a debugging build. The fix resets the retransmission's read position to the start of the message before resending, and skips retransmission entirely whenever a handshake write is still suspended, deferring to the next call that resumes it instead. FIPS impact: no The affected code is outside the FIPS module boundary. — /lib/apk/db/installed | |
| HIGH | CVE-2026-72897 | libssl3 | 3.5.8-r0 | Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a connection to a different SSL_CTX part way through a handshake may access memory beyond the end of an internal array if the replacement context knows about more provider signature algorithms than the context the connection was created from. Applications which never call SSL_set_SSL_CTX() are not affected. Impact summary: A remote peer may be able to cause a small out-of-bounds read, and in some circumstances a fixed-value out-of-bounds write, on the server heap. This may lead to a Denial of Service. CWE: CWE-787: Out-of-bounds Write Description: A TLS connection records how many certificate slots it has when it is created, taken from the SSL_CTX that created it: the built-in certificate types plus one slot for each provider TLS-SIGALG entry that context was aware of. That count sizes an internal array of per-slot certificate validity flags. An application may replace a connection's SSL_CTX part way through the handshake by calling SSL_set_SSL_CTX(), most commonly from a servername callback in order to serve a different virtual host. Doing so did not refresh the recorded count. A provider signature algorithm's slot index is its position in the list of whichever context resolves it, so if the replacement context is aware of more of them than the original, an algorithm offered by the peer can resolve to an index beyond the end of the array. Processing the peer's signature algorithms then reads one four byte word past the end for each such algorithm and, where the word read is zero, writes a fixed value over it. A peer offering many of them can corrupt heap metadata and abort the process. Only provider signature algorithms which occupy one of the excess slots, and which the server also has configured, have this effect. Codepoints the replacement context does not recognise are discarded without being resolved to a slot, and provider signature algorithms are usable only from TLS 1.3. The two contexts must therefore be aware of different numbers of provider signature algorithms, which requires separate library contexts, a provider loaded between the two being created, or providers which differ in what they advertise - in 4.0, for example, the default provider advertises SM2 where the FIPS provider does not. A deployment meeting the condition is also unable to negotiate the affected algorithms with legitimate clients, since the same stale count hides the corresponding certificates, so the misconfiguration is likely to be noticed. For that reason, and because the configuration is not the default, this issue has been assessed as Low severity. FIPS impact: no No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| HIGH | CVE-2026-58050 | libssh2-dev | 1.11.1-r3 | libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attrs * sizeof(libssh2_publickey_attribute) without bounds checking, so on 32-bit platforms the multiplication overflows to an undersized buffer. A malicious SSH server can then drive the attribute-parsing loop to write past the allocation, causing a heap buffer overflow in a connecting libssh2 client. — /lib/apk/db/installed | |
| HIGH | CVE-2026-58050 | libssh2 | 1.11.1-r3 | libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attrs * sizeof(libssh2_publickey_attribute) without bounds checking, so on 32-bit platforms the multiplication overflows to an undersized buffer. A malicious SSH server can then drive the attribute-parsing loop to write past the allocation, causing a heap buffer overflow in a connecting libssh2 client. — /lib/apk/db/installed | |
| HIGH | CVE-2026-54873 | openssl-dev | 3.5.8-r0 | Issue summary: QUIC process may keep memory for QUIC packet buffer for much longer period than necessary. Impact summary: Remote peer can exploit this vulnerability by sending maliciously crafted packets, making the local QUIC stack to keep the memory for packet buffers allocated. The time for which the memory remains allocated is entirely under the control of the potentially malicious remote peer. CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: To save copy operation from the packet buffer to the stream reassemble buffer the QUIC stack leaves the stream data on the packet buffer waiting to be copied to a buffer provided by the local receiving application. The QUIC stack releases a reference to the packet buffer only after the data are copied to the application buffer. This design is more efficient for legitimate data transfers but enables an attacker to allocate a lot more memory than actually required by the data kept in the receiving stream buffer. To mitigate the vulnerability, the QUIC stack now calculates and monitors memory overhead for every stream. The memory overhead for a single stream frame is calculated as a difference between the size of the whole packet that carries the stream frame and the size of the stream frame itself. The memory overhead for a single stream frame is added to the total (cumulative) memory overhead QUIC stack keeps for each stream. Once the cumulative memory overhead exceeds 64kB, the QUIC stack moves the stream frame data from the packet buffer to the stream buffer, starting with the next packet received. FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| HIGH | CVE-2026-54873 | openssl | 3.5.8-r0 | Issue summary: QUIC process may keep memory for QUIC packet buffer for much longer period than necessary. Impact summary: Remote peer can exploit this vulnerability by sending maliciously crafted packets, making the local QUIC stack to keep the memory for packet buffers allocated. The time for which the memory remains allocated is entirely under the control of the potentially malicious remote peer. CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: To save copy operation from the packet buffer to the stream reassemble buffer the QUIC stack leaves the stream data on the packet buffer waiting to be copied to a buffer provided by the local receiving application. The QUIC stack releases a reference to the packet buffer only after the data are copied to the application buffer. This design is more efficient for legitimate data transfers but enables an attacker to allocate a lot more memory than actually required by the data kept in the receiving stream buffer. To mitigate the vulnerability, the QUIC stack now calculates and monitors memory overhead for every stream. The memory overhead for a single stream frame is calculated as a difference between the size of the whole packet that carries the stream frame and the size of the stream frame itself. The memory overhead for a single stream frame is added to the total (cumulative) memory overhead QUIC stack keeps for each stream. Once the cumulative memory overhead exceeds 64kB, the QUIC stack moves the stream frame data from the packet buffer to the stream buffer, starting with the next packet received. FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| HIGH | CVE-2026-54873 | libssl3 | 3.5.8-r0 | Issue summary: QUIC process may keep memory for QUIC packet buffer for much longer period than necessary. Impact summary: Remote peer can exploit this vulnerability by sending maliciously crafted packets, making the local QUIC stack to keep the memory for packet buffers allocated. The time for which the memory remains allocated is entirely under the control of the potentially malicious remote peer. CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: To save copy operation from the packet buffer to the stream reassemble buffer the QUIC stack leaves the stream data on the packet buffer waiting to be copied to a buffer provided by the local receiving application. The QUIC stack releases a reference to the packet buffer only after the data are copied to the application buffer. This design is more efficient for legitimate data transfers but enables an attacker to allocate a lot more memory than actually required by the data kept in the receiving stream buffer. To mitigate the vulnerability, the QUIC stack now calculates and monitors memory overhead for every stream. The memory overhead for a single stream frame is calculated as a difference between the size of the whole packet that carries the stream frame and the size of the stream frame itself. The memory overhead for a single stream frame is added to the total (cumulative) memory overhead QUIC stack keeps for each stream. Once the cumulative memory overhead exceeds 64kB, the QUIC stack moves the stream frame data from the packet buffer to the stream buffer, starting with the next packet received. FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| HIGH | CVE-2026-54873 | libcrypto3 | 3.5.8-r0 | Issue summary: QUIC process may keep memory for QUIC packet buffer for much longer period than necessary. Impact summary: Remote peer can exploit this vulnerability by sending maliciously crafted packets, making the local QUIC stack to keep the memory for packet buffers allocated. The time for which the memory remains allocated is entirely under the control of the potentially malicious remote peer. CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: To save copy operation from the packet buffer to the stream reassemble buffer the QUIC stack leaves the stream data on the packet buffer waiting to be copied to a buffer provided by the local receiving application. The QUIC stack releases a reference to the packet buffer only after the data are copied to the application buffer. This design is more efficient for legitimate data transfers but enables an attacker to allocate a lot more memory than actually required by the data kept in the receiving stream buffer. To mitigate the vulnerability, the QUIC stack now calculates and monitors memory overhead for every stream. The memory overhead for a single stream frame is calculated as a difference between the size of the whole packet that carries the stream frame and the size of the stream frame itself. The memory overhead for a single stream frame is added to the total (cumulative) memory overhead QUIC stack keeps for each stream. Once the cumulative memory overhead exceeds 64kB, the QUIC stack moves the stream frame data from the packet buffer to the stream buffer, starting with the next packet received. FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| HIGH | CVE-2026-66032 | libssh2-dev | 1.11.1-r3 | libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt the heap of any authenticated client opening an SFTP session. When a server responds to SSH_FXP_OPEN with SSH_FXP_STATUS containing FX_OK, the response data buffer is freed, and if a subsequent sftp_packet_require() call returns a specific error such as LIBSSH2_ERROR_CHANNEL_PACKET_EXCEEDED, the same pointer is freed a second time, enabling tcache dup conditions on glibc systems that allow overlapping allocations and function pointer overwrites. — /lib/apk/db/installed | |
| HIGH | CVE-2026-66032 | libssh2 | 1.11.1-r3 | libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt the heap of any authenticated client opening an SFTP session. When a server responds to SSH_FXP_OPEN with SSH_FXP_STATUS containing FX_OK, the response data buffer is freed, and if a subsequent sftp_packet_require() call returns a specific error such as LIBSSH2_ERROR_CHANNEL_PACKET_EXCEEDED, the same pointer is freed a second time, enabling tcache dup conditions on glibc systems that allow overlapping allocations and function pointer overwrites. — /lib/apk/db/installed | |
| HIGH | CVE-2026-72897 | openssl | 3.5.8-r0 | Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a connection to a different SSL_CTX part way through a handshake may access memory beyond the end of an internal array if the replacement context knows about more provider signature algorithms than the context the connection was created from. Applications which never call SSL_set_SSL_CTX() are not affected. Impact summary: A remote peer may be able to cause a small out-of-bounds read, and in some circumstances a fixed-value out-of-bounds write, on the server heap. This may lead to a Denial of Service. CWE: CWE-787: Out-of-bounds Write Description: A TLS connection records how many certificate slots it has when it is created, taken from the SSL_CTX that created it: the built-in certificate types plus one slot for each provider TLS-SIGALG entry that context was aware of. That count sizes an internal array of per-slot certificate validity flags. An application may replace a connection's SSL_CTX part way through the handshake by calling SSL_set_SSL_CTX(), most commonly from a servername callback in order to serve a different virtual host. Doing so did not refresh the recorded count. A provider signature algorithm's slot index is its position in the list of whichever context resolves it, so if the replacement context is aware of more of them than the original, an algorithm offered by the peer can resolve to an index beyond the end of the array. Processing the peer's signature algorithms then reads one four byte word past the end for each such algorithm and, where the word read is zero, writes a fixed value over it. A peer offering many of them can corrupt heap metadata and abort the process. Only provider signature algorithms which occupy one of the excess slots, and which the server also has configured, have this effect. Codepoints the replacement context does not recognise are discarded without being resolved to a slot, and provider signature algorithms are usable only from TLS 1.3. The two contexts must therefore be aware of different numbers of provider signature algorithms, which requires separate library contexts, a provider loaded between the two being created, or providers which differ in what they advertise - in 4.0, for example, the default provider advertises SM2 where the FIPS provider does not. A deployment meeting the condition is also unable to negotiate the affected algorithms with legitimate clients, since the same stale count hides the corresponding certificates, so the misconfiguration is likely to be noticed. For that reason, and because the configuration is not the default, this issue has been assessed as Low severity. FIPS impact: no No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| HIGH | CVE-2026-72897 | openssl-dev | 3.5.8-r0 | Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a connection to a different SSL_CTX part way through a handshake may access memory beyond the end of an internal array if the replacement context knows about more provider signature algorithms than the context the connection was created from. Applications which never call SSL_set_SSL_CTX() are not affected. Impact summary: A remote peer may be able to cause a small out-of-bounds read, and in some circumstances a fixed-value out-of-bounds write, on the server heap. This may lead to a Denial of Service. CWE: CWE-787: Out-of-bounds Write Description: A TLS connection records how many certificate slots it has when it is created, taken from the SSL_CTX that created it: the built-in certificate types plus one slot for each provider TLS-SIGALG entry that context was aware of. That count sizes an internal array of per-slot certificate validity flags. An application may replace a connection's SSL_CTX part way through the handshake by calling SSL_set_SSL_CTX(), most commonly from a servername callback in order to serve a different virtual host. Doing so did not refresh the recorded count. A provider signature algorithm's slot index is its position in the list of whichever context resolves it, so if the replacement context is aware of more of them than the original, an algorithm offered by the peer can resolve to an index beyond the end of the array. Processing the peer's signature algorithms then reads one four byte word past the end for each such algorithm and, where the word read is zero, writes a fixed value over it. A peer offering many of them can corrupt heap metadata and abort the process. Only provider signature algorithms which occupy one of the excess slots, and which the server also has configured, have this effect. Codepoints the replacement context does not recognise are discarded without being resolved to a slot, and provider signature algorithms are usable only from TLS 1.3. The two contexts must therefore be aware of different numbers of provider signature algorithms, which requires separate library contexts, a provider loaded between the two being created, or providers which differ in what they advertise - in 4.0, for example, the default provider advertises SM2 where the FIPS provider does not. A deployment meeting the condition is also unable to negotiate the affected algorithms with legitimate clients, since the same stale count hides the corresponding certificates, so the misconfiguration is likely to be noticed. For that reason, and because the configuration is not the default, this issue has been assessed as Low severity. FIPS impact: no No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| HIGH | CVE-2026-59851 | libssh2 | 1.11.1-r3 | A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssapi-keyex path does not verify whether the authenticated Kerberos principal is authorized for the requested local user, allowing authenticated clients to log in as arbitrary users. — /lib/apk/db/installed | |
| HIGH | CVE-2026-66035 | libssh2-dev | 1.11.1-r3 | libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that allows a malicious SSH server to corrupt heap metadata in any connecting client by sending a packet with a packet_length smaller than the cipher's block size during Encrypt-then-MAC cipher negotiation. In the fullpacket() function in src/transport.c, the ETM path allocates a buffer of packet_length bytes but copies blocksize minus one bytes via memcpy, causing an overflow that on 32-bit glibc writes attacker-controlled bytes into an adjacent chunk's SIZE field, enabling tcache bin confusion, overlapping live objects, and function pointer overwrite during the session handshake before authentication. — /lib/apk/db/installed | |
| HIGH | CVE-2026-66035 | libssh2 | 1.11.1-r3 | libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that allows a malicious SSH server to corrupt heap metadata in any connecting client by sending a packet with a packet_length smaller than the cipher's block size during Encrypt-then-MAC cipher negotiation. In the fullpacket() function in src/transport.c, the ETM path allocates a buffer of packet_length bytes but copies blocksize minus one bytes via memcpy, causing an overflow that on 32-bit glibc writes attacker-controlled bytes into an adjacent chunk's SIZE field, enabling tcache bin confusion, overlapping live objects, and function pointer overwrite during the session handshake before authentication. — /lib/apk/db/installed | |
| HIGH | CVE-2026-66033 | libssh2-dev | 1.11.1-r3 | libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in src/openssl.c that allows a malicious SSH server to crash any connecting client by negotiating AES-GCM ciphers during handshake. Attackers can exploit the underflow in the expression computing blocksize minus aadlen minus authentication tag length to trigger an out-of-bounds read and a memcpy call with a near-SIZE_MAX length argument, causing immediate process crash before any authentication occurs. — /lib/apk/db/installed | |
| HIGH | CVE-2026-66033 | libssh2 | 1.11.1-r3 | libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in src/openssl.c that allows a malicious SSH server to crash any connecting client by negotiating AES-GCM ciphers during handshake. Attackers can exploit the underflow in the expression computing blocksize minus aadlen minus authentication tag length to trigger an out-of-bounds read and a memcpy call with a near-SIZE_MAX length argument, causing immediate process crash before any authentication occurs. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-75805 | openssl | 3.5.8-r0 | Issue summary: A CMP client that requests certificate revocation on the basis of a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when processing a crafted revocation response. Impact summary: The NULL pointer dereference happens on a read which leads to a crash and a Denial of Service for the affected client application. CWE: CWE-476: NULL-pointer dereference Description: A CMP client revoking a certificate has to tell the server which certificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the certificate itself or its issuer name and serial number. This is 'openssl cmp -cmd rr -csr <file>' on the command line, or OSSL_CMP_exec_RR_ses() with the certificate supplied via OSSL_CMP_CTX_set1_p10CSR() through the API. A CSR does not contain the issuer name and serial number of the certificate, so the client does not send them. A server may optionally name the certificate it revoked in its response, and the client then compares that name against what it sent. Having sent neither an issuer name nor a serial number, it has nothing to compare against, and a server returning a specially crafted name causes the client to read from a NULL pointer and crash. The revocation response is checked for valid message protection before the affected code is reached, so an attacker must be a malicious or compromised CMP server, or a man-in-the-middle in possession of the secret used for message protection. Clients that identify the certificate to be revoked by a certificate or by issuer and serial number rather than by a PKCS#10 CSR are not affected. FIPS impact: no No FIPS modules are affected by this issue, as the CMP protocol implementation is outside the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-75805 | libssl3 | 3.5.8-r0 | Issue summary: A CMP client that requests certificate revocation on the basis of a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when processing a crafted revocation response. Impact summary: The NULL pointer dereference happens on a read which leads to a crash and a Denial of Service for the affected client application. CWE: CWE-476: NULL-pointer dereference Description: A CMP client revoking a certificate has to tell the server which certificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the certificate itself or its issuer name and serial number. This is 'openssl cmp -cmd rr -csr <file>' on the command line, or OSSL_CMP_exec_RR_ses() with the certificate supplied via OSSL_CMP_CTX_set1_p10CSR() through the API. A CSR does not contain the issuer name and serial number of the certificate, so the client does not send them. A server may optionally name the certificate it revoked in its response, and the client then compares that name against what it sent. Having sent neither an issuer name nor a serial number, it has nothing to compare against, and a server returning a specially crafted name causes the client to read from a NULL pointer and crash. The revocation response is checked for valid message protection before the affected code is reached, so an attacker must be a malicious or compromised CMP server, or a man-in-the-middle in possession of the secret used for message protection. Clients that identify the certificate to be revoked by a certificate or by issuer and serial number rather than by a PKCS#10 CSR are not affected. FIPS impact: no No FIPS modules are affected by this issue, as the CMP protocol implementation is outside the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-75805 | openssl-dev | 3.5.8-r0 | Issue summary: A CMP client that requests certificate revocation on the basis of a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when processing a crafted revocation response. Impact summary: The NULL pointer dereference happens on a read which leads to a crash and a Denial of Service for the affected client application. CWE: CWE-476: NULL-pointer dereference Description: A CMP client revoking a certificate has to tell the server which certificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the certificate itself or its issuer name and serial number. This is 'openssl cmp -cmd rr -csr <file>' on the command line, or OSSL_CMP_exec_RR_ses() with the certificate supplied via OSSL_CMP_CTX_set1_p10CSR() through the API. A CSR does not contain the issuer name and serial number of the certificate, so the client does not send them. A server may optionally name the certificate it revoked in its response, and the client then compares that name against what it sent. Having sent neither an issuer name nor a serial number, it has nothing to compare against, and a server returning a specially crafted name causes the client to read from a NULL pointer and crash. The revocation response is checked for valid message protection before the affected code is reached, so an attacker must be a malicious or compromised CMP server, or a man-in-the-middle in possession of the secret used for message protection. Clients that identify the certificate to be revoked by a certificate or by issuer and serial number rather than by a PKCS#10 CSR are not affected. FIPS impact: no No FIPS modules are affected by this issue, as the CMP protocol implementation is outside the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-5745 | libarchive | 3.8.7-r0 | A flaw was found in libarchive. A NULL pointer dereference vulnerability exists in the ACL parsing logic, specifically within the archive_acl_from_text_nl() function. When processing a malformed ACL string (such as a bare "d" or "default" tag without subsequent fields), the function fails to perform adequate validation before advancing the pointer. An attacker can exploit this by providing a maliciously crafted archive, causing an application utilizing the libarchive API (such as bsdtar) to crash, resulting in a Denial of Service (DoS). — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-75805 | libcrypto3 | 3.5.8-r0 | Issue summary: A CMP client that requests certificate revocation on the basis of a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when processing a crafted revocation response. Impact summary: The NULL pointer dereference happens on a read which leads to a crash and a Denial of Service for the affected client application. CWE: CWE-476: NULL-pointer dereference Description: A CMP client revoking a certificate has to tell the server which certificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the certificate itself or its issuer name and serial number. This is 'openssl cmp -cmd rr -csr <file>' on the command line, or OSSL_CMP_exec_RR_ses() with the certificate supplied via OSSL_CMP_CTX_set1_p10CSR() through the API. A CSR does not contain the issuer name and serial number of the certificate, so the client does not send them. A server may optionally name the certificate it revoked in its response, and the client then compares that name against what it sent. Having sent neither an issuer name nor a serial number, it has nothing to compare against, and a server returning a specially crafted name causes the client to read from a NULL pointer and crash. The revocation response is checked for valid message protection before the affected code is reached, so an attacker must be a malicious or compromised CMP server, or a man-in-the-middle in possession of the secret used for message protection. Clients that identify the certificate to be revoked by a certificate or by issuer and serial number rather than by a PKCS#10 CSR are not affected. FIPS impact: no No FIPS modules are affected by this issue, as the CMP protocol implementation is outside the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-35189 | openssl-dev | 3.5.8-r0 | Issue summary: A certificate with many nameRelativeToCRLIssuer CRL distribution points causes disproportionate heap growth when OpenSSL caches X.509 extensions. Impact summary: Receiving a crafted certificate from a malicious peer can lead to significant memory pressure and possible Denial of Service in clients or in servers that solicit client certificates. CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: A certificate or a set of certificates that fits under the limit for size of certificates accepted from the peer (~100 KiB) can result in allocation of several hundred MiB of resident memory on the receiving side during a normal TLS handshake. This may be enough to crash the client or server, if multiple concurrent connections lead to similarly large memory allocations. The fix postpones processing of the CRL distribution points extensions in certificates to the time when the processed value is required for CRL processing. This avoids keeping large memory allocations for a long time when such certificates are received. FIPS impact: no The affected code is outside the FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-35189 | openssl | 3.5.8-r0 | Issue summary: A certificate with many nameRelativeToCRLIssuer CRL distribution points causes disproportionate heap growth when OpenSSL caches X.509 extensions. Impact summary: Receiving a crafted certificate from a malicious peer can lead to significant memory pressure and possible Denial of Service in clients or in servers that solicit client certificates. CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: A certificate or a set of certificates that fits under the limit for size of certificates accepted from the peer (~100 KiB) can result in allocation of several hundred MiB of resident memory on the receiving side during a normal TLS handshake. This may be enough to crash the client or server, if multiple concurrent connections lead to similarly large memory allocations. The fix postpones processing of the CRL distribution points extensions in certificates to the time when the processed value is required for CRL processing. This avoids keeping large memory allocations for a long time when such certificates are received. FIPS impact: no The affected code is outside the FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-35189 | libssl3 | 3.5.8-r0 | Issue summary: A certificate with many nameRelativeToCRLIssuer CRL distribution points causes disproportionate heap growth when OpenSSL caches X.509 extensions. Impact summary: Receiving a crafted certificate from a malicious peer can lead to significant memory pressure and possible Denial of Service in clients or in servers that solicit client certificates. CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: A certificate or a set of certificates that fits under the limit for size of certificates accepted from the peer (~100 KiB) can result in allocation of several hundred MiB of resident memory on the receiving side during a normal TLS handshake. This may be enough to crash the client or server, if multiple concurrent connections lead to similarly large memory allocations. The fix postpones processing of the CRL distribution points extensions in certificates to the time when the processed value is required for CRL processing. This avoids keeping large memory allocations for a long time when such certificates are received. FIPS impact: no The affected code is outside the FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-35189 | libcrypto3 | 3.5.8-r0 | Issue summary: A certificate with many nameRelativeToCRLIssuer CRL distribution points causes disproportionate heap growth when OpenSSL caches X.509 extensions. Impact summary: Receiving a crafted certificate from a malicious peer can lead to significant memory pressure and possible Denial of Service in clients or in servers that solicit client certificates. CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: A certificate or a set of certificates that fits under the limit for size of certificates accepted from the peer (~100 KiB) can result in allocation of several hundred MiB of resident memory on the receiving side during a normal TLS handshake. This may be enough to crash the client or server, if multiple concurrent connections lead to similarly large memory allocations. The fix postpones processing of the CRL distribution points extensions in certificates to the time when the processed value is required for CRL processing. This avoids keeping large memory allocations for a long time when such certificates are received. FIPS impact: no The affected code is outside the FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-60876 | ssl_client | 1.37.0-r31 | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-60876 | busybox-binsh | 1.37.0-r31 | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-60876 | busybox | 1.37.0-r31 | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-56391 | coreutils | 9.11-r0 | GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. This incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input. When running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure. This issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-56391 | coreutils-env | 9.11-r0 | GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. This incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input. When running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure. This issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-56391 | coreutils-fmt | 9.11-r0 | GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. This incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input. When running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure. This issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-56391 | coreutils-sha512sum | 9.11-r0 | GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. This incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input. When running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure. This issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-56392 | coreutils | 9.11-r0 | GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer. When processing crafted input, subsequent writes exceed the allocated memory, leading to an out‑of‑bounds heap write. When running GNU coreutils unexpand with attacker-provided large tab stop (-t) arguments, this behavior leads to a crash and potentially achieve a heap write primitive depending on memory layout. This issue has been fixed in the commit b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-56392 | coreutils-env | 9.11-r0 | GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer. When processing crafted input, subsequent writes exceed the allocated memory, leading to an out‑of‑bounds heap write. When running GNU coreutils unexpand with attacker-provided large tab stop (-t) arguments, this behavior leads to a crash and potentially achieve a heap write primitive depending on memory layout. This issue has been fixed in the commit b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-56392 | coreutils-fmt | 9.11-r0 | GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer. When processing crafted input, subsequent writes exceed the allocated memory, leading to an out‑of‑bounds heap write. When running GNU coreutils unexpand with attacker-provided large tab stop (-t) arguments, this behavior leads to a crash and potentially achieve a heap write primitive depending on memory layout. This issue has been fixed in the commit b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-56392 | coreutils-sha512sum | 9.11-r0 | GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer. When processing crafted input, subsequent writes exceed the allocated memory, leading to an out‑of‑bounds heap write. When running GNU coreutils unexpand with attacker-provided large tab stop (-t) arguments, this behavior leads to a crash and potentially achieve a heap write primitive depending on memory layout. This issue has been fixed in the commit b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-18508 | tar | 1.35-r5 | A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-59845 | libssh2 | 1.11.1-r3 | A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may then be sent across the caller's accessible process tree, leading to local denial of service. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-18477 | tar | 1.35-r5 | A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. This could lead to unauthorized file modification or, in some cases, privilege escalation. Exploitation does not require the attacker to modify or craft the archive, and standard backup and restore workflows—including extracting into a newly created directory without using the -P option do not mitigate the issue. — /lib/apk/db/installed | |
| MEDIUM | CVE-2013-0256 | ruby-rdoc | 3.4.9-r0 | darkfish.js in RDoc 2.3.0 through 3.12 and 4.x before 4.0.0.preview2.1, as used in Ruby, does not properly generate documents, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted URL. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-59843 | libssh2 | 1.11.1-r3 | A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel writes to loop indefinitely and consume CPU, leading to denial of service. — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-15661 | libssh2 | 1.11.1-r3 | libssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bounds heap read vulnerability in the sftp_symlink() function in src/sftp.c that allows a malicious SSH server or man-in-the-middle attacker to disclose heap memory contents or cause a crash by sending a crafted SSH_FXP_NAME response. Attackers can supply a link_len value larger than the actual packet data in SSH_FXP_NAME responses for SFTP READLINK and REALPATH operations, triggering a heap buffer over-read of up to target_len minus one bytes due to the missing validation of available packet buffer size before the memcpy operation. — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-15661 | libssh2-dev | 1.11.1-r3 | libssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bounds heap read vulnerability in the sftp_symlink() function in src/sftp.c that allows a malicious SSH server or man-in-the-middle attacker to disclose heap memory contents or cause a crash by sending a crafted SSH_FXP_NAME response. Attackers can supply a link_len value larger than the actual packet data in SSH_FXP_NAME responses for SFTP READLINK and REALPATH operations, triggering a heap buffer over-read of up to target_len minus one bytes due to the missing validation of available packet buffer size before the memcpy operation. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-59844 | libssh2 | 1.11.1-r3 | A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large length, causing a libssh SFTP server to allocate excessive memory and potentially exhaust it through repeated requests. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-5704 | tar | 1.35-r5 | A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection. — /lib/apk/db/installed | |
| MEDIUM | CVE-2016-2781 | coreutils | 9.11-r0 | chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer. — /lib/apk/db/installed | |
| MEDIUM | CVE-2016-2781 | coreutils-env | 9.11-r0 | chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer. — /lib/apk/db/installed | |
| MEDIUM | CVE-2016-2781 | coreutils-fmt | 9.11-r0 | chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer. — /lib/apk/db/installed | |
| MEDIUM | CVE-2016-2781 | coreutils-sha512sum | 9.11-r0 | chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-75806 | libcrypto3 | 3.5.8-r0 | Issue summary: An established DTLS 1.2 association using an AEAD cipher suite can be terminated by a single unauthenticated datagram whose encrypted fragment is shorter than the mandatory explicit IV and authentication tag overhead. Impact summary: An attacker who can send a datagram that is routed to an existing DTLS 1.2 association can tear that association down without knowing any key material. This is a Denial of Service limited to the targeted association. There is no memory safety or confidentiality impact. CWE: CWE-1284: Improper Validation of Specified Quantity in Input Description: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher suite carries an explicit IV followed by the ciphertext and an authentication tag. When decrypting such a record the record layer passed the record length to the cipher implementation before checking that the record was long enough to contain the explicit IV and the tag. For a record shorter than that overhead the cipher implementation rejected the impossible length, and the record layer treated this as an internal failure and raised a fatal internal_error alert instead of treating the record as one that failed authentication. In TLS 1.2 the same record causes a fatal internal_error alert instead of the expected bad_record_mac alert. Since any undecryptable record already terminates a TLS connection, this is a protocol conformance issue rather than a security issue in TLS. The fix validates the record length against the explicit IV and tag length before any AEAD processing, so that TLS reports bad_record_mac and DTLS silently discards the record. FIPS impact: no The affected code is outside the FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-75806 | libssl3 | 3.5.8-r0 | Issue summary: An established DTLS 1.2 association using an AEAD cipher suite can be terminated by a single unauthenticated datagram whose encrypted fragment is shorter than the mandatory explicit IV and authentication tag overhead. Impact summary: An attacker who can send a datagram that is routed to an existing DTLS 1.2 association can tear that association down without knowing any key material. This is a Denial of Service limited to the targeted association. There is no memory safety or confidentiality impact. CWE: CWE-1284: Improper Validation of Specified Quantity in Input Description: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher suite carries an explicit IV followed by the ciphertext and an authentication tag. When decrypting such a record the record layer passed the record length to the cipher implementation before checking that the record was long enough to contain the explicit IV and the tag. For a record shorter than that overhead the cipher implementation rejected the impossible length, and the record layer treated this as an internal failure and raised a fatal internal_error alert instead of treating the record as one that failed authentication. In TLS 1.2 the same record causes a fatal internal_error alert instead of the expected bad_record_mac alert. Since any undecryptable record already terminates a TLS connection, this is a protocol conformance issue rather than a security issue in TLS. The fix validates the record length against the explicit IV and tag length before any AEAD processing, so that TLS reports bad_record_mac and DTLS silently discards the record. FIPS impact: no The affected code is outside the FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-75806 | openssl | 3.5.8-r0 | Issue summary: An established DTLS 1.2 association using an AEAD cipher suite can be terminated by a single unauthenticated datagram whose encrypted fragment is shorter than the mandatory explicit IV and authentication tag overhead. Impact summary: An attacker who can send a datagram that is routed to an existing DTLS 1.2 association can tear that association down without knowing any key material. This is a Denial of Service limited to the targeted association. There is no memory safety or confidentiality impact. CWE: CWE-1284: Improper Validation of Specified Quantity in Input Description: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher suite carries an explicit IV followed by the ciphertext and an authentication tag. When decrypting such a record the record layer passed the record length to the cipher implementation before checking that the record was long enough to contain the explicit IV and the tag. For a record shorter than that overhead the cipher implementation rejected the impossible length, and the record layer treated this as an internal failure and raised a fatal internal_error alert instead of treating the record as one that failed authentication. In TLS 1.2 the same record causes a fatal internal_error alert instead of the expected bad_record_mac alert. Since any undecryptable record already terminates a TLS connection, this is a protocol conformance issue rather than a security issue in TLS. The fix validates the record length against the explicit IV and tag length before any AEAD processing, so that TLS reports bad_record_mac and DTLS silently discards the record. FIPS impact: no The affected code is outside the FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-42772 | openssl-dev | 3.5.8-r0 | Issue summary: The QUIC stream reassembly algorithm performance deteriorates progressively as packets are arriving out of order. The worst case has a quadratic complexity proportional to the number of stream frames kept in the buffer for the received stream data. Impact summary: A remote QUIC peer that completes the handshake can create a connection-scoped CPU pressure and potentially a Denial of Service using compliant STREAM frames inside the advertised receive window, with low attacker bandwidth. CWE: CWE-407: Inefficient Algorithmic Complexity Description: OpenSSL manages received QUIC stream fragments using a doubly-linked list. While it optimizes for append operations (at the end of the list), it falls back to a head-to-tail linear search for any fragment that does not immediately follow the current `tail`. By manipulating the sequence of offsets, an attacker can force the server to perform O(n^2) operations, consuming excessive CPU time for the QUIC process. FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-42772 | openssl | 3.5.8-r0 | Issue summary: The QUIC stream reassembly algorithm performance deteriorates progressively as packets are arriving out of order. The worst case has a quadratic complexity proportional to the number of stream frames kept in the buffer for the received stream data. Impact summary: A remote QUIC peer that completes the handshake can create a connection-scoped CPU pressure and potentially a Denial of Service using compliant STREAM frames inside the advertised receive window, with low attacker bandwidth. CWE: CWE-407: Inefficient Algorithmic Complexity Description: OpenSSL manages received QUIC stream fragments using a doubly-linked list. While it optimizes for append operations (at the end of the list), it falls back to a head-to-tail linear search for any fragment that does not immediately follow the current `tail`. By manipulating the sequence of offsets, an attacker can force the server to perform O(n^2) operations, consuming excessive CPU time for the QUIC process. FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-42772 | libssl3 | 3.5.8-r0 | Issue summary: The QUIC stream reassembly algorithm performance deteriorates progressively as packets are arriving out of order. The worst case has a quadratic complexity proportional to the number of stream frames kept in the buffer for the received stream data. Impact summary: A remote QUIC peer that completes the handshake can create a connection-scoped CPU pressure and potentially a Denial of Service using compliant STREAM frames inside the advertised receive window, with low attacker bandwidth. CWE: CWE-407: Inefficient Algorithmic Complexity Description: OpenSSL manages received QUIC stream fragments using a doubly-linked list. While it optimizes for append operations (at the end of the list), it falls back to a head-to-tail linear search for any fragment that does not immediately follow the current `tail`. By manipulating the sequence of offsets, an attacker can force the server to perform O(n^2) operations, consuming excessive CPU time for the QUIC process. FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-42772 | libcrypto3 | 3.5.8-r0 | Issue summary: The QUIC stream reassembly algorithm performance deteriorates progressively as packets are arriving out of order. The worst case has a quadratic complexity proportional to the number of stream frames kept in the buffer for the received stream data. Impact summary: A remote QUIC peer that completes the handshake can create a connection-scoped CPU pressure and potentially a Denial of Service using compliant STREAM frames inside the advertised receive window, with low attacker bandwidth. CWE: CWE-407: Inefficient Algorithmic Complexity Description: OpenSSL manages received QUIC stream fragments using a doubly-linked list. While it optimizes for append operations (at the end of the list), it falls back to a head-to-tail linear search for any fragment that does not immediately follow the current `tail`. By manipulating the sequence of offsets, an attacker can force the server to perform O(n^2) operations, consuming excessive CPU time for the QUIC process. FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-59848 | libssh2 | 1.11.1-r3 | A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh clients keep queued indefinitely, causing unbounded memory growth and client-side denial of service. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-75804 | openssl-dev | 3.5.8-r0 | Issue summary: OpenSSL QUIC stack does not enforce connection level flow control for streams. Remote peers may send more bytes as long as they fit within the stream flow control limits. Impact summary: A malicious remote peer may exploit the lack of connection flow control for streams to make the QUIC stack receive ~100MB of memory instead of 768 KiB (default flow control window size). CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: The local QUIC stack advertises two flow control limits to its remote peer: stream flow control limit and connection flow control limit. The remote peer must follow both limits when transmitting stream data. Whenever the local QUIC stack receives a stream frame, it validates that the size of the received stream frame stays within flow control limits. If either limit is exceeded (stream level or connection level), then the QUIC stack must close the connection with a flow control error. The vulnerable OpenSSL QUIC stack enforces the stream-level but not the connection-level limit. To exploit the issue, three conditions must be met: - the remote peer opens several streams - each stream must stay within the stream-level flow control limit - there must be no zero-offset byte sent on any of the streams (to prevent the vulnerable QUIC stack from consuming data). By meeting the conditions above, the remote peer may make the local stack allocate 2 x MAX_STREAMS x (stream flow control limit) bytes of memory. MAX_STREAMS defaults to 100, and the limit applies to both bidirectional and unidirectional streams, making it 200 in total. The default flow control window for a stream is 512kB. The remote peer may force the vulnerable QUIC stack to allocate 100MB of heap per connection. FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-75804 | openssl | 3.5.8-r0 | Issue summary: OpenSSL QUIC stack does not enforce connection level flow control for streams. Remote peers may send more bytes as long as they fit within the stream flow control limits. Impact summary: A malicious remote peer may exploit the lack of connection flow control for streams to make the QUIC stack receive ~100MB of memory instead of 768 KiB (default flow control window size). CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: The local QUIC stack advertises two flow control limits to its remote peer: stream flow control limit and connection flow control limit. The remote peer must follow both limits when transmitting stream data. Whenever the local QUIC stack receives a stream frame, it validates that the size of the received stream frame stays within flow control limits. If either limit is exceeded (stream level or connection level), then the QUIC stack must close the connection with a flow control error. The vulnerable OpenSSL QUIC stack enforces the stream-level but not the connection-level limit. To exploit the issue, three conditions must be met: - the remote peer opens several streams - each stream must stay within the stream-level flow control limit - there must be no zero-offset byte sent on any of the streams (to prevent the vulnerable QUIC stack from consuming data). By meeting the conditions above, the remote peer may make the local stack allocate 2 x MAX_STREAMS x (stream flow control limit) bytes of memory. MAX_STREAMS defaults to 100, and the limit applies to both bidirectional and unidirectional streams, making it 200 in total. The default flow control window for a stream is 512kB. The remote peer may force the vulnerable QUIC stack to allocate 100MB of heap per connection. FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-75806 | openssl-dev | 3.5.8-r0 | Issue summary: An established DTLS 1.2 association using an AEAD cipher suite can be terminated by a single unauthenticated datagram whose encrypted fragment is shorter than the mandatory explicit IV and authentication tag overhead. Impact summary: An attacker who can send a datagram that is routed to an existing DTLS 1.2 association can tear that association down without knowing any key material. This is a Denial of Service limited to the targeted association. There is no memory safety or confidentiality impact. CWE: CWE-1284: Improper Validation of Specified Quantity in Input Description: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher suite carries an explicit IV followed by the ciphertext and an authentication tag. When decrypting such a record the record layer passed the record length to the cipher implementation before checking that the record was long enough to contain the explicit IV and the tag. For a record shorter than that overhead the cipher implementation rejected the impossible length, and the record layer treated this as an internal failure and raised a fatal internal_error alert instead of treating the record as one that failed authentication. In TLS 1.2 the same record causes a fatal internal_error alert instead of the expected bad_record_mac alert. Since any undecryptable record already terminates a TLS connection, this is a protocol conformance issue rather than a security issue in TLS. The fix validates the record length against the explicit IV and tag length before any AEAD processing, so that TLS reports bad_record_mac and DTLS silently discards the record. FIPS impact: no The affected code is outside the FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-75804 | libcrypto3 | 3.5.8-r0 | Issue summary: OpenSSL QUIC stack does not enforce connection level flow control for streams. Remote peers may send more bytes as long as they fit within the stream flow control limits. Impact summary: A malicious remote peer may exploit the lack of connection flow control for streams to make the QUIC stack receive ~100MB of memory instead of 768 KiB (default flow control window size). CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: The local QUIC stack advertises two flow control limits to its remote peer: stream flow control limit and connection flow control limit. The remote peer must follow both limits when transmitting stream data. Whenever the local QUIC stack receives a stream frame, it validates that the size of the received stream frame stays within flow control limits. If either limit is exceeded (stream level or connection level), then the QUIC stack must close the connection with a flow control error. The vulnerable OpenSSL QUIC stack enforces the stream-level but not the connection-level limit. To exploit the issue, three conditions must be met: - the remote peer opens several streams - each stream must stay within the stream-level flow control limit - there must be no zero-offset byte sent on any of the streams (to prevent the vulnerable QUIC stack from consuming data). By meeting the conditions above, the remote peer may make the local stack allocate 2 x MAX_STREAMS x (stream flow control limit) bytes of memory. MAX_STREAMS defaults to 100, and the limit applies to both bidirectional and unidirectional streams, making it 200 in total. The default flow control window for a stream is 512kB. The remote peer may force the vulnerable QUIC stack to allocate 100MB of heap per connection. FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-75804 | libssl3 | 3.5.8-r0 | Issue summary: OpenSSL QUIC stack does not enforce connection level flow control for streams. Remote peers may send more bytes as long as they fit within the stream flow control limits. Impact summary: A malicious remote peer may exploit the lack of connection flow control for streams to make the QUIC stack receive ~100MB of memory instead of 768 KiB (default flow control window size). CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: The local QUIC stack advertises two flow control limits to its remote peer: stream flow control limit and connection flow control limit. The remote peer must follow both limits when transmitting stream data. Whenever the local QUIC stack receives a stream frame, it validates that the size of the received stream frame stays within flow control limits. If either limit is exceeded (stream level or connection level), then the QUIC stack must close the connection with a flow control error. The vulnerable OpenSSL QUIC stack enforces the stream-level but not the connection-level limit. To exploit the issue, three conditions must be met: - the remote peer opens several streams - each stream must stay within the stream-level flow control limit - there must be no zero-offset byte sent on any of the streams (to prevent the vulnerable QUIC stack from consuming data). By meeting the conditions above, the remote peer may make the local stack allocate 2 x MAX_STREAMS x (stream flow control limit) bytes of memory. MAX_STREAMS defaults to 100, and the limit applies to both bidirectional and unidirectional streams, making it 200 in total. The default flow control window for a stream is 512kB. The remote peer may force the vulnerable QUIC stack to allocate 100MB of heap per connection. FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| LOW | CVE-2026-59846 | libssh2 | 1.11.1-r3 | A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing unintended shell behavior. — /lib/apk/db/installed | |
| LOW | CVE-2026-54875 | libcrypto3 | 3.5.8-r0 | Issue summary: A non-constant-time optimized implementation of scalar point multiplication is used for SM2 private key operations on ARM64 and RISC-V platforms. Impact summary: An attacker able to measure the time taken by, or to observe the cache-line access pattern of SM2 signing or decryption on an affected platform can learn information about the secret scalar. CWE: CWE-208: Observable Timing Discrepancy Description: On ARM64 and RISC-V processors, the SM2 curve uses an optimized scalar multiplication implementation whose conditional branches and table look ups are chosen according to the bits of the secret scalar. The execution time and the cache-access pattern therefore depend on the long-term private key (during SM2 decryption) or the per-signature nonce (during SM2 signature generation), forming a timing and cache side-channel. FIPS Impact: no SM2 is not a FIPS algorithm and the optimized SM2 implementation is not part of the FIPS module. OpenSSL 4.0, 3.6, 3.5 and 3.4 are vulnerable to this issue on AArch64 and RISC-V. OpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue. OpenSSL 4.0 users should upgrade to OpenSSL 4.0.3. OpenSSL 3.6 users should upgrade to OpenSSL 3.6.5. OpenSSL 3.5 users should upgrade to OpenSSL 3.5.9. OpenSSL 3.4 users should upgrade to OpenSSL 3.4.8. This issue was reported on 2 May 2026 by Abhinav Agarwal. It was independently reported on 6 June 2026 by Feng Xue. The fix was developed by Igor Ustinov. -- cut (non-publishing metadata for internal use) -- Reported by: Abhinav Agarwal, Feng Xue Fixed by: Igor Ustinov — /lib/apk/db/installed | |
| LOW | CVE-2026-77696 | openssl-dev | 3.5.8-r0 | Issue summary: SM2 signature generation uses non-constant-time arithmetic on secret values, forming a timing side-channel. Impact summary: An attacker able to measure SM2 signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key. CWE: CWE-208: Observable Timing Discrepancy Description: SM2 signature generation computes the signature value using variable-time BIGNUM operations on the secret nonce and the private key, so the time taken to produce an SM2 signature depends on these secret values, forming a timing side-channel. Applications performing SM2 signature generation are affected on all platforms. FIPS Impact: no SM2 is not a FIPS algorithm. — /lib/apk/db/installed | |
| LOW | CVE-2026-77696 | openssl | 3.5.8-r0 | Issue summary: SM2 signature generation uses non-constant-time arithmetic on secret values, forming a timing side-channel. Impact summary: An attacker able to measure SM2 signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key. CWE: CWE-208: Observable Timing Discrepancy Description: SM2 signature generation computes the signature value using variable-time BIGNUM operations on the secret nonce and the private key, so the time taken to produce an SM2 signature depends on these secret values, forming a timing side-channel. Applications performing SM2 signature generation are affected on all platforms. FIPS Impact: no SM2 is not a FIPS algorithm. — /lib/apk/db/installed | |
| LOW | CVE-2026-77696 | libssl3 | 3.5.8-r0 | Issue summary: SM2 signature generation uses non-constant-time arithmetic on secret values, forming a timing side-channel. Impact summary: An attacker able to measure SM2 signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key. CWE: CWE-208: Observable Timing Discrepancy Description: SM2 signature generation computes the signature value using variable-time BIGNUM operations on the secret nonce and the private key, so the time taken to produce an SM2 signature depends on these secret values, forming a timing side-channel. Applications performing SM2 signature generation are affected on all platforms. FIPS Impact: no SM2 is not a FIPS algorithm. — /lib/apk/db/installed | |
| LOW | CVE-2026-77696 | libcrypto3 | 3.5.8-r0 | Issue summary: SM2 signature generation uses non-constant-time arithmetic on secret values, forming a timing side-channel. Impact summary: An attacker able to measure SM2 signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key. CWE: CWE-208: Observable Timing Discrepancy Description: SM2 signature generation computes the signature value using variable-time BIGNUM operations on the secret nonce and the private key, so the time taken to produce an SM2 signature depends on these secret values, forming a timing side-channel. Applications performing SM2 signature generation are affected on all platforms. FIPS Impact: no SM2 is not a FIPS algorithm. — /lib/apk/db/installed | |
| LOW | CVE-2026-54875 | libssl3 | 3.5.8-r0 | Issue summary: A non-constant-time optimized implementation of scalar point multiplication is used for SM2 private key operations on ARM64 and RISC-V platforms. Impact summary: An attacker able to measure the time taken by, or to observe the cache-line access pattern of SM2 signing or decryption on an affected platform can learn information about the secret scalar. CWE: CWE-208: Observable Timing Discrepancy Description: On ARM64 and RISC-V processors, the SM2 curve uses an optimized scalar multiplication implementation whose conditional branches and table look ups are chosen according to the bits of the secret scalar. The execution time and the cache-access pattern therefore depend on the long-term private key (during SM2 decryption) or the per-signature nonce (during SM2 signature generation), forming a timing and cache side-channel. FIPS Impact: no SM2 is not a FIPS algorithm and the optimized SM2 implementation is not part of the FIPS module. OpenSSL 4.0, 3.6, 3.5 and 3.4 are vulnerable to this issue on AArch64 and RISC-V. OpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue. OpenSSL 4.0 users should upgrade to OpenSSL 4.0.3. OpenSSL 3.6 users should upgrade to OpenSSL 3.6.5. OpenSSL 3.5 users should upgrade to OpenSSL 3.5.9. OpenSSL 3.4 users should upgrade to OpenSSL 3.4.8. This issue was reported on 2 May 2026 by Abhinav Agarwal. It was independently reported on 6 June 2026 by Feng Xue. The fix was developed by Igor Ustinov. -- cut (non-publishing metadata for internal use) -- Reported by: Abhinav Agarwal, Feng Xue Fixed by: Igor Ustinov — /lib/apk/db/installed | |
| LOW | CVE-2026-54875 | openssl | 3.5.8-r0 | Issue summary: A non-constant-time optimized implementation of scalar point multiplication is used for SM2 private key operations on ARM64 and RISC-V platforms. Impact summary: An attacker able to measure the time taken by, or to observe the cache-line access pattern of SM2 signing or decryption on an affected platform can learn information about the secret scalar. CWE: CWE-208: Observable Timing Discrepancy Description: On ARM64 and RISC-V processors, the SM2 curve uses an optimized scalar multiplication implementation whose conditional branches and table look ups are chosen according to the bits of the secret scalar. The execution time and the cache-access pattern therefore depend on the long-term private key (during SM2 decryption) or the per-signature nonce (during SM2 signature generation), forming a timing and cache side-channel. FIPS Impact: no SM2 is not a FIPS algorithm and the optimized SM2 implementation is not part of the FIPS module. OpenSSL 4.0, 3.6, 3.5 and 3.4 are vulnerable to this issue on AArch64 and RISC-V. OpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue. OpenSSL 4.0 users should upgrade to OpenSSL 4.0.3. OpenSSL 3.6 users should upgrade to OpenSSL 3.6.5. OpenSSL 3.5 users should upgrade to OpenSSL 3.5.9. OpenSSL 3.4 users should upgrade to OpenSSL 3.4.8. This issue was reported on 2 May 2026 by Abhinav Agarwal. It was independently reported on 6 June 2026 by Feng Xue. The fix was developed by Igor Ustinov. -- cut (non-publishing metadata for internal use) -- Reported by: Abhinav Agarwal, Feng Xue Fixed by: Igor Ustinov — /lib/apk/db/installed | |
| LOW | CVE-2026-54875 | openssl-dev | 3.5.8-r0 | Issue summary: A non-constant-time optimized implementation of scalar point multiplication is used for SM2 private key operations on ARM64 and RISC-V platforms. Impact summary: An attacker able to measure the time taken by, or to observe the cache-line access pattern of SM2 signing or decryption on an affected platform can learn information about the secret scalar. CWE: CWE-208: Observable Timing Discrepancy Description: On ARM64 and RISC-V processors, the SM2 curve uses an optimized scalar multiplication implementation whose conditional branches and table look ups are chosen according to the bits of the secret scalar. The execution time and the cache-access pattern therefore depend on the long-term private key (during SM2 decryption) or the per-signature nonce (during SM2 signature generation), forming a timing and cache side-channel. FIPS Impact: no SM2 is not a FIPS algorithm and the optimized SM2 implementation is not part of the FIPS module. OpenSSL 4.0, 3.6, 3.5 and 3.4 are vulnerable to this issue on AArch64 and RISC-V. OpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue. OpenSSL 4.0 users should upgrade to OpenSSL 4.0.3. OpenSSL 3.6 users should upgrade to OpenSSL 3.6.5. OpenSSL 3.5 users should upgrade to OpenSSL 3.5.9. OpenSSL 3.4 users should upgrade to OpenSSL 3.4.8. This issue was reported on 2 May 2026 by Abhinav Agarwal. It was independently reported on 6 June 2026 by Feng Xue. The fix was developed by Igor Ustinov. -- cut (non-publishing metadata for internal use) -- Reported by: Abhinav Agarwal, Feng Xue Fixed by: Igor Ustinov — /lib/apk/db/installed | |
| LOW | CVE-2026-54872 | openssl-dev | 3.5.8-r0 | Issue summary: The generic elliptic-curve scalar multiplication used for ECDSA and SM2 signature operations with curves that do not have a dedicated implementation leaks information about the secret nonce through timing. Impact summary: An attacker able to measure signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key. CWE: CWE-208: Observable Timing Discrepancy Description: The generic elliptic-curve scalar multiplication used for curves that do not have a dedicated constant-time implementation pads the secret scalar with non-constant-time BIGNUM operations, so the time taken depends on the value of the secret scalar derived from the ECDSA and SM2 nonce. The leak is very small; observing it requires a large number of measurements. The effect is largest for curves whose group order lies on a machine-word boundary, such as brainpoolP384r1. Applications using ECDSA signing over the Brainpool and other generic prime curves, and SM2 signing on platforms that use the generic implementation, are vulnerable to this issue. The NIST curves P-256, P-384 and P-521 use dedicated constant-time implementations and are not affected. FIPS Impact: no The FIPS modules are not affected: the approved NIST curves used in the FIPS provider have dedicated constant-time implementations and do not use the affected code path. — /lib/apk/db/installed | |
| LOW | CVE-2026-54872 | openssl | 3.5.8-r0 | Issue summary: The generic elliptic-curve scalar multiplication used for ECDSA and SM2 signature operations with curves that do not have a dedicated implementation leaks information about the secret nonce through timing. Impact summary: An attacker able to measure signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key. CWE: CWE-208: Observable Timing Discrepancy Description: The generic elliptic-curve scalar multiplication used for curves that do not have a dedicated constant-time implementation pads the secret scalar with non-constant-time BIGNUM operations, so the time taken depends on the value of the secret scalar derived from the ECDSA and SM2 nonce. The leak is very small; observing it requires a large number of measurements. The effect is largest for curves whose group order lies on a machine-word boundary, such as brainpoolP384r1. Applications using ECDSA signing over the Brainpool and other generic prime curves, and SM2 signing on platforms that use the generic implementation, are vulnerable to this issue. The NIST curves P-256, P-384 and P-521 use dedicated constant-time implementations and are not affected. FIPS Impact: no The FIPS modules are not affected: the approved NIST curves used in the FIPS provider have dedicated constant-time implementations and do not use the affected code path. — /lib/apk/db/installed | |
| LOW | CVE-2026-54872 | libssl3 | 3.5.8-r0 | Issue summary: The generic elliptic-curve scalar multiplication used for ECDSA and SM2 signature operations with curves that do not have a dedicated implementation leaks information about the secret nonce through timing. Impact summary: An attacker able to measure signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key. CWE: CWE-208: Observable Timing Discrepancy Description: The generic elliptic-curve scalar multiplication used for curves that do not have a dedicated constant-time implementation pads the secret scalar with non-constant-time BIGNUM operations, so the time taken depends on the value of the secret scalar derived from the ECDSA and SM2 nonce. The leak is very small; observing it requires a large number of measurements. The effect is largest for curves whose group order lies on a machine-word boundary, such as brainpoolP384r1. Applications using ECDSA signing over the Brainpool and other generic prime curves, and SM2 signing on platforms that use the generic implementation, are vulnerable to this issue. The NIST curves P-256, P-384 and P-521 use dedicated constant-time implementations and are not affected. FIPS Impact: no The FIPS modules are not affected: the approved NIST curves used in the FIPS provider have dedicated constant-time implementations and do not use the affected code path. — /lib/apk/db/installed | |
| LOW | CVE-2026-54872 | libcrypto3 | 3.5.8-r0 | Issue summary: The generic elliptic-curve scalar multiplication used for ECDSA and SM2 signature operations with curves that do not have a dedicated implementation leaks information about the secret nonce through timing. Impact summary: An attacker able to measure signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key. CWE: CWE-208: Observable Timing Discrepancy Description: The generic elliptic-curve scalar multiplication used for curves that do not have a dedicated constant-time implementation pads the secret scalar with non-constant-time BIGNUM operations, so the time taken depends on the value of the secret scalar derived from the ECDSA and SM2 nonce. The leak is very small; observing it requires a large number of measurements. The effect is largest for curves whose group order lies on a machine-word boundary, such as brainpoolP384r1. Applications using ECDSA signing over the Brainpool and other generic prime curves, and SM2 signing on platforms that use the generic implementation, are vulnerable to this issue. The NIST curves P-256, P-384 and P-521 use dedicated constant-time implementations and are not affected. FIPS Impact: no The FIPS modules are not affected: the approved NIST curves used in the FIPS provider have dedicated constant-time implementations and do not use the affected code path. — /lib/apk/db/installed | |
| LOW | CVE-2026-35191 | libcrypto3 | 3.5.8-r0 | Issue summary: The OpenSSL QUIC server, when configured to not preform address validation, can be forced to count incoming packets multiple times in its unvalidated credit computation, leading to a violation of the RFC 9000 unvalidated connection amplification limit of 3 times the amount of data received. Impact summary: A remote attacker able to spoof packets to a server using the OpenSSL QUIC implementation might use the server for an amplification of a DDoS attack. CWE: CWE-440: Expected Behavior Violation Description: OpenSSL's QUIC stack, when operating as a server, enforces client address validation (RFC 9000, Section 8), to confirm the peer address is not used for a traffic amplification attack. If this feature is disabled on the server, the QUIC stack limits the amount of server data that can be sent to 3 times the amount of data received from the peer address, until such time as the TLS handshake is completed. The OpenSSL QUIC server, when operating in non-validation mode, adds the length of the whole datagram received to the unvalidated credit limit when processing each QUIC packet in the datagram. A remote peer may, after establishing a connection with an initial client hello frame, send a subsequent datagram containing multiple QUIC packets, leading the server to account the entire datagram length for each packet in the datagram, resulting in the server believing that the peer has sent more data than it actually has, thereby violating the 3x amplification limit mandated by the RFC. FIPS impact: no As the QUIC stack lives outside the FIPS module boundary, no FIPS modules are affected by this CVE. — /lib/apk/db/installed | |
| LOW | CVE-2026-35191 | libssl3 | 3.5.8-r0 | Issue summary: The OpenSSL QUIC server, when configured to not preform address validation, can be forced to count incoming packets multiple times in its unvalidated credit computation, leading to a violation of the RFC 9000 unvalidated connection amplification limit of 3 times the amount of data received. Impact summary: A remote attacker able to spoof packets to a server using the OpenSSL QUIC implementation might use the server for an amplification of a DDoS attack. CWE: CWE-440: Expected Behavior Violation Description: OpenSSL's QUIC stack, when operating as a server, enforces client address validation (RFC 9000, Section 8), to confirm the peer address is not used for a traffic amplification attack. If this feature is disabled on the server, the QUIC stack limits the amount of server data that can be sent to 3 times the amount of data received from the peer address, until such time as the TLS handshake is completed. The OpenSSL QUIC server, when operating in non-validation mode, adds the length of the whole datagram received to the unvalidated credit limit when processing each QUIC packet in the datagram. A remote peer may, after establishing a connection with an initial client hello frame, send a subsequent datagram containing multiple QUIC packets, leading the server to account the entire datagram length for each packet in the datagram, resulting in the server believing that the peer has sent more data than it actually has, thereby violating the 3x amplification limit mandated by the RFC. FIPS impact: no As the QUIC stack lives outside the FIPS module boundary, no FIPS modules are affected by this CVE. — /lib/apk/db/installed | |
| LOW | CVE-2026-35191 | openssl | 3.5.8-r0 | Issue summary: The OpenSSL QUIC server, when configured to not preform address validation, can be forced to count incoming packets multiple times in its unvalidated credit computation, leading to a violation of the RFC 9000 unvalidated connection amplification limit of 3 times the amount of data received. Impact summary: A remote attacker able to spoof packets to a server using the OpenSSL QUIC implementation might use the server for an amplification of a DDoS attack. CWE: CWE-440: Expected Behavior Violation Description: OpenSSL's QUIC stack, when operating as a server, enforces client address validation (RFC 9000, Section 8), to confirm the peer address is not used for a traffic amplification attack. If this feature is disabled on the server, the QUIC stack limits the amount of server data that can be sent to 3 times the amount of data received from the peer address, until such time as the TLS handshake is completed. The OpenSSL QUIC server, when operating in non-validation mode, adds the length of the whole datagram received to the unvalidated credit limit when processing each QUIC packet in the datagram. A remote peer may, after establishing a connection with an initial client hello frame, send a subsequent datagram containing multiple QUIC packets, leading the server to account the entire datagram length for each packet in the datagram, resulting in the server believing that the peer has sent more data than it actually has, thereby violating the 3x amplification limit mandated by the RFC. FIPS impact: no As the QUIC stack lives outside the FIPS module boundary, no FIPS modules are affected by this CVE. — /lib/apk/db/installed | |
| LOW | CVE-2026-35191 | openssl-dev | 3.5.8-r0 | Issue summary: The OpenSSL QUIC server, when configured to not preform address validation, can be forced to count incoming packets multiple times in its unvalidated credit computation, leading to a violation of the RFC 9000 unvalidated connection amplification limit of 3 times the amount of data received. Impact summary: A remote attacker able to spoof packets to a server using the OpenSSL QUIC implementation might use the server for an amplification of a DDoS attack. CWE: CWE-440: Expected Behavior Violation Description: OpenSSL's QUIC stack, when operating as a server, enforces client address validation (RFC 9000, Section 8), to confirm the peer address is not used for a traffic amplification attack. If this feature is disabled on the server, the QUIC stack limits the amount of server data that can be sent to 3 times the amount of data received from the peer address, until such time as the TLS handshake is completed. The OpenSSL QUIC server, when operating in non-validation mode, adds the length of the whole datagram received to the unvalidated credit limit when processing each QUIC packet in the datagram. A remote peer may, after establishing a connection with an initial client hello frame, send a subsequent datagram containing multiple QUIC packets, leading the server to account the entire datagram length for each packet in the datagram, resulting in the server believing that the peer has sent more data than it actually has, thereby violating the 3x amplification limit mandated by the RFC. FIPS impact: no As the QUIC stack lives outside the FIPS module boundary, no FIPS modules are affected by this CVE. — /lib/apk/db/installed |
ghcr.io/voxpupuli/commitlint
Downloads
ghcr.io/voxpupuli/commitlint:latest (2026-08-27)
Trivy
HIGH 29
MEDIUM 22
LOW 8
UNKNOWN 15
| Severity | ID | Package | Installed | Fixed | Title / target |
|---|---|---|---|---|---|
| HIGH | CVE-2026-73566 | tar | 7.5.19 | 7.5.21 | tar: node-tar: Denial of Service via crafted long-path tar archive — Node.js |
| HIGH | CVE-2026-69152 | brace-expansion | 5.0.7 | 1.1.18, 2.1.4, 3.0.6, 5.0.9 | brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation — Node.js |
| HIGH | CVE-2026-14257 | brace-expansion | 5.0.7 | 5.0.8, 3.0.3, 2.1.3, 1.1.17 | brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function — Node.js |
| HIGH | CVE-2026-102278 | brace-expansion | 5.0.7 | 5.0.11, 3.0.8, 2.1.6, 1.1.20 | brace-expansion: brace-expansion: Denial of Service via uncontrolled recursion in nested brace patterns — Node.js |
| HIGH | CVE-2026-102276 | brace-expansion | 5.0.7 | 5.0.10, 3.0.7, 2.1.5, 1.1.19 | brace-expansion: brace-expansion: Denial of Service via stack exhaustion from crafted brace patterns — Node.js |
| HIGH | CVE-2026-19534 | undici | 6.27.0 | 6.28.1, 7.29.1, 8.10.2 | undici: undici: Denial of Service via unrequested WebSocket subprotocol — Node.js |
| HIGH | CVE-2026-93748 | http-cache-semantics | 4.2.0 | http-cache-semantics: http-cache-semantics: Information Disclosure via max-stale directive — Node.js | |
| HIGH | CVE-2026-69192 | ip-address | 10.2.0 | 10.3.1 | ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass — Node.js |
| HIGH | CVE-2026-84292 | fast-uri | 3.1.6 | 2.4.6, 3.1.7, 4.1.4 | fast-uri: fast-uri: Authority Injection via Unvalidated Port Serialization — Node.js |
| HIGH | CVE-2026-84394 | fast-uri | 3.1.6 | 2.4.6, 3.1.7, 4.1.4 | fast-uri: fast-uri: Host confusion via unbalanced URI brackets can bypass security policies — Node.js |
| HIGH | CVE-2026-89161 | pcre2 | 10.47-r1 | 10.48-r0 | pcre2: PCRE2: Memory corruption vulnerability in pcre2_jit_match — ghcr.io/voxpupuli/commitlint:latest (alpine 3.24.1) |
| HIGH | CVE-2026-89157 | pcre2 | 10.47-r1 | 10.48-r0 | pcre2: PCRE2: Out-of-bounds write via large pattern input — ghcr.io/voxpupuli/commitlint:latest (alpine 3.24.1) |
| HIGH | CVE-2026-86145 | pcre2 | 10.47-r1 | 10.48-r0 | pcre2: PCRE2: Out-of-bounds write allows arbitrary code execution via crafted regular expressions — ghcr.io/voxpupuli/commitlint:latest (alpine 3.24.1) |
| HIGH | CVE-2026-103111 | pcre2 | 10.47-r1 | 10.49-r0 | pcre2: pcre2: Out-of-bounds write via crafted regular expression — ghcr.io/voxpupuli/commitlint:latest (alpine 3.24.1) |
| HIGH | CVE-2026-56852 | golang.org/x/text | v0.38.0 | 0.39.0 | golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc |
| HIGH | CVE-2026-93990 | libexpat | 2.8.3-r0 | 2.8.5-r0 | expat: Expat: XML Injection via Malformed UTF-16 Input — ghcr.io/voxpupuli/commitlint:latest (alpine 3.24.1) |
| HIGH | CVE-2026-76957 | libexpat | 2.8.3-r0 | 2.8.4-r0 | libexpat: libexpat: Memory corruption vulnerability allows arbitrary code execution or denial of service — ghcr.io/voxpupuli/commitlint:latest (alpine 3.24.1) |
| HIGH | CVE-2026-76956 | libexpat | 2.8.3-r0 | 2.8.4-r0 | libexpat: libexpat: Denial of Service via hash flooding attack with crafted XML — ghcr.io/voxpupuli/commitlint:latest (alpine 3.24.1) |
| HIGH | CVE-2026-76641 | libexpat | 2.8.3-r0 | 2.8.4-r0 | expat: Expat: Denial of Service via XML external entity parsing — ghcr.io/voxpupuli/commitlint:latest (alpine 3.24.1) |
| HIGH | CVE-2026-66046 | libexpat | 2.8.3-r0 | 2.8.4-r0 | expat: Expat: Denial of Service via quadratic complexity in attribute processing — ghcr.io/voxpupuli/commitlint:latest (alpine 3.24.1) |
| HIGH | CVE-2026-33818 | stdlib | v1.26.4 | 1.25.13, 1.26.6, 1.27.0-rc.3 | encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc |
| HIGH | CVE-2026-39821 | stdlib | v1.26.4 | 1.25.13, 1.26.6, 1.27.0-rc.3 | golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc |
| HIGH | CVE-2026-39822 | stdlib | v1.26.4 | 1.25.12, 1.26.5, 1.27.0-rc.2 | golang: Go os.Root: Symlink following vulnerability allows directory traversal — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc |
| HIGH | CVE-2026-46600 | stdlib | v1.26.4 | 1.26.6, 1.27.0-rc.3 | golang.org/x/net/dns/dnsmessage: golang.org/x/net/dns/dnsmessage: Denial of Service via invalid DNS record parsing — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc |
| HIGH | CVE-2026-56853 | stdlib | v1.26.4 | 1.25.13, 1.26.6, 1.27.0-rc.3 | net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc |
| HIGH | CVE-2026-56858 | stdlib | v1.26.4 | 1.25.13, 1.26.6, 1.27.0-rc.3 | html/template: golang: Go html/template: Cross-Site Scripting via pathological input — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc |
| HIGH | CVE-2026-56859 | stdlib | v1.26.4 | 1.25.13, 1.26.6, 1.27.0-rc.3 | encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc |
| HIGH | CVE-2026-56860 | stdlib | v1.26.4 | 1.25.13, 1.26.6, 1.27.0-rc.3 | net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc |
| HIGH | CVE-2026-56862 | stdlib | v1.26.4 | 1.25.13, 1.26.6, 1.27.0-rc.3 | crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc |
| MEDIUM | CVE-2026-104844 | postcss-selector-parser | 7.1.4 | 7.1.6 | postcss-selector-parser: postcss-selector-parser: Denial of Service via crafted CSS selectors — Node.js |
| MEDIUM | CVE-2026-69198 | ip-address | 10.2.0 | 10.2.2 | ip-address: ip-address: Server-Side Request Forgery (SSRF) and trust-boundary bypass — Node.js |
| MEDIUM | CVE-2026-54272 | ip-address | 10.2.0 | 10.2.1 | ip-address: ip-address: Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification — Node.js |
| MEDIUM | CVE-2026-101913 | ip-address | 10.2.0 | 10.5.1 | ip-address: ip-address: Security bypass via incomplete IPv6 link-local address validation — Node.js |
| MEDIUM | CVE-2026-15157 | undici | 6.27.0 | 6.28.0, 7.29.0, 8.9.0 | undici: undici: HTTP header injection via unvalidated blob-like body type property — Node.js |
| MEDIUM | CVE-2026-16728 | undici | 6.27.0 | 6.28.0, 7.29.0, 8.9.0 | undici: undici: Response desynchronization via retry interceptor with mismatched Content-Length — Node.js |
| MEDIUM | CVE-2026-16729 | undici | 6.27.0 | 6.28.0, 7.29.0, 8.9.0 | undici: Undici: Cookie attribute injection allows bypassing security protections — Node.js |
| MEDIUM | CVE-2026-85024 | undici | 6.27.0 | 6.28.1, 7.29.1, 8.10.2 | undici: undici: Denial of Service via unhandled error in WebSocket permessage-deflate decompression — Node.js |
| MEDIUM | CVE-2026-42505 | stdlib | v1.26.4 | 1.25.12, 1.26.5, 1.27.0-rc.2 | crypto/tls: golang: Go crypto/tls: Information disclosure in Encrypted Client Hello — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc |
| MEDIUM | CVE-2026-82208 | libcurl | 8.21.0-r0 | 8.22.0-r0 | curl: libcurl: Improper certificate validation when using wolfSSL CA cache — ghcr.io/voxpupuli/commitlint:latest (alpine 3.24.1) |
| MEDIUM | CVE-2026-58055 | nghttp2-libs | 1.69.0-r0 | 1.70.0-r0 | nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests — ghcr.io/voxpupuli/commitlint:latest (alpine 3.24.1) |
| MEDIUM | CVE-2026-80229 | libcurl | 8.21.0-r0 | 8.22.0-r0 | When performing transfers via libcurl\u2019s multi interface, pooled T ... — ghcr.io/voxpupuli/commitlint:latest (alpine 3.24.1) |
| MEDIUM | CVE-2026-89156 | pcre2 | 10.47-r1 | 10.48-r0 | PCRE2: PCRE2: Out-of-bounds read via invalid UTF data during JIT fallback — ghcr.io/voxpupuli/commitlint:latest (alpine 3.24.1) |
| MEDIUM | CVE-2026-89158 | pcre2 | 10.47-r1 | 10.48-r0 | PCRE2: PCRE2: Out-of-bounds write via integer overflow on 32-bit platforms — ghcr.io/voxpupuli/commitlint:latest (alpine 3.24.1) |
| MEDIUM | CVE-2026-89160 | pcre2 | 10.47-r1 | 10.48-r0 | pcre2: PCRE2: Denial of Service via out-of-bounds read during invalid UTF matching — ghcr.io/voxpupuli/commitlint:latest (alpine 3.24.1) |
| MEDIUM | CVE-2026-19931 | libcurl | 8.21.0-r0 | 8.22.0-r0 | curl: libcurl: Information disclosure via incorrect connection reuse with Negotiate authentication — ghcr.io/voxpupuli/commitlint:latest (alpine 3.24.1) |
| MEDIUM | CVE-2026-85091 | zlib | 1.3.2-r0 | 1.3.2-r1 | zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vul ... — ghcr.io/voxpupuli/commitlint:latest (alpine 3.24.1) |
| MEDIUM | CVE-2026-102277 | brace-expansion | 5.0.7 | 5.0.12, 3.0.9, 2.1.7, 1.1.21 | brace-expansion: brace-expansion: Denial of Service via crafted brace patterns — Node.js |
| MEDIUM | CVE-2026-86472 | fast-uri | 3.1.6 | 2.4.7, 3.1.8, 4.1.5 | fast-uri: fast-uri: Security bypass due to inconsistent host case normalization — Node.js |
| MEDIUM | CVE-2026-101910 | ip-address | 10.2.0 | 10.5.1 | ip-address: ip-address: Security boundary bypass via unclassified NAT64 local-use address range — Node.js |
| MEDIUM | CVE-2026-101911 | ip-address | 10.2.0 | 10.7.1 | ip-address: ip-address: Denial of Service via unbounded IPv6 address parsing — Node.js |
| MEDIUM | CVE-2026-101912 | ip-address | 10.2.0 | 10.7.1 | ip-address: ip-address: Access control bypass via cross-family subnet comparison — Node.js |
| LOW | CVE-2026-13608 | libcurl | 8.21.0-r0 | 8.22.0-r0 | curl: curl: Authentication bypass in OpenLDAP SASL negotiation via Man-in-the-Middle (MITM) attack — ghcr.io/voxpupuli/commitlint:latest (alpine 3.24.1) |
| LOW | CVE-2026-18924 | libcurl | 8.21.0-r0 | 8.22.0-r0 | curl: libcurl: Use-after-free in HTTP/2 Server Push with shared connections — ghcr.io/voxpupuli/commitlint:latest (alpine 3.24.1) |
| LOW | CVE-2026-80230 | libcurl | 8.21.0-r0 | 8.22.0-r0 | curl: curl: Public key pinning bypass allows unauthenticated connections — ghcr.io/voxpupuli/commitlint:latest (alpine 3.24.1) |
| LOW | CVE-2026-80231 | libcurl | 8.21.0-r0 | 8.22.0-r0 | curl: curl: Incorrect HTTPS connection reuse with Native CA Store — ghcr.io/voxpupuli/commitlint:latest (alpine 3.24.1) |
| LOW | CVE-2026-80255 | libcurl | 8.21.0-r0 | 8.22.0-r0 | curl: curl: Information disclosure due to secure cookie attribute bypass — ghcr.io/voxpupuli/commitlint:latest (alpine 3.24.1) |
| LOW | CVE-2026-82209 | libcurl | 8.21.0-r0 | 8.22.0-r0 | curl: libcurl: Information disclosure via improper Public Suffix List boundary check — ghcr.io/voxpupuli/commitlint:latest (alpine 3.24.1) |
| LOW | CVE-2026-18540 | undici | 6.27.0 | 6.28.1, 7.29.1, 8.10.2 | undici: undici: HTTP response splitting via retry interceptor — Node.js |
| LOW | CVE-2026-89162 | pcre2 | 10.47-r1 | 10.48-r0 | pcre2: PCRE2: Information disclosure via pcre2_serialize_encode — ghcr.io/voxpupuli/commitlint:latest (alpine 3.24.1) |
| UNKNOWN | CVE-2026-97032 | stdlib | v1.26.4 | 1.26.9, 1.27.2 | HTTP/2 server crash due to HPACK encoder race in net/http — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc |
| UNKNOWN | CVE-2026-97031 | stdlib | v1.26.4 | 1.26.9, 1.27.2 | Reject malformed ECH outer extension references in crypto/tls — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc |
| UNKNOWN | CVE-2026-97030 | stdlib | v1.26.4 | 1.26.9, 1.27.2 | Recognize yield as regexp preceder keyword in html/template — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc |
| UNKNOWN | CVE-2026-94448 | stdlib | v1.26.4 | 1.26.9, 1.27.2 | Reset context tracking on consecutive template expressions in html/template — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc |
| UNKNOWN | CVE-2026-94440 | stdlib | v1.26.4 | 1.26.9, 1.27.2 | Memory limit bypass when parsing MIME headers in net/textproto, mime/multipart — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc |
| UNKNOWN | CVE-2026-94439 | stdlib | v1.26.4 | 1.26.9, 1.27.2 | HTTP/1 server connection desynchronization after 2xx CONNECT response in net/http — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc |
| UNKNOWN | CVE-2026-78669 | stdlib | v1.26.4 | 1.26.9, 1.27.2 | Excessive CPU consumption from repeated initial window changes in net/http — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc |
| UNKNOWN | CVE-2026-78667 | stdlib | v1.26.4 | 1.26.9, 1.27.2 | Lack of limit on size of parsed Range headers in net/http — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc |
| UNKNOWN | CVE-2026-78663 | stdlib | v1.26.4 | 1.26.9, 1.27.2 | Double flow control refund on HTTP/2 server streams in net/http — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc |
| UNKNOWN | CVE-2026-78660 | stdlib | v1.26.4 | 1.26.9, 1.27.2 | HTTP/2 transport accepts malformed framing-related headers in net/http — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc |
| UNKNOWN | CVE-2026-78659 | stdlib | v1.26.4 | 1.26.9, 1.27.2 | HTTP/2 server memory exhaustion due to Trailer headers in net/http — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc |
| UNKNOWN | CVE-2026-56866 | stdlib | v1.26.4 | 1.26.9, 1.27.2 | HTTP/1 client connection desynchronization after CONNECT rejection in net/http — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc |
| UNKNOWN | CVE-2026-56857 | stdlib | v1.26.4 | 1.26.9, 1.27.2 | Root.Mkdir(All) can follow junctions out of the root on Windows in os — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc |
| UNKNOWN | CVE-2026-56851 | golang.org/x/text | v0.38.0 | 0.41.0 | The Nickname profile can panic with an out-of-bounds slice error when ... — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc |
| UNKNOWN | CVE-2026-80256 | libcurl | 8.21.0-r0 | 8.22.0-r0 | Title Not Available — ghcr.io/voxpupuli/commitlint:latest (alpine 3.24.1) |
Grype
CRITICAL 2
HIGH 36
MEDIUM 20
LOW 2
UNKNOWN 1
NVD/CPE filtered 29
| Severity | ID | Package | Installed | Fixed | Title / target |
|---|---|---|---|---|---|
| CRITICAL | CVE-2026-19931 | libcurl | 8.21.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| CRITICAL | CVE-2026-18924 | libcurl | 8.21.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | GO-2026-5970 | golang.org/x/text | v0.37.0 | 0.39.0 | A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes. — /usr/bin/git-lfs |
| HIGH | GO-2026-5970 | golang.org/x/text | v0.38.0 | 0.39.0 | A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes. — /npm/node_modules/@typescript/typescript-linux-x64/lib/tsc |
| HIGH | CVE-2026-93990 | libexpat | 2.8.3-r0 | 2.8.5-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-86145 | pcre2 | 10.47-r1 | 10.48-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-82208 | libcurl | 8.21.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | GHSA-rfgv-xxqx-mfg5 | undici | 6.27.0 | 6.28.1 | undici vulnerable to Denial of Service via unrequested WebSocket subprotocol — /usr/local/lib/node_modules/npm/node_modules/undici/package.json |
| HIGH | CVE-2026-82209 | libcurl | 8.21.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-76641 | libexpat | 2.8.3-r0 | 2.8.4-r0 | /lib/apk/db/installed |
| HIGH | GHSA-58mr-gqgx-xq4g | fast-uri | 3.1.6 | 3.1.7 | fast-uri vulnerable to host confusion via an unclosed bracket in the URI authority — /npm/node_modules/fast-uri/package.json |
| HIGH | CVE-2026-80230 | libcurl | 8.21.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | GHSA-qhr7-859c-m2p7 | brace-expansion | 5.0.7 | 5.0.11 | brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion — /usr/local/lib/node_modules/npm/node_modules/brace-expansion/package.json |
| HIGH | GHSA-6j4f-fj2g-mc7p | brace-expansion | 5.0.7 | 5.0.10 | brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion — /usr/local/lib/node_modules/npm/node_modules/brace-expansion/package.json |
| HIGH | CVE-2026-76956 | libexpat | 2.8.3-r0 | 2.8.4-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-89157 | pcre2 | 10.47-r1 | 10.48-r0 | /lib/apk/db/installed |
| HIGH | GHSA-qw65-cvwx-89v3 | fast-uri | 3.1.6 | 3.1.7 | fast-uri vulnerable to authority injection via an unvalidated port in serialize — /npm/node_modules/fast-uri/package.json |
| HIGH | CVE-2026-103111 | pcre2 | 10.47-r1 | 10.49-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-89161 | pcre2 | 10.47-r1 | 10.48-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-76957 | libexpat | 2.8.3-r0 | 2.8.4-r0 | /lib/apk/db/installed |
| HIGH | GO-2026-5026 | stdlib | go1.26.3 | 1.25.13, 1.26.6, 1.27.0-rc.3 | The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com". — /usr/bin/git-lfs |
| HIGH | GO-2026-5026 | golang.org/x/net | v0.54.0 | 0.55.0 | The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com". — /usr/bin/git-lfs |
| HIGH | GHSA-mwp4-54f8-5fhr | ip-address | 10.2.0 | 10.3.1 | ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass — /usr/local/lib/node_modules/npm/node_modules/ip-address/package.json |
| HIGH | GHSA-rgw5-rvv9-x895 | brace-expansion | 5.0.7 | 5.0.9 | brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation — /usr/local/lib/node_modules/npm/node_modules/brace-expansion/package.json |
| HIGH | CVE-2026-66046 | libexpat | 2.8.3-r0 | 2.8.4-r0 | /lib/apk/db/installed |
| HIGH | GHSA-mh99-v99m-4gvg | brace-expansion | 5.0.7 | 5.0.8 | brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash — /usr/local/lib/node_modules/npm/node_modules/brace-expansion/package.json |
| HIGH | GO-2026-5942 | golang.org/x/net | v0.54.0 | 0.56.0 | Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer. — /usr/bin/git-lfs |
| HIGH | GO-2026-5942 | stdlib | go1.26.3 | 1.26.6, 1.27.0-rc.3 | Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer. — /usr/bin/git-lfs |
| HIGH | CVE-2026-85091 | zlib | 1.3.2-r0 | 1.3.2-r1 | /lib/apk/db/installed |
| HIGH | GO-2026-5037 | stdlib | go1.26.3 | 1.25.11, 1.26.4 | (*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates. — /usr/bin/git-lfs |
| HIGH | GO-2026-6090 | stdlib | go1.26.3 | 1.25.13, 1.26.6, 1.27.0-rc.3 | Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely. — /usr/bin/git-lfs |
| HIGH | GO-2026-5972 | stdlib | go1.26.3 | 1.25.13, 1.26.6, 1.27.0-rc.3 | Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures. — /usr/bin/git-lfs |
| HIGH | CVE-2026-80231 | libcurl | 8.21.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-13608 | libcurl | 8.21.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-80255 | libcurl | 8.21.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-80229 | libcurl | 8.21.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | GHSA-ch52-4w7c-c8xp | http-cache-semantics | 4.2.0 | http-cache-semantics max-stale handling can disclose cross-user cached responses — /usr/local/lib/node_modules/npm/node_modules/http-cache-semantics/package.json | |
| HIGH | GHSA-r292-9mhp-454m | tar | 7.5.19 | 7.5.21 | node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection — /usr/local/lib/node_modules/npm/node_modules/tar/package.json |
| MEDIUM | GHSA-h3mg-xc3c-68pw | ip-address | 10.2.0 | 10.7.1 | ip-address: Address6 builds a parse diagnostic proportional to the input with no length bound, allowing a single long string to stall or crash the process — /usr/local/lib/node_modules/npm/node_modules/ip-address/package.json |
| MEDIUM | CVE-2026-89156 | pcre2 | 10.47-r1 | 10.48-r0 | /lib/apk/db/installed |
| MEDIUM | GHSA-q2hr-2g5m-vwhr | brace-expansion | 5.0.7 | 5.0.12 | brace-expansion: Quadratic-time expansion of the `{a},b}` rewrite causes CPU denial of service — /usr/local/lib/node_modules/npm/node_modules/brace-expansion/package.json |
| MEDIUM | CVE-2026-89160 | pcre2 | 10.47-r1 | 10.48-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-89158 | pcre2 | 10.47-r1 | 10.48-r0 | /lib/apk/db/installed |
| MEDIUM | GHSA-hrr3-gc8f-f4qj | fast-uri | 3.1.6 | 3.1.8 | fast-uri vulnerable to inconsistent host case normalization via percent-encoded octets — /npm/node_modules/fast-uri/package.json |
| MEDIUM | GHSA-v3r7-h72x-cjcm | undici | 6.27.0 | 6.28.0 | undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields — /usr/local/lib/node_modules/npm/node_modules/undici/package.json |
| MEDIUM | GHSA-m8rv-5g2x-5cg5 | undici | 6.27.0 | 6.28.0 | undici vulnerable to CRLF Injection via blob-like body 'type' property — /usr/local/lib/node_modules/npm/node_modules/undici/package.json |
| MEDIUM | GHSA-8xcm-r25x-g524 | undici | 6.27.0 | 6.28.0 | undici vulnerable to downstream response desynchronization via retry interceptor — /usr/local/lib/node_modules/npm/node_modules/undici/package.json |
| MEDIUM | CVE-2026-58055 | nghttp2-libs | 1.69.0-r0 | 1.70.0-r0 | /lib/apk/db/installed |
| MEDIUM | GO-2026-5856 | stdlib | go1.26.3 | 1.25.12, 1.26.5, 1.27.0-rc.2 | Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello. — /usr/bin/git-lfs |
| MEDIUM | GHSA-j6r3-76f7-8jcv | ip-address | 10.2.0 | 10.7.1 | ip-address: isInSubnet() and isHostInSubnet() compare addresses of different families as if they shared an address space, allowing an allowlist check to admit an address outside its range — /usr/local/lib/node_modules/npm/node_modules/ip-address/package.json |
| MEDIUM | GO-2026-5039 | stdlib | go1.26.3 | 1.25.11, 1.26.4 | When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or logged. — /usr/bin/git-lfs |
| MEDIUM | GHSA-rj75-hqrm-r3gf | postcss-selector-parser | 7.1.4 | 7.1.6 | PostCSS: Quadratic complexity in flat selector parsing allows CPU exhaustion — /usr/local/lib/node_modules/npm/node_modules/postcss-selector-parser/package.json |
| MEDIUM | GHSA-rpw4-54j3-4h4q | ip-address | 10.2.0 | 10.5.1 | ip-address: Address6.isLinkLocal() recognizes fe80::/64 rather than fe80::/10, allowing SSRF and trust-boundary bypass to on-link hosts — /usr/local/lib/node_modules/npm/node_modules/ip-address/package.json |
| MEDIUM | GHSA-3wwx-pv8p-q78v | undici | 6.27.0 | 6.28.1 | undici vulnerable to Denial of Service via unhandled error in WebSocket permessage-deflate decompression — /usr/local/lib/node_modules/npm/node_modules/undici/package.json |
| MEDIUM | GHSA-2vr4-cq9g-pvrc | ip-address | 10.2.0 | 10.5.1 | ip-address: no classifier recognizes the NAT64 local-use range 64:ff9b:1::/48, allowing SSRF and trust-boundary bypass — /usr/local/lib/node_modules/npm/node_modules/ip-address/package.json |
| MEDIUM | GHSA-22jq-vg5j-6vgg | ip-address | 10.2.0 | 10.2.1 | ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSRF and trust-boundary checks — /usr/local/lib/node_modules/npm/node_modules/ip-address/package.json |
| MEDIUM | GHSA-4xrf-jv44-h6hh | ip-address | 10.2.0 | 10.2.2 | ip-address: a CIDR suffix on the parsed address suppresses special-use classification and can bypass SSRF and trust-boundary checks — /usr/local/lib/node_modules/npm/node_modules/ip-address/package.json |
| MEDIUM | GO-2026-6218 | stdlib | go1.26.3 | 1.25.13, 1.26.6, 1.27.0-rc.3 | Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations. — /usr/bin/git-lfs |
| LOW | GHSA-r53p-7pc4-xj5r | undici | 6.27.0 | 6.28.1 | undici vulnerable to downstream response splitting via retry interceptor — /usr/local/lib/node_modules/npm/node_modules/undici/package.json |
| LOW | CVE-2026-89162 | pcre2 | 10.47-r1 | 10.48-r0 | /lib/apk/db/installed |
| UNKNOWN | CVE-2026-80256 | libcurl | 8.21.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
Filtered NVD/CPE matches (29)
These broad CPE matches are unconfirmed for the distribution package and excluded from scanner totals.
| Severity | ID | Package | Installed | Fixed | Title / target |
|---|---|---|---|---|---|
| HIGH | CVE-2026-54873 | libcrypto3 | 3.5.8-r0 | Issue summary: QUIC process may keep memory for QUIC packet buffer for much longer period than necessary. Impact summary: Remote peer can exploit this vulnerability by sending maliciously crafted packets, making the local QUIC stack to keep the memory for packet buffers allocated. The time for which the memory remains allocated is entirely under the control of the potentially malicious remote peer. CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: To save copy operation from the packet buffer to the stream reassemble buffer the QUIC stack leaves the stream data on the packet buffer waiting to be copied to a buffer provided by the local receiving application. The QUIC stack releases a reference to the packet buffer only after the data are copied to the application buffer. This design is more efficient for legitimate data transfers but enables an attacker to allocate a lot more memory than actually required by the data kept in the receiving stream buffer. To mitigate the vulnerability, the QUIC stack now calculates and monitors memory overhead for every stream. The memory overhead for a single stream frame is calculated as a difference between the size of the whole packet that carries the stream frame and the size of the stream frame itself. The memory overhead for a single stream frame is added to the total (cumulative) memory overhead QUIC stack keeps for each stream. Once the cumulative memory overhead exceeds 64kB, the QUIC stack moves the stream frame data from the packet buffer to the stream buffer, starting with the next packet received. FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| HIGH | CVE-2026-54873 | libssl3 | 3.5.8-r0 | Issue summary: QUIC process may keep memory for QUIC packet buffer for much longer period than necessary. Impact summary: Remote peer can exploit this vulnerability by sending maliciously crafted packets, making the local QUIC stack to keep the memory for packet buffers allocated. The time for which the memory remains allocated is entirely under the control of the potentially malicious remote peer. CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: To save copy operation from the packet buffer to the stream reassemble buffer the QUIC stack leaves the stream data on the packet buffer waiting to be copied to a buffer provided by the local receiving application. The QUIC stack releases a reference to the packet buffer only after the data are copied to the application buffer. This design is more efficient for legitimate data transfers but enables an attacker to allocate a lot more memory than actually required by the data kept in the receiving stream buffer. To mitigate the vulnerability, the QUIC stack now calculates and monitors memory overhead for every stream. The memory overhead for a single stream frame is calculated as a difference between the size of the whole packet that carries the stream frame and the size of the stream frame itself. The memory overhead for a single stream frame is added to the total (cumulative) memory overhead QUIC stack keeps for each stream. Once the cumulative memory overhead exceeds 64kB, the QUIC stack moves the stream frame data from the packet buffer to the stream buffer, starting with the next packet received. FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| HIGH | CVE-2026-84782 | libcrypto3 | 3.5.8-r0 | Issue summary: The DTLS retransmission logic does not correctly handle a handshake message write that is suspended part-way through. The retransmitted message can be read past the message buffer and the retransmission overwrites the internal state the suspended write needs to resume correctly. Impact summary: The retransmitted message can disclose a heap memory to the peer as plaintext handshake data or cause a crash and a Denial of Service when the read reaches an unmapped memory region. CWE: CWE-125: Out-of-bounds Read Description: DTLS handshake messages can be written out in multiple fragments, and a write can suspend mid-message (returning WANT_WRITE) if the underlying transport temporarily cannot accept more data. While such a write is suspended, the DTLS retransmission timer may independently fire and ask the retransmission logic to resend an earlier, already-acknowledged-as-sent message from its retransmit queue. The retransmission logic reused the same internal buffer and position tracking as the message that was still being written, without resetting the position back to the start of the message being retransmitted. As a result the retransmission was read starting from wherever the suspended write had left off, producing a mislabelled message whose body was leftover bytes from the other, larger message still in flight - content that was never meant to be sent at that point, and which could run past the end of the allocated buffer. Separately, even when the retransmission is positioned correctly, allowing it to run to completion while another write is suspended overwrites the same shared bookkeeping that the suspended write depends on to resume. When the application later resumes the suspended write (via a subsequent SSL_read(), SSL_write(), SSL_accept(), or SSL_connect() call), it finds that bookkeeping in a state inconsistent with the message and aborts the process in a debugging build. The fix resets the retransmission's read position to the start of the message before resending, and skips retransmission entirely whenever a handshake write is still suspended, deferring to the next call that resumes it instead. FIPS impact: no The affected code is outside the FIPS module boundary. — /lib/apk/db/installed | |
| HIGH | CVE-2026-84782 | libssl3 | 3.5.8-r0 | Issue summary: The DTLS retransmission logic does not correctly handle a handshake message write that is suspended part-way through. The retransmitted message can be read past the message buffer and the retransmission overwrites the internal state the suspended write needs to resume correctly. Impact summary: The retransmitted message can disclose a heap memory to the peer as plaintext handshake data or cause a crash and a Denial of Service when the read reaches an unmapped memory region. CWE: CWE-125: Out-of-bounds Read Description: DTLS handshake messages can be written out in multiple fragments, and a write can suspend mid-message (returning WANT_WRITE) if the underlying transport temporarily cannot accept more data. While such a write is suspended, the DTLS retransmission timer may independently fire and ask the retransmission logic to resend an earlier, already-acknowledged-as-sent message from its retransmit queue. The retransmission logic reused the same internal buffer and position tracking as the message that was still being written, without resetting the position back to the start of the message being retransmitted. As a result the retransmission was read starting from wherever the suspended write had left off, producing a mislabelled message whose body was leftover bytes from the other, larger message still in flight - content that was never meant to be sent at that point, and which could run past the end of the allocated buffer. Separately, even when the retransmission is positioned correctly, allowing it to run to completion while another write is suspended overwrites the same shared bookkeeping that the suspended write depends on to resume. When the application later resumes the suspended write (via a subsequent SSL_read(), SSL_write(), SSL_accept(), or SSL_connect() call), it finds that bookkeeping in a state inconsistent with the message and aborts the process in a debugging build. The fix resets the retransmission's read position to the start of the message before resending, and skips retransmission entirely whenever a handshake write is still suspended, deferring to the next call that resumes it instead. FIPS impact: no The affected code is outside the FIPS module boundary. — /lib/apk/db/installed | |
| HIGH | CVE-2026-84784 | libcrypto3 | 3.5.8-r0 | Issue summary: A malicious remote peer may flood the local QUIC stack with NEW_CONNECTION_ID frames by avoiding a limit check on how many connection IDs the remote QUIC stack can use. Impact summary: The local QUIC stack sends a RETIRE_CONN_ID frame for every NEW_CONNECTION_ID frame it receives. The RETIRE_CONN_ID frame is dispatched via the Control Frame Queue (CFQ). If the remote peer also withholds ACKs, then it can force the local stack to allocate ~400MB (depending on ACK delay). CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: RFC 9000 sections 5.1.1 and 5.1.2 [1] describe the mechanism by which a remote peer can notify the local QUIC stack to change the destination connection ID (a.k.a. CID) the local stack uses to identify the connection at the remote peer. Each CID is associated with a sequence number. The sequence number is transmitted in NEW_CONNECTION_ID and RETIRE_CONNECTION_ID frames to identify the CID which is being either associated with a connection or retired. The remote peer sends a NEW_CONNECTION_ID frame to let the local stack know a new CID is being associated with an existing connection. The NEW_CONNECTION_ID frame carries the new CID, its sequence number, and the retire-prior-to number. The retire-prior-to identifies existing CIDs that are to be retired. The local QUIC stack must send a RETIRE_CONNECTION_ID for every destination CID whose sequence number is less than retire-prior-to. The CID becomes retired after the local stack receives an ACK for its RETIRE_CONNECTION_ID frame. Although the OpenSSL QUIC stack supports at most one destination CID for every connection, it can be tricked into processing more than one RETIRE_CONNECTION_ID frame per connection. The OpenSSL QUIC stack currently retires the destination CID as soon as it receives the NEW_CONNECTION_ID, while in fact the destination CID must be retired after an ACK for the RETIRE_CONNECTION_ID frame is received. Correcting the flawed logic also fixes the backlog growth. [1] https://datatracker.ietf.org/doc/html/rfc9000#name-issuing-connection-ids FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| HIGH | CVE-2026-84784 | libssl3 | 3.5.8-r0 | Issue summary: A malicious remote peer may flood the local QUIC stack with NEW_CONNECTION_ID frames by avoiding a limit check on how many connection IDs the remote QUIC stack can use. Impact summary: The local QUIC stack sends a RETIRE_CONN_ID frame for every NEW_CONNECTION_ID frame it receives. The RETIRE_CONN_ID frame is dispatched via the Control Frame Queue (CFQ). If the remote peer also withholds ACKs, then it can force the local stack to allocate ~400MB (depending on ACK delay). CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: RFC 9000 sections 5.1.1 and 5.1.2 [1] describe the mechanism by which a remote peer can notify the local QUIC stack to change the destination connection ID (a.k.a. CID) the local stack uses to identify the connection at the remote peer. Each CID is associated with a sequence number. The sequence number is transmitted in NEW_CONNECTION_ID and RETIRE_CONNECTION_ID frames to identify the CID which is being either associated with a connection or retired. The remote peer sends a NEW_CONNECTION_ID frame to let the local stack know a new CID is being associated with an existing connection. The NEW_CONNECTION_ID frame carries the new CID, its sequence number, and the retire-prior-to number. The retire-prior-to identifies existing CIDs that are to be retired. The local QUIC stack must send a RETIRE_CONNECTION_ID for every destination CID whose sequence number is less than retire-prior-to. The CID becomes retired after the local stack receives an ACK for its RETIRE_CONNECTION_ID frame. Although the OpenSSL QUIC stack supports at most one destination CID for every connection, it can be tricked into processing more than one RETIRE_CONNECTION_ID frame per connection. The OpenSSL QUIC stack currently retires the destination CID as soon as it receives the NEW_CONNECTION_ID, while in fact the destination CID must be retired after an ACK for the RETIRE_CONNECTION_ID frame is received. Correcting the flawed logic also fixes the backlog growth. [1] https://datatracker.ietf.org/doc/html/rfc9000#name-issuing-connection-ids FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| HIGH | CVE-2026-72897 | libcrypto3 | 3.5.8-r0 | Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a connection to a different SSL_CTX part way through a handshake may access memory beyond the end of an internal array if the replacement context knows about more provider signature algorithms than the context the connection was created from. Applications which never call SSL_set_SSL_CTX() are not affected. Impact summary: A remote peer may be able to cause a small out-of-bounds read, and in some circumstances a fixed-value out-of-bounds write, on the server heap. This may lead to a Denial of Service. CWE: CWE-787: Out-of-bounds Write Description: A TLS connection records how many certificate slots it has when it is created, taken from the SSL_CTX that created it: the built-in certificate types plus one slot for each provider TLS-SIGALG entry that context was aware of. That count sizes an internal array of per-slot certificate validity flags. An application may replace a connection's SSL_CTX part way through the handshake by calling SSL_set_SSL_CTX(), most commonly from a servername callback in order to serve a different virtual host. Doing so did not refresh the recorded count. A provider signature algorithm's slot index is its position in the list of whichever context resolves it, so if the replacement context is aware of more of them than the original, an algorithm offered by the peer can resolve to an index beyond the end of the array. Processing the peer's signature algorithms then reads one four byte word past the end for each such algorithm and, where the word read is zero, writes a fixed value over it. A peer offering many of them can corrupt heap metadata and abort the process. Only provider signature algorithms which occupy one of the excess slots, and which the server also has configured, have this effect. Codepoints the replacement context does not recognise are discarded without being resolved to a slot, and provider signature algorithms are usable only from TLS 1.3. The two contexts must therefore be aware of different numbers of provider signature algorithms, which requires separate library contexts, a provider loaded between the two being created, or providers which differ in what they advertise - in 4.0, for example, the default provider advertises SM2 where the FIPS provider does not. A deployment meeting the condition is also unable to negotiate the affected algorithms with legitimate clients, since the same stale count hides the corresponding certificates, so the misconfiguration is likely to be noticed. For that reason, and because the configuration is not the default, this issue has been assessed as Low severity. FIPS impact: no No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| HIGH | CVE-2026-72897 | libssl3 | 3.5.8-r0 | Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a connection to a different SSL_CTX part way through a handshake may access memory beyond the end of an internal array if the replacement context knows about more provider signature algorithms than the context the connection was created from. Applications which never call SSL_set_SSL_CTX() are not affected. Impact summary: A remote peer may be able to cause a small out-of-bounds read, and in some circumstances a fixed-value out-of-bounds write, on the server heap. This may lead to a Denial of Service. CWE: CWE-787: Out-of-bounds Write Description: A TLS connection records how many certificate slots it has when it is created, taken from the SSL_CTX that created it: the built-in certificate types plus one slot for each provider TLS-SIGALG entry that context was aware of. That count sizes an internal array of per-slot certificate validity flags. An application may replace a connection's SSL_CTX part way through the handshake by calling SSL_set_SSL_CTX(), most commonly from a servername callback in order to serve a different virtual host. Doing so did not refresh the recorded count. A provider signature algorithm's slot index is its position in the list of whichever context resolves it, so if the replacement context is aware of more of them than the original, an algorithm offered by the peer can resolve to an index beyond the end of the array. Processing the peer's signature algorithms then reads one four byte word past the end for each such algorithm and, where the word read is zero, writes a fixed value over it. A peer offering many of them can corrupt heap metadata and abort the process. Only provider signature algorithms which occupy one of the excess slots, and which the server also has configured, have this effect. Codepoints the replacement context does not recognise are discarded without being resolved to a slot, and provider signature algorithms are usable only from TLS 1.3. The two contexts must therefore be aware of different numbers of provider signature algorithms, which requires separate library contexts, a provider loaded between the two being created, or providers which differ in what they advertise - in 4.0, for example, the default provider advertises SM2 where the FIPS provider does not. A deployment meeting the condition is also unable to negotiate the affected algorithms with legitimate clients, since the same stale count hides the corresponding certificates, so the misconfiguration is likely to be noticed. For that reason, and because the configuration is not the default, this issue has been assessed as Low severity. FIPS impact: no No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-75805 | libssl3 | 3.5.8-r0 | Issue summary: A CMP client that requests certificate revocation on the basis of a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when processing a crafted revocation response. Impact summary: The NULL pointer dereference happens on a read which leads to a crash and a Denial of Service for the affected client application. CWE: CWE-476: NULL-pointer dereference Description: A CMP client revoking a certificate has to tell the server which certificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the certificate itself or its issuer name and serial number. This is 'openssl cmp -cmd rr -csr <file>' on the command line, or OSSL_CMP_exec_RR_ses() with the certificate supplied via OSSL_CMP_CTX_set1_p10CSR() through the API. A CSR does not contain the issuer name and serial number of the certificate, so the client does not send them. A server may optionally name the certificate it revoked in its response, and the client then compares that name against what it sent. Having sent neither an issuer name nor a serial number, it has nothing to compare against, and a server returning a specially crafted name causes the client to read from a NULL pointer and crash. The revocation response is checked for valid message protection before the affected code is reached, so an attacker must be a malicious or compromised CMP server, or a man-in-the-middle in possession of the secret used for message protection. Clients that identify the certificate to be revoked by a certificate or by issuer and serial number rather than by a PKCS#10 CSR are not affected. FIPS impact: no No FIPS modules are affected by this issue, as the CMP protocol implementation is outside the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-75805 | libcrypto3 | 3.5.8-r0 | Issue summary: A CMP client that requests certificate revocation on the basis of a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when processing a crafted revocation response. Impact summary: The NULL pointer dereference happens on a read which leads to a crash and a Denial of Service for the affected client application. CWE: CWE-476: NULL-pointer dereference Description: A CMP client revoking a certificate has to tell the server which certificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the certificate itself or its issuer name and serial number. This is 'openssl cmp -cmd rr -csr <file>' on the command line, or OSSL_CMP_exec_RR_ses() with the certificate supplied via OSSL_CMP_CTX_set1_p10CSR() through the API. A CSR does not contain the issuer name and serial number of the certificate, so the client does not send them. A server may optionally name the certificate it revoked in its response, and the client then compares that name against what it sent. Having sent neither an issuer name nor a serial number, it has nothing to compare against, and a server returning a specially crafted name causes the client to read from a NULL pointer and crash. The revocation response is checked for valid message protection before the affected code is reached, so an attacker must be a malicious or compromised CMP server, or a man-in-the-middle in possession of the secret used for message protection. Clients that identify the certificate to be revoked by a certificate or by issuer and serial number rather than by a PKCS#10 CSR are not affected. FIPS impact: no No FIPS modules are affected by this issue, as the CMP protocol implementation is outside the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-35189 | libssl3 | 3.5.8-r0 | Issue summary: A certificate with many nameRelativeToCRLIssuer CRL distribution points causes disproportionate heap growth when OpenSSL caches X.509 extensions. Impact summary: Receiving a crafted certificate from a malicious peer can lead to significant memory pressure and possible Denial of Service in clients or in servers that solicit client certificates. CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: A certificate or a set of certificates that fits under the limit for size of certificates accepted from the peer (~100 KiB) can result in allocation of several hundred MiB of resident memory on the receiving side during a normal TLS handshake. This may be enough to crash the client or server, if multiple concurrent connections lead to similarly large memory allocations. The fix postpones processing of the CRL distribution points extensions in certificates to the time when the processed value is required for CRL processing. This avoids keeping large memory allocations for a long time when such certificates are received. FIPS impact: no The affected code is outside the FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-35189 | libcrypto3 | 3.5.8-r0 | Issue summary: A certificate with many nameRelativeToCRLIssuer CRL distribution points causes disproportionate heap growth when OpenSSL caches X.509 extensions. Impact summary: Receiving a crafted certificate from a malicious peer can lead to significant memory pressure and possible Denial of Service in clients or in servers that solicit client certificates. CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: A certificate or a set of certificates that fits under the limit for size of certificates accepted from the peer (~100 KiB) can result in allocation of several hundred MiB of resident memory on the receiving side during a normal TLS handshake. This may be enough to crash the client or server, if multiple concurrent connections lead to similarly large memory allocations. The fix postpones processing of the CRL distribution points extensions in certificates to the time when the processed value is required for CRL processing. This avoids keeping large memory allocations for a long time when such certificates are received. FIPS impact: no The affected code is outside the FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-60876 | ssl_client | 1.37.0-r31 | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-60876 | busybox-binsh | 1.37.0-r31 | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-60876 | busybox | 1.37.0-r31 | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-42772 | libssl3 | 3.5.8-r0 | Issue summary: The QUIC stream reassembly algorithm performance deteriorates progressively as packets are arriving out of order. The worst case has a quadratic complexity proportional to the number of stream frames kept in the buffer for the received stream data. Impact summary: A remote QUIC peer that completes the handshake can create a connection-scoped CPU pressure and potentially a Denial of Service using compliant STREAM frames inside the advertised receive window, with low attacker bandwidth. CWE: CWE-407: Inefficient Algorithmic Complexity Description: OpenSSL manages received QUIC stream fragments using a doubly-linked list. While it optimizes for append operations (at the end of the list), it falls back to a head-to-tail linear search for any fragment that does not immediately follow the current `tail`. By manipulating the sequence of offsets, an attacker can force the server to perform O(n^2) operations, consuming excessive CPU time for the QUIC process. FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-42772 | libcrypto3 | 3.5.8-r0 | Issue summary: The QUIC stream reassembly algorithm performance deteriorates progressively as packets are arriving out of order. The worst case has a quadratic complexity proportional to the number of stream frames kept in the buffer for the received stream data. Impact summary: A remote QUIC peer that completes the handshake can create a connection-scoped CPU pressure and potentially a Denial of Service using compliant STREAM frames inside the advertised receive window, with low attacker bandwidth. CWE: CWE-407: Inefficient Algorithmic Complexity Description: OpenSSL manages received QUIC stream fragments using a doubly-linked list. While it optimizes for append operations (at the end of the list), it falls back to a head-to-tail linear search for any fragment that does not immediately follow the current `tail`. By manipulating the sequence of offsets, an attacker can force the server to perform O(n^2) operations, consuming excessive CPU time for the QUIC process. FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-75804 | libssl3 | 3.5.8-r0 | Issue summary: OpenSSL QUIC stack does not enforce connection level flow control for streams. Remote peers may send more bytes as long as they fit within the stream flow control limits. Impact summary: A malicious remote peer may exploit the lack of connection flow control for streams to make the QUIC stack receive ~100MB of memory instead of 768 KiB (default flow control window size). CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: The local QUIC stack advertises two flow control limits to its remote peer: stream flow control limit and connection flow control limit. The remote peer must follow both limits when transmitting stream data. Whenever the local QUIC stack receives a stream frame, it validates that the size of the received stream frame stays within flow control limits. If either limit is exceeded (stream level or connection level), then the QUIC stack must close the connection with a flow control error. The vulnerable OpenSSL QUIC stack enforces the stream-level but not the connection-level limit. To exploit the issue, three conditions must be met: - the remote peer opens several streams - each stream must stay within the stream-level flow control limit - there must be no zero-offset byte sent on any of the streams (to prevent the vulnerable QUIC stack from consuming data). By meeting the conditions above, the remote peer may make the local stack allocate 2 x MAX_STREAMS x (stream flow control limit) bytes of memory. MAX_STREAMS defaults to 100, and the limit applies to both bidirectional and unidirectional streams, making it 200 in total. The default flow control window for a stream is 512kB. The remote peer may force the vulnerable QUIC stack to allocate 100MB of heap per connection. FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-75804 | libcrypto3 | 3.5.8-r0 | Issue summary: OpenSSL QUIC stack does not enforce connection level flow control for streams. Remote peers may send more bytes as long as they fit within the stream flow control limits. Impact summary: A malicious remote peer may exploit the lack of connection flow control for streams to make the QUIC stack receive ~100MB of memory instead of 768 KiB (default flow control window size). CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: The local QUIC stack advertises two flow control limits to its remote peer: stream flow control limit and connection flow control limit. The remote peer must follow both limits when transmitting stream data. Whenever the local QUIC stack receives a stream frame, it validates that the size of the received stream frame stays within flow control limits. If either limit is exceeded (stream level or connection level), then the QUIC stack must close the connection with a flow control error. The vulnerable OpenSSL QUIC stack enforces the stream-level but not the connection-level limit. To exploit the issue, three conditions must be met: - the remote peer opens several streams - each stream must stay within the stream-level flow control limit - there must be no zero-offset byte sent on any of the streams (to prevent the vulnerable QUIC stack from consuming data). By meeting the conditions above, the remote peer may make the local stack allocate 2 x MAX_STREAMS x (stream flow control limit) bytes of memory. MAX_STREAMS defaults to 100, and the limit applies to both bidirectional and unidirectional streams, making it 200 in total. The default flow control window for a stream is 512kB. The remote peer may force the vulnerable QUIC stack to allocate 100MB of heap per connection. FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-75806 | libssl3 | 3.5.8-r0 | Issue summary: An established DTLS 1.2 association using an AEAD cipher suite can be terminated by a single unauthenticated datagram whose encrypted fragment is shorter than the mandatory explicit IV and authentication tag overhead. Impact summary: An attacker who can send a datagram that is routed to an existing DTLS 1.2 association can tear that association down without knowing any key material. This is a Denial of Service limited to the targeted association. There is no memory safety or confidentiality impact. CWE: CWE-1284: Improper Validation of Specified Quantity in Input Description: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher suite carries an explicit IV followed by the ciphertext and an authentication tag. When decrypting such a record the record layer passed the record length to the cipher implementation before checking that the record was long enough to contain the explicit IV and the tag. For a record shorter than that overhead the cipher implementation rejected the impossible length, and the record layer treated this as an internal failure and raised a fatal internal_error alert instead of treating the record as one that failed authentication. In TLS 1.2 the same record causes a fatal internal_error alert instead of the expected bad_record_mac alert. Since any undecryptable record already terminates a TLS connection, this is a protocol conformance issue rather than a security issue in TLS. The fix validates the record length against the explicit IV and tag length before any AEAD processing, so that TLS reports bad_record_mac and DTLS silently discards the record. FIPS impact: no The affected code is outside the FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-75806 | libcrypto3 | 3.5.8-r0 | Issue summary: An established DTLS 1.2 association using an AEAD cipher suite can be terminated by a single unauthenticated datagram whose encrypted fragment is shorter than the mandatory explicit IV and authentication tag overhead. Impact summary: An attacker who can send a datagram that is routed to an existing DTLS 1.2 association can tear that association down without knowing any key material. This is a Denial of Service limited to the targeted association. There is no memory safety or confidentiality impact. CWE: CWE-1284: Improper Validation of Specified Quantity in Input Description: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher suite carries an explicit IV followed by the ciphertext and an authentication tag. When decrypting such a record the record layer passed the record length to the cipher implementation before checking that the record was long enough to contain the explicit IV and the tag. For a record shorter than that overhead the cipher implementation rejected the impossible length, and the record layer treated this as an internal failure and raised a fatal internal_error alert instead of treating the record as one that failed authentication. In TLS 1.2 the same record causes a fatal internal_error alert instead of the expected bad_record_mac alert. Since any undecryptable record already terminates a TLS connection, this is a protocol conformance issue rather than a security issue in TLS. The fix validates the record length against the explicit IV and tag length before any AEAD processing, so that TLS reports bad_record_mac and DTLS silently discards the record. FIPS impact: no The affected code is outside the FIPS module boundary. — /lib/apk/db/installed | |
| LOW | CVE-2026-35191 | libcrypto3 | 3.5.8-r0 | Issue summary: The OpenSSL QUIC server, when configured to not preform address validation, can be forced to count incoming packets multiple times in its unvalidated credit computation, leading to a violation of the RFC 9000 unvalidated connection amplification limit of 3 times the amount of data received. Impact summary: A remote attacker able to spoof packets to a server using the OpenSSL QUIC implementation might use the server for an amplification of a DDoS attack. CWE: CWE-440: Expected Behavior Violation Description: OpenSSL's QUIC stack, when operating as a server, enforces client address validation (RFC 9000, Section 8), to confirm the peer address is not used for a traffic amplification attack. If this feature is disabled on the server, the QUIC stack limits the amount of server data that can be sent to 3 times the amount of data received from the peer address, until such time as the TLS handshake is completed. The OpenSSL QUIC server, when operating in non-validation mode, adds the length of the whole datagram received to the unvalidated credit limit when processing each QUIC packet in the datagram. A remote peer may, after establishing a connection with an initial client hello frame, send a subsequent datagram containing multiple QUIC packets, leading the server to account the entire datagram length for each packet in the datagram, resulting in the server believing that the peer has sent more data than it actually has, thereby violating the 3x amplification limit mandated by the RFC. FIPS impact: no As the QUIC stack lives outside the FIPS module boundary, no FIPS modules are affected by this CVE. — /lib/apk/db/installed | |
| LOW | CVE-2026-35191 | libssl3 | 3.5.8-r0 | Issue summary: The OpenSSL QUIC server, when configured to not preform address validation, can be forced to count incoming packets multiple times in its unvalidated credit computation, leading to a violation of the RFC 9000 unvalidated connection amplification limit of 3 times the amount of data received. Impact summary: A remote attacker able to spoof packets to a server using the OpenSSL QUIC implementation might use the server for an amplification of a DDoS attack. CWE: CWE-440: Expected Behavior Violation Description: OpenSSL's QUIC stack, when operating as a server, enforces client address validation (RFC 9000, Section 8), to confirm the peer address is not used for a traffic amplification attack. If this feature is disabled on the server, the QUIC stack limits the amount of server data that can be sent to 3 times the amount of data received from the peer address, until such time as the TLS handshake is completed. The OpenSSL QUIC server, when operating in non-validation mode, adds the length of the whole datagram received to the unvalidated credit limit when processing each QUIC packet in the datagram. A remote peer may, after establishing a connection with an initial client hello frame, send a subsequent datagram containing multiple QUIC packets, leading the server to account the entire datagram length for each packet in the datagram, resulting in the server believing that the peer has sent more data than it actually has, thereby violating the 3x amplification limit mandated by the RFC. FIPS impact: no As the QUIC stack lives outside the FIPS module boundary, no FIPS modules are affected by this CVE. — /lib/apk/db/installed | |
| LOW | CVE-2026-54875 | libcrypto3 | 3.5.8-r0 | Issue summary: A non-constant-time optimized implementation of scalar point multiplication is used for SM2 private key operations on ARM64 and RISC-V platforms. Impact summary: An attacker able to measure the time taken by, or to observe the cache-line access pattern of SM2 signing or decryption on an affected platform can learn information about the secret scalar. CWE: CWE-208: Observable Timing Discrepancy Description: On ARM64 and RISC-V processors, the SM2 curve uses an optimized scalar multiplication implementation whose conditional branches and table look ups are chosen according to the bits of the secret scalar. The execution time and the cache-access pattern therefore depend on the long-term private key (during SM2 decryption) or the per-signature nonce (during SM2 signature generation), forming a timing and cache side-channel. FIPS Impact: no SM2 is not a FIPS algorithm and the optimized SM2 implementation is not part of the FIPS module. OpenSSL 4.0, 3.6, 3.5 and 3.4 are vulnerable to this issue on AArch64 and RISC-V. OpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue. OpenSSL 4.0 users should upgrade to OpenSSL 4.0.3. OpenSSL 3.6 users should upgrade to OpenSSL 3.6.5. OpenSSL 3.5 users should upgrade to OpenSSL 3.5.9. OpenSSL 3.4 users should upgrade to OpenSSL 3.4.8. This issue was reported on 2 May 2026 by Abhinav Agarwal. It was independently reported on 6 June 2026 by Feng Xue. The fix was developed by Igor Ustinov. -- cut (non-publishing metadata for internal use) -- Reported by: Abhinav Agarwal, Feng Xue Fixed by: Igor Ustinov — /lib/apk/db/installed | |
| LOW | CVE-2026-54875 | libssl3 | 3.5.8-r0 | Issue summary: A non-constant-time optimized implementation of scalar point multiplication is used for SM2 private key operations on ARM64 and RISC-V platforms. Impact summary: An attacker able to measure the time taken by, or to observe the cache-line access pattern of SM2 signing or decryption on an affected platform can learn information about the secret scalar. CWE: CWE-208: Observable Timing Discrepancy Description: On ARM64 and RISC-V processors, the SM2 curve uses an optimized scalar multiplication implementation whose conditional branches and table look ups are chosen according to the bits of the secret scalar. The execution time and the cache-access pattern therefore depend on the long-term private key (during SM2 decryption) or the per-signature nonce (during SM2 signature generation), forming a timing and cache side-channel. FIPS Impact: no SM2 is not a FIPS algorithm and the optimized SM2 implementation is not part of the FIPS module. OpenSSL 4.0, 3.6, 3.5 and 3.4 are vulnerable to this issue on AArch64 and RISC-V. OpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue. OpenSSL 4.0 users should upgrade to OpenSSL 4.0.3. OpenSSL 3.6 users should upgrade to OpenSSL 3.6.5. OpenSSL 3.5 users should upgrade to OpenSSL 3.5.9. OpenSSL 3.4 users should upgrade to OpenSSL 3.4.8. This issue was reported on 2 May 2026 by Abhinav Agarwal. It was independently reported on 6 June 2026 by Feng Xue. The fix was developed by Igor Ustinov. -- cut (non-publishing metadata for internal use) -- Reported by: Abhinav Agarwal, Feng Xue Fixed by: Igor Ustinov — /lib/apk/db/installed | |
| LOW | CVE-2026-54872 | libcrypto3 | 3.5.8-r0 | Issue summary: The generic elliptic-curve scalar multiplication used for ECDSA and SM2 signature operations with curves that do not have a dedicated implementation leaks information about the secret nonce through timing. Impact summary: An attacker able to measure signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key. CWE: CWE-208: Observable Timing Discrepancy Description: The generic elliptic-curve scalar multiplication used for curves that do not have a dedicated constant-time implementation pads the secret scalar with non-constant-time BIGNUM operations, so the time taken depends on the value of the secret scalar derived from the ECDSA and SM2 nonce. The leak is very small; observing it requires a large number of measurements. The effect is largest for curves whose group order lies on a machine-word boundary, such as brainpoolP384r1. Applications using ECDSA signing over the Brainpool and other generic prime curves, and SM2 signing on platforms that use the generic implementation, are vulnerable to this issue. The NIST curves P-256, P-384 and P-521 use dedicated constant-time implementations and are not affected. FIPS Impact: no The FIPS modules are not affected: the approved NIST curves used in the FIPS provider have dedicated constant-time implementations and do not use the affected code path. — /lib/apk/db/installed | |
| LOW | CVE-2026-54872 | libssl3 | 3.5.8-r0 | Issue summary: The generic elliptic-curve scalar multiplication used for ECDSA and SM2 signature operations with curves that do not have a dedicated implementation leaks information about the secret nonce through timing. Impact summary: An attacker able to measure signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key. CWE: CWE-208: Observable Timing Discrepancy Description: The generic elliptic-curve scalar multiplication used for curves that do not have a dedicated constant-time implementation pads the secret scalar with non-constant-time BIGNUM operations, so the time taken depends on the value of the secret scalar derived from the ECDSA and SM2 nonce. The leak is very small; observing it requires a large number of measurements. The effect is largest for curves whose group order lies on a machine-word boundary, such as brainpoolP384r1. Applications using ECDSA signing over the Brainpool and other generic prime curves, and SM2 signing on platforms that use the generic implementation, are vulnerable to this issue. The NIST curves P-256, P-384 and P-521 use dedicated constant-time implementations and are not affected. FIPS Impact: no The FIPS modules are not affected: the approved NIST curves used in the FIPS provider have dedicated constant-time implementations and do not use the affected code path. — /lib/apk/db/installed | |
| LOW | CVE-2026-77696 | libcrypto3 | 3.5.8-r0 | Issue summary: SM2 signature generation uses non-constant-time arithmetic on secret values, forming a timing side-channel. Impact summary: An attacker able to measure SM2 signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key. CWE: CWE-208: Observable Timing Discrepancy Description: SM2 signature generation computes the signature value using variable-time BIGNUM operations on the secret nonce and the private key, so the time taken to produce an SM2 signature depends on these secret values, forming a timing side-channel. Applications performing SM2 signature generation are affected on all platforms. FIPS Impact: no SM2 is not a FIPS algorithm. — /lib/apk/db/installed | |
| LOW | CVE-2026-77696 | libssl3 | 3.5.8-r0 | Issue summary: SM2 signature generation uses non-constant-time arithmetic on secret values, forming a timing side-channel. Impact summary: An attacker able to measure SM2 signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key. CWE: CWE-208: Observable Timing Discrepancy Description: SM2 signature generation computes the signature value using variable-time BIGNUM operations on the secret nonce and the private key, so the time taken to produce an SM2 signature depends on these secret values, forming a timing side-channel. Applications performing SM2 signature generation are affected on all platforms. FIPS Impact: no SM2 is not a FIPS algorithm. — /lib/apk/db/installed |
ghcr.io/voxpupuli/onceover
Downloads
ghcr.io/voxpupuli/onceover:latest (2026-09-02)
Trivy
CRITICAL 1
HIGH 35
MEDIUM 46
LOW 17
UNKNOWN 2
| Severity | ID | Package | Installed | Fixed | Title / target |
|---|---|---|---|---|---|
| CRITICAL | CVE-2026-42257 | net-imap | 0.3.9 | ~> 0.4.24, ~> 0.5.14, >= 0.6.4 | net-imap: Net::IMAP: Arbitrary IMAP command injection via CRLF sequences in unvalidated input — Ruby |
| HIGH | CVE-2026-11352 | curl | 8.20.0-r0 | 8.22.0-r0 | curl: libcurl: curl/libcurl: Remote denial of service via QUIC UDP receive function vulnerability — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| HIGH | CVE-2026-19553 | python3-pycache-pyc0 | 3.12.14-r0 | 3.12.15-r0 | python: python: Certificate verification bypass via missing server_hostname validation in SSLContext.wrap_bio() — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| HIGH | CVE-2026-19445 | python3-pycache-pyc0 | 3.12.14-r0 | 3.12.15-r0 | python: Use-after-free of a server-side SSLContext when sni_callback switches contexts — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| HIGH | CVE-2026-11352 | libcurl | 8.20.0-r0 | 8.22.0-r0 | curl: libcurl: curl/libcurl: Remote denial of service via QUIC UDP receive function vulnerability — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| HIGH | CVE-2026-11586 | libcurl | 8.20.0-r0 | 8.22.0-r0 | curl: curl: Denial of Service via WebSocket PING flood — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| HIGH | CVE-2026-12064 | libcurl | 8.20.0-r0 | 8.22.0-r0 | curl: curl: SSH host verification bypass when using schemeless URLs with SFTP/SCP — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| HIGH | CVE-2026-8286 | libcurl | 8.20.0-r0 | 8.22.0-r0 | curl: curl: Insecure connection establishment due to TLS configuration mismatch — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| HIGH | CVE-2026-8458 | libcurl | 8.20.0-r0 | 8.22.0-r0 | curl: libcurl: Unauthorized connection reuse due to a logical error — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| HIGH | CVE-2026-8925 | libcurl | 8.20.0-r0 | 8.22.0-r0 | curl: curl: Double-free vulnerability in SASL authentication — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| HIGH | CVE-2026-8927 | libcurl | 8.20.0-r0 | 8.22.0-r0 | curl: Information disclosure due to uncleared proxy authentication state — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| HIGH | CVE-2026-9547 | libcurl | 8.20.0-r0 | 8.22.0-r0 | curl: curl: Man-in-the-middle attack via SSH host key bypass — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| HIGH | CVE-2026-82049 | python3-pyc | 3.12.14-r0 | 3.12.15-r0 | python: Python tarfile module: File modification and content disclosure via crafted archives — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| HIGH | CVE-2026-19553 | python3-pyc | 3.12.14-r0 | 3.12.15-r0 | python: python: Certificate verification bypass via missing server_hostname validation in SSLContext.wrap_bio() — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| HIGH | CVE-2026-19445 | python3-pyc | 3.12.14-r0 | 3.12.15-r0 | python: Use-after-free of a server-side SSLContext when sni_callback switches contexts — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| HIGH | CVE-2026-82049 | python3 | 3.12.14-r0 | 3.12.15-r0 | python: Python tarfile module: File modification and content disclosure via crafted archives — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| HIGH | CVE-2026-19553 | python3 | 3.12.14-r0 | 3.12.15-r0 | python: python: Certificate verification bypass via missing server_hostname validation in SSLContext.wrap_bio() — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| HIGH | CVE-2026-19445 | python3 | 3.12.14-r0 | 3.12.15-r0 | python: Use-after-free of a server-side SSLContext when sni_callback switches contexts — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| HIGH | CVE-2026-82049 | pyc | 3.12.14-r0 | 3.12.15-r0 | python: Python tarfile module: File modification and content disclosure via crafted archives — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| HIGH | CVE-2026-19553 | pyc | 3.12.14-r0 | 3.12.15-r0 | python: python: Certificate verification bypass via missing server_hostname validation in SSLContext.wrap_bio() — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| HIGH | CVE-2026-19445 | pyc | 3.12.14-r0 | 3.12.15-r0 | python: Use-after-free of a server-side SSLContext when sni_callback switches contexts — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| HIGH | CVE-2026-103111 | pcre2 | 10.48-r0 | 10.49-r0 | pcre2: pcre2: Out-of-bounds write via crafted regular expression — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| HIGH | CVE-2026-93990 | libexpat | 2.8.4-r0 | 2.8.5-r0 | expat: Expat: XML Injection via Malformed UTF-16 Input — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| HIGH | CVE-2026-11586 | curl | 8.20.0-r0 | 8.22.0-r0 | curl: curl: Denial of Service via WebSocket PING flood — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| HIGH | CVE-2026-12064 | curl | 8.20.0-r0 | 8.22.0-r0 | curl: curl: SSH host verification bypass when using schemeless URLs with SFTP/SCP — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| HIGH | CVE-2026-8286 | curl | 8.20.0-r0 | 8.22.0-r0 | curl: curl: Insecure connection establishment due to TLS configuration mismatch — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| HIGH | CVE-2026-8458 | curl | 8.20.0-r0 | 8.22.0-r0 | curl: libcurl: Unauthorized connection reuse due to a logical error — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| HIGH | CVE-2026-8925 | curl | 8.20.0-r0 | 8.22.0-r0 | curl: curl: Double-free vulnerability in SASL authentication — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| HIGH | CVE-2026-8927 | curl | 8.20.0-r0 | 8.22.0-r0 | curl: Information disclosure due to uncleared proxy authentication state — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| HIGH | CVE-2026-9547 | curl | 8.20.0-r0 | 8.22.0-r0 | curl: curl: Man-in-the-middle attack via SSH host key bypass — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| HIGH | CVE-2026-80212 | resolv | 0.2.3 | ~> 0.3.2, >= 0.7.2 | resolv: resolv gem: Denial of Service via uncontrolled memory growth from crafted DNS responses — Ruby |
| HIGH | CVE-2026-42258 | net-imap | 0.3.9 | ~> 0.4.24, ~> 0.5.14, >= 0.6.4 | ruby/net-imap: ruby: Net::IMAP: IMAP Command Injection via Symbol Arguments — Ruby |
| HIGH | CVE-2026-42246 | net-imap | 0.3.9 | ~> 0.3.10, ~> 0.4.24, ~> 0.5.14, >= 0.6.4 | net-imap: ruby: Net::IMAP: Information disclosure via man-in-the-middle attack bypassing TLS — Ruby |
| HIGH | CVE-2026-82049 | python3-pycache-pyc0 | 3.12.14-r0 | 3.12.15-r0 | python: Python tarfile module: File modification and content disclosure via crafted archives — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| HIGH | CVE-2026-42245 | net-imap | 0.3.9 | ~> 0.4.24, ~> 0.5.14, >= 0.6.4 | ruby: net-imap: Net::IMAP: Denial of Service via crafted IMAP responses — Ruby |
| HIGH | CVE-2026-41316 | erb | 4.0.2 | ~> 4.0.3.1, ~> 4.0.4.1, ~> 6.0.1.1, >= 6.0.4 | erb: ERB: Arbitrary code execution via deserialization bypass — Ruby |
| MEDIUM | CVE-2026-15806 | python3-pycache-pyc0 | 3.12.14-r0 | 3.12.15-r0 | python: Python: Information disclosure due to incorrect URL scheme matching — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-17084 | python3-pycache-pyc0 | 3.12.14-r0 | 3.12.15-r0 | python: Python stringprep module: Incorrect domain name processing breaks IDNA interoperability — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-87910 | python3-pyc | 3.12.14-r0 | 3.12.15-r0 | python: Python tarfile module: Security filter bypass allows arbitrary file write — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-19672 | python3-pyc | 3.12.14-r0 | 3.12.15-r0 | python: Python tarfile module: Directory traversal allows creation of empty directories outside extraction destination — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-15806 | pyc | 3.12.14-r0 | 3.12.15-r0 | python: Python: Information disclosure due to incorrect URL scheme matching — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-17084 | pyc | 3.12.14-r0 | 3.12.15-r0 | python: Python stringprep module: Incorrect domain name processing breaks IDNA interoperability — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-19672 | pyc | 3.12.14-r0 | 3.12.15-r0 | python: Python tarfile module: Directory traversal allows creation of empty directories outside extraction destination — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-87910 | pyc | 3.12.14-r0 | 3.12.15-r0 | python: Python tarfile module: Security filter bypass allows arbitrary file write — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-17084 | python3-pyc | 3.12.14-r0 | 3.12.15-r0 | python: Python stringprep module: Incorrect domain name processing breaks IDNA interoperability — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-19672 | python3-pycache-pyc0 | 3.12.14-r0 | 3.12.15-r0 | python: Python tarfile module: Directory traversal allows creation of empty directories outside extraction destination — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-87910 | python3-pycache-pyc0 | 3.12.14-r0 | 3.12.15-r0 | python: Python tarfile module: Security filter bypass allows arbitrary file write — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-15806 | python3 | 3.12.14-r0 | 3.12.15-r0 | python: Python: Information disclosure due to incorrect URL scheme matching — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-17084 | python3 | 3.12.14-r0 | 3.12.15-r0 | python: Python stringprep module: Incorrect domain name processing breaks IDNA interoperability — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-19672 | python3 | 3.12.14-r0 | 3.12.15-r0 | python: Python tarfile module: Directory traversal allows creation of empty directories outside extraction destination — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-87910 | python3 | 3.12.14-r0 | 3.12.15-r0 | python: Python tarfile module: Security filter bypass allows arbitrary file write — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-80213 | resolv | 0.2.3 | ~> 0.3.2, >= 0.7.2 | resolv: Resolv gem: DNS allowlist and egress bypass, and cache poisoning via crafted hostnames — Ruby |
| MEDIUM | CVE-2026-85091 | zlib | 1.3.2-r0 | 1.3.2-r1 | zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vul ... — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-47242 | net-imap | 0.3.9 | ~> 0.5.15, >= 0.6.4.1 | net-imap: Net::IMAP: Arbitrary IMAP command injection due to improper input validation — Ruby |
| MEDIUM | CVE-2026-15806 | python3-pyc | 3.12.14-r0 | 3.12.15-r0 | python: Python: Information disclosure due to incorrect URL scheme matching — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-47240 | net-imap | 0.3.9 | ~> 0.5.15, >= 0.6.4.1 | net-imap: Net::IMAP: Command injection via non-synchronizing literals — Ruby |
| MEDIUM | CVE-2026-80229 | libcurl | 8.20.0-r0 | 8.22.0-r0 | When performing transfers via libcurl\u2019s multi interface, pooled T ... — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-19931 | libcurl | 8.20.0-r0 | 8.22.0-r0 | curl: libcurl: Information disclosure via incorrect connection reuse with Negotiate authentication — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-11856 | libcurl | 8.20.0-r0 | 8.22.0-r0 | curl: curl: Information disclosure via incorrect Digest authentication header reuse — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-11564 | libcurl | 8.20.0-r0 | 8.22.0-r0 | libcurl: libcurl: Certificate validation bypass due to incorrect connection reuse — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-10536 | libcurl | 8.20.0-r0 | 8.22.0-r0 | libcurl: libcurl: Use-after-free vulnerability leading to Denial of Service — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-11564 | curl | 8.20.0-r0 | 8.22.0-r0 | libcurl: libcurl: Certificate validation bypass due to incorrect connection reuse — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-9546 | curl | 8.20.0-r0 | 8.22.0-r0 | libcurl: libcurl: Information disclosure due to persistent Referer header — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-9545 | curl | 8.20.0-r0 | 8.22.0-r0 | libcurl: libcurl: Information disclosure via cached SSL session and early data — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-9080 | curl | 8.20.0-r0 | 8.22.0-r0 | libcurl: libcurl: Use-after-free via curl_easy_pause() in CURLMOPT_SOCKETFUNCTION callback — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-9079 | curl | 8.20.0-r0 | 8.22.0-r0 | libcurl: libcurl: Information disclosure due to failure to clear proxy authentication credentials — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-8932 | curl | 8.20.0-r0 | 8.22.0-r0 | libcurl: libcurl: Security feature bypass due to improper mTLS connection reuse — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-8926 | curl | 8.20.0-r0 | 8.22.0-r0 | curl: curl: Information disclosure via incorrect .netrc password lookup — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-8924 | curl | 8.20.0-r0 | 8.22.0-r0 | curl: curl: Cookie injection via malicious HTTP server using super cookies — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-82208 | curl | 8.20.0-r0 | 8.22.0-r0 | curl: libcurl: Improper certificate validation when using wolfSSL CA cache — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-80229 | curl | 8.20.0-r0 | 8.22.0-r0 | When performing transfers via libcurl\u2019s multi interface, pooled T ... — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-19931 | curl | 8.20.0-r0 | 8.22.0-r0 | curl: libcurl: Information disclosure via incorrect connection reuse with Negotiate authentication — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-11856 | curl | 8.20.0-r0 | 8.22.0-r0 | curl: curl: Information disclosure via incorrect Digest authentication header reuse — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-82208 | libcurl | 8.20.0-r0 | 8.22.0-r0 | curl: libcurl: Improper certificate validation when using wolfSSL CA cache — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-8924 | libcurl | 8.20.0-r0 | 8.22.0-r0 | curl: curl: Cookie injection via malicious HTTP server using super cookies — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-8926 | libcurl | 8.20.0-r0 | 8.22.0-r0 | curl: curl: Information disclosure via incorrect .netrc password lookup — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-8932 | libcurl | 8.20.0-r0 | 8.22.0-r0 | libcurl: libcurl: Security feature bypass due to improper mTLS connection reuse — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-9079 | libcurl | 8.20.0-r0 | 8.22.0-r0 | libcurl: libcurl: Information disclosure due to failure to clear proxy authentication credentials — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-10536 | curl | 8.20.0-r0 | 8.22.0-r0 | libcurl: libcurl: Use-after-free vulnerability leading to Denial of Service — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-9545 | libcurl | 8.20.0-r0 | 8.22.0-r0 | libcurl: libcurl: Information disclosure via cached SSL session and early data — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-9546 | libcurl | 8.20.0-r0 | 8.22.0-r0 | libcurl: libcurl: Information disclosure due to persistent Referer header — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-9080 | libcurl | 8.20.0-r0 | 8.22.0-r0 | libcurl: libcurl: Use-after-free via curl_easy_pause() in CURLMOPT_SOCKETFUNCTION callback — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| LOW | CVE-2026-15310 | python3-pycache-pyc0 | 3.12.14-r0 | 3.12.15-r0 | When decompressing crafted zip files using the bzip/LZMA/Zstandard c ... — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| LOW | CVE-2026-13608 | libcurl | 8.20.0-r0 | 8.22.0-r0 | curl: curl: Authentication bypass in OpenLDAP SASL negotiation via Man-in-the-Middle (MITM) attack — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| LOW | CVE-2026-18924 | libcurl | 8.20.0-r0 | 8.22.0-r0 | curl: libcurl: Use-after-free in HTTP/2 Server Push with shared connections — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| LOW | CVE-2026-80230 | libcurl | 8.20.0-r0 | 8.22.0-r0 | curl: curl: Public key pinning bypass allows unauthenticated connections — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| LOW | CVE-2026-80231 | libcurl | 8.20.0-r0 | 8.22.0-r0 | curl: curl: Incorrect HTTPS connection reuse with Native CA Store — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| LOW | CVE-2026-80255 | libcurl | 8.20.0-r0 | 8.22.0-r0 | curl: curl: Information disclosure due to secure cookie attribute bypass — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| LOW | CVE-2026-82209 | libcurl | 8.20.0-r0 | 8.22.0-r0 | curl: libcurl: Information disclosure via improper Public Suffix List boundary check — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| LOW | CVE-2026-47241 | net-imap | 0.3.9 | ~> 0.5.15, >= 0.6.4.1 | net-imap: rubygem-net-imap: Net::IMAP: Denial of Service via malformed command input — Ruby |
| LOW | CVE-2026-15310 | pyc | 3.12.14-r0 | 3.12.15-r0 | When decompressing crafted zip files using the bzip/LZMA/Zstandard c ... — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| LOW | CVE-2026-13608 | curl | 8.20.0-r0 | 8.22.0-r0 | curl: curl: Authentication bypass in OpenLDAP SASL negotiation via Man-in-the-Middle (MITM) attack — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| LOW | CVE-2026-18924 | curl | 8.20.0-r0 | 8.22.0-r0 | curl: libcurl: Use-after-free in HTTP/2 Server Push with shared connections — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| LOW | CVE-2026-80230 | curl | 8.20.0-r0 | 8.22.0-r0 | curl: curl: Public key pinning bypass allows unauthenticated connections — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| LOW | CVE-2026-80231 | curl | 8.20.0-r0 | 8.22.0-r0 | curl: curl: Incorrect HTTPS connection reuse with Native CA Store — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| LOW | CVE-2026-15310 | python3-pyc | 3.12.14-r0 | 3.12.15-r0 | When decompressing crafted zip files using the bzip/LZMA/Zstandard c ... — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| LOW | CVE-2026-80255 | curl | 8.20.0-r0 | 8.22.0-r0 | curl: curl: Information disclosure due to secure cookie attribute bypass — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| LOW | CVE-2026-82209 | curl | 8.20.0-r0 | 8.22.0-r0 | curl: libcurl: Information disclosure via improper Public Suffix List boundary check — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| LOW | CVE-2026-15310 | python3 | 3.12.14-r0 | 3.12.15-r0 | When decompressing crafted zip files using the bzip/LZMA/Zstandard c ... — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| UNKNOWN | CVE-2026-80256 | curl | 8.20.0-r0 | 8.22.0-r0 | Title Not Available — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
| UNKNOWN | CVE-2026-80256 | libcurl | 8.20.0-r0 | 8.22.0-r0 | Title Not Available — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4) |
Grype
CRITICAL 24
HIGH 45
MEDIUM 22
LOW 6
UNKNOWN 2
NVD/CPE filtered 37
| Severity | ID | Package | Installed | Fixed | Title / target |
|---|---|---|---|---|---|
| CRITICAL | CVE-2026-8927 | curl | 8.20.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| CRITICAL | CVE-2026-19445 | python3-pycache-pyc0 | 3.12.14-r0 | 3.12.15-r0 | /lib/apk/db/installed |
| CRITICAL | CVE-2026-11564 | curl | 8.20.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| CRITICAL | CVE-2026-11564 | libcurl | 8.20.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| CRITICAL | CVE-2026-8927 | libcurl | 8.20.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| CRITICAL | CVE-2026-19445 | python3-pyc | 3.12.14-r0 | 3.12.15-r0 | /lib/apk/db/installed |
| CRITICAL | CVE-2026-18924 | libcurl | 8.20.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| CRITICAL | CVE-2026-18924 | curl | 8.20.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| CRITICAL | CVE-2026-19445 | python3 | 3.12.14-r0 | 3.12.15-r0 | /lib/apk/db/installed |
| CRITICAL | CVE-2026-19445 | pyc | 3.12.14-r0 | 3.12.15-r0 | /lib/apk/db/installed |
| CRITICAL | CVE-2026-9079 | libcurl | 8.20.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| CRITICAL | CVE-2026-9079 | curl | 8.20.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| CRITICAL | CVE-2026-10536 | libcurl | 8.20.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| CRITICAL | CVE-2026-10536 | curl | 8.20.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| CRITICAL | CVE-2026-8924 | libcurl | 8.20.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| CRITICAL | CVE-2026-8924 | curl | 8.20.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| CRITICAL | CVE-2026-11856 | libcurl | 8.20.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| CRITICAL | CVE-2026-11856 | curl | 8.20.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| CRITICAL | CVE-2026-8926 | curl | 8.20.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| CRITICAL | CVE-2026-8926 | libcurl | 8.20.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| CRITICAL | CVE-2026-19931 | libcurl | 8.20.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| CRITICAL | CVE-2026-19931 | curl | 8.20.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| CRITICAL | CVE-2026-8925 | libcurl | 8.20.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| CRITICAL | CVE-2026-8925 | curl | 8.20.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-19553 | python3-pyc | 3.12.14-r0 | 3.12.15-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-19553 | python3-pycache-pyc0 | 3.12.14-r0 | 3.12.15-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-19553 | python3 | 3.12.14-r0 | 3.12.15-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-19553 | pyc | 3.12.14-r0 | 3.12.15-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-82208 | libcurl | 8.20.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-82208 | curl | 8.20.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-9545 | libcurl | 8.20.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-9545 | curl | 8.20.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-93990 | libexpat | 2.8.4-r0 | 2.8.5-r0 | /lib/apk/db/installed |
| HIGH | GHSA-q339-8rmv-2mhv | erb | 4.0.2 | 4.0.3.1 | ERB has an @_init deserialization guard bypass via def_module / def_method / def_class — /usr/local/lib/ruby/gems/3.2.0/specifications/default/erb-4.0.2.gemspec |
| HIGH | CVE-2026-12064 | curl | 8.20.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-12064 | libcurl | 8.20.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-8932 | curl | 8.20.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-8932 | libcurl | 8.20.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-82209 | curl | 8.20.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-82209 | libcurl | 8.20.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-80230 | curl | 8.20.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-80230 | libcurl | 8.20.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-8286 | curl | 8.20.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-8286 | libcurl | 8.20.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | GHSA-vcgp-9326-pqcp | net-imap | 0.3.9 | 0.3.10 | net-imap vulnerable to STARTTLS stripping via invalid response timing — /usr/local/lib/ruby/gems/3.2.0/specifications/net-imap-0.3.9.gemspec |
| HIGH | CVE-2026-82049 | pyc | 3.12.14-r0 | 3.12.15-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-82049 | python3 | 3.12.14-r0 | 3.12.15-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-82049 | python3-pyc | 3.12.14-r0 | 3.12.15-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-82049 | python3-pycache-pyc0 | 3.12.14-r0 | 3.12.15-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-103111 | pcre2 | 10.48-r0 | 10.49-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-80231 | curl | 8.20.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-80231 | libcurl | 8.20.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-11352 | curl | 8.20.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-11352 | libcurl | 8.20.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-9546 | curl | 8.20.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-9546 | libcurl | 8.20.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-85091 | zlib | 1.3.2-r0 | 1.3.2-r1 | /lib/apk/db/installed |
| HIGH | CVE-2026-11586 | curl | 8.20.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-11586 | libcurl | 8.20.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-80229 | curl | 8.20.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-80229 | libcurl | 8.20.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-13608 | libcurl | 8.20.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-80255 | libcurl | 8.20.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-9547 | curl | 8.20.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-9547 | libcurl | 8.20.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-80255 | curl | 8.20.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-9080 | libcurl | 8.20.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-13608 | curl | 8.20.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-9080 | curl | 8.20.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-17084 | python3-pycache-pyc0 | 3.12.14-r0 | 3.12.15-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-15806 | python3-pycache-pyc0 | 3.12.14-r0 | 3.12.15-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-87910 | python3-pycache-pyc0 | 3.12.14-r0 | 3.12.15-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-8458 | curl | 8.20.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-8458 | libcurl | 8.20.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-87910 | python3-pyc | 3.12.14-r0 | 3.12.15-r0 | /lib/apk/db/installed |
| MEDIUM | GHSA-75xq-5h9v-w6px | net-imap | 0.3.9 | 0.4.24 | net-imap vulnerable to command Injection via unvalidated Symbol inputs — /usr/local/lib/ruby/gems/3.2.0/specifications/net-imap-0.3.9.gemspec |
| MEDIUM | CVE-2026-87910 | python3 | 3.12.14-r0 | 3.12.15-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-87910 | pyc | 3.12.14-r0 | 3.12.15-r0 | /lib/apk/db/installed |
| MEDIUM | GHSA-46q3-7gv7-qmgg | net-imap | 0.3.9 | 0.5.15 | Net::IMAP: Command Injection via ID command argument — /usr/local/lib/ruby/gems/3.2.0/specifications/net-imap-0.3.9.gemspec |
| MEDIUM | CVE-2026-17084 | python3-pyc | 3.12.14-r0 | 3.12.15-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-17084 | python3 | 3.12.14-r0 | 3.12.15-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-17084 | pyc | 3.12.14-r0 | 3.12.15-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-19672 | pyc | 3.12.14-r0 | 3.12.15-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-19672 | python3 | 3.12.14-r0 | 3.12.15-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-19672 | python3-pyc | 3.12.14-r0 | 3.12.15-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-19672 | python3-pycache-pyc0 | 3.12.14-r0 | 3.12.15-r0 | /lib/apk/db/installed |
| MEDIUM | GHSA-8p34-64r3-mwg8 | net-imap | 0.3.9 | 0.5.15 | Net::IMAP: Command Injection via non-synchronizing literal in "raw" argument — /usr/local/lib/ruby/gems/3.2.0/specifications/net-imap-0.3.9.gemspec |
| MEDIUM | GHSA-hm49-wcqc-g2xg | net-imap | 0.3.9 | 0.4.24 | net-imap vulnerable to command Injection via "raw" arguments to multiple commands — /usr/local/lib/ruby/gems/3.2.0/specifications/net-imap-0.3.9.gemspec |
| MEDIUM | CVE-2026-15806 | pyc | 3.12.14-r0 | 3.12.15-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-15806 | python3 | 3.12.14-r0 | 3.12.15-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-15806 | python3-pyc | 3.12.14-r0 | 3.12.15-r0 | /lib/apk/db/installed |
| LOW | GHSA-q2mw-fvj9-vvcw | net-imap | 0.3.9 | 0.4.24 | net-imap has quadratic complexity when reading response literals — /usr/local/lib/ruby/gems/3.2.0/specifications/net-imap-0.3.9.gemspec |
| LOW | CVE-2026-15310 | pyc | 3.12.14-r0 | 3.12.15-r0 | /lib/apk/db/installed |
| LOW | CVE-2026-15310 | python3 | 3.12.14-r0 | 3.12.15-r0 | /lib/apk/db/installed |
| LOW | CVE-2026-15310 | python3-pyc | 3.12.14-r0 | 3.12.15-r0 | /lib/apk/db/installed |
| LOW | CVE-2026-15310 | python3-pycache-pyc0 | 3.12.14-r0 | 3.12.15-r0 | /lib/apk/db/installed |
| LOW | GHSA-c4fp-cxrr-mj66 | net-imap | 0.3.9 | 0.5.15 | Net::IMAP: Denial of Service via incomplete raw argument validation — /usr/local/lib/ruby/gems/3.2.0/specifications/net-imap-0.3.9.gemspec |
| UNKNOWN | CVE-2026-80256 | curl | 8.20.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| UNKNOWN | CVE-2026-80256 | libcurl | 8.20.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
Filtered NVD/CPE matches (37)
These broad CPE matches are unconfirmed for the distribution package and excluded from scanner totals.
| Severity | ID | Package | Installed | Fixed | Title / target |
|---|---|---|---|---|---|
| HIGH | CVE-2026-54873 | libcrypto3 | 3.5.8-r0 | Issue summary: QUIC process may keep memory for QUIC packet buffer for much longer period than necessary. Impact summary: Remote peer can exploit this vulnerability by sending maliciously crafted packets, making the local QUIC stack to keep the memory for packet buffers allocated. The time for which the memory remains allocated is entirely under the control of the potentially malicious remote peer. CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: To save copy operation from the packet buffer to the stream reassemble buffer the QUIC stack leaves the stream data on the packet buffer waiting to be copied to a buffer provided by the local receiving application. The QUIC stack releases a reference to the packet buffer only after the data are copied to the application buffer. This design is more efficient for legitimate data transfers but enables an attacker to allocate a lot more memory than actually required by the data kept in the receiving stream buffer. To mitigate the vulnerability, the QUIC stack now calculates and monitors memory overhead for every stream. The memory overhead for a single stream frame is calculated as a difference between the size of the whole packet that carries the stream frame and the size of the stream frame itself. The memory overhead for a single stream frame is added to the total (cumulative) memory overhead QUIC stack keeps for each stream. Once the cumulative memory overhead exceeds 64kB, the QUIC stack moves the stream frame data from the packet buffer to the stream buffer, starting with the next packet received. FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| HIGH | CVE-2026-54873 | libssl3 | 3.5.8-r0 | Issue summary: QUIC process may keep memory for QUIC packet buffer for much longer period than necessary. Impact summary: Remote peer can exploit this vulnerability by sending maliciously crafted packets, making the local QUIC stack to keep the memory for packet buffers allocated. The time for which the memory remains allocated is entirely under the control of the potentially malicious remote peer. CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: To save copy operation from the packet buffer to the stream reassemble buffer the QUIC stack leaves the stream data on the packet buffer waiting to be copied to a buffer provided by the local receiving application. The QUIC stack releases a reference to the packet buffer only after the data are copied to the application buffer. This design is more efficient for legitimate data transfers but enables an attacker to allocate a lot more memory than actually required by the data kept in the receiving stream buffer. To mitigate the vulnerability, the QUIC stack now calculates and monitors memory overhead for every stream. The memory overhead for a single stream frame is calculated as a difference between the size of the whole packet that carries the stream frame and the size of the stream frame itself. The memory overhead for a single stream frame is added to the total (cumulative) memory overhead QUIC stack keeps for each stream. Once the cumulative memory overhead exceeds 64kB, the QUIC stack moves the stream frame data from the packet buffer to the stream buffer, starting with the next packet received. FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| HIGH | CVE-2026-84782 | libcrypto3 | 3.5.8-r0 | Issue summary: The DTLS retransmission logic does not correctly handle a handshake message write that is suspended part-way through. The retransmitted message can be read past the message buffer and the retransmission overwrites the internal state the suspended write needs to resume correctly. Impact summary: The retransmitted message can disclose a heap memory to the peer as plaintext handshake data or cause a crash and a Denial of Service when the read reaches an unmapped memory region. CWE: CWE-125: Out-of-bounds Read Description: DTLS handshake messages can be written out in multiple fragments, and a write can suspend mid-message (returning WANT_WRITE) if the underlying transport temporarily cannot accept more data. While such a write is suspended, the DTLS retransmission timer may independently fire and ask the retransmission logic to resend an earlier, already-acknowledged-as-sent message from its retransmit queue. The retransmission logic reused the same internal buffer and position tracking as the message that was still being written, without resetting the position back to the start of the message being retransmitted. As a result the retransmission was read starting from wherever the suspended write had left off, producing a mislabelled message whose body was leftover bytes from the other, larger message still in flight - content that was never meant to be sent at that point, and which could run past the end of the allocated buffer. Separately, even when the retransmission is positioned correctly, allowing it to run to completion while another write is suspended overwrites the same shared bookkeeping that the suspended write depends on to resume. When the application later resumes the suspended write (via a subsequent SSL_read(), SSL_write(), SSL_accept(), or SSL_connect() call), it finds that bookkeeping in a state inconsistent with the message and aborts the process in a debugging build. The fix resets the retransmission's read position to the start of the message before resending, and skips retransmission entirely whenever a handshake write is still suspended, deferring to the next call that resumes it instead. FIPS impact: no The affected code is outside the FIPS module boundary. — /lib/apk/db/installed | |
| HIGH | CVE-2026-84782 | libssl3 | 3.5.8-r0 | Issue summary: The DTLS retransmission logic does not correctly handle a handshake message write that is suspended part-way through. The retransmitted message can be read past the message buffer and the retransmission overwrites the internal state the suspended write needs to resume correctly. Impact summary: The retransmitted message can disclose a heap memory to the peer as plaintext handshake data or cause a crash and a Denial of Service when the read reaches an unmapped memory region. CWE: CWE-125: Out-of-bounds Read Description: DTLS handshake messages can be written out in multiple fragments, and a write can suspend mid-message (returning WANT_WRITE) if the underlying transport temporarily cannot accept more data. While such a write is suspended, the DTLS retransmission timer may independently fire and ask the retransmission logic to resend an earlier, already-acknowledged-as-sent message from its retransmit queue. The retransmission logic reused the same internal buffer and position tracking as the message that was still being written, without resetting the position back to the start of the message being retransmitted. As a result the retransmission was read starting from wherever the suspended write had left off, producing a mislabelled message whose body was leftover bytes from the other, larger message still in flight - content that was never meant to be sent at that point, and which could run past the end of the allocated buffer. Separately, even when the retransmission is positioned correctly, allowing it to run to completion while another write is suspended overwrites the same shared bookkeeping that the suspended write depends on to resume. When the application later resumes the suspended write (via a subsequent SSL_read(), SSL_write(), SSL_accept(), or SSL_connect() call), it finds that bookkeeping in a state inconsistent with the message and aborts the process in a debugging build. The fix resets the retransmission's read position to the start of the message before resending, and skips retransmission entirely whenever a handshake write is still suspended, deferring to the next call that resumes it instead. FIPS impact: no The affected code is outside the FIPS module boundary. — /lib/apk/db/installed | |
| HIGH | CVE-2026-84784 | libcrypto3 | 3.5.8-r0 | Issue summary: A malicious remote peer may flood the local QUIC stack with NEW_CONNECTION_ID frames by avoiding a limit check on how many connection IDs the remote QUIC stack can use. Impact summary: The local QUIC stack sends a RETIRE_CONN_ID frame for every NEW_CONNECTION_ID frame it receives. The RETIRE_CONN_ID frame is dispatched via the Control Frame Queue (CFQ). If the remote peer also withholds ACKs, then it can force the local stack to allocate ~400MB (depending on ACK delay). CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: RFC 9000 sections 5.1.1 and 5.1.2 [1] describe the mechanism by which a remote peer can notify the local QUIC stack to change the destination connection ID (a.k.a. CID) the local stack uses to identify the connection at the remote peer. Each CID is associated with a sequence number. The sequence number is transmitted in NEW_CONNECTION_ID and RETIRE_CONNECTION_ID frames to identify the CID which is being either associated with a connection or retired. The remote peer sends a NEW_CONNECTION_ID frame to let the local stack know a new CID is being associated with an existing connection. The NEW_CONNECTION_ID frame carries the new CID, its sequence number, and the retire-prior-to number. The retire-prior-to identifies existing CIDs that are to be retired. The local QUIC stack must send a RETIRE_CONNECTION_ID for every destination CID whose sequence number is less than retire-prior-to. The CID becomes retired after the local stack receives an ACK for its RETIRE_CONNECTION_ID frame. Although the OpenSSL QUIC stack supports at most one destination CID for every connection, it can be tricked into processing more than one RETIRE_CONNECTION_ID frame per connection. The OpenSSL QUIC stack currently retires the destination CID as soon as it receives the NEW_CONNECTION_ID, while in fact the destination CID must be retired after an ACK for the RETIRE_CONNECTION_ID frame is received. Correcting the flawed logic also fixes the backlog growth. [1] https://datatracker.ietf.org/doc/html/rfc9000#name-issuing-connection-ids FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| HIGH | CVE-2026-84784 | libssl3 | 3.5.8-r0 | Issue summary: A malicious remote peer may flood the local QUIC stack with NEW_CONNECTION_ID frames by avoiding a limit check on how many connection IDs the remote QUIC stack can use. Impact summary: The local QUIC stack sends a RETIRE_CONN_ID frame for every NEW_CONNECTION_ID frame it receives. The RETIRE_CONN_ID frame is dispatched via the Control Frame Queue (CFQ). If the remote peer also withholds ACKs, then it can force the local stack to allocate ~400MB (depending on ACK delay). CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: RFC 9000 sections 5.1.1 and 5.1.2 [1] describe the mechanism by which a remote peer can notify the local QUIC stack to change the destination connection ID (a.k.a. CID) the local stack uses to identify the connection at the remote peer. Each CID is associated with a sequence number. The sequence number is transmitted in NEW_CONNECTION_ID and RETIRE_CONNECTION_ID frames to identify the CID which is being either associated with a connection or retired. The remote peer sends a NEW_CONNECTION_ID frame to let the local stack know a new CID is being associated with an existing connection. The NEW_CONNECTION_ID frame carries the new CID, its sequence number, and the retire-prior-to number. The retire-prior-to identifies existing CIDs that are to be retired. The local QUIC stack must send a RETIRE_CONNECTION_ID for every destination CID whose sequence number is less than retire-prior-to. The CID becomes retired after the local stack receives an ACK for its RETIRE_CONNECTION_ID frame. Although the OpenSSL QUIC stack supports at most one destination CID for every connection, it can be tricked into processing more than one RETIRE_CONNECTION_ID frame per connection. The OpenSSL QUIC stack currently retires the destination CID as soon as it receives the NEW_CONNECTION_ID, while in fact the destination CID must be retired after an ACK for the RETIRE_CONNECTION_ID frame is received. Correcting the flawed logic also fixes the backlog growth. [1] https://datatracker.ietf.org/doc/html/rfc9000#name-issuing-connection-ids FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| HIGH | CVE-2026-72897 | libcrypto3 | 3.5.8-r0 | Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a connection to a different SSL_CTX part way through a handshake may access memory beyond the end of an internal array if the replacement context knows about more provider signature algorithms than the context the connection was created from. Applications which never call SSL_set_SSL_CTX() are not affected. Impact summary: A remote peer may be able to cause a small out-of-bounds read, and in some circumstances a fixed-value out-of-bounds write, on the server heap. This may lead to a Denial of Service. CWE: CWE-787: Out-of-bounds Write Description: A TLS connection records how many certificate slots it has when it is created, taken from the SSL_CTX that created it: the built-in certificate types plus one slot for each provider TLS-SIGALG entry that context was aware of. That count sizes an internal array of per-slot certificate validity flags. An application may replace a connection's SSL_CTX part way through the handshake by calling SSL_set_SSL_CTX(), most commonly from a servername callback in order to serve a different virtual host. Doing so did not refresh the recorded count. A provider signature algorithm's slot index is its position in the list of whichever context resolves it, so if the replacement context is aware of more of them than the original, an algorithm offered by the peer can resolve to an index beyond the end of the array. Processing the peer's signature algorithms then reads one four byte word past the end for each such algorithm and, where the word read is zero, writes a fixed value over it. A peer offering many of them can corrupt heap metadata and abort the process. Only provider signature algorithms which occupy one of the excess slots, and which the server also has configured, have this effect. Codepoints the replacement context does not recognise are discarded without being resolved to a slot, and provider signature algorithms are usable only from TLS 1.3. The two contexts must therefore be aware of different numbers of provider signature algorithms, which requires separate library contexts, a provider loaded between the two being created, or providers which differ in what they advertise - in 4.0, for example, the default provider advertises SM2 where the FIPS provider does not. A deployment meeting the condition is also unable to negotiate the affected algorithms with legitimate clients, since the same stale count hides the corresponding certificates, so the misconfiguration is likely to be noticed. For that reason, and because the configuration is not the default, this issue has been assessed as Low severity. FIPS impact: no No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| HIGH | CVE-2026-72897 | libssl3 | 3.5.8-r0 | Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a connection to a different SSL_CTX part way through a handshake may access memory beyond the end of an internal array if the replacement context knows about more provider signature algorithms than the context the connection was created from. Applications which never call SSL_set_SSL_CTX() are not affected. Impact summary: A remote peer may be able to cause a small out-of-bounds read, and in some circumstances a fixed-value out-of-bounds write, on the server heap. This may lead to a Denial of Service. CWE: CWE-787: Out-of-bounds Write Description: A TLS connection records how many certificate slots it has when it is created, taken from the SSL_CTX that created it: the built-in certificate types plus one slot for each provider TLS-SIGALG entry that context was aware of. That count sizes an internal array of per-slot certificate validity flags. An application may replace a connection's SSL_CTX part way through the handshake by calling SSL_set_SSL_CTX(), most commonly from a servername callback in order to serve a different virtual host. Doing so did not refresh the recorded count. A provider signature algorithm's slot index is its position in the list of whichever context resolves it, so if the replacement context is aware of more of them than the original, an algorithm offered by the peer can resolve to an index beyond the end of the array. Processing the peer's signature algorithms then reads one four byte word past the end for each such algorithm and, where the word read is zero, writes a fixed value over it. A peer offering many of them can corrupt heap metadata and abort the process. Only provider signature algorithms which occupy one of the excess slots, and which the server also has configured, have this effect. Codepoints the replacement context does not recognise are discarded without being resolved to a slot, and provider signature algorithms are usable only from TLS 1.3. The two contexts must therefore be aware of different numbers of provider signature algorithms, which requires separate library contexts, a provider loaded between the two being created, or providers which differ in what they advertise - in 4.0, for example, the default provider advertises SM2 where the FIPS provider does not. A deployment meeting the condition is also unable to negotiate the affected algorithms with legitimate clients, since the same stale count hides the corresponding certificates, so the misconfiguration is likely to be noticed. For that reason, and because the configuration is not the default, this issue has been assessed as Low severity. FIPS impact: no No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-42772 | libssl3 | 3.5.8-r0 | Issue summary: The QUIC stream reassembly algorithm performance deteriorates progressively as packets are arriving out of order. The worst case has a quadratic complexity proportional to the number of stream frames kept in the buffer for the received stream data. Impact summary: A remote QUIC peer that completes the handshake can create a connection-scoped CPU pressure and potentially a Denial of Service using compliant STREAM frames inside the advertised receive window, with low attacker bandwidth. CWE: CWE-407: Inefficient Algorithmic Complexity Description: OpenSSL manages received QUIC stream fragments using a doubly-linked list. While it optimizes for append operations (at the end of the list), it falls back to a head-to-tail linear search for any fragment that does not immediately follow the current `tail`. By manipulating the sequence of offsets, an attacker can force the server to perform O(n^2) operations, consuming excessive CPU time for the QUIC process. FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-60876 | busybox | 1.37.0-r30 | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-60876 | busybox-binsh | 1.37.0-r30 | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-60876 | ssl_client | 1.37.0-r30 | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-35189 | libcrypto3 | 3.5.8-r0 | Issue summary: A certificate with many nameRelativeToCRLIssuer CRL distribution points causes disproportionate heap growth when OpenSSL caches X.509 extensions. Impact summary: Receiving a crafted certificate from a malicious peer can lead to significant memory pressure and possible Denial of Service in clients or in servers that solicit client certificates. CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: A certificate or a set of certificates that fits under the limit for size of certificates accepted from the peer (~100 KiB) can result in allocation of several hundred MiB of resident memory on the receiving side during a normal TLS handshake. This may be enough to crash the client or server, if multiple concurrent connections lead to similarly large memory allocations. The fix postpones processing of the CRL distribution points extensions in certificates to the time when the processed value is required for CRL processing. This avoids keeping large memory allocations for a long time when such certificates are received. FIPS impact: no The affected code is outside the FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-35189 | libssl3 | 3.5.8-r0 | Issue summary: A certificate with many nameRelativeToCRLIssuer CRL distribution points causes disproportionate heap growth when OpenSSL caches X.509 extensions. Impact summary: Receiving a crafted certificate from a malicious peer can lead to significant memory pressure and possible Denial of Service in clients or in servers that solicit client certificates. CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: A certificate or a set of certificates that fits under the limit for size of certificates accepted from the peer (~100 KiB) can result in allocation of several hundred MiB of resident memory on the receiving side during a normal TLS handshake. This may be enough to crash the client or server, if multiple concurrent connections lead to similarly large memory allocations. The fix postpones processing of the CRL distribution points extensions in certificates to the time when the processed value is required for CRL processing. This avoids keeping large memory allocations for a long time when such certificates are received. FIPS impact: no The affected code is outside the FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-3446 | python3 | 3.12.14-r0 | When calling base64.b64decode() or related functions the decoding process would stop after encountering the first padded quad regardless of whether there was more information to be processed. This can lead to data being accepted which may be processed differently by other implementations. Use "validate=True" to enable stricter processing of base64 data. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-75805 | libcrypto3 | 3.5.8-r0 | Issue summary: A CMP client that requests certificate revocation on the basis of a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when processing a crafted revocation response. Impact summary: The NULL pointer dereference happens on a read which leads to a crash and a Denial of Service for the affected client application. CWE: CWE-476: NULL-pointer dereference Description: A CMP client revoking a certificate has to tell the server which certificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the certificate itself or its issuer name and serial number. This is 'openssl cmp -cmd rr -csr <file>' on the command line, or OSSL_CMP_exec_RR_ses() with the certificate supplied via OSSL_CMP_CTX_set1_p10CSR() through the API. A CSR does not contain the issuer name and serial number of the certificate, so the client does not send them. A server may optionally name the certificate it revoked in its response, and the client then compares that name against what it sent. Having sent neither an issuer name nor a serial number, it has nothing to compare against, and a server returning a specially crafted name causes the client to read from a NULL pointer and crash. The revocation response is checked for valid message protection before the affected code is reached, so an attacker must be a malicious or compromised CMP server, or a man-in-the-middle in possession of the secret used for message protection. Clients that identify the certificate to be revoked by a certificate or by issuer and serial number rather than by a PKCS#10 CSR are not affected. FIPS impact: no No FIPS modules are affected by this issue, as the CMP protocol implementation is outside the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-75805 | libssl3 | 3.5.8-r0 | Issue summary: A CMP client that requests certificate revocation on the basis of a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when processing a crafted revocation response. Impact summary: The NULL pointer dereference happens on a read which leads to a crash and a Denial of Service for the affected client application. CWE: CWE-476: NULL-pointer dereference Description: A CMP client revoking a certificate has to tell the server which certificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the certificate itself or its issuer name and serial number. This is 'openssl cmp -cmd rr -csr <file>' on the command line, or OSSL_CMP_exec_RR_ses() with the certificate supplied via OSSL_CMP_CTX_set1_p10CSR() through the API. A CSR does not contain the issuer name and serial number of the certificate, so the client does not send them. A server may optionally name the certificate it revoked in its response, and the client then compares that name against what it sent. Having sent neither an issuer name nor a serial number, it has nothing to compare against, and a server returning a specially crafted name causes the client to read from a NULL pointer and crash. The revocation response is checked for valid message protection before the affected code is reached, so an attacker must be a malicious or compromised CMP server, or a man-in-the-middle in possession of the secret used for message protection. Clients that identify the certificate to be revoked by a certificate or by issuer and serial number rather than by a PKCS#10 CSR are not affected. FIPS impact: no No FIPS modules are affected by this issue, as the CMP protocol implementation is outside the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-12345 | python3 | 3.12.14-r0 | The cleanup of tempfile.TemporaryDirectory is vulnerable to a race condition. An attacker who can modify the tree during cleanup can replace a directory with a symbolic link, causing files outside of the temporary directory to be deleted or have their permissions and file flags reset, with the privileges of the process performing the cleanup. Note that platforms where shutil.rmtree.avoids_symlink_attacks is false, remain affected, and file flags may still be reset outside of the tree on all platforms. — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-12781 | python3 | 3.12.14-r0 | When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the "base64" module the characters "+/" will always be accepted, regardless of the value of "altchars" parameter, typically used to establish an "alternative base64 alphabet" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues. This behavior can only be insecure if your application uses an alternate base64 alphabet (without "+/"). If your application does not use the "altchars" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet. The attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64 alphabet they are expecting or verify that their application would not be affected if the b64decode() functions accepted "+" or "/" outside of altchars. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-6019 | python3 | 3.12.14-r0 | http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value. — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-15366 | python3 | 3.12.14-r0 | The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters. — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-15367 | python3 | 3.12.14-r0 | The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-75806 | libcrypto3 | 3.5.8-r0 | Issue summary: An established DTLS 1.2 association using an AEAD cipher suite can be terminated by a single unauthenticated datagram whose encrypted fragment is shorter than the mandatory explicit IV and authentication tag overhead. Impact summary: An attacker who can send a datagram that is routed to an existing DTLS 1.2 association can tear that association down without knowing any key material. This is a Denial of Service limited to the targeted association. There is no memory safety or confidentiality impact. CWE: CWE-1284: Improper Validation of Specified Quantity in Input Description: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher suite carries an explicit IV followed by the ciphertext and an authentication tag. When decrypting such a record the record layer passed the record length to the cipher implementation before checking that the record was long enough to contain the explicit IV and the tag. For a record shorter than that overhead the cipher implementation rejected the impossible length, and the record layer treated this as an internal failure and raised a fatal internal_error alert instead of treating the record as one that failed authentication. In TLS 1.2 the same record causes a fatal internal_error alert instead of the expected bad_record_mac alert. Since any undecryptable record already terminates a TLS connection, this is a protocol conformance issue rather than a security issue in TLS. The fix validates the record length against the explicit IV and tag length before any AEAD processing, so that TLS reports bad_record_mac and DTLS silently discards the record. FIPS impact: no The affected code is outside the FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-75806 | libssl3 | 3.5.8-r0 | Issue summary: An established DTLS 1.2 association using an AEAD cipher suite can be terminated by a single unauthenticated datagram whose encrypted fragment is shorter than the mandatory explicit IV and authentication tag overhead. Impact summary: An attacker who can send a datagram that is routed to an existing DTLS 1.2 association can tear that association down without knowing any key material. This is a Denial of Service limited to the targeted association. There is no memory safety or confidentiality impact. CWE: CWE-1284: Improper Validation of Specified Quantity in Input Description: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher suite carries an explicit IV followed by the ciphertext and an authentication tag. When decrypting such a record the record layer passed the record length to the cipher implementation before checking that the record was long enough to contain the explicit IV and the tag. For a record shorter than that overhead the cipher implementation rejected the impossible length, and the record layer treated this as an internal failure and raised a fatal internal_error alert instead of treating the record as one that failed authentication. In TLS 1.2 the same record causes a fatal internal_error alert instead of the expected bad_record_mac alert. Since any undecryptable record already terminates a TLS connection, this is a protocol conformance issue rather than a security issue in TLS. The fix validates the record length against the explicit IV and tag length before any AEAD processing, so that TLS reports bad_record_mac and DTLS silently discards the record. FIPS impact: no The affected code is outside the FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-75804 | libcrypto3 | 3.5.8-r0 | Issue summary: OpenSSL QUIC stack does not enforce connection level flow control for streams. Remote peers may send more bytes as long as they fit within the stream flow control limits. Impact summary: A malicious remote peer may exploit the lack of connection flow control for streams to make the QUIC stack receive ~100MB of memory instead of 768 KiB (default flow control window size). CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: The local QUIC stack advertises two flow control limits to its remote peer: stream flow control limit and connection flow control limit. The remote peer must follow both limits when transmitting stream data. Whenever the local QUIC stack receives a stream frame, it validates that the size of the received stream frame stays within flow control limits. If either limit is exceeded (stream level or connection level), then the QUIC stack must close the connection with a flow control error. The vulnerable OpenSSL QUIC stack enforces the stream-level but not the connection-level limit. To exploit the issue, three conditions must be met: - the remote peer opens several streams - each stream must stay within the stream-level flow control limit - there must be no zero-offset byte sent on any of the streams (to prevent the vulnerable QUIC stack from consuming data). By meeting the conditions above, the remote peer may make the local stack allocate 2 x MAX_STREAMS x (stream flow control limit) bytes of memory. MAX_STREAMS defaults to 100, and the limit applies to both bidirectional and unidirectional streams, making it 200 in total. The default flow control window for a stream is 512kB. The remote peer may force the vulnerable QUIC stack to allocate 100MB of heap per connection. FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-75804 | libssl3 | 3.5.8-r0 | Issue summary: OpenSSL QUIC stack does not enforce connection level flow control for streams. Remote peers may send more bytes as long as they fit within the stream flow control limits. Impact summary: A malicious remote peer may exploit the lack of connection flow control for streams to make the QUIC stack receive ~100MB of memory instead of 768 KiB (default flow control window size). CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: The local QUIC stack advertises two flow control limits to its remote peer: stream flow control limit and connection flow control limit. The remote peer must follow both limits when transmitting stream data. Whenever the local QUIC stack receives a stream frame, it validates that the size of the received stream frame stays within flow control limits. If either limit is exceeded (stream level or connection level), then the QUIC stack must close the connection with a flow control error. The vulnerable OpenSSL QUIC stack enforces the stream-level but not the connection-level limit. To exploit the issue, three conditions must be met: - the remote peer opens several streams - each stream must stay within the stream-level flow control limit - there must be no zero-offset byte sent on any of the streams (to prevent the vulnerable QUIC stack from consuming data). By meeting the conditions above, the remote peer may make the local stack allocate 2 x MAX_STREAMS x (stream flow control limit) bytes of memory. MAX_STREAMS defaults to 100, and the limit applies to both bidirectional and unidirectional streams, making it 200 in total. The default flow control window for a stream is 512kB. The remote peer may force the vulnerable QUIC stack to allocate 100MB of heap per connection. FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-58055 | nghttp2-libs | 1.69.0-r0 | nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-42772 | libcrypto3 | 3.5.8-r0 | Issue summary: The QUIC stream reassembly algorithm performance deteriorates progressively as packets are arriving out of order. The worst case has a quadratic complexity proportional to the number of stream frames kept in the buffer for the received stream data. Impact summary: A remote QUIC peer that completes the handshake can create a connection-scoped CPU pressure and potentially a Denial of Service using compliant STREAM frames inside the advertised receive window, with low attacker bandwidth. CWE: CWE-407: Inefficient Algorithmic Complexity Description: OpenSSL manages received QUIC stream fragments using a doubly-linked list. While it optimizes for append operations (at the end of the list), it falls back to a head-to-tail linear search for any fragment that does not immediately follow the current `tail`. By manipulating the sequence of offsets, an attacker can force the server to perform O(n^2) operations, consuming excessive CPU time for the QUIC process. FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| LOW | CVE-2026-35191 | libcrypto3 | 3.5.8-r0 | Issue summary: The OpenSSL QUIC server, when configured to not preform address validation, can be forced to count incoming packets multiple times in its unvalidated credit computation, leading to a violation of the RFC 9000 unvalidated connection amplification limit of 3 times the amount of data received. Impact summary: A remote attacker able to spoof packets to a server using the OpenSSL QUIC implementation might use the server for an amplification of a DDoS attack. CWE: CWE-440: Expected Behavior Violation Description: OpenSSL's QUIC stack, when operating as a server, enforces client address validation (RFC 9000, Section 8), to confirm the peer address is not used for a traffic amplification attack. If this feature is disabled on the server, the QUIC stack limits the amount of server data that can be sent to 3 times the amount of data received from the peer address, until such time as the TLS handshake is completed. The OpenSSL QUIC server, when operating in non-validation mode, adds the length of the whole datagram received to the unvalidated credit limit when processing each QUIC packet in the datagram. A remote peer may, after establishing a connection with an initial client hello frame, send a subsequent datagram containing multiple QUIC packets, leading the server to account the entire datagram length for each packet in the datagram, resulting in the server believing that the peer has sent more data than it actually has, thereby violating the 3x amplification limit mandated by the RFC. FIPS impact: no As the QUIC stack lives outside the FIPS module boundary, no FIPS modules are affected by this CVE. — /lib/apk/db/installed | |
| LOW | CVE-2026-35191 | libssl3 | 3.5.8-r0 | Issue summary: The OpenSSL QUIC server, when configured to not preform address validation, can be forced to count incoming packets multiple times in its unvalidated credit computation, leading to a violation of the RFC 9000 unvalidated connection amplification limit of 3 times the amount of data received. Impact summary: A remote attacker able to spoof packets to a server using the OpenSSL QUIC implementation might use the server for an amplification of a DDoS attack. CWE: CWE-440: Expected Behavior Violation Description: OpenSSL's QUIC stack, when operating as a server, enforces client address validation (RFC 9000, Section 8), to confirm the peer address is not used for a traffic amplification attack. If this feature is disabled on the server, the QUIC stack limits the amount of server data that can be sent to 3 times the amount of data received from the peer address, until such time as the TLS handshake is completed. The OpenSSL QUIC server, when operating in non-validation mode, adds the length of the whole datagram received to the unvalidated credit limit when processing each QUIC packet in the datagram. A remote peer may, after establishing a connection with an initial client hello frame, send a subsequent datagram containing multiple QUIC packets, leading the server to account the entire datagram length for each packet in the datagram, resulting in the server believing that the peer has sent more data than it actually has, thereby violating the 3x amplification limit mandated by the RFC. FIPS impact: no As the QUIC stack lives outside the FIPS module boundary, no FIPS modules are affected by this CVE. — /lib/apk/db/installed | |
| LOW | CVE-2026-54875 | libcrypto3 | 3.5.8-r0 | Issue summary: A non-constant-time optimized implementation of scalar point multiplication is used for SM2 private key operations on ARM64 and RISC-V platforms. Impact summary: An attacker able to measure the time taken by, or to observe the cache-line access pattern of SM2 signing or decryption on an affected platform can learn information about the secret scalar. CWE: CWE-208: Observable Timing Discrepancy Description: On ARM64 and RISC-V processors, the SM2 curve uses an optimized scalar multiplication implementation whose conditional branches and table look ups are chosen according to the bits of the secret scalar. The execution time and the cache-access pattern therefore depend on the long-term private key (during SM2 decryption) or the per-signature nonce (during SM2 signature generation), forming a timing and cache side-channel. FIPS Impact: no SM2 is not a FIPS algorithm and the optimized SM2 implementation is not part of the FIPS module. OpenSSL 4.0, 3.6, 3.5 and 3.4 are vulnerable to this issue on AArch64 and RISC-V. OpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue. OpenSSL 4.0 users should upgrade to OpenSSL 4.0.3. OpenSSL 3.6 users should upgrade to OpenSSL 3.6.5. OpenSSL 3.5 users should upgrade to OpenSSL 3.5.9. OpenSSL 3.4 users should upgrade to OpenSSL 3.4.8. This issue was reported on 2 May 2026 by Abhinav Agarwal. It was independently reported on 6 June 2026 by Feng Xue. The fix was developed by Igor Ustinov. -- cut (non-publishing metadata for internal use) -- Reported by: Abhinav Agarwal, Feng Xue Fixed by: Igor Ustinov — /lib/apk/db/installed | |
| LOW | CVE-2026-54875 | libssl3 | 3.5.8-r0 | Issue summary: A non-constant-time optimized implementation of scalar point multiplication is used for SM2 private key operations on ARM64 and RISC-V platforms. Impact summary: An attacker able to measure the time taken by, or to observe the cache-line access pattern of SM2 signing or decryption on an affected platform can learn information about the secret scalar. CWE: CWE-208: Observable Timing Discrepancy Description: On ARM64 and RISC-V processors, the SM2 curve uses an optimized scalar multiplication implementation whose conditional branches and table look ups are chosen according to the bits of the secret scalar. The execution time and the cache-access pattern therefore depend on the long-term private key (during SM2 decryption) or the per-signature nonce (during SM2 signature generation), forming a timing and cache side-channel. FIPS Impact: no SM2 is not a FIPS algorithm and the optimized SM2 implementation is not part of the FIPS module. OpenSSL 4.0, 3.6, 3.5 and 3.4 are vulnerable to this issue on AArch64 and RISC-V. OpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue. OpenSSL 4.0 users should upgrade to OpenSSL 4.0.3. OpenSSL 3.6 users should upgrade to OpenSSL 3.6.5. OpenSSL 3.5 users should upgrade to OpenSSL 3.5.9. OpenSSL 3.4 users should upgrade to OpenSSL 3.4.8. This issue was reported on 2 May 2026 by Abhinav Agarwal. It was independently reported on 6 June 2026 by Feng Xue. The fix was developed by Igor Ustinov. -- cut (non-publishing metadata for internal use) -- Reported by: Abhinav Agarwal, Feng Xue Fixed by: Igor Ustinov — /lib/apk/db/installed | |
| LOW | CVE-2026-54872 | libcrypto3 | 3.5.8-r0 | Issue summary: The generic elliptic-curve scalar multiplication used for ECDSA and SM2 signature operations with curves that do not have a dedicated implementation leaks information about the secret nonce through timing. Impact summary: An attacker able to measure signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key. CWE: CWE-208: Observable Timing Discrepancy Description: The generic elliptic-curve scalar multiplication used for curves that do not have a dedicated constant-time implementation pads the secret scalar with non-constant-time BIGNUM operations, so the time taken depends on the value of the secret scalar derived from the ECDSA and SM2 nonce. The leak is very small; observing it requires a large number of measurements. The effect is largest for curves whose group order lies on a machine-word boundary, such as brainpoolP384r1. Applications using ECDSA signing over the Brainpool and other generic prime curves, and SM2 signing on platforms that use the generic implementation, are vulnerable to this issue. The NIST curves P-256, P-384 and P-521 use dedicated constant-time implementations and are not affected. FIPS Impact: no The FIPS modules are not affected: the approved NIST curves used in the FIPS provider have dedicated constant-time implementations and do not use the affected code path. — /lib/apk/db/installed | |
| LOW | CVE-2026-54872 | libssl3 | 3.5.8-r0 | Issue summary: The generic elliptic-curve scalar multiplication used for ECDSA and SM2 signature operations with curves that do not have a dedicated implementation leaks information about the secret nonce through timing. Impact summary: An attacker able to measure signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key. CWE: CWE-208: Observable Timing Discrepancy Description: The generic elliptic-curve scalar multiplication used for curves that do not have a dedicated constant-time implementation pads the secret scalar with non-constant-time BIGNUM operations, so the time taken depends on the value of the secret scalar derived from the ECDSA and SM2 nonce. The leak is very small; observing it requires a large number of measurements. The effect is largest for curves whose group order lies on a machine-word boundary, such as brainpoolP384r1. Applications using ECDSA signing over the Brainpool and other generic prime curves, and SM2 signing on platforms that use the generic implementation, are vulnerable to this issue. The NIST curves P-256, P-384 and P-521 use dedicated constant-time implementations and are not affected. FIPS Impact: no The FIPS modules are not affected: the approved NIST curves used in the FIPS provider have dedicated constant-time implementations and do not use the affected code path. — /lib/apk/db/installed | |
| LOW | CVE-2026-77696 | libcrypto3 | 3.5.8-r0 | Issue summary: SM2 signature generation uses non-constant-time arithmetic on secret values, forming a timing side-channel. Impact summary: An attacker able to measure SM2 signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key. CWE: CWE-208: Observable Timing Discrepancy Description: SM2 signature generation computes the signature value using variable-time BIGNUM operations on the secret nonce and the private key, so the time taken to produce an SM2 signature depends on these secret values, forming a timing side-channel. Applications performing SM2 signature generation are affected on all platforms. FIPS Impact: no SM2 is not a FIPS algorithm. — /lib/apk/db/installed | |
| LOW | CVE-2026-77696 | libssl3 | 3.5.8-r0 | Issue summary: SM2 signature generation uses non-constant-time arithmetic on secret values, forming a timing side-channel. Impact summary: An attacker able to measure SM2 signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key. CWE: CWE-208: Observable Timing Discrepancy Description: SM2 signature generation computes the signature value using variable-time BIGNUM operations on the secret nonce and the private key, so the time taken to produce an SM2 signature depends on these secret values, forming a timing side-channel. Applications performing SM2 signature generation are affected on all platforms. FIPS Impact: no SM2 is not a FIPS algorithm. — /lib/apk/db/installed | |
| UNKNOWN | CVE-2026-3479 | python3 | 3.12.14-r0 | DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point. There is no vulnerability in the function if following the intended security model. pkgutil.get_data() did not validate the resource argument as documented, allowing path traversals. — /lib/apk/db/installed |
ghcr.io/voxpupuli/r10k-webhook
Downloads
ghcr.io/voxpupuli/r10k-webhook:latest (2026-08-27)
Trivy
CRITICAL 1
HIGH 77
MEDIUM 103
LOW 47
UNKNOWN 37
| Severity | ID | Package | Installed | Fixed | Title / target |
|---|---|---|---|---|---|
| CRITICAL | CVE-2026-54906 | concurrent-ruby | 1.3.6 | >= 1.3.7 | concurrent-ruby: rubygem-concurrent-ruby: concurrent-ruby: Synchronization flaw in ReadWriteLock allows unauthorized lock release and denial of service — Ruby |
| HIGH | CVE-2026-93990 | libexpat | 2.7.5-r0 | 2.8.5-r0 | expat: Expat: XML Injection via Malformed UTF-16 Input — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| HIGH | CVE-2026-86145 | pcre2 | 10.47-r0 | 10.48-r0 | pcre2: PCRE2: Out-of-bounds write allows arbitrary code execution via crafted regular expressions — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| HIGH | CVE-2026-89157 | pcre2 | 10.47-r0 | 10.48-r0 | pcre2: PCRE2: Out-of-bounds write via large pattern input — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| HIGH | CVE-2026-89161 | pcre2 | 10.47-r0 | 10.48-r0 | pcre2: PCRE2: Memory corruption vulnerability in pcre2_jit_match — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| HIGH | CVE-2026-54904 | concurrent-ruby | 1.3.6 | >= 1.3.7 | concurrent-ruby: rubygem-concurrent-ruby: concurrent-ruby: Denial of Service due to infinite loop in AtomicReference#update — Ruby |
| HIGH | CVE-2026-54297 | faraday | 2.14.2 | ~> 1.10.6, >= 2.14.3 | faraday: Faraday: Denial of Service via crafted nested query strings — Ruby |
| HIGH | CVE-2026-45363 | jwt | 2.10.2 | ~> 2.10.3, >= 3.2.0 | ruby-jwt: ruby-jwt: Authentication bypass due to empty key in HMAC verification — Ruby |
| HIGH | CVE-2026-27145 | stdlib | v1.26.2 | 1.25.11, 1.26.4 | crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries — usr/local/bin/supercronic-linux-amd64 |
| HIGH | CVE-2026-33811 | stdlib | v1.26.2 | 1.25.10, 1.26.3 | net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME — usr/local/bin/supercronic-linux-amd64 |
| HIGH | CVE-2026-33814 | stdlib | v1.26.2 | 1.25.10, 1.26.3 | net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame — usr/local/bin/supercronic-linux-amd64 |
| HIGH | CVE-2026-33818 | stdlib | v1.26.2 | 1.25.13, 1.26.6, 1.27.0-rc.3 | encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal — usr/local/bin/supercronic-linux-amd64 |
| HIGH | CVE-2026-39820 | stdlib | v1.26.2 | 1.25.10, 1.26.3 | net/mail: golang: Go net/mail: Denial of Service via crafted email inputs — usr/local/bin/supercronic-linux-amd64 |
| HIGH | CVE-2026-39821 | stdlib | v1.26.2 | 1.25.13, 1.26.6, 1.27.0-rc.3 | golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing — usr/local/bin/supercronic-linux-amd64 |
| HIGH | CVE-2026-39822 | stdlib | v1.26.2 | 1.25.12, 1.26.5, 1.27.0-rc.2 | golang: Go os.Root: Symlink following vulnerability allows directory traversal — usr/local/bin/supercronic-linux-amd64 |
| HIGH | CVE-2026-39836 | stdlib | v1.26.2 | 1.25.10, 1.26.3 | net: golang: Go net package: Denial of Service via NUL byte in Dial and LookupPort on Windows — usr/local/bin/supercronic-linux-amd64 |
| HIGH | CVE-2026-45447 | libcrypto3 | 3.5.6-r0 | 3.5.7-r0 | openssl: Heap Use-After-Free in OpenSSL PKCS7_verify() — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| HIGH | CVE-2026-14456 | libcrypto3 | 3.5.6-r0 | 3.5.8-r0 | openssl: OpenSSL: Denial of Service via unbounded memory growth in QUIC server — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| HIGH | CVE-2026-42499 | stdlib | v1.26.2 | 1.25.10, 1.26.3 | net/mail: golang: net/mail: Denial of Service via pathological email address parsing — usr/local/bin/supercronic-linux-amd64 |
| HIGH | CVE-2026-42504 | stdlib | v1.26.2 | 1.25.11, 1.26.4 | mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header — usr/local/bin/supercronic-linux-amd64 |
| HIGH | CVE-2026-46600 | stdlib | v1.26.2 | 1.26.6, 1.27.0-rc.3 | golang.org/x/net/dns/dnsmessage: golang.org/x/net/dns/dnsmessage: Denial of Service via invalid DNS record parsing — usr/local/bin/supercronic-linux-amd64 |
| HIGH | CVE-2026-56853 | stdlib | v1.26.2 | 1.25.13, 1.26.6, 1.27.0-rc.3 | net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service — usr/local/bin/supercronic-linux-amd64 |
| HIGH | CVE-2026-56858 | stdlib | v1.26.2 | 1.25.13, 1.26.6, 1.27.0-rc.3 | html/template: golang: Go html/template: Cross-Site Scripting via pathological input — usr/local/bin/supercronic-linux-amd64 |
| HIGH | CVE-2026-56859 | stdlib | v1.26.2 | 1.25.13, 1.26.6, 1.27.0-rc.3 | encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue — usr/local/bin/supercronic-linux-amd64 |
| HIGH | CVE-2026-76957 | libexpat | 2.7.5-r0 | 2.8.4-r0 | libexpat: libexpat: Memory corruption vulnerability allows arbitrary code execution or denial of service — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| HIGH | CVE-2026-76956 | libexpat | 2.7.5-r0 | 2.8.4-r0 | libexpat: libexpat: Denial of Service via hash flooding attack with crafted XML — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| HIGH | CVE-2026-76641 | libexpat | 2.7.5-r0 | 2.8.4-r0 | expat: Expat: Denial of Service via XML external entity parsing — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| HIGH | CVE-2026-66046 | libexpat | 2.7.5-r0 | 2.8.4-r0 | expat: Expat: Denial of Service via quadratic complexity in attribute processing — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| HIGH | CVE-2026-45186 | libexpat | 2.7.5-r0 | 2.8.1-r0 | libexpat: denial of service via crafted XML input — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| HIGH | CVE-2026-53587 | libgit2 | 1.9.2-r0 | 1.9.6-r0 | libgit2: libgit2: Denial of Service due to heap out-of-bounds read from malicious Git server — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| HIGH | CVE-2026-5917 | libgit2 | 1.9.2-r0 | 1.9.7-r0 | libgit2: libgit2: Arbitrary code execution via shell command injection in SSH backend — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| HIGH | CVE-2026-55199 | libssh2 | 1.11.1-r1 | 1.11.1-r3 | libssh2: libssh2: Denial of Service via crafted SSH_MSG_EXT_INFO message — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| HIGH | CVE-2026-55200 | libssh2 | 1.11.1-r1 | 1.11.1-r3 | libssh2: libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| HIGH | CVE-2026-7598 | libssh2 | 1.11.1-r1 | 1.11.1-r2 | libssh2: integer overflow via large username or password arguments — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| HIGH | CVE-2026-14456 | libssl3 | 3.5.6-r0 | 3.5.8-r0 | openssl: OpenSSL: Denial of Service via unbounded memory growth in QUIC server — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| HIGH | CVE-2026-45447 | libssl3 | 3.5.6-r0 | 3.5.7-r0 | openssl: Heap Use-After-Free in OpenSSL PKCS7_verify() — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| HIGH | CVE-2026-9547 | libcurl | 8.19.0-r0 | 8.22.0-r0 | curl: curl: Man-in-the-middle attack via SSH host key bypass — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| HIGH | CVE-2026-8927 | libcurl | 8.19.0-r0 | 8.22.0-r0 | curl: Information disclosure due to uncleared proxy authentication state — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| HIGH | CVE-2026-8925 | libcurl | 8.19.0-r0 | 8.22.0-r0 | curl: curl: Double-free vulnerability in SASL authentication — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| HIGH | CVE-2026-8458 | libcurl | 8.19.0-r0 | 8.22.0-r0 | curl: libcurl: Unauthorized connection reuse due to a logical error — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| HIGH | CVE-2026-8286 | libcurl | 8.19.0-r0 | 8.22.0-r0 | curl: curl: Insecure connection establishment due to TLS configuration mismatch — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| HIGH | CVE-2026-6276 | libcurl | 8.19.0-r0 | 8.20.0-r0 | curl: libcurl: Information disclosure due to cookie leak when reusing connections with custom Host headers — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| HIGH | CVE-2026-5773 | libcurl | 8.19.0-r0 | 8.20.0-r0 | curl: libcurl: Wrong file transfer due to incorrect SMB connection reuse — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| HIGH | CVE-2026-12064 | libcurl | 8.19.0-r0 | 8.22.0-r0 | curl: curl: SSH host verification bypass when using schemeless URLs with SFTP/SCP — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| HIGH | CVE-2026-11586 | libcurl | 8.19.0-r0 | 8.22.0-r0 | curl: curl: Denial of Service via WebSocket PING flood — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| HIGH | CVE-2026-11352 | libcurl | 8.19.0-r0 | 8.22.0-r0 | curl: libcurl: curl/libcurl: Remote denial of service via QUIC UDP receive function vulnerability — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| HIGH | CVE-2026-103111 | pcre2 | 10.47-r0 | 10.49-r0 | pcre2: pcre2: Out-of-bounds write via crafted regular expression — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| HIGH | CVE-2026-40164 | jq | 1.8.1-r0 | 1.8.2-r0 | jq: jq: Denial of Service via crafted JSON object causing hash collisions — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| HIGH | CVE-2026-46597 | golang.org/x/crypto | v0.48.0 | 0.52.0 | golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs — usr/sbin/webhook-go |
| HIGH | CVE-2026-56854 | golang.org/x/crypto | v0.48.0 | 0.55.0 | golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authentication bypass due to unenforced source-address restrictions — usr/sbin/webhook-go |
| HIGH | CVE-2026-25681 | golang.org/x/net | v0.51.0 | 0.55.0 | golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting — usr/sbin/webhook-go |
| HIGH | CVE-2026-27136 | golang.org/x/net | v0.51.0 | 0.55.0 | golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass — usr/sbin/webhook-go |
| HIGH | CVE-2026-33814 | golang.org/x/net | v0.51.0 | 0.53.0 | net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame — usr/sbin/webhook-go |
| HIGH | CVE-2026-39821 | golang.org/x/net | v0.51.0 | 0.55.0 | golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing — usr/sbin/webhook-go |
| HIGH | CVE-2026-46600 | golang.org/x/net | v0.51.0 | 0.56.0 | golang.org/x/net/dns/dnsmessage: golang.org/x/net/dns/dnsmessage: Denial of Service via invalid DNS record parsing — usr/sbin/webhook-go |
| HIGH | CVE-2026-56852 | golang.org/x/text | v0.34.0 | 0.39.0 | golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input — usr/sbin/webhook-go |
| HIGH | CVE-2026-9547 | curl | 8.19.0-r0 | 8.22.0-r0 | curl: curl: Man-in-the-middle attack via SSH host key bypass — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| HIGH | CVE-2026-8927 | curl | 8.19.0-r0 | 8.22.0-r0 | curl: Information disclosure due to uncleared proxy authentication state — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| HIGH | CVE-2026-8925 | curl | 8.19.0-r0 | 8.22.0-r0 | curl: curl: Double-free vulnerability in SASL authentication — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| HIGH | CVE-2026-8458 | curl | 8.19.0-r0 | 8.22.0-r0 | curl: libcurl: Unauthorized connection reuse due to a logical error — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| HIGH | CVE-2026-8286 | curl | 8.19.0-r0 | 8.22.0-r0 | curl: curl: Insecure connection establishment due to TLS configuration mismatch — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| HIGH | CVE-2026-6276 | curl | 8.19.0-r0 | 8.20.0-r0 | curl: libcurl: Information disclosure due to cookie leak when reusing connections with custom Host headers — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| HIGH | CVE-2026-5773 | curl | 8.19.0-r0 | 8.20.0-r0 | curl: libcurl: Wrong file transfer due to incorrect SMB connection reuse — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| HIGH | CVE-2026-12064 | curl | 8.19.0-r0 | 8.22.0-r0 | curl: curl: SSH host verification bypass when using schemeless URLs with SFTP/SCP — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| HIGH | CVE-2026-11586 | curl | 8.19.0-r0 | 8.22.0-r0 | curl: curl: Denial of Service via WebSocket PING flood — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| HIGH | CVE-2026-11352 | curl | 8.19.0-r0 | 8.22.0-r0 | curl: libcurl: curl/libcurl: Remote denial of service via QUIC UDP receive function vulnerability — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| HIGH | CVE-2026-33630 | c-ares | 1.34.6-r0 | 1.34.8-r0 | c-ares: c-ares: Use-after-free / double-free in query-completion handling — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| HIGH | CVE-2026-32316 | jq | 1.8.1-r0 | 1.8.2-r0 | jq: jq: Denial of Service or potential arbitrary code execution due to integer overflow and heap-based buffer overflow — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| HIGH | CVE-2026-39828 | golang.org/x/crypto | v0.48.0 | 0.52.0 | golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions — usr/sbin/webhook-go |
| HIGH | CVE-2026-39829 | golang.org/x/crypto | v0.48.0 | 0.52.0 | golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters — usr/sbin/webhook-go |
| HIGH | CVE-2026-39830 | golang.org/x/crypto | v0.48.0 | 0.52.0 | golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses — usr/sbin/webhook-go |
| HIGH | CVE-2026-39831 | golang.org/x/crypto | v0.48.0 | 0.52.0 | golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check — usr/sbin/webhook-go |
| HIGH | CVE-2026-39832 | golang.org/x/crypto | v0.48.0 | 0.52.0 | golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions — usr/sbin/webhook-go |
| HIGH | CVE-2026-39835 | golang.org/x/crypto | v0.48.0 | 0.52.0 | golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate — usr/sbin/webhook-go |
| HIGH | CVE-2026-46595 | golang.org/x/crypto | v0.48.0 | 0.52.0 | golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authorization bypass due to skipped source-address validation — usr/sbin/webhook-go |
| HIGH | CVE-2026-56860 | stdlib | v1.26.2 | 1.25.13, 1.26.6, 1.27.0-rc.3 | net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution — usr/local/bin/supercronic-linux-amd64 |
| HIGH | CVE-2026-42508 | golang.org/x/crypto | v0.48.0 | 0.52.0 | golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey — usr/sbin/webhook-go |
| HIGH | CVE-2026-56862 | stdlib | v1.26.2 | 1.25.13, 1.26.6, 1.27.0-rc.3 | crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages — usr/local/bin/supercronic-linux-amd64 |
| MEDIUM | CVE-2026-54905 | concurrent-ruby | 1.3.6 | >= 1.3.7 | concurrent-ruby: Concurrent-ruby: Incorrect write lock granting leading to broken mutual exclusion — Ruby |
| MEDIUM | CVE-2026-56131 | libexpat | 2.7.5-r0 | 2.8.2-r0 | libexpat: libexpat: Use-after-free vulnerability due to insufficient handler call depth tracking — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-53585 | libgit2 | 1.9.2-r0 | 1.9.6-r0 | libgit2: libgit2: Denial of Service via Unbounded Memory Allocation — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-53583 | libgit2 | 1.9.2-r0 | 1.9.6-r0 | libgit2: libgit2: Network attacker can intercept HTTPS connections via inverted IP SubjectAltName comparison — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-40898 | github.com/quic-go/quic-go | v0.59.0 | 0.59.1 | github.com/quic-go/quic-go: quic-go: Denial of Service via excessive memory allocation in HTTP/3 trailers — usr/sbin/webhook-go |
| MEDIUM | CVE-2026-42507 | stdlib | v1.26.2 | 1.25.11, 1.26.4 | net/textproto: golang: Golang net/textproto: Misleading error messages via input injection — usr/local/bin/supercronic-linux-amd64 |
| MEDIUM | CVE-2026-56412 | libexpat | 2.7.5-r0 | 2.8.2-r0 | libexpat: libexpat: Use-after-free vulnerability due to improper handling of XML CDATA sections — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-56411 | libexpat | 2.7.5-r0 | 2.8.2-r0 | expat: libexpat: Integer Overflow Vulnerability Leading to Information Disclosure or Code Execution — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-56410 | libexpat | 2.7.5-r0 | 2.8.2-r0 | libexpat: libexpat: Integer overflow in xmlwf can lead to information disclosure and arbitrary code execution. — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-56409 | libexpat | 2.7.5-r0 | 2.8.2-r0 | xmlwf in libexpat before 2.8.2 has an integer overflow for the output ... — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-56408 | libexpat | 2.7.5-r0 | 2.8.2-r0 | libexpat before 2.8.2 has an integer overflow in copyString. — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-39823 | stdlib | v1.26.2 | 1.25.10, 1.26.3 | html/template: golang: Go html/template: Cross-Site Scripting via improper URL escaping in meta tag content — usr/local/bin/supercronic-linux-amd64 |
| MEDIUM | CVE-2026-39825 | stdlib | v1.26.2 | 1.25.10, 1.26.3 | net/http/httputil: golang: net/http/httputil: ReverseProxy forwards hidden query parameters, potentially bypassing security controls — usr/local/bin/supercronic-linux-amd64 |
| MEDIUM | CVE-2026-39826 | stdlib | v1.26.2 | 1.25.10, 1.26.3 | html/template: golang: html/template: Cross-site scripting due to incorrect script tag escaping — usr/local/bin/supercronic-linux-amd64 |
| MEDIUM | CVE-2026-56407 | libexpat | 2.7.5-r0 | 2.8.2-r0 | libexpat: libexpat: Arbitrary code execution due to integer overflow — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-56406 | libexpat | 2.7.5-r0 | 2.8.2-r0 | libexpat: libexpat: Arbitrary code execution via integer overflow in XML_ParseBuffer — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-56405 | libexpat | 2.7.5-r0 | 2.8.2-r0 | libexpat: libexpat: Information disclosure and arbitrary code execution via integer overflow — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-56404 | libexpat | 2.7.5-r0 | 2.8.2-r0 | libexpat: libexpat: Arbitrary Code Execution via integer overflow in addBinding — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-56403 | libexpat | 2.7.5-r0 | 2.8.2-r0 | libexpat: libexpat: Arbitrary code execution due to integer overflow in storeAtts — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-56132 | libexpat | 2.7.5-r0 | 2.8.2-r0 | expat: libexpat: Arbitrary Code Execution via Heap-based Buffer Overflow — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-42505 | stdlib | v1.26.2 | 1.25.12, 1.26.5, 1.27.0-rc.2 | crypto/tls: golang: Go crypto/tls: Information disclosure in Encrypted Client Hello — usr/local/bin/supercronic-linux-amd64 |
| MEDIUM | CVE-2026-85091 | zlib | 1.3.2-r0 | 1.3.2-r1 | zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vul ... — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-89160 | pcre2 | 10.47-r0 | 10.48-r0 | pcre2: PCRE2: Denial of Service via out-of-bounds read during invalid UTF matching — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-89158 | pcre2 | 10.47-r0 | 10.48-r0 | PCRE2: PCRE2: Out-of-bounds write via integer overflow on 32-bit platforms — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-89156 | pcre2 | 10.47-r0 | 10.48-r0 | PCRE2: PCRE2: Out-of-bounds read via invalid UTF data during JIT fallback — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-39827 | golang.org/x/crypto | v0.48.0 | 0.52.0 | golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via repeated rejected channel openings — usr/sbin/webhook-go |
| MEDIUM | CVE-2026-39833 | golang.org/x/crypto | v0.48.0 | 0.52.0 | golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to unenforced key confirmation — usr/sbin/webhook-go |
| MEDIUM | CVE-2026-39834 | golang.org/x/crypto | v0.48.0 | 0.52.0 | golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service due to integer overflow in SSH channel write — usr/sbin/webhook-go |
| MEDIUM | CVE-2026-63076 | libssl3 | 3.5.6-r0 | 3.5.8-r0 | openssl: invalid pointer dereference in CMP server via crafted protectionAlg — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-63072 | libssl3 | 3.5.6-r0 | 3.5.8-r0 | openssl: heap buffer overflow in CMS key unwrapping — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-46598 | golang.org/x/crypto | v0.48.0 | 0.52.0 | golang.org/x/crypto/ssh/agent: golang: golang.org/x/crypto/ssh/agent: Denial of Service via malformed input — usr/sbin/webhook-go |
| MEDIUM | CVE-2026-56855 | golang.org/x/crypto | v0.48.0 | 0.56.0 | golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted messages — usr/sbin/webhook-go |
| MEDIUM | CVE-2026-78662 | golang.org/x/crypto | v0.48.0 | 0.56.0 | golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via channel request flooding — usr/sbin/webhook-go |
| MEDIUM | CVE-2026-25680 | golang.org/x/net | v0.51.0 | 0.55.0 | golang.org/x/net/html: golang.org/x/net/html: Denial of Service due to excessive HTML parsing — usr/sbin/webhook-go |
| MEDIUM | CVE-2026-42502 | golang.org/x/net | v0.51.0 | 0.55.0 | golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering — usr/sbin/webhook-go |
| MEDIUM | CVE-2026-45445 | libssl3 | 3.5.6-r0 | 3.5.7-r0 | openssl: AES-OCB IV Ignored on EVP_Cipher() Path — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-42764 | libssl3 | 3.5.6-r0 | 3.5.7-r0 | openssl: NULL pointer dereference in QUIC server initial packet handling — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-34183 | libssl3 | 3.5.6-r0 | 3.5.7-r0 | openssl: Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-34182 | libssl3 | 3.5.6-r0 | 3.5.7-r0 | openssl: CMS AuthEnvelopedData Processing May Accept Forged Messages — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-18798 | libssl3 | 3.5.6-r0 | 3.5.8-r0 | openssl: QUIC server may trigger double free when processing INITIAL packet — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-42506 | golang.org/x/net | v0.51.0 | 0.55.0 | golang.org/x/net/html: golang.org/x/net/html: Cross-Site Scripting (XSS) via arbitrary HTML parsing — usr/sbin/webhook-go |
| MEDIUM | GHSA-gxhx-2686-5h9g | github.com/slack-go/slack | v0.18.0 | 0.23.1 | slack-go `SecretsVerifier` accepts empty signing secret without precondition — usr/sbin/webhook-go |
| MEDIUM | CVE-2026-53586 | libgit2 | 1.9.2-r0 | 1.9.6-r0 | libgit2: libgit2: Information disclosure via HTTP redirect allows credential leakage — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-33948 | jq | 1.8.1-r0 | 1.8.2-r0 | jq: jq: Input validation bypass via embedded NUL bytes allows parser differential attacks — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-39956 | jq | 1.8.1-r0 | 1.8.2-r0 | jq: missing runtime type checks for _strindices lead to crash and limited memory disclosure — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-39979 | jq | 1.8.1-r0 | 1.8.2-r0 | jq: out-of-bounds read in jv_parse_sized() on error formatting for non-NUL-terminated buffers — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-40612 | jq | 1.8.1-r0 | 1.8.2-r0 | jq: stack overflow via unbounded recursion in jv_contains — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-41256 | jq | 1.8.1-r0 | 1.8.2-r0 | jq: embedded NUL truncates top-level jq programs loaded with -f — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-41257 | jq | 1.8.1-r0 | 1.8.2-r0 | jq: signed-int overflow in stack_reallocate — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-43894 | jq | 1.8.1-r0 | 1.8.2-r0 | jq: jq: Arbitrary Code Execution or Denial of Service via Signed Integer Overflow — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-43895 | jq | 1.8.1-r0 | 1.8.2-r0 | jq: embedded NUL in jq import paths causes local redaction-policy bypass and preserves sensitive fields in published artifacts — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-43896 | jq | 1.8.1-r0 | 1.8.2-r0 | jq: stack overflow in recursive object merge — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-44777 | jq | 1.8.1-r0 | 1.8.2-r0 | jq: stack overflow in module loading on mutual include — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-47770 | jq | 1.8.1-r0 | 1.8.2-r0 | jq: jq: Denial of Service via deeply nested array comparison — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-49839 | jq | 1.8.1-r0 | 1.8.2-r0 | jq: jq: Heap out-of-bounds write via oversized raw file processing — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-54679 | jq | 1.8.1-r0 | 1.8.2-r0 | jq: jq: Denial of Service via integer overflow and buffer overrun on 32-bit systems — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-18798 | libcrypto3 | 3.5.6-r0 | 3.5.8-r0 | openssl: QUIC server may trigger double free when processing INITIAL packet — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-34182 | libcrypto3 | 3.5.6-r0 | 3.5.7-r0 | openssl: CMS AuthEnvelopedData Processing May Accept Forged Messages — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-34183 | libcrypto3 | 3.5.6-r0 | 3.5.7-r0 | openssl: Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-42764 | libcrypto3 | 3.5.6-r0 | 3.5.7-r0 | openssl: NULL pointer dereference in QUIC server initial packet handling — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-45445 | libcrypto3 | 3.5.6-r0 | 3.5.7-r0 | openssl: AES-OCB IV Ignored on EVP_Cipher() Path — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-63072 | libcrypto3 | 3.5.6-r0 | 3.5.8-r0 | openssl: heap buffer overflow in CMS key unwrapping — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-63076 | libcrypto3 | 3.5.6-r0 | 3.5.8-r0 | openssl: invalid pointer dereference in CMP server via crafted protectionAlg — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-10536 | curl | 8.19.0-r0 | 8.22.0-r0 | libcurl: libcurl: Use-after-free vulnerability leading to Denial of Service — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-11564 | curl | 8.19.0-r0 | 8.22.0-r0 | libcurl: libcurl: Certificate validation bypass due to incorrect connection reuse — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-11856 | curl | 8.19.0-r0 | 8.22.0-r0 | curl: curl: Information disclosure via incorrect Digest authentication header reuse — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-19931 | curl | 8.19.0-r0 | 8.22.0-r0 | curl: libcurl: Information disclosure via incorrect connection reuse with Negotiate authentication — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-4873 | curl | 8.19.0-r0 | 8.20.0-r0 | curl: curl: Information disclosure due to incorrect TLS connection reuse — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-5545 | curl | 8.19.0-r0 | 8.20.0-r0 | curl: libcurl: Authentication bypass due to incorrect HTTP Negotiate connection reuse — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-6253 | curl | 8.19.0-r0 | 8.20.0-r0 | curl: curl: Proxy credential disclosure via redirects to unauthenticated proxies — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-6429 | curl | 8.19.0-r0 | 8.20.0-r0 | curl: libcurl: Credential leak via reused proxy connection during HTTP redirects — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-7009 | curl | 8.19.0-r0 | 8.20.0-r0 | curl: Curl: Certificate validation bypass due to OCSP stapling flaw — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-7168 | curl | 8.19.0-r0 | 8.20.0-r0 | curl: libcurl: Information disclosure via incorrect Proxy-Authorization header reuse — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-80229 | curl | 8.19.0-r0 | 8.22.0-r0 | When performing transfers via libcurl\u2019s multi interface, pooled T ... — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-82208 | curl | 8.19.0-r0 | 8.22.0-r0 | curl: libcurl: Improper certificate validation when using wolfSSL CA cache — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-8924 | curl | 8.19.0-r0 | 8.22.0-r0 | curl: curl: Cookie injection via malicious HTTP server using super cookies — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-8926 | curl | 8.19.0-r0 | 8.22.0-r0 | curl: curl: Information disclosure via incorrect .netrc password lookup — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-8932 | curl | 8.19.0-r0 | 8.22.0-r0 | libcurl: libcurl: Security feature bypass due to improper mTLS connection reuse — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-9079 | curl | 8.19.0-r0 | 8.22.0-r0 | libcurl: libcurl: Information disclosure due to failure to clear proxy authentication credentials — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-9080 | curl | 8.19.0-r0 | 8.22.0-r0 | libcurl: libcurl: Use-after-free via curl_easy_pause() in CURLMOPT_SOCKETFUNCTION callback — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-9545 | curl | 8.19.0-r0 | 8.22.0-r0 | libcurl: libcurl: Information disclosure via cached SSL session and early data — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-9546 | curl | 8.19.0-r0 | 8.22.0-r0 | libcurl: libcurl: Information disclosure due to persistent Referer header — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-33947 | jq | 1.8.1-r0 | 1.8.2-r0 | jq: unbounded Recursion in jv_setpath() / jv_getpath() / delpaths_sorted() — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-50219 | libexpat | 2.7.5-r0 | 2.8.2-r0 | expat: libexpat: Use-after-free vulnerability due to improper handler call depth tracking — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-7168 | libcurl | 8.19.0-r0 | 8.20.0-r0 | curl: libcurl: Information disclosure via incorrect Proxy-Authorization header reuse — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-7009 | libcurl | 8.19.0-r0 | 8.20.0-r0 | curl: Curl: Certificate validation bypass due to OCSP stapling flaw — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-6429 | libcurl | 8.19.0-r0 | 8.20.0-r0 | curl: libcurl: Credential leak via reused proxy connection during HTTP redirects — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-80229 | libcurl | 8.19.0-r0 | 8.22.0-r0 | When performing transfers via libcurl\u2019s multi interface, pooled T ... — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-82208 | libcurl | 8.19.0-r0 | 8.22.0-r0 | curl: libcurl: Improper certificate validation when using wolfSSL CA cache — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-8924 | libcurl | 8.19.0-r0 | 8.22.0-r0 | curl: curl: Cookie injection via malicious HTTP server using super cookies — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-8926 | libcurl | 8.19.0-r0 | 8.22.0-r0 | curl: curl: Information disclosure via incorrect .netrc password lookup — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-8932 | libcurl | 8.19.0-r0 | 8.22.0-r0 | libcurl: libcurl: Security feature bypass due to improper mTLS connection reuse — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-6253 | libcurl | 8.19.0-r0 | 8.20.0-r0 | curl: curl: Proxy credential disclosure via redirects to unauthenticated proxies — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-9079 | libcurl | 8.19.0-r0 | 8.22.0-r0 | libcurl: libcurl: Information disclosure due to failure to clear proxy authentication credentials — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-9080 | libcurl | 8.19.0-r0 | 8.22.0-r0 | libcurl: libcurl: Use-after-free via curl_easy_pause() in CURLMOPT_SOCKETFUNCTION callback — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-9545 | libcurl | 8.19.0-r0 | 8.22.0-r0 | libcurl: libcurl: Information disclosure via cached SSL session and early data — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-9546 | libcurl | 8.19.0-r0 | 8.22.0-r0 | libcurl: libcurl: Information disclosure due to persistent Referer header — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-5545 | libcurl | 8.19.0-r0 | 8.20.0-r0 | curl: libcurl: Authentication bypass due to incorrect HTTP Negotiate connection reuse — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-4873 | libcurl | 8.19.0-r0 | 8.20.0-r0 | curl: curl: Information disclosure due to incorrect TLS connection reuse — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-19931 | libcurl | 8.19.0-r0 | 8.22.0-r0 | curl: libcurl: Information disclosure via incorrect connection reuse with Negotiate authentication — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-11856 | libcurl | 8.19.0-r0 | 8.22.0-r0 | curl: curl: Information disclosure via incorrect Digest authentication header reuse — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-11564 | libcurl | 8.19.0-r0 | 8.22.0-r0 | libcurl: libcurl: Certificate validation bypass due to incorrect connection reuse — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| MEDIUM | CVE-2026-10536 | libcurl | 8.19.0-r0 | 8.22.0-r0 | libcurl: libcurl: Use-after-free vulnerability leading to Denial of Service — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| LOW | CVE-2026-82209 | curl | 8.19.0-r0 | 8.22.0-r0 | curl: libcurl: Information disclosure via improper Public Suffix List boundary check — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| LOW | CVE-2026-80255 | curl | 8.19.0-r0 | 8.22.0-r0 | curl: curl: Information disclosure due to secure cookie attribute bypass — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| LOW | CVE-2026-80231 | curl | 8.19.0-r0 | 8.22.0-r0 | curl: curl: Incorrect HTTPS connection reuse with Native CA Store — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| LOW | CVE-2026-80230 | curl | 8.19.0-r0 | 8.22.0-r0 | curl: curl: Public key pinning bypass allows unauthenticated connections — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| LOW | CVE-2026-18924 | curl | 8.19.0-r0 | 8.22.0-r0 | curl: libcurl: Use-after-free in HTTP/2 Server Push with shared connections — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| LOW | CVE-2026-13608 | curl | 8.19.0-r0 | 8.22.0-r0 | curl: curl: Authentication bypass in OpenLDAP SASL negotiation via Man-in-the-Middle (MITM) attack — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| LOW | CVE-2026-53584 | libgit2 | 1.9.2-r0 | 1.9.6-r0 | libgit2: libgit2: Submodule path traversal allows arbitrary directory creation — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| LOW | CVE-2026-41080 | libexpat | 2.7.5-r0 | 2.8.1-r0 | libexpat: expat: libexpat: Denial of Service via hash flooding with crafted XML — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| LOW | CVE-2026-13608 | libcurl | 8.19.0-r0 | 8.22.0-r0 | curl: curl: Authentication bypass in OpenLDAP SASL negotiation via Man-in-the-Middle (MITM) attack — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| LOW | CVE-2026-18924 | libcurl | 8.19.0-r0 | 8.22.0-r0 | curl: libcurl: Use-after-free in HTTP/2 Server Push with shared connections — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| LOW | CVE-2026-80230 | libcurl | 8.19.0-r0 | 8.22.0-r0 | curl: curl: Public key pinning bypass allows unauthenticated connections — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| LOW | CVE-2026-80231 | libcurl | 8.19.0-r0 | 8.22.0-r0 | curl: curl: Incorrect HTTPS connection reuse with Native CA Store — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| LOW | CVE-2026-80255 | libcurl | 8.19.0-r0 | 8.22.0-r0 | curl: curl: Information disclosure due to secure cookie attribute bypass — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| LOW | CVE-2026-82209 | libcurl | 8.19.0-r0 | 8.22.0-r0 | curl: libcurl: Information disclosure via improper Public Suffix List boundary check — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| LOW | CVE-2026-9076 | libssl3 | 3.5.6-r0 | 3.5.7-r0 | openssl: OpenSSL: Denial of Service due to heap out-of-bounds read in CMS password-based decryption — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| LOW | CVE-2026-7383 | libcrypto3 | 3.5.6-r0 | 3.5.7-r0 | openssl: OpenSSL: Heap buffer overflow due to signed integer overflow in Unicode output sizing — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| LOW | CVE-2026-63075 | libcrypto3 | 3.5.6-r0 | 3.5.8-r0 | openssl: QUIC ACK-only packet retention can cause memory exhaustion — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| LOW | CVE-2026-42770 | libssl3 | 3.5.6-r0 | 3.5.7-r0 | openssl: FFC-DH Peer Validation Uses Attacker-Supplied q — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| LOW | CVE-2026-45446 | libssl3 | 3.5.6-r0 | 3.5.7-r0 | openssl: Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| LOW | CVE-2026-14457 | libcrypto3 | 3.5.6-r0 | 3.5.8-r0 | openssl: RPK server signature algorithm selection can dereference a missing certificate — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| LOW | CVE-2026-63074 | libcrypto3 | 3.5.6-r0 | 3.5.8-r0 | openssl: CMP indefinite cache growth of ExtraCerts — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| LOW | CVE-2026-34180 | libcrypto3 | 3.5.6-r0 | 3.5.7-r0 | openssl: OpenSSL: Heap buffer over-read in ASN.1 decoding can lead to denial of service or information disclosure. — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| LOW | CVE-2026-34181 | libcrypto3 | 3.5.6-r0 | 3.5.7-r0 | openssl: PKCS#12 Files with PBMAC1 Are Accepted with Short HMAC Keys — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| LOW | CVE-2026-42766 | libcrypto3 | 3.5.6-r0 | 3.5.7-r0 | openssl: Possible NULL Dereference in Password-Based CMS Decryption — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| LOW | CVE-2026-42767 | libcrypto3 | 3.5.6-r0 | 3.5.7-r0 | openssl: NULL Pointer Dereference in CRMF EncryptedValue Decryption — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| LOW | CVE-2026-42768 | libcrypto3 | 3.5.6-r0 | 3.5.7-r0 | openssl: Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt() — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| LOW | CVE-2026-42769 | libcrypto3 | 3.5.6-r0 | 3.5.7-r0 | openssl: Trust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdate — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| LOW | CVE-2026-89162 | pcre2 | 10.47-r0 | 10.48-r0 | pcre2: PCRE2: Information disclosure via pcre2_serialize_encode — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| LOW | CVE-2026-42770 | libcrypto3 | 3.5.6-r0 | 3.5.7-r0 | openssl: FFC-DH Peer Validation Uses Attacker-Supplied q — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| LOW | CVE-2026-45446 | libcrypto3 | 3.5.6-r0 | 3.5.7-r0 | openssl: Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| LOW | CVE-2026-54874 | libcrypto3 | 3.5.6-r0 | 3.5.8-r0 | openssl: excessive memory use buffering DTLS records for a future epoch — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| LOW | CVE-2026-63073 | libcrypto3 | 3.5.6-r0 | 3.5.8-r0 | openssl: untrusted sender DN used as format string in CMP response validation — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| LOW | CVE-2026-9076 | libcrypto3 | 3.5.6-r0 | 3.5.7-r0 | openssl: OpenSSL: Denial of Service due to heap out-of-bounds read in CMS password-based decryption — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| LOW | CVE-2026-75803 | libcrypto3 | 3.5.6-r0 | 3.5.8-r0 | openssl: openssl: AEAD forgeries possible with empty ciphertext in EVP_Cipher() — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| LOW | CVE-2026-14457 | libssl3 | 3.5.6-r0 | 3.5.8-r0 | openssl: RPK server signature algorithm selection can dereference a missing certificate — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| LOW | CVE-2026-34180 | libssl3 | 3.5.6-r0 | 3.5.7-r0 | openssl: OpenSSL: Heap buffer over-read in ASN.1 decoding can lead to denial of service or information disclosure. — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| LOW | CVE-2026-34181 | libssl3 | 3.5.6-r0 | 3.5.7-r0 | openssl: PKCS#12 Files with PBMAC1 Are Accepted with Short HMAC Keys — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| LOW | CVE-2026-42766 | libssl3 | 3.5.6-r0 | 3.5.7-r0 | openssl: Possible NULL Dereference in Password-Based CMS Decryption — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| LOW | CVE-2026-42767 | libssl3 | 3.5.6-r0 | 3.5.7-r0 | openssl: NULL Pointer Dereference in CRMF EncryptedValue Decryption — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| LOW | CVE-2026-42768 | libssl3 | 3.5.6-r0 | 3.5.7-r0 | openssl: Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt() — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| LOW | CVE-2026-42769 | libssl3 | 3.5.6-r0 | 3.5.7-r0 | openssl: Trust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdate — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| LOW | CVE-2026-54874 | libssl3 | 3.5.6-r0 | 3.5.8-r0 | openssl: excessive memory use buffering DTLS records for a future epoch — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| LOW | CVE-2026-63073 | libssl3 | 3.5.6-r0 | 3.5.8-r0 | openssl: untrusted sender DN used as format string in CMP response validation — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| LOW | CVE-2026-63074 | libssl3 | 3.5.6-r0 | 3.5.8-r0 | openssl: CMP indefinite cache growth of ExtraCerts — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| LOW | CVE-2026-63075 | libssl3 | 3.5.6-r0 | 3.5.8-r0 | openssl: QUIC ACK-only packet retention can cause memory exhaustion — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| LOW | CVE-2026-7383 | libssl3 | 3.5.6-r0 | 3.5.7-r0 | openssl: OpenSSL: Heap buffer overflow due to signed integer overflow in Unicode output sizing — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| LOW | CVE-2026-75803 | libssl3 | 3.5.6-r0 | 3.5.8-r0 | openssl: openssl: AEAD forgeries possible with empty ciphertext in EVP_Cipher() — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| UNKNOWN | CVE-2026-78663 | golang.org/x/net | v0.51.0 | 0.60.0 | Double flow control refund on HTTP/2 server streams in net/http — usr/sbin/webhook-go |
| UNKNOWN | CVE-2026-78669 | golang.org/x/net | v0.51.0 | 0.60.0 | Excessive CPU consumption from repeated initial window changes in net/http — usr/sbin/webhook-go |
| UNKNOWN | CVE-2026-97032 | golang.org/x/net | v0.51.0 | 0.60.0 | HTTP/2 server crash due to HPACK encoder race in net/http — usr/sbin/webhook-go |
| UNKNOWN | CVE-2026-39824 | golang.org/x/sys | v0.41.0 | 0.44.0 | Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows — usr/sbin/webhook-go |
| UNKNOWN | CVE-2026-97032 | stdlib | v1.27.0 | 1.26.9, 1.27.2 | HTTP/2 server crash due to HPACK encoder race in net/http — usr/sbin/webhook-go |
| UNKNOWN | CVE-2026-56851 | golang.org/x/text | v0.34.0 | 0.41.0 | The Nickname profile can panic with an out-of-bounds slice error when ... — usr/sbin/webhook-go |
| UNKNOWN | CVE-2026-56857 | stdlib | v1.27.0 | 1.26.9, 1.27.2 | Root.Mkdir(All) can follow junctions out of the root on Windows in os — usr/sbin/webhook-go |
| UNKNOWN | CVE-2026-56866 | stdlib | v1.27.0 | 1.26.9, 1.27.2 | HTTP/1 client connection desynchronization after CONNECT rejection in net/http — usr/sbin/webhook-go |
| UNKNOWN | CVE-2026-78659 | stdlib | v1.27.0 | 1.26.9, 1.27.2 | HTTP/2 server memory exhaustion due to Trailer headers in net/http — usr/sbin/webhook-go |
| UNKNOWN | CVE-2026-78660 | stdlib | v1.27.0 | 1.26.9, 1.27.2 | HTTP/2 transport accepts malformed framing-related headers in net/http — usr/sbin/webhook-go |
| UNKNOWN | CVE-2026-78663 | stdlib | v1.27.0 | 1.26.9, 1.27.2 | Double flow control refund on HTTP/2 server streams in net/http — usr/sbin/webhook-go |
| UNKNOWN | CVE-2026-78667 | stdlib | v1.27.0 | 1.26.9, 1.27.2 | Lack of limit on size of parsed Range headers in net/http — usr/sbin/webhook-go |
| UNKNOWN | CVE-2026-78669 | stdlib | v1.27.0 | 1.26.9, 1.27.2 | Excessive CPU consumption from repeated initial window changes in net/http — usr/sbin/webhook-go |
| UNKNOWN | CVE-2026-94439 | stdlib | v1.27.0 | 1.26.9, 1.27.2 | HTTP/1 server connection desynchronization after 2xx CONNECT response in net/http — usr/sbin/webhook-go |
| UNKNOWN | CVE-2026-94440 | stdlib | v1.27.0 | 1.26.9, 1.27.2 | Memory limit bypass when parsing MIME headers in net/textproto, mime/multipart — usr/sbin/webhook-go |
| UNKNOWN | CVE-2026-94448 | stdlib | v1.27.0 | 1.26.9, 1.27.2 | Reset context tracking on consecutive template expressions in html/template — usr/sbin/webhook-go |
| UNKNOWN | CVE-2026-97030 | stdlib | v1.27.0 | 1.26.9, 1.27.2 | Recognize yield as regexp preceder keyword in html/template — usr/sbin/webhook-go |
| UNKNOWN | CVE-2026-97031 | stdlib | v1.27.0 | 1.26.9, 1.27.2 | Reject malformed ECH outer extension references in crypto/tls — usr/sbin/webhook-go |
| UNKNOWN | CVE-2026-39824 | golang.org/x/sys | v0.43.0 | 0.44.0 | Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows — usr/local/bin/supercronic-linux-amd64 |
| UNKNOWN | CVE-2026-56857 | stdlib | v1.26.2 | 1.26.9, 1.27.2 | Root.Mkdir(All) can follow junctions out of the root on Windows in os — usr/local/bin/supercronic-linux-amd64 |
| UNKNOWN | CVE-2026-56866 | stdlib | v1.26.2 | 1.26.9, 1.27.2 | HTTP/1 client connection desynchronization after CONNECT rejection in net/http — usr/local/bin/supercronic-linux-amd64 |
| UNKNOWN | CVE-2026-78659 | stdlib | v1.26.2 | 1.26.9, 1.27.2 | HTTP/2 server memory exhaustion due to Trailer headers in net/http — usr/local/bin/supercronic-linux-amd64 |
| UNKNOWN | CVE-2026-78660 | stdlib | v1.26.2 | 1.26.9, 1.27.2 | HTTP/2 transport accepts malformed framing-related headers in net/http — usr/local/bin/supercronic-linux-amd64 |
| UNKNOWN | CVE-2026-78663 | stdlib | v1.26.2 | 1.26.9, 1.27.2 | Double flow control refund on HTTP/2 server streams in net/http — usr/local/bin/supercronic-linux-amd64 |
| UNKNOWN | CVE-2026-78667 | stdlib | v1.26.2 | 1.26.9, 1.27.2 | Lack of limit on size of parsed Range headers in net/http — usr/local/bin/supercronic-linux-amd64 |
| UNKNOWN | CVE-2026-78669 | stdlib | v1.26.2 | 1.26.9, 1.27.2 | Excessive CPU consumption from repeated initial window changes in net/http — usr/local/bin/supercronic-linux-amd64 |
| UNKNOWN | CVE-2026-94439 | stdlib | v1.26.2 | 1.26.9, 1.27.2 | HTTP/1 server connection desynchronization after 2xx CONNECT response in net/http — usr/local/bin/supercronic-linux-amd64 |
| UNKNOWN | CVE-2026-94440 | stdlib | v1.26.2 | 1.26.9, 1.27.2 | Memory limit bypass when parsing MIME headers in net/textproto, mime/multipart — usr/local/bin/supercronic-linux-amd64 |
| UNKNOWN | CVE-2026-94448 | stdlib | v1.26.2 | 1.26.9, 1.27.2 | Reset context tracking on consecutive template expressions in html/template — usr/local/bin/supercronic-linux-amd64 |
| UNKNOWN | CVE-2026-97030 | stdlib | v1.26.2 | 1.26.9, 1.27.2 | Recognize yield as regexp preceder keyword in html/template — usr/local/bin/supercronic-linux-amd64 |
| UNKNOWN | CVE-2026-97031 | stdlib | v1.26.2 | 1.26.9, 1.27.2 | Reject malformed ECH outer extension references in crypto/tls — usr/local/bin/supercronic-linux-amd64 |
| UNKNOWN | CVE-2026-97032 | stdlib | v1.26.2 | 1.26.9, 1.27.2 | HTTP/2 server crash due to HPACK encoder race in net/http — usr/local/bin/supercronic-linux-amd64 |
| UNKNOWN | CVE-2026-80256 | curl | 8.19.0-r0 | 8.22.0-r0 | Title Not Available — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| UNKNOWN | GO-2026-5932 | golang.org/x/crypto | v0.48.0 | The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues — usr/sbin/webhook-go | |
| UNKNOWN | CVE-2026-80256 | libcurl | 8.19.0-r0 | 8.22.0-r0 | Title Not Available — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4) |
| UNKNOWN | CVE-2026-78659 | golang.org/x/net | v0.51.0 | 0.60.0 | HTTP/2 server memory exhaustion due to Trailer headers in net/http — usr/sbin/webhook-go |
| UNKNOWN | CVE-2026-78660 | golang.org/x/net | v0.51.0 | 0.60.0 | HTTP/2 transport accepts malformed framing-related headers in net/http — usr/sbin/webhook-go |
Grype
CRITICAL 27
HIGH 99
MEDIUM 60
LOW 8
UNKNOWN 2
NVD/CPE filtered 46
| Severity | ID | Package | Installed | Fixed | Title / target |
|---|---|---|---|---|---|
| CRITICAL | CVE-2026-7598 | libssh2 | 1.11.1-r1 | 1.11.1-r2 | /lib/apk/db/installed |
| CRITICAL | CVE-2026-19931 | curl | 8.19.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| CRITICAL | CVE-2026-19931 | libcurl | 8.19.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| CRITICAL | CVE-2026-11856 | curl | 8.19.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| CRITICAL | CVE-2026-11856 | libcurl | 8.19.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| CRITICAL | CVE-2026-8924 | curl | 8.19.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| CRITICAL | CVE-2026-8924 | libcurl | 8.19.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| CRITICAL | CVE-2026-10536 | curl | 8.19.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| CRITICAL | CVE-2026-10536 | libcurl | 8.19.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| CRITICAL | CVE-2026-9079 | curl | 8.19.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| CRITICAL | CVE-2026-9079 | libcurl | 8.19.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| CRITICAL | CVE-2026-18924 | curl | 8.19.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| CRITICAL | CVE-2026-18924 | libcurl | 8.19.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| CRITICAL | CVE-2026-11564 | libcurl | 8.19.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| CRITICAL | CVE-2026-11564 | curl | 8.19.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| CRITICAL | CVE-2026-8926 | libcurl | 8.19.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| CRITICAL | CVE-2026-8926 | curl | 8.19.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| CRITICAL | CVE-2026-8927 | curl | 8.19.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| CRITICAL | CVE-2026-8927 | libcurl | 8.19.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| CRITICAL | CVE-2026-75803 | libcrypto3 | 3.5.6-r0 | 3.5.8-r0 | /lib/apk/db/installed |
| CRITICAL | CVE-2026-63073 | libssl3 | 3.5.6-r0 | 3.5.8-r0 | /lib/apk/db/installed |
| CRITICAL | CVE-2026-75803 | libssl3 | 3.5.6-r0 | 3.5.8-r0 | /lib/apk/db/installed |
| CRITICAL | CVE-2026-8925 | curl | 8.19.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| CRITICAL | CVE-2026-8925 | libcurl | 8.19.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| CRITICAL | CVE-2026-34182 | libcrypto3 | 3.5.6-r0 | 3.5.7-r0 | /lib/apk/db/installed |
| CRITICAL | CVE-2026-34182 | libssl3 | 3.5.6-r0 | 3.5.7-r0 | /lib/apk/db/installed |
| CRITICAL | CVE-2026-63073 | libcrypto3 | 3.5.6-r0 | 3.5.8-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-9080 | curl | 8.19.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-9080 | libcurl | 8.19.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-89157 | pcre2 | 10.47-r0 | 10.48-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-32316 | jq | 1.8.1-r0 | 1.8.2-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-45186 | libexpat | 2.7.5-r0 | 2.8.1-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-80255 | curl | 8.19.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-80255 | libcurl | 8.19.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-13608 | curl | 8.19.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-6276 | curl | 8.19.0-r0 | 8.20.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-9547 | libcurl | 8.19.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-9547 | curl | 8.19.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-103111 | pcre2 | 10.47-r0 | 10.49-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-34181 | libcrypto3 | 3.5.6-r0 | 3.5.7-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-34181 | libssl3 | 3.5.6-r0 | 3.5.7-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-49839 | jq | 1.8.1-r0 | 1.8.2-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-80229 | libcurl | 8.19.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-80229 | curl | 8.19.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | GO-2026-6089 | stdlib | go1.26.2 | 1.25.13, 1.26.6, 1.27.0-rc.3 | When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this. — /usr/local/bin/supercronic-linux-amd64 |
| HIGH | GO-2026-5972 | stdlib | go1.26.2 | 1.25.13, 1.26.6, 1.27.0-rc.3 | Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures. — /usr/local/bin/supercronic-linux-amd64 |
| HIGH | GO-2026-6090 | stdlib | go1.26.2 | 1.25.13, 1.26.6, 1.27.0-rc.3 | Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely. — /usr/local/bin/supercronic-linux-amd64 |
| HIGH | GO-2026-5037 | stdlib | go1.26.2 | 1.25.11, 1.26.4 | (*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates. — /usr/local/bin/supercronic-linux-amd64 |
| HIGH | CVE-2026-40164 | jq | 1.8.1-r0 | 1.8.2-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-89161 | pcre2 | 10.47-r0 | 10.48-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-76957 | libexpat | 2.7.5-r0 | 2.8.4-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-6276 | libcurl | 8.19.0-r0 | 8.20.0-r0 | /lib/apk/db/installed |
| HIGH | GHSA-c32j-vqhx-rx3x | jwt | 2.10.2 | 2.10.3 | ruby-jwt: Empty-key HMAC bypass; cross-language sibling of CVE-2026-44351 — /usr/lib/ruby/gems/3.4.0/specifications/jwt-2.10.2.gemspec |
| HIGH | CVE-2026-80230 | libcurl | 8.19.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-8286 | curl | 8.19.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-8286 | libcurl | 8.19.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-80230 | curl | 8.19.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-76641 | libexpat | 2.7.5-r0 | 2.8.4-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-82209 | libcurl | 8.19.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-82209 | curl | 8.19.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-8932 | libcurl | 8.19.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-8932 | curl | 8.19.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-41080 | libexpat | 2.7.5-r0 | 2.8.1-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-12064 | libcurl | 8.19.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-12064 | curl | 8.19.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-76956 | libexpat | 2.7.5-r0 | 2.8.4-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-82208 | libcurl | 8.19.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-82208 | curl | 8.19.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-9545 | libcurl | 8.19.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-9545 | curl | 8.19.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-86145 | pcre2 | 10.47-r0 | 10.48-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-93990 | libexpat | 2.7.5-r0 | 2.8.5-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-53587 | libgit2 | 1.9.2-r0 | 1.9.6-r0 | /lib/apk/db/installed |
| HIGH | GO-2026-5970 | golang.org/x/text | v0.34.0 | 0.39.0 | A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes. — /usr/sbin/webhook-go |
| HIGH | CVE-2026-13608 | libcurl | 8.19.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-63075 | libssl3 | 3.5.6-r0 | 3.5.8-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-42764 | libssl3 | 3.5.6-r0 | 3.5.7-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-63075 | libcrypto3 | 3.5.6-r0 | 3.5.8-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-42764 | libcrypto3 | 3.5.6-r0 | 3.5.7-r0 | /lib/apk/db/installed |
| HIGH | GO-2026-4918 | stdlib | go1.26.2 | 1.25.10, 1.26.3 | When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0. — /usr/local/bin/supercronic-linux-amd64 |
| HIGH | CVE-2026-66046 | libexpat | 2.7.5-r0 | 2.8.4-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-33630 | c-ares | 1.34.6-r0 | 1.34.8-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-55200 | libssh2 | 1.11.1-r1 | 1.11.1-r3 | /lib/apk/db/installed |
| HIGH | CVE-2026-80231 | libcurl | 8.19.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-80231 | curl | 8.19.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-63072 | libssl3 | 3.5.6-r0 | 3.5.8-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-45447 | libcrypto3 | 3.5.6-r0 | 3.5.7-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-63072 | libcrypto3 | 3.5.6-r0 | 3.5.8-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-9076 | libssl3 | 3.5.6-r0 | 3.5.7-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-9076 | libcrypto3 | 3.5.6-r0 | 3.5.7-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-14457 | libssl3 | 3.5.6-r0 | 3.5.8-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-14457 | libcrypto3 | 3.5.6-r0 | 3.5.8-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-34183 | libssl3 | 3.5.6-r0 | 3.5.7-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-34183 | libcrypto3 | 3.5.6-r0 | 3.5.7-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-34180 | libssl3 | 3.5.6-r0 | 3.5.7-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-45447 | libssl3 | 3.5.6-r0 | 3.5.7-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-34180 | libcrypto3 | 3.5.6-r0 | 3.5.7-r0 | /lib/apk/db/installed |
| HIGH | GHSA-q339-8rmv-2mhv | erb | 4.0.4 | 4.0.4.1 | ERB has an @_init deserialization guard bypass via def_module / def_method / def_class — /usr/lib/ruby/gems/3.4.0/specifications/default/erb-4.0.4.gemspec |
| HIGH | CVE-2026-18798 | libssl3 | 3.5.6-r0 | 3.5.8-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-18798 | libcrypto3 | 3.5.6-r0 | 3.5.8-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-63076 | libcrypto3 | 3.5.6-r0 | 3.5.8-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-63076 | libssl3 | 3.5.6-r0 | 3.5.8-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-5917 | libgit2 | 1.9.2-r0 | 1.9.7-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-11586 | libcurl | 8.19.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-11586 | curl | 8.19.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | GO-2026-4971 | stdlib | go1.26.2 | 1.25.10, 1.26.3 | The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0). — /usr/local/bin/supercronic-linux-amd64 |
| HIGH | CVE-2026-54874 | libssl3 | 3.5.6-r0 | 3.5.8-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-54874 | libcrypto3 | 3.5.6-r0 | 3.5.8-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-85091 | zlib | 1.3.2-r0 | 1.3.2-r1 | /lib/apk/db/installed |
| HIGH | CVE-2026-9546 | libcurl | 8.19.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-9546 | curl | 8.19.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-5773 | libcurl | 8.19.0-r0 | 8.20.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-5773 | curl | 8.19.0-r0 | 8.20.0-r0 | /lib/apk/db/installed |
| HIGH | GHSA-h8w8-99g7-qmvj | concurrent-ruby | 1.3.6 | 1.3.7 | Concurrent Ruby : `AtomicReference#update` livelocks when the stored value is `Float::NAN` — /usr/lib/ruby/gems/3.4.0/specifications/concurrent-ruby-1.3.6.gemspec |
| HIGH | CVE-2026-55199 | libssh2 | 1.11.1-r1 | 1.11.1-r3 | /lib/apk/db/installed |
| HIGH | CVE-2026-45445 | libssl3 | 3.5.6-r0 | 3.5.7-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-45445 | libcrypto3 | 3.5.6-r0 | 3.5.7-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-11352 | libcurl | 8.19.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-11352 | curl | 8.19.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-7383 | libssl3 | 3.5.6-r0 | 3.5.7-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-14456 | libcrypto3 | 3.5.6-r0 | 3.5.8-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-7383 | libcrypto3 | 3.5.6-r0 | 3.5.7-r0 | /lib/apk/db/installed |
| HIGH | GHSA-98m9-hrrm-r99r | faraday | 2.14.2 | 2.14.3 | Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters — /usr/lib/ruby/gems/3.4.0/specifications/faraday-2.14.2.gemspec |
| HIGH | CVE-2026-14456 | libssl3 | 3.5.6-r0 | 3.5.8-r0 | /lib/apk/db/installed |
| HIGH | GO-2026-5026 | golang.org/x/net | v0.51.0 | 0.55.0 | The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com". — /usr/sbin/webhook-go |
| HIGH | GO-2026-5026 | stdlib | go1.26.2 | 1.25.13, 1.26.6, 1.27.0-rc.3 | The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com". — /usr/local/bin/supercronic-linux-amd64 |
| MEDIUM | CVE-2026-42769 | libcrypto3 | 3.5.6-r0 | 3.5.7-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-42769 | libssl3 | 3.5.6-r0 | 3.5.7-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-41257 | jq | 1.8.1-r0 | 1.8.2-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-45446 | libcrypto3 | 3.5.6-r0 | 3.5.7-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-56405 | libexpat | 2.7.5-r0 | 2.8.2-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-45446 | libssl3 | 3.5.6-r0 | 3.5.7-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-56406 | libexpat | 2.7.5-r0 | 2.8.2-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-56407 | libexpat | 2.7.5-r0 | 2.8.2-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-56403 | libexpat | 2.7.5-r0 | 2.8.2-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-50219 | libexpat | 2.7.5-r0 | 2.8.2-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-56412 | libexpat | 2.7.5-r0 | 2.8.2-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-56408 | libexpat | 2.7.5-r0 | 2.8.2-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-56132 | libexpat | 2.7.5-r0 | 2.8.2-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-56409 | libexpat | 2.7.5-r0 | 2.8.2-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-33947 | jq | 1.8.1-r0 | 1.8.2-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-39956 | jq | 1.8.1-r0 | 1.8.2-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-43895 | jq | 1.8.1-r0 | 1.8.2-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-56131 | libexpat | 2.7.5-r0 | 2.8.2-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-41256 | jq | 1.8.1-r0 | 1.8.2-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-56411 | libexpat | 2.7.5-r0 | 2.8.2-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-56410 | libexpat | 2.7.5-r0 | 2.8.2-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-54679 | jq | 1.8.1-r0 | 1.8.2-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-40612 | jq | 1.8.1-r0 | 1.8.2-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-44777 | jq | 1.8.1-r0 | 1.8.2-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-56404 | libexpat | 2.7.5-r0 | 2.8.2-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-47770 | jq | 1.8.1-r0 | 1.8.2-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-43896 | jq | 1.8.1-r0 | 1.8.2-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-43894 | jq | 1.8.1-r0 | 1.8.2-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-53583 | libgit2 | 1.9.2-r0 | 1.9.6-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-42767 | libcrypto3 | 3.5.6-r0 | 3.5.7-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-6429 | libcurl | 8.19.0-r0 | 8.20.0-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-6429 | curl | 8.19.0-r0 | 8.20.0-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-53586 | libgit2 | 1.9.2-r0 | 1.9.6-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-53585 | libgit2 | 1.9.2-r0 | 1.9.6-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-5545 | libcurl | 8.19.0-r0 | 8.20.0-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-5545 | curl | 8.19.0-r0 | 8.20.0-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-42766 | libcrypto3 | 3.5.6-r0 | 3.5.7-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-42766 | libssl3 | 3.5.6-r0 | 3.5.7-r0 | /lib/apk/db/installed |
| MEDIUM | GO-2026-6218 | stdlib | go1.26.2 | 1.25.13, 1.26.6, 1.27.0-rc.3 | Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations. — /usr/local/bin/supercronic-linux-amd64 |
| MEDIUM | CVE-2026-7168 | libcurl | 8.19.0-r0 | 8.20.0-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-7168 | curl | 8.19.0-r0 | 8.20.0-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-63074 | libssl3 | 3.5.6-r0 | 3.5.8-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-63074 | libcrypto3 | 3.5.6-r0 | 3.5.8-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-6253 | libcurl | 8.19.0-r0 | 8.20.0-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-6253 | curl | 8.19.0-r0 | 8.20.0-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-39979 | jq | 1.8.1-r0 | 1.8.2-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-89158 | pcre2 | 10.47-r0 | 10.48-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-89160 | pcre2 | 10.47-r0 | 10.48-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-89156 | pcre2 | 10.47-r0 | 10.48-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-7009 | libcurl | 8.19.0-r0 | 8.20.0-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-7009 | curl | 8.19.0-r0 | 8.20.0-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-33948 | jq | 1.8.1-r0 | 1.8.2-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-53584 | libgit2 | 1.9.2-r0 | 1.9.6-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-4873 | libcurl | 8.19.0-r0 | 8.20.0-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-4873 | curl | 8.19.0-r0 | 8.20.0-r0 | /lib/apk/db/installed |
| MEDIUM | GO-2026-5856 | stdlib | go1.26.2 | 1.25.12, 1.26.5, 1.27.0-rc.2 | Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello. — /usr/local/bin/supercronic-linux-amd64 |
| MEDIUM | GO-2026-5039 | stdlib | go1.26.2 | 1.25.11, 1.26.4 | When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or logged. — /usr/local/bin/supercronic-linux-amd64 |
| MEDIUM | CVE-2026-8458 | libcurl | 8.19.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-8458 | curl | 8.19.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-42767 | libssl3 | 3.5.6-r0 | 3.5.7-r0 | /lib/apk/db/installed |
| LOW | CVE-2026-42768 | libcrypto3 | 3.5.6-r0 | 3.5.7-r0 | /lib/apk/db/installed |
| LOW | CVE-2026-42768 | libssl3 | 3.5.6-r0 | 3.5.7-r0 | /lib/apk/db/installed |
| LOW | CVE-2026-42770 | libssl3 | 3.5.6-r0 | 3.5.7-r0 | /lib/apk/db/installed |
| LOW | CVE-2026-42770 | libcrypto3 | 3.5.6-r0 | 3.5.7-r0 | /lib/apk/db/installed |
| LOW | GHSA-x2f5-4prf-w687 | json | 2.9.1 | 2.19.9 | Ruby json: JSON generator heap buffer overflow when streaming to an IO — /usr/lib/ruby/gems/3.4.0/specifications/default/json-2.9.1.gemspec |
| LOW | GHSA-6wx8-w4f5-wwcr | concurrent-ruby | 1.3.6 | 1.3.7 | Concurrent Ruby: ReadWriteLock allows wrong-thread write release and stray read-release counter corruption — /usr/lib/ruby/gems/3.4.0/specifications/concurrent-ruby-1.3.6.gemspec |
| LOW | GHSA-wv3x-4vxv-whpp | concurrent-ruby | 1.3.6 | 1.3.7 | Concurrent Ruby: `ReentrantReadWriteLock` read-count overflow grants a write lock without exclusivity — /usr/lib/ruby/gems/3.4.0/specifications/concurrent-ruby-1.3.6.gemspec |
| LOW | CVE-2026-89162 | pcre2 | 10.47-r0 | 10.48-r0 | /lib/apk/db/installed |
| UNKNOWN | CVE-2026-80256 | curl | 8.19.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| UNKNOWN | CVE-2026-80256 | libcurl | 8.19.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
Filtered NVD/CPE matches (46)
These broad CPE matches are unconfirmed for the distribution package and excluded from scanner totals.
| Severity | ID | Package | Installed | Fixed | Title / target |
|---|---|---|---|---|---|
| HIGH | CVE-2026-72897 | libssl3 | 3.5.6-r0 | Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a connection to a different SSL_CTX part way through a handshake may access memory beyond the end of an internal array if the replacement context knows about more provider signature algorithms than the context the connection was created from. Applications which never call SSL_set_SSL_CTX() are not affected. Impact summary: A remote peer may be able to cause a small out-of-bounds read, and in some circumstances a fixed-value out-of-bounds write, on the server heap. This may lead to a Denial of Service. CWE: CWE-787: Out-of-bounds Write Description: A TLS connection records how many certificate slots it has when it is created, taken from the SSL_CTX that created it: the built-in certificate types plus one slot for each provider TLS-SIGALG entry that context was aware of. That count sizes an internal array of per-slot certificate validity flags. An application may replace a connection's SSL_CTX part way through the handshake by calling SSL_set_SSL_CTX(), most commonly from a servername callback in order to serve a different virtual host. Doing so did not refresh the recorded count. A provider signature algorithm's slot index is its position in the list of whichever context resolves it, so if the replacement context is aware of more of them than the original, an algorithm offered by the peer can resolve to an index beyond the end of the array. Processing the peer's signature algorithms then reads one four byte word past the end for each such algorithm and, where the word read is zero, writes a fixed value over it. A peer offering many of them can corrupt heap metadata and abort the process. Only provider signature algorithms which occupy one of the excess slots, and which the server also has configured, have this effect. Codepoints the replacement context does not recognise are discarded without being resolved to a slot, and provider signature algorithms are usable only from TLS 1.3. The two contexts must therefore be aware of different numbers of provider signature algorithms, which requires separate library contexts, a provider loaded between the two being created, or providers which differ in what they advertise - in 4.0, for example, the default provider advertises SM2 where the FIPS provider does not. A deployment meeting the condition is also unable to negotiate the affected algorithms with legitimate clients, since the same stale count hides the corresponding certificates, so the misconfiguration is likely to be noticed. For that reason, and because the configuration is not the default, this issue has been assessed as Low severity. FIPS impact: no No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| HIGH | CVE-2026-72897 | libcrypto3 | 3.5.6-r0 | Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a connection to a different SSL_CTX part way through a handshake may access memory beyond the end of an internal array if the replacement context knows about more provider signature algorithms than the context the connection was created from. Applications which never call SSL_set_SSL_CTX() are not affected. Impact summary: A remote peer may be able to cause a small out-of-bounds read, and in some circumstances a fixed-value out-of-bounds write, on the server heap. This may lead to a Denial of Service. CWE: CWE-787: Out-of-bounds Write Description: A TLS connection records how many certificate slots it has when it is created, taken from the SSL_CTX that created it: the built-in certificate types plus one slot for each provider TLS-SIGALG entry that context was aware of. That count sizes an internal array of per-slot certificate validity flags. An application may replace a connection's SSL_CTX part way through the handshake by calling SSL_set_SSL_CTX(), most commonly from a servername callback in order to serve a different virtual host. Doing so did not refresh the recorded count. A provider signature algorithm's slot index is its position in the list of whichever context resolves it, so if the replacement context is aware of more of them than the original, an algorithm offered by the peer can resolve to an index beyond the end of the array. Processing the peer's signature algorithms then reads one four byte word past the end for each such algorithm and, where the word read is zero, writes a fixed value over it. A peer offering many of them can corrupt heap metadata and abort the process. Only provider signature algorithms which occupy one of the excess slots, and which the server also has configured, have this effect. Codepoints the replacement context does not recognise are discarded without being resolved to a slot, and provider signature algorithms are usable only from TLS 1.3. The two contexts must therefore be aware of different numbers of provider signature algorithms, which requires separate library contexts, a provider loaded between the two being created, or providers which differ in what they advertise - in 4.0, for example, the default provider advertises SM2 where the FIPS provider does not. A deployment meeting the condition is also unable to negotiate the affected algorithms with legitimate clients, since the same stale count hides the corresponding certificates, so the misconfiguration is likely to be noticed. For that reason, and because the configuration is not the default, this issue has been assessed as Low severity. FIPS impact: no No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| HIGH | CVE-2026-58051 | libssh2 | 1.11.1-r1 | libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsing populates them, so a parse failure reaching the cleanup path leaves libssh2_publickey_list_free operating on an uninitialized entry. A malicious SSH server offering the publickey subsystem can use a malformed response to make cleanup free an uninitialized, attacker-influenceable attrs pointer in a connecting libssh2 client. — /lib/apk/db/installed | |
| HIGH | CVE-2026-59850 | libssh2 | 1.11.1-r1 | A flaw was found in libssh. If data packets are processed after a channel is closed, channel data callbacks can be invoked after the associated data has already been freed, leading to crashes or possible use-after-free conditions. — /lib/apk/db/installed | |
| HIGH | CVE-2026-84784 | libssl3 | 3.5.6-r0 | Issue summary: A malicious remote peer may flood the local QUIC stack with NEW_CONNECTION_ID frames by avoiding a limit check on how many connection IDs the remote QUIC stack can use. Impact summary: The local QUIC stack sends a RETIRE_CONN_ID frame for every NEW_CONNECTION_ID frame it receives. The RETIRE_CONN_ID frame is dispatched via the Control Frame Queue (CFQ). If the remote peer also withholds ACKs, then it can force the local stack to allocate ~400MB (depending on ACK delay). CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: RFC 9000 sections 5.1.1 and 5.1.2 [1] describe the mechanism by which a remote peer can notify the local QUIC stack to change the destination connection ID (a.k.a. CID) the local stack uses to identify the connection at the remote peer. Each CID is associated with a sequence number. The sequence number is transmitted in NEW_CONNECTION_ID and RETIRE_CONNECTION_ID frames to identify the CID which is being either associated with a connection or retired. The remote peer sends a NEW_CONNECTION_ID frame to let the local stack know a new CID is being associated with an existing connection. The NEW_CONNECTION_ID frame carries the new CID, its sequence number, and the retire-prior-to number. The retire-prior-to identifies existing CIDs that are to be retired. The local QUIC stack must send a RETIRE_CONNECTION_ID for every destination CID whose sequence number is less than retire-prior-to. The CID becomes retired after the local stack receives an ACK for its RETIRE_CONNECTION_ID frame. Although the OpenSSL QUIC stack supports at most one destination CID for every connection, it can be tricked into processing more than one RETIRE_CONNECTION_ID frame per connection. The OpenSSL QUIC stack currently retires the destination CID as soon as it receives the NEW_CONNECTION_ID, while in fact the destination CID must be retired after an ACK for the RETIRE_CONNECTION_ID frame is received. Correcting the flawed logic also fixes the backlog growth. [1] https://datatracker.ietf.org/doc/html/rfc9000#name-issuing-connection-ids FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| HIGH | CVE-2026-84784 | libcrypto3 | 3.5.6-r0 | Issue summary: A malicious remote peer may flood the local QUIC stack with NEW_CONNECTION_ID frames by avoiding a limit check on how many connection IDs the remote QUIC stack can use. Impact summary: The local QUIC stack sends a RETIRE_CONN_ID frame for every NEW_CONNECTION_ID frame it receives. The RETIRE_CONN_ID frame is dispatched via the Control Frame Queue (CFQ). If the remote peer also withholds ACKs, then it can force the local stack to allocate ~400MB (depending on ACK delay). CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: RFC 9000 sections 5.1.1 and 5.1.2 [1] describe the mechanism by which a remote peer can notify the local QUIC stack to change the destination connection ID (a.k.a. CID) the local stack uses to identify the connection at the remote peer. Each CID is associated with a sequence number. The sequence number is transmitted in NEW_CONNECTION_ID and RETIRE_CONNECTION_ID frames to identify the CID which is being either associated with a connection or retired. The remote peer sends a NEW_CONNECTION_ID frame to let the local stack know a new CID is being associated with an existing connection. The NEW_CONNECTION_ID frame carries the new CID, its sequence number, and the retire-prior-to number. The retire-prior-to identifies existing CIDs that are to be retired. The local QUIC stack must send a RETIRE_CONNECTION_ID for every destination CID whose sequence number is less than retire-prior-to. The CID becomes retired after the local stack receives an ACK for its RETIRE_CONNECTION_ID frame. Although the OpenSSL QUIC stack supports at most one destination CID for every connection, it can be tricked into processing more than one RETIRE_CONNECTION_ID frame per connection. The OpenSSL QUIC stack currently retires the destination CID as soon as it receives the NEW_CONNECTION_ID, while in fact the destination CID must be retired after an ACK for the RETIRE_CONNECTION_ID frame is received. Correcting the flawed logic also fixes the backlog growth. [1] https://datatracker.ietf.org/doc/html/rfc9000#name-issuing-connection-ids FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| HIGH | CVE-2026-66034 | libssh2 | 1.11.1-r1 | libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitrary-length heap out-of-bounds read and a free of an uninitialized pointer via the publickey subsystem. In libssh2_publickey_list_fetch(), the version 1 response parser reads a server-controlled comment_len value and advances the parse pointer without verifying sufficient bytes remain in the buffer, causing the out-of-bounds read to leak heap pointers from adjacent allocations defeating ASLR, followed by heap allocator state corruption when the error cleanup path frees an uninitialized pointer from a non-zeroed realloc() region. — /lib/apk/db/installed | |
| HIGH | CVE-2026-84782 | libssl3 | 3.5.6-r0 | Issue summary: The DTLS retransmission logic does not correctly handle a handshake message write that is suspended part-way through. The retransmitted message can be read past the message buffer and the retransmission overwrites the internal state the suspended write needs to resume correctly. Impact summary: The retransmitted message can disclose a heap memory to the peer as plaintext handshake data or cause a crash and a Denial of Service when the read reaches an unmapped memory region. CWE: CWE-125: Out-of-bounds Read Description: DTLS handshake messages can be written out in multiple fragments, and a write can suspend mid-message (returning WANT_WRITE) if the underlying transport temporarily cannot accept more data. While such a write is suspended, the DTLS retransmission timer may independently fire and ask the retransmission logic to resend an earlier, already-acknowledged-as-sent message from its retransmit queue. The retransmission logic reused the same internal buffer and position tracking as the message that was still being written, without resetting the position back to the start of the message being retransmitted. As a result the retransmission was read starting from wherever the suspended write had left off, producing a mislabelled message whose body was leftover bytes from the other, larger message still in flight - content that was never meant to be sent at that point, and which could run past the end of the allocated buffer. Separately, even when the retransmission is positioned correctly, allowing it to run to completion while another write is suspended overwrites the same shared bookkeeping that the suspended write depends on to resume. When the application later resumes the suspended write (via a subsequent SSL_read(), SSL_write(), SSL_accept(), or SSL_connect() call), it finds that bookkeeping in a state inconsistent with the message and aborts the process in a debugging build. The fix resets the retransmission's read position to the start of the message before resending, and skips retransmission entirely whenever a handshake write is still suspended, deferring to the next call that resumes it instead. FIPS impact: no The affected code is outside the FIPS module boundary. — /lib/apk/db/installed | |
| HIGH | CVE-2026-84782 | libcrypto3 | 3.5.6-r0 | Issue summary: The DTLS retransmission logic does not correctly handle a handshake message write that is suspended part-way through. The retransmitted message can be read past the message buffer and the retransmission overwrites the internal state the suspended write needs to resume correctly. Impact summary: The retransmitted message can disclose a heap memory to the peer as plaintext handshake data or cause a crash and a Denial of Service when the read reaches an unmapped memory region. CWE: CWE-125: Out-of-bounds Read Description: DTLS handshake messages can be written out in multiple fragments, and a write can suspend mid-message (returning WANT_WRITE) if the underlying transport temporarily cannot accept more data. While such a write is suspended, the DTLS retransmission timer may independently fire and ask the retransmission logic to resend an earlier, already-acknowledged-as-sent message from its retransmit queue. The retransmission logic reused the same internal buffer and position tracking as the message that was still being written, without resetting the position back to the start of the message being retransmitted. As a result the retransmission was read starting from wherever the suspended write had left off, producing a mislabelled message whose body was leftover bytes from the other, larger message still in flight - content that was never meant to be sent at that point, and which could run past the end of the allocated buffer. Separately, even when the retransmission is positioned correctly, allowing it to run to completion while another write is suspended overwrites the same shared bookkeeping that the suspended write depends on to resume. When the application later resumes the suspended write (via a subsequent SSL_read(), SSL_write(), SSL_accept(), or SSL_connect() call), it finds that bookkeeping in a state inconsistent with the message and aborts the process in a debugging build. The fix resets the retransmission's read position to the start of the message before resending, and skips retransmission entirely whenever a handshake write is still suspended, deferring to the next call that resumes it instead. FIPS impact: no The affected code is outside the FIPS module boundary. — /lib/apk/db/installed | |
| HIGH | CVE-2026-58050 | libssh2 | 1.11.1-r1 | libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attrs * sizeof(libssh2_publickey_attribute) without bounds checking, so on 32-bit platforms the multiplication overflows to an undersized buffer. A malicious SSH server can then drive the attribute-parsing loop to write past the allocation, causing a heap buffer overflow in a connecting libssh2 client. — /lib/apk/db/installed | |
| HIGH | CVE-2026-54873 | libssl3 | 3.5.6-r0 | Issue summary: QUIC process may keep memory for QUIC packet buffer for much longer period than necessary. Impact summary: Remote peer can exploit this vulnerability by sending maliciously crafted packets, making the local QUIC stack to keep the memory for packet buffers allocated. The time for which the memory remains allocated is entirely under the control of the potentially malicious remote peer. CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: To save copy operation from the packet buffer to the stream reassemble buffer the QUIC stack leaves the stream data on the packet buffer waiting to be copied to a buffer provided by the local receiving application. The QUIC stack releases a reference to the packet buffer only after the data are copied to the application buffer. This design is more efficient for legitimate data transfers but enables an attacker to allocate a lot more memory than actually required by the data kept in the receiving stream buffer. To mitigate the vulnerability, the QUIC stack now calculates and monitors memory overhead for every stream. The memory overhead for a single stream frame is calculated as a difference between the size of the whole packet that carries the stream frame and the size of the stream frame itself. The memory overhead for a single stream frame is added to the total (cumulative) memory overhead QUIC stack keeps for each stream. Once the cumulative memory overhead exceeds 64kB, the QUIC stack moves the stream frame data from the packet buffer to the stream buffer, starting with the next packet received. FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| HIGH | CVE-2026-54873 | libcrypto3 | 3.5.6-r0 | Issue summary: QUIC process may keep memory for QUIC packet buffer for much longer period than necessary. Impact summary: Remote peer can exploit this vulnerability by sending maliciously crafted packets, making the local QUIC stack to keep the memory for packet buffers allocated. The time for which the memory remains allocated is entirely under the control of the potentially malicious remote peer. CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: To save copy operation from the packet buffer to the stream reassemble buffer the QUIC stack leaves the stream data on the packet buffer waiting to be copied to a buffer provided by the local receiving application. The QUIC stack releases a reference to the packet buffer only after the data are copied to the application buffer. This design is more efficient for legitimate data transfers but enables an attacker to allocate a lot more memory than actually required by the data kept in the receiving stream buffer. To mitigate the vulnerability, the QUIC stack now calculates and monitors memory overhead for every stream. The memory overhead for a single stream frame is calculated as a difference between the size of the whole packet that carries the stream frame and the size of the stream frame itself. The memory overhead for a single stream frame is added to the total (cumulative) memory overhead QUIC stack keeps for each stream. Once the cumulative memory overhead exceeds 64kB, the QUIC stack moves the stream frame data from the packet buffer to the stream buffer, starting with the next packet received. FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| HIGH | CVE-2026-66032 | libssh2 | 1.11.1-r1 | libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt the heap of any authenticated client opening an SFTP session. When a server responds to SSH_FXP_OPEN with SSH_FXP_STATUS containing FX_OK, the response data buffer is freed, and if a subsequent sftp_packet_require() call returns a specific error such as LIBSSH2_ERROR_CHANNEL_PACKET_EXCEEDED, the same pointer is freed a second time, enabling tcache dup conditions on glibc systems that allow overlapping allocations and function pointer overwrites. — /lib/apk/db/installed | |
| HIGH | CVE-2026-59851 | libssh2 | 1.11.1-r1 | A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssapi-keyex path does not verify whether the authenticated Kerberos principal is authorized for the requested local user, allowing authenticated clients to log in as arbitrary users. — /lib/apk/db/installed | |
| HIGH | CVE-2026-66035 | libssh2 | 1.11.1-r1 | libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that allows a malicious SSH server to corrupt heap metadata in any connecting client by sending a packet with a packet_length smaller than the cipher's block size during Encrypt-then-MAC cipher negotiation. In the fullpacket() function in src/transport.c, the ETM path allocates a buffer of packet_length bytes but copies blocksize minus one bytes via memcpy, causing an overflow that on 32-bit glibc writes attacker-controlled bytes into an adjacent chunk's SIZE field, enabling tcache bin confusion, overlapping live objects, and function pointer overwrite during the session handshake before authentication. — /lib/apk/db/installed | |
| HIGH | CVE-2026-69184 | c-ares | 1.34.6-r0 | c-ares is an asynchronous resolver library. Prior to 1.34.7, ares_dns_name_parse() enforces backward DNS compression pointers but does not bound the total pointer hops or assembled name length. A malicious DNS server can send a response containing a long descending pointer chain and many resource records whose NAME or RDATA fields refer to the chain, causing repeated decompression work that grows quadratically with message size. A single crafted response can stall the single-threaded c-ares event loop and deny DNS resolution, without causing memory corruption or information disclosure. This issue is fixed in version 1.34.7. — /lib/apk/db/installed | |
| HIGH | CVE-2026-66033 | libssh2 | 1.11.1-r1 | libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in src/openssl.c that allows a malicious SSH server to crash any connecting client by negotiating AES-GCM ciphers during handshake. Attackers can exploit the underflow in the expression computing blocksize minus aadlen minus authentication tag length to trigger an out-of-bounds read and a memcpy call with a near-SIZE_MAX length argument, causing immediate process crash before any authentication occurs. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-42772 | libcrypto3 | 3.5.6-r0 | Issue summary: The QUIC stream reassembly algorithm performance deteriorates progressively as packets are arriving out of order. The worst case has a quadratic complexity proportional to the number of stream frames kept in the buffer for the received stream data. Impact summary: A remote QUIC peer that completes the handshake can create a connection-scoped CPU pressure and potentially a Denial of Service using compliant STREAM frames inside the advertised receive window, with low attacker bandwidth. CWE: CWE-407: Inefficient Algorithmic Complexity Description: OpenSSL manages received QUIC stream fragments using a doubly-linked list. While it optimizes for append operations (at the end of the list), it falls back to a head-to-tail linear search for any fragment that does not immediately follow the current `tail`. By manipulating the sequence of offsets, an attacker can force the server to perform O(n^2) operations, consuming excessive CPU time for the QUIC process. FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-42772 | libssl3 | 3.5.6-r0 | Issue summary: The QUIC stream reassembly algorithm performance deteriorates progressively as packets are arriving out of order. The worst case has a quadratic complexity proportional to the number of stream frames kept in the buffer for the received stream data. Impact summary: A remote QUIC peer that completes the handshake can create a connection-scoped CPU pressure and potentially a Denial of Service using compliant STREAM frames inside the advertised receive window, with low attacker bandwidth. CWE: CWE-407: Inefficient Algorithmic Complexity Description: OpenSSL manages received QUIC stream fragments using a doubly-linked list. While it optimizes for append operations (at the end of the list), it falls back to a head-to-tail linear search for any fragment that does not immediately follow the current `tail`. By manipulating the sequence of offsets, an attacker can force the server to perform O(n^2) operations, consuming excessive CPU time for the QUIC process. FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-60876 | busybox | 1.37.0-r30 | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-60876 | busybox-binsh | 1.37.0-r30 | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-60876 | ssl_client | 1.37.0-r30 | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-35189 | libcrypto3 | 3.5.6-r0 | Issue summary: A certificate with many nameRelativeToCRLIssuer CRL distribution points causes disproportionate heap growth when OpenSSL caches X.509 extensions. Impact summary: Receiving a crafted certificate from a malicious peer can lead to significant memory pressure and possible Denial of Service in clients or in servers that solicit client certificates. CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: A certificate or a set of certificates that fits under the limit for size of certificates accepted from the peer (~100 KiB) can result in allocation of several hundred MiB of resident memory on the receiving side during a normal TLS handshake. This may be enough to crash the client or server, if multiple concurrent connections lead to similarly large memory allocations. The fix postpones processing of the CRL distribution points extensions in certificates to the time when the processed value is required for CRL processing. This avoids keeping large memory allocations for a long time when such certificates are received. FIPS impact: no The affected code is outside the FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-59845 | libssh2 | 1.11.1-r1 | A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may then be sent across the caller's accessible process tree, leading to local denial of service. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-35189 | libssl3 | 3.5.6-r0 | Issue summary: A certificate with many nameRelativeToCRLIssuer CRL distribution points causes disproportionate heap growth when OpenSSL caches X.509 extensions. Impact summary: Receiving a crafted certificate from a malicious peer can lead to significant memory pressure and possible Denial of Service in clients or in servers that solicit client certificates. CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: A certificate or a set of certificates that fits under the limit for size of certificates accepted from the peer (~100 KiB) can result in allocation of several hundred MiB of resident memory on the receiving side during a normal TLS handshake. This may be enough to crash the client or server, if multiple concurrent connections lead to similarly large memory allocations. The fix postpones processing of the CRL distribution points extensions in certificates to the time when the processed value is required for CRL processing. This avoids keeping large memory allocations for a long time when such certificates are received. FIPS impact: no The affected code is outside the FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-75805 | libssl3 | 3.5.6-r0 | Issue summary: A CMP client that requests certificate revocation on the basis of a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when processing a crafted revocation response. Impact summary: The NULL pointer dereference happens on a read which leads to a crash and a Denial of Service for the affected client application. CWE: CWE-476: NULL-pointer dereference Description: A CMP client revoking a certificate has to tell the server which certificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the certificate itself or its issuer name and serial number. This is 'openssl cmp -cmd rr -csr <file>' on the command line, or OSSL_CMP_exec_RR_ses() with the certificate supplied via OSSL_CMP_CTX_set1_p10CSR() through the API. A CSR does not contain the issuer name and serial number of the certificate, so the client does not send them. A server may optionally name the certificate it revoked in its response, and the client then compares that name against what it sent. Having sent neither an issuer name nor a serial number, it has nothing to compare against, and a server returning a specially crafted name causes the client to read from a NULL pointer and crash. The revocation response is checked for valid message protection before the affected code is reached, so an attacker must be a malicious or compromised CMP server, or a man-in-the-middle in possession of the secret used for message protection. Clients that identify the certificate to be revoked by a certificate or by issuer and serial number rather than by a PKCS#10 CSR are not affected. FIPS impact: no No FIPS modules are affected by this issue, as the CMP protocol implementation is outside the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-75805 | libcrypto3 | 3.5.6-r0 | Issue summary: A CMP client that requests certificate revocation on the basis of a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when processing a crafted revocation response. Impact summary: The NULL pointer dereference happens on a read which leads to a crash and a Denial of Service for the affected client application. CWE: CWE-476: NULL-pointer dereference Description: A CMP client revoking a certificate has to tell the server which certificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the certificate itself or its issuer name and serial number. This is 'openssl cmp -cmd rr -csr <file>' on the command line, or OSSL_CMP_exec_RR_ses() with the certificate supplied via OSSL_CMP_CTX_set1_p10CSR() through the API. A CSR does not contain the issuer name and serial number of the certificate, so the client does not send them. A server may optionally name the certificate it revoked in its response, and the client then compares that name against what it sent. Having sent neither an issuer name nor a serial number, it has nothing to compare against, and a server returning a specially crafted name causes the client to read from a NULL pointer and crash. The revocation response is checked for valid message protection before the affected code is reached, so an attacker must be a malicious or compromised CMP server, or a man-in-the-middle in possession of the secret used for message protection. Clients that identify the certificate to be revoked by a certificate or by issuer and serial number rather than by a PKCS#10 CSR are not affected. FIPS impact: no No FIPS modules are affected by this issue, as the CMP protocol implementation is outside the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-59843 | libssh2 | 1.11.1-r1 | A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel writes to loop indefinitely and consume CPU, leading to denial of service. — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-15661 | libssh2 | 1.11.1-r1 | libssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bounds heap read vulnerability in the sftp_symlink() function in src/sftp.c that allows a malicious SSH server or man-in-the-middle attacker to disclose heap memory contents or cause a crash by sending a crafted SSH_FXP_NAME response. Attackers can supply a link_len value larger than the actual packet data in SSH_FXP_NAME responses for SFTP READLINK and REALPATH operations, triggering a heap buffer over-read of up to target_len minus one bytes due to the missing validation of available packet buffer size before the memcpy operation. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-59844 | libssh2 | 1.11.1-r1 | A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large length, causing a libssh SFTP server to allocate excessive memory and potentially exhaust it through repeated requests. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-69186 | c-ares | 1.34.6-r0 | c-ares is an asynchronous resolver library. Prior to 1.34.7, ares_dns_parse() trusts the attacker-controlled ANCOUNT, NSCOUNT, and ARCOUNT fields before confirming that the DNS response contains enough bytes for the claimed records. Because process_answer() invokes parsing before transaction ID and question validation, a malicious DNS response can cause ares_dns_record_rr_prealloc() and ares_array_set_size() to reserve disproportionate heap memory for a tiny message. Repeated responses create large allocation and release cycles that can degrade or deny name resolution, without causing memory corruption or information disclosure. This issue is fixed in version 1.34.7. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-75806 | libcrypto3 | 3.5.6-r0 | Issue summary: An established DTLS 1.2 association using an AEAD cipher suite can be terminated by a single unauthenticated datagram whose encrypted fragment is shorter than the mandatory explicit IV and authentication tag overhead. Impact summary: An attacker who can send a datagram that is routed to an existing DTLS 1.2 association can tear that association down without knowing any key material. This is a Denial of Service limited to the targeted association. There is no memory safety or confidentiality impact. CWE: CWE-1284: Improper Validation of Specified Quantity in Input Description: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher suite carries an explicit IV followed by the ciphertext and an authentication tag. When decrypting such a record the record layer passed the record length to the cipher implementation before checking that the record was long enough to contain the explicit IV and the tag. For a record shorter than that overhead the cipher implementation rejected the impossible length, and the record layer treated this as an internal failure and raised a fatal internal_error alert instead of treating the record as one that failed authentication. In TLS 1.2 the same record causes a fatal internal_error alert instead of the expected bad_record_mac alert. Since any undecryptable record already terminates a TLS connection, this is a protocol conformance issue rather than a security issue in TLS. The fix validates the record length against the explicit IV and tag length before any AEAD processing, so that TLS reports bad_record_mac and DTLS silently discards the record. FIPS impact: no The affected code is outside the FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-75806 | libssl3 | 3.5.6-r0 | Issue summary: An established DTLS 1.2 association using an AEAD cipher suite can be terminated by a single unauthenticated datagram whose encrypted fragment is shorter than the mandatory explicit IV and authentication tag overhead. Impact summary: An attacker who can send a datagram that is routed to an existing DTLS 1.2 association can tear that association down without knowing any key material. This is a Denial of Service limited to the targeted association. There is no memory safety or confidentiality impact. CWE: CWE-1284: Improper Validation of Specified Quantity in Input Description: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher suite carries an explicit IV followed by the ciphertext and an authentication tag. When decrypting such a record the record layer passed the record length to the cipher implementation before checking that the record was long enough to contain the explicit IV and the tag. For a record shorter than that overhead the cipher implementation rejected the impossible length, and the record layer treated this as an internal failure and raised a fatal internal_error alert instead of treating the record as one that failed authentication. In TLS 1.2 the same record causes a fatal internal_error alert instead of the expected bad_record_mac alert. Since any undecryptable record already terminates a TLS connection, this is a protocol conformance issue rather than a security issue in TLS. The fix validates the record length against the explicit IV and tag length before any AEAD processing, so that TLS reports bad_record_mac and DTLS silently discards the record. FIPS impact: no The affected code is outside the FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-75804 | libcrypto3 | 3.5.6-r0 | Issue summary: OpenSSL QUIC stack does not enforce connection level flow control for streams. Remote peers may send more bytes as long as they fit within the stream flow control limits. Impact summary: A malicious remote peer may exploit the lack of connection flow control for streams to make the QUIC stack receive ~100MB of memory instead of 768 KiB (default flow control window size). CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: The local QUIC stack advertises two flow control limits to its remote peer: stream flow control limit and connection flow control limit. The remote peer must follow both limits when transmitting stream data. Whenever the local QUIC stack receives a stream frame, it validates that the size of the received stream frame stays within flow control limits. If either limit is exceeded (stream level or connection level), then the QUIC stack must close the connection with a flow control error. The vulnerable OpenSSL QUIC stack enforces the stream-level but not the connection-level limit. To exploit the issue, three conditions must be met: - the remote peer opens several streams - each stream must stay within the stream-level flow control limit - there must be no zero-offset byte sent on any of the streams (to prevent the vulnerable QUIC stack from consuming data). By meeting the conditions above, the remote peer may make the local stack allocate 2 x MAX_STREAMS x (stream flow control limit) bytes of memory. MAX_STREAMS defaults to 100, and the limit applies to both bidirectional and unidirectional streams, making it 200 in total. The default flow control window for a stream is 512kB. The remote peer may force the vulnerable QUIC stack to allocate 100MB of heap per connection. FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-75804 | libssl3 | 3.5.6-r0 | Issue summary: OpenSSL QUIC stack does not enforce connection level flow control for streams. Remote peers may send more bytes as long as they fit within the stream flow control limits. Impact summary: A malicious remote peer may exploit the lack of connection flow control for streams to make the QUIC stack receive ~100MB of memory instead of 768 KiB (default flow control window size). CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: The local QUIC stack advertises two flow control limits to its remote peer: stream flow control limit and connection flow control limit. The remote peer must follow both limits when transmitting stream data. Whenever the local QUIC stack receives a stream frame, it validates that the size of the received stream frame stays within flow control limits. If either limit is exceeded (stream level or connection level), then the QUIC stack must close the connection with a flow control error. The vulnerable OpenSSL QUIC stack enforces the stream-level but not the connection-level limit. To exploit the issue, three conditions must be met: - the remote peer opens several streams - each stream must stay within the stream-level flow control limit - there must be no zero-offset byte sent on any of the streams (to prevent the vulnerable QUIC stack from consuming data). By meeting the conditions above, the remote peer may make the local stack allocate 2 x MAX_STREAMS x (stream flow control limit) bytes of memory. MAX_STREAMS defaults to 100, and the limit applies to both bidirectional and unidirectional streams, making it 200 in total. The default flow control window for a stream is 512kB. The remote peer may force the vulnerable QUIC stack to allocate 100MB of heap per connection. FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-59848 | libssh2 | 1.11.1-r1 | A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh clients keep queued indefinitely, causing unbounded memory growth and client-side denial of service. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-58055 | nghttp2-libs | 1.69.0-r0 | nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning. — /lib/apk/db/installed | |
| LOW | CVE-2026-35191 | libcrypto3 | 3.5.6-r0 | Issue summary: The OpenSSL QUIC server, when configured to not preform address validation, can be forced to count incoming packets multiple times in its unvalidated credit computation, leading to a violation of the RFC 9000 unvalidated connection amplification limit of 3 times the amount of data received. Impact summary: A remote attacker able to spoof packets to a server using the OpenSSL QUIC implementation might use the server for an amplification of a DDoS attack. CWE: CWE-440: Expected Behavior Violation Description: OpenSSL's QUIC stack, when operating as a server, enforces client address validation (RFC 9000, Section 8), to confirm the peer address is not used for a traffic amplification attack. If this feature is disabled on the server, the QUIC stack limits the amount of server data that can be sent to 3 times the amount of data received from the peer address, until such time as the TLS handshake is completed. The OpenSSL QUIC server, when operating in non-validation mode, adds the length of the whole datagram received to the unvalidated credit limit when processing each QUIC packet in the datagram. A remote peer may, after establishing a connection with an initial client hello frame, send a subsequent datagram containing multiple QUIC packets, leading the server to account the entire datagram length for each packet in the datagram, resulting in the server believing that the peer has sent more data than it actually has, thereby violating the 3x amplification limit mandated by the RFC. FIPS impact: no As the QUIC stack lives outside the FIPS module boundary, no FIPS modules are affected by this CVE. — /lib/apk/db/installed | |
| LOW | CVE-2026-35191 | libssl3 | 3.5.6-r0 | Issue summary: The OpenSSL QUIC server, when configured to not preform address validation, can be forced to count incoming packets multiple times in its unvalidated credit computation, leading to a violation of the RFC 9000 unvalidated connection amplification limit of 3 times the amount of data received. Impact summary: A remote attacker able to spoof packets to a server using the OpenSSL QUIC implementation might use the server for an amplification of a DDoS attack. CWE: CWE-440: Expected Behavior Violation Description: OpenSSL's QUIC stack, when operating as a server, enforces client address validation (RFC 9000, Section 8), to confirm the peer address is not used for a traffic amplification attack. If this feature is disabled on the server, the QUIC stack limits the amount of server data that can be sent to 3 times the amount of data received from the peer address, until such time as the TLS handshake is completed. The OpenSSL QUIC server, when operating in non-validation mode, adds the length of the whole datagram received to the unvalidated credit limit when processing each QUIC packet in the datagram. A remote peer may, after establishing a connection with an initial client hello frame, send a subsequent datagram containing multiple QUIC packets, leading the server to account the entire datagram length for each packet in the datagram, resulting in the server believing that the peer has sent more data than it actually has, thereby violating the 3x amplification limit mandated by the RFC. FIPS impact: no As the QUIC stack lives outside the FIPS module boundary, no FIPS modules are affected by this CVE. — /lib/apk/db/installed | |
| LOW | CVE-2026-54875 | libcrypto3 | 3.5.6-r0 | Issue summary: A non-constant-time optimized implementation of scalar point multiplication is used for SM2 private key operations on ARM64 and RISC-V platforms. Impact summary: An attacker able to measure the time taken by, or to observe the cache-line access pattern of SM2 signing or decryption on an affected platform can learn information about the secret scalar. CWE: CWE-208: Observable Timing Discrepancy Description: On ARM64 and RISC-V processors, the SM2 curve uses an optimized scalar multiplication implementation whose conditional branches and table look ups are chosen according to the bits of the secret scalar. The execution time and the cache-access pattern therefore depend on the long-term private key (during SM2 decryption) or the per-signature nonce (during SM2 signature generation), forming a timing and cache side-channel. FIPS Impact: no SM2 is not a FIPS algorithm and the optimized SM2 implementation is not part of the FIPS module. OpenSSL 4.0, 3.6, 3.5 and 3.4 are vulnerable to this issue on AArch64 and RISC-V. OpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue. OpenSSL 4.0 users should upgrade to OpenSSL 4.0.3. OpenSSL 3.6 users should upgrade to OpenSSL 3.6.5. OpenSSL 3.5 users should upgrade to OpenSSL 3.5.9. OpenSSL 3.4 users should upgrade to OpenSSL 3.4.8. This issue was reported on 2 May 2026 by Abhinav Agarwal. It was independently reported on 6 June 2026 by Feng Xue. The fix was developed by Igor Ustinov. -- cut (non-publishing metadata for internal use) -- Reported by: Abhinav Agarwal, Feng Xue Fixed by: Igor Ustinov — /lib/apk/db/installed | |
| LOW | CVE-2026-54875 | libssl3 | 3.5.6-r0 | Issue summary: A non-constant-time optimized implementation of scalar point multiplication is used for SM2 private key operations on ARM64 and RISC-V platforms. Impact summary: An attacker able to measure the time taken by, or to observe the cache-line access pattern of SM2 signing or decryption on an affected platform can learn information about the secret scalar. CWE: CWE-208: Observable Timing Discrepancy Description: On ARM64 and RISC-V processors, the SM2 curve uses an optimized scalar multiplication implementation whose conditional branches and table look ups are chosen according to the bits of the secret scalar. The execution time and the cache-access pattern therefore depend on the long-term private key (during SM2 decryption) or the per-signature nonce (during SM2 signature generation), forming a timing and cache side-channel. FIPS Impact: no SM2 is not a FIPS algorithm and the optimized SM2 implementation is not part of the FIPS module. OpenSSL 4.0, 3.6, 3.5 and 3.4 are vulnerable to this issue on AArch64 and RISC-V. OpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue. OpenSSL 4.0 users should upgrade to OpenSSL 4.0.3. OpenSSL 3.6 users should upgrade to OpenSSL 3.6.5. OpenSSL 3.5 users should upgrade to OpenSSL 3.5.9. OpenSSL 3.4 users should upgrade to OpenSSL 3.4.8. This issue was reported on 2 May 2026 by Abhinav Agarwal. It was independently reported on 6 June 2026 by Feng Xue. The fix was developed by Igor Ustinov. -- cut (non-publishing metadata for internal use) -- Reported by: Abhinav Agarwal, Feng Xue Fixed by: Igor Ustinov — /lib/apk/db/installed | |
| LOW | CVE-2026-54872 | libcrypto3 | 3.5.6-r0 | Issue summary: The generic elliptic-curve scalar multiplication used for ECDSA and SM2 signature operations with curves that do not have a dedicated implementation leaks information about the secret nonce through timing. Impact summary: An attacker able to measure signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key. CWE: CWE-208: Observable Timing Discrepancy Description: The generic elliptic-curve scalar multiplication used for curves that do not have a dedicated constant-time implementation pads the secret scalar with non-constant-time BIGNUM operations, so the time taken depends on the value of the secret scalar derived from the ECDSA and SM2 nonce. The leak is very small; observing it requires a large number of measurements. The effect is largest for curves whose group order lies on a machine-word boundary, such as brainpoolP384r1. Applications using ECDSA signing over the Brainpool and other generic prime curves, and SM2 signing on platforms that use the generic implementation, are vulnerable to this issue. The NIST curves P-256, P-384 and P-521 use dedicated constant-time implementations and are not affected. FIPS Impact: no The FIPS modules are not affected: the approved NIST curves used in the FIPS provider have dedicated constant-time implementations and do not use the affected code path. — /lib/apk/db/installed | |
| LOW | CVE-2026-54872 | libssl3 | 3.5.6-r0 | Issue summary: The generic elliptic-curve scalar multiplication used for ECDSA and SM2 signature operations with curves that do not have a dedicated implementation leaks information about the secret nonce through timing. Impact summary: An attacker able to measure signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key. CWE: CWE-208: Observable Timing Discrepancy Description: The generic elliptic-curve scalar multiplication used for curves that do not have a dedicated constant-time implementation pads the secret scalar with non-constant-time BIGNUM operations, so the time taken depends on the value of the secret scalar derived from the ECDSA and SM2 nonce. The leak is very small; observing it requires a large number of measurements. The effect is largest for curves whose group order lies on a machine-word boundary, such as brainpoolP384r1. Applications using ECDSA signing over the Brainpool and other generic prime curves, and SM2 signing on platforms that use the generic implementation, are vulnerable to this issue. The NIST curves P-256, P-384 and P-521 use dedicated constant-time implementations and are not affected. FIPS Impact: no The FIPS modules are not affected: the approved NIST curves used in the FIPS provider have dedicated constant-time implementations and do not use the affected code path. — /lib/apk/db/installed | |
| LOW | CVE-2026-77696 | libcrypto3 | 3.5.6-r0 | Issue summary: SM2 signature generation uses non-constant-time arithmetic on secret values, forming a timing side-channel. Impact summary: An attacker able to measure SM2 signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key. CWE: CWE-208: Observable Timing Discrepancy Description: SM2 signature generation computes the signature value using variable-time BIGNUM operations on the secret nonce and the private key, so the time taken to produce an SM2 signature depends on these secret values, forming a timing side-channel. Applications performing SM2 signature generation are affected on all platforms. FIPS Impact: no SM2 is not a FIPS algorithm. — /lib/apk/db/installed | |
| LOW | CVE-2026-77696 | libssl3 | 3.5.6-r0 | Issue summary: SM2 signature generation uses non-constant-time arithmetic on secret values, forming a timing side-channel. Impact summary: An attacker able to measure SM2 signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key. CWE: CWE-208: Observable Timing Discrepancy Description: SM2 signature generation computes the signature value using variable-time BIGNUM operations on the secret nonce and the private key, so the time taken to produce an SM2 signature depends on these secret values, forming a timing side-channel. Applications performing SM2 signature generation are affected on all platforms. FIPS Impact: no SM2 is not a FIPS algorithm. — /lib/apk/db/installed | |
| LOW | CVE-2026-59846 | libssh2 | 1.11.1-r1 | A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing unintended shell behavior. — /lib/apk/db/installed |
ghcr.io/voxpupuli/r10k
Downloads
ghcr.io/voxpupuli/r10k:latest (2026-08-27)
Trivy
CRITICAL 3
HIGH 31
MEDIUM 37
LOW 16
UNKNOWN 16
| Severity | ID | Package | Installed | Fixed | Title / target |
|---|---|---|---|---|---|
| CRITICAL | CVE-2026-60002 | openssh-keygen | 10.3_p1-r0 | 10.3_p1-r1 | openssh: OpenSSH: Use-after-free vulnerability during host key re-exchange on the client side — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1) |
| CRITICAL | CVE-2026-60002 | openssh-client-default | 10.3_p1-r0 | 10.3_p1-r1 | openssh: OpenSSH: Use-after-free vulnerability during host key re-exchange on the client side — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1) |
| CRITICAL | CVE-2026-60002 | openssh-client-common | 10.3_p1-r0 | 10.3_p1-r1 | openssh: OpenSSH: Use-after-free vulnerability during host key re-exchange on the client side — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1) |
| HIGH | CVE-2026-56862 | stdlib | v1.26.2 | 1.25.13, 1.26.6, 1.27.0-rc.3 | crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages — usr/local/bin/supercronic-linux-amd64 |
| HIGH | CVE-2026-66046 | libexpat | 2.8.3-r0 | 2.8.4-r0 | expat: Expat: Denial of Service via quadratic complexity in attribute processing — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1) |
| HIGH | CVE-2026-76641 | libexpat | 2.8.3-r0 | 2.8.4-r0 | expat: Expat: Denial of Service via XML external entity parsing — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1) |
| HIGH | CVE-2026-76956 | libexpat | 2.8.3-r0 | 2.8.4-r0 | libexpat: libexpat: Denial of Service via hash flooding attack with crafted XML — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1) |
| HIGH | CVE-2026-76957 | libexpat | 2.8.3-r0 | 2.8.4-r0 | libexpat: libexpat: Memory corruption vulnerability allows arbitrary code execution or denial of service — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1) |
| HIGH | CVE-2026-93990 | libexpat | 2.8.3-r0 | 2.8.5-r0 | expat: Expat: XML Injection via Malformed UTF-16 Input — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1) |
| HIGH | CVE-2026-27145 | stdlib | v1.26.2 | 1.25.11, 1.26.4 | crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries — usr/local/bin/supercronic-linux-amd64 |
| HIGH | CVE-2026-59999 | openssh-client-common | 10.3_p1-r0 | 10.3_p1-r1 | openssh: OpenSSH sshd: Security bypass due to incorrect handling of forwarding and tunneling options — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1) |
| HIGH | CVE-2026-60000 | openssh-client-common | 10.3_p1-r0 | 10.3_p1-r1 | openssh: OpenSSH: Denial of Service via excessive GSSAPI authentication attempts — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1) |
| HIGH | CVE-2026-89161 | pcre2 | 10.47-r1 | 10.48-r0 | pcre2: PCRE2: Memory corruption vulnerability in pcre2_jit_match — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1) |
| HIGH | CVE-2026-89157 | pcre2 | 10.47-r1 | 10.48-r0 | pcre2: PCRE2: Out-of-bounds write via large pattern input — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1) |
| HIGH | CVE-2026-86145 | pcre2 | 10.47-r1 | 10.48-r0 | pcre2: PCRE2: Out-of-bounds write allows arbitrary code execution via crafted regular expressions — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1) |
| HIGH | CVE-2026-103111 | pcre2 | 10.47-r1 | 10.49-r0 | pcre2: pcre2: Out-of-bounds write via crafted regular expression — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1) |
| HIGH | CVE-2026-59999 | openssh-client-default | 10.3_p1-r0 | 10.3_p1-r1 | openssh: OpenSSH sshd: Security bypass due to incorrect handling of forwarding and tunneling options — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1) |
| HIGH | CVE-2026-60000 | openssh-client-default | 10.3_p1-r0 | 10.3_p1-r1 | openssh: OpenSSH: Denial of Service via excessive GSSAPI authentication attempts — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1) |
| HIGH | CVE-2026-60000 | openssh-keygen | 10.3_p1-r0 | 10.3_p1-r1 | openssh: OpenSSH: Denial of Service via excessive GSSAPI authentication attempts — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1) |
| HIGH | CVE-2026-59999 | openssh-keygen | 10.3_p1-r0 | 10.3_p1-r1 | openssh: OpenSSH sshd: Security bypass due to incorrect handling of forwarding and tunneling options — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1) |
| HIGH | CVE-2026-56860 | stdlib | v1.26.2 | 1.25.13, 1.26.6, 1.27.0-rc.3 | net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution — usr/local/bin/supercronic-linux-amd64 |
| HIGH | CVE-2026-56859 | stdlib | v1.26.2 | 1.25.13, 1.26.6, 1.27.0-rc.3 | encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue — usr/local/bin/supercronic-linux-amd64 |
| HIGH | CVE-2026-56858 | stdlib | v1.26.2 | 1.25.13, 1.26.6, 1.27.0-rc.3 | html/template: golang: Go html/template: Cross-Site Scripting via pathological input — usr/local/bin/supercronic-linux-amd64 |
| HIGH | CVE-2026-56853 | stdlib | v1.26.2 | 1.25.13, 1.26.6, 1.27.0-rc.3 | net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service — usr/local/bin/supercronic-linux-amd64 |
| HIGH | CVE-2026-46600 | stdlib | v1.26.2 | 1.26.6, 1.27.0-rc.3 | golang.org/x/net/dns/dnsmessage: golang.org/x/net/dns/dnsmessage: Denial of Service via invalid DNS record parsing — usr/local/bin/supercronic-linux-amd64 |
| HIGH | CVE-2026-42504 | stdlib | v1.26.2 | 1.25.11, 1.26.4 | mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header — usr/local/bin/supercronic-linux-amd64 |
| HIGH | CVE-2026-42499 | stdlib | v1.26.2 | 1.25.10, 1.26.3 | net/mail: golang: net/mail: Denial of Service via pathological email address parsing — usr/local/bin/supercronic-linux-amd64 |
| HIGH | CVE-2026-39836 | stdlib | v1.26.2 | 1.25.10, 1.26.3 | net: golang: Go net package: Denial of Service via NUL byte in Dial and LookupPort on Windows — usr/local/bin/supercronic-linux-amd64 |
| HIGH | CVE-2026-39822 | stdlib | v1.26.2 | 1.25.12, 1.26.5, 1.27.0-rc.2 | golang: Go os.Root: Symlink following vulnerability allows directory traversal — usr/local/bin/supercronic-linux-amd64 |
| HIGH | CVE-2026-39821 | stdlib | v1.26.2 | 1.25.13, 1.26.6, 1.27.0-rc.3 | golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing — usr/local/bin/supercronic-linux-amd64 |
| HIGH | CVE-2026-39820 | stdlib | v1.26.2 | 1.25.10, 1.26.3 | net/mail: golang: Go net/mail: Denial of Service via crafted email inputs — usr/local/bin/supercronic-linux-amd64 |
| HIGH | CVE-2026-33818 | stdlib | v1.26.2 | 1.25.13, 1.26.6, 1.27.0-rc.3 | encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal — usr/local/bin/supercronic-linux-amd64 |
| HIGH | CVE-2026-33814 | stdlib | v1.26.2 | 1.25.10, 1.26.3 | net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame — usr/local/bin/supercronic-linux-amd64 |
| HIGH | CVE-2026-33811 | stdlib | v1.26.2 | 1.25.10, 1.26.3 | net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME — usr/local/bin/supercronic-linux-amd64 |
| MEDIUM | CVE-2026-42507 | stdlib | v1.26.2 | 1.25.11, 1.26.4 | net/textproto: golang: Golang net/textproto: Misleading error messages via input injection — usr/local/bin/supercronic-linux-amd64 |
| MEDIUM | CVE-2026-42505 | stdlib | v1.26.2 | 1.25.12, 1.26.5, 1.27.0-rc.2 | crypto/tls: golang: Go crypto/tls: Information disclosure in Encrypted Client Hello — usr/local/bin/supercronic-linux-amd64 |
| MEDIUM | CVE-2026-39826 | stdlib | v1.26.2 | 1.25.10, 1.26.3 | html/template: golang: html/template: Cross-site scripting due to incorrect script tag escaping — usr/local/bin/supercronic-linux-amd64 |
| MEDIUM | CVE-2026-59995 | openssh-keygen | 10.3_p1-r0 | 10.3_p1-r1 | openssh: OpenSSH: sftp client allows attacker to control downloaded file location — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1) |
| MEDIUM | CVE-2026-59996 | openssh-keygen | 10.3_p1-r0 | 10.3_p1-r1 | openssh: OpenSSH: `scp` file misplacement vulnerability during remote copy — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1) |
| MEDIUM | CVE-2026-59997 | openssh-keygen | 10.3_p1-r0 | 10.3_p1-r1 | openssh: OpenSSH: SFTP security bypass due to command-line argument parsing flaw — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1) |
| MEDIUM | CVE-2026-59998 | openssh-keygen | 10.3_p1-r0 | 10.3_p1-r1 | openssh: OpenSSH: Undocumented GSSAPIStrictAcceptorCheck behavior impacts security in Windows Active Directory — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1) |
| MEDIUM | CVE-2026-60001 | openssh-keygen | 10.3_p1-r0 | 10.3_p1-r1 | openssh: OpenSSH: Brute-force attacks facilitated due to insufficient authentication delay — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1) |
| MEDIUM | CVE-2026-73282 | openssh-keygen | 10.3_p1-r0 | 10.3_p1-r1 | openssh: OpenSSH: Information disclosure and data corruption via use-after-free in ssh client — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1) |
| MEDIUM | CVE-2026-73283 | openssh-keygen | 10.3_p1-r0 | 10.3_p1-r1 | openssh: OpenSSH: Tunnel forwarding restriction bypass — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1) |
| MEDIUM | CVE-2026-39825 | stdlib | v1.26.2 | 1.25.10, 1.26.3 | net/http/httputil: golang: net/http/httputil: ReverseProxy forwards hidden query parameters, potentially bypassing security controls — usr/local/bin/supercronic-linux-amd64 |
| MEDIUM | CVE-2026-39823 | stdlib | v1.26.2 | 1.25.10, 1.26.3 | html/template: golang: Go html/template: Cross-Site Scripting via improper URL escaping in meta tag content — usr/local/bin/supercronic-linux-amd64 |
| MEDIUM | CVE-2026-89156 | pcre2 | 10.47-r1 | 10.48-r0 | PCRE2: PCRE2: Out-of-bounds read via invalid UTF data during JIT fallback — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1) |
| MEDIUM | CVE-2026-89158 | pcre2 | 10.47-r1 | 10.48-r0 | PCRE2: PCRE2: Out-of-bounds write via integer overflow on 32-bit platforms — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1) |
| MEDIUM | CVE-2026-89160 | pcre2 | 10.47-r1 | 10.48-r0 | pcre2: PCRE2: Denial of Service via out-of-bounds read during invalid UTF matching — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1) |
| MEDIUM | CVE-2026-85091 | zlib | 1.3.2-r0 | 1.3.2-r1 | zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vul ... — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1) |
| MEDIUM | CVE-2026-82208 | libcurl | 8.21.0-r0 | 8.22.0-r0 | curl: libcurl: Improper certificate validation when using wolfSSL CA cache — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1) |
| MEDIUM | CVE-2026-80229 | libcurl | 8.21.0-r0 | 8.22.0-r0 | When performing transfers via libcurl\u2019s multi interface, pooled T ... — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1) |
| MEDIUM | CVE-2026-19931 | libcurl | 8.21.0-r0 | 8.22.0-r0 | curl: libcurl: Information disclosure via incorrect connection reuse with Negotiate authentication — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1) |
| MEDIUM | CVE-2026-58055 | nghttp2-libs | 1.69.0-r0 | 1.70.0-r0 | nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1) |
| MEDIUM | CVE-2026-59995 | openssh-client-common | 10.3_p1-r0 | 10.3_p1-r1 | openssh: OpenSSH: sftp client allows attacker to control downloaded file location — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1) |
| MEDIUM | CVE-2026-59996 | openssh-client-common | 10.3_p1-r0 | 10.3_p1-r1 | openssh: OpenSSH: `scp` file misplacement vulnerability during remote copy — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1) |
| MEDIUM | CVE-2026-59997 | openssh-client-common | 10.3_p1-r0 | 10.3_p1-r1 | openssh: OpenSSH: SFTP security bypass due to command-line argument parsing flaw — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1) |
| MEDIUM | CVE-2026-59998 | openssh-client-common | 10.3_p1-r0 | 10.3_p1-r1 | openssh: OpenSSH: Undocumented GSSAPIStrictAcceptorCheck behavior impacts security in Windows Active Directory — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1) |
| MEDIUM | CVE-2026-60001 | openssh-client-common | 10.3_p1-r0 | 10.3_p1-r1 | openssh: OpenSSH: Brute-force attacks facilitated due to insufficient authentication delay — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1) |
| MEDIUM | CVE-2026-73282 | openssh-client-common | 10.3_p1-r0 | 10.3_p1-r1 | openssh: OpenSSH: Information disclosure and data corruption via use-after-free in ssh client — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1) |
| MEDIUM | CVE-2026-19931 | curl | 8.21.0-r0 | 8.22.0-r0 | curl: libcurl: Information disclosure via incorrect connection reuse with Negotiate authentication — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1) |
| MEDIUM | CVE-2026-73283 | openssh-client-default | 10.3_p1-r0 | 10.3_p1-r1 | openssh: OpenSSH: Tunnel forwarding restriction bypass — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1) |
| MEDIUM | CVE-2026-73282 | openssh-client-default | 10.3_p1-r0 | 10.3_p1-r1 | openssh: OpenSSH: Information disclosure and data corruption via use-after-free in ssh client — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1) |
| MEDIUM | CVE-2026-60001 | openssh-client-default | 10.3_p1-r0 | 10.3_p1-r1 | openssh: OpenSSH: Brute-force attacks facilitated due to insufficient authentication delay — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1) |
| MEDIUM | CVE-2026-59998 | openssh-client-default | 10.3_p1-r0 | 10.3_p1-r1 | openssh: OpenSSH: Undocumented GSSAPIStrictAcceptorCheck behavior impacts security in Windows Active Directory — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1) |
| MEDIUM | CVE-2026-59997 | openssh-client-default | 10.3_p1-r0 | 10.3_p1-r1 | openssh: OpenSSH: SFTP security bypass due to command-line argument parsing flaw — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1) |
| MEDIUM | CVE-2026-59996 | openssh-client-default | 10.3_p1-r0 | 10.3_p1-r1 | openssh: OpenSSH: `scp` file misplacement vulnerability during remote copy — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1) |
| MEDIUM | CVE-2026-59995 | openssh-client-default | 10.3_p1-r0 | 10.3_p1-r1 | openssh: OpenSSH: sftp client allows attacker to control downloaded file location — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1) |
| MEDIUM | CVE-2026-80229 | curl | 8.21.0-r0 | 8.22.0-r0 | When performing transfers via libcurl\u2019s multi interface, pooled T ... — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1) |
| MEDIUM | CVE-2026-82208 | curl | 8.21.0-r0 | 8.22.0-r0 | curl: libcurl: Improper certificate validation when using wolfSSL CA cache — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1) |
| MEDIUM | CVE-2026-73283 | openssh-client-common | 10.3_p1-r0 | 10.3_p1-r1 | openssh: OpenSSH: Tunnel forwarding restriction bypass — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1) |
| LOW | CVE-2026-13608 | curl | 8.21.0-r0 | 8.22.0-r0 | curl: curl: Authentication bypass in OpenLDAP SASL negotiation via Man-in-the-Middle (MITM) attack — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1) |
| LOW | CVE-2026-18924 | curl | 8.21.0-r0 | 8.22.0-r0 | curl: libcurl: Use-after-free in HTTP/2 Server Push with shared connections — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1) |
| LOW | CVE-2026-80230 | curl | 8.21.0-r0 | 8.22.0-r0 | curl: curl: Public key pinning bypass allows unauthenticated connections — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1) |
| LOW | CVE-2026-80231 | curl | 8.21.0-r0 | 8.22.0-r0 | curl: curl: Incorrect HTTPS connection reuse with Native CA Store — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1) |
| LOW | CVE-2026-80255 | curl | 8.21.0-r0 | 8.22.0-r0 | curl: curl: Information disclosure due to secure cookie attribute bypass — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1) |
| LOW | CVE-2026-82209 | curl | 8.21.0-r0 | 8.22.0-r0 | curl: libcurl: Information disclosure via improper Public Suffix List boundary check — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1) |
| LOW | CVE-2026-73281 | openssh-client-default | 10.3_p1-r0 | 10.3_p1-r1 | openssh: OpenSSH: ssh-agent allows remote execution of local operations — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1) |
| LOW | CVE-2026-73281 | openssh-keygen | 10.3_p1-r0 | 10.3_p1-r1 | openssh: OpenSSH: ssh-agent allows remote execution of local operations — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1) |
| LOW | CVE-2026-73281 | openssh-client-common | 10.3_p1-r0 | 10.3_p1-r1 | openssh: OpenSSH: ssh-agent allows remote execution of local operations — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1) |
| LOW | CVE-2026-89162 | pcre2 | 10.47-r1 | 10.48-r0 | pcre2: PCRE2: Information disclosure via pcre2_serialize_encode — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1) |
| LOW | CVE-2026-82209 | libcurl | 8.21.0-r0 | 8.22.0-r0 | curl: libcurl: Information disclosure via improper Public Suffix List boundary check — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1) |
| LOW | CVE-2026-80255 | libcurl | 8.21.0-r0 | 8.22.0-r0 | curl: curl: Information disclosure due to secure cookie attribute bypass — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1) |
| LOW | CVE-2026-80231 | libcurl | 8.21.0-r0 | 8.22.0-r0 | curl: curl: Incorrect HTTPS connection reuse with Native CA Store — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1) |
| LOW | CVE-2026-80230 | libcurl | 8.21.0-r0 | 8.22.0-r0 | curl: curl: Public key pinning bypass allows unauthenticated connections — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1) |
| LOW | CVE-2026-18924 | libcurl | 8.21.0-r0 | 8.22.0-r0 | curl: libcurl: Use-after-free in HTTP/2 Server Push with shared connections — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1) |
| LOW | CVE-2026-13608 | libcurl | 8.21.0-r0 | 8.22.0-r0 | curl: curl: Authentication bypass in OpenLDAP SASL negotiation via Man-in-the-Middle (MITM) attack — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1) |
| UNKNOWN | CVE-2026-97031 | stdlib | v1.26.2 | 1.26.9, 1.27.2 | Reject malformed ECH outer extension references in crypto/tls — usr/local/bin/supercronic-linux-amd64 |
| UNKNOWN | CVE-2026-97030 | stdlib | v1.26.2 | 1.26.9, 1.27.2 | Recognize yield as regexp preceder keyword in html/template — usr/local/bin/supercronic-linux-amd64 |
| UNKNOWN | CVE-2026-97032 | stdlib | v1.26.2 | 1.26.9, 1.27.2 | HTTP/2 server crash due to HPACK encoder race in net/http — usr/local/bin/supercronic-linux-amd64 |
| UNKNOWN | CVE-2026-94448 | stdlib | v1.26.2 | 1.26.9, 1.27.2 | Reset context tracking on consecutive template expressions in html/template — usr/local/bin/supercronic-linux-amd64 |
| UNKNOWN | CVE-2026-94440 | stdlib | v1.26.2 | 1.26.9, 1.27.2 | Memory limit bypass when parsing MIME headers in net/textproto, mime/multipart — usr/local/bin/supercronic-linux-amd64 |
| UNKNOWN | CVE-2026-94439 | stdlib | v1.26.2 | 1.26.9, 1.27.2 | HTTP/1 server connection desynchronization after 2xx CONNECT response in net/http — usr/local/bin/supercronic-linux-amd64 |
| UNKNOWN | CVE-2026-78669 | stdlib | v1.26.2 | 1.26.9, 1.27.2 | Excessive CPU consumption from repeated initial window changes in net/http — usr/local/bin/supercronic-linux-amd64 |
| UNKNOWN | CVE-2026-78667 | stdlib | v1.26.2 | 1.26.9, 1.27.2 | Lack of limit on size of parsed Range headers in net/http — usr/local/bin/supercronic-linux-amd64 |
| UNKNOWN | CVE-2026-78663 | stdlib | v1.26.2 | 1.26.9, 1.27.2 | Double flow control refund on HTTP/2 server streams in net/http — usr/local/bin/supercronic-linux-amd64 |
| UNKNOWN | CVE-2026-78660 | stdlib | v1.26.2 | 1.26.9, 1.27.2 | HTTP/2 transport accepts malformed framing-related headers in net/http — usr/local/bin/supercronic-linux-amd64 |
| UNKNOWN | CVE-2026-78659 | stdlib | v1.26.2 | 1.26.9, 1.27.2 | HTTP/2 server memory exhaustion due to Trailer headers in net/http — usr/local/bin/supercronic-linux-amd64 |
| UNKNOWN | CVE-2026-56866 | stdlib | v1.26.2 | 1.26.9, 1.27.2 | HTTP/1 client connection desynchronization after CONNECT rejection in net/http — usr/local/bin/supercronic-linux-amd64 |
| UNKNOWN | CVE-2026-56857 | stdlib | v1.26.2 | 1.26.9, 1.27.2 | Root.Mkdir(All) can follow junctions out of the root on Windows in os — usr/local/bin/supercronic-linux-amd64 |
| UNKNOWN | CVE-2026-39824 | golang.org/x/sys | v0.43.0 | 0.44.0 | Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows — usr/local/bin/supercronic-linux-amd64 |
| UNKNOWN | CVE-2026-80256 | libcurl | 8.21.0-r0 | 8.22.0-r0 | Title Not Available — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1) |
| UNKNOWN | CVE-2026-80256 | curl | 8.21.0-r0 | 8.22.0-r0 | Title Not Available — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1) |
Grype
CRITICAL 7
HIGH 38
MEDIUM 25
LOW 8
UNKNOWN 2
NVD/CPE filtered 43
| Severity | ID | Package | Installed | Fixed | Title / target |
|---|---|---|---|---|---|
| CRITICAL | CVE-2026-19931 | curl | 8.21.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| CRITICAL | CVE-2026-19931 | libcurl | 8.21.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| CRITICAL | CVE-2026-18924 | curl | 8.21.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| CRITICAL | CVE-2026-18924 | libcurl | 8.21.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| CRITICAL | CVE-2026-60002 | openssh-keygen | 10.3_p1-r0 | 10.3_p1-r1 | /lib/apk/db/installed |
| CRITICAL | CVE-2026-60002 | openssh-client-default | 10.3_p1-r0 | 10.3_p1-r1 | /lib/apk/db/installed |
| CRITICAL | CVE-2026-60002 | openssh-client-common | 10.3_p1-r0 | 10.3_p1-r1 | /lib/apk/db/installed |
| HIGH | CVE-2026-80231 | curl | 8.21.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-93990 | libexpat | 2.8.3-r0 | 2.8.5-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-86145 | pcre2 | 10.47-r1 | 10.48-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-82208 | curl | 8.21.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-82208 | libcurl | 8.21.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-82209 | curl | 8.21.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-82209 | libcurl | 8.21.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-76641 | libexpat | 2.8.3-r0 | 2.8.4-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-80230 | curl | 8.21.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-80230 | libcurl | 8.21.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-76956 | libexpat | 2.8.3-r0 | 2.8.4-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-89157 | pcre2 | 10.47-r1 | 10.48-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-103111 | pcre2 | 10.47-r1 | 10.49-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-59999 | openssh-client-common | 10.3_p1-r0 | 10.3_p1-r1 | /lib/apk/db/installed |
| HIGH | CVE-2026-59999 | openssh-client-default | 10.3_p1-r0 | 10.3_p1-r1 | /lib/apk/db/installed |
| HIGH | CVE-2026-59999 | openssh-keygen | 10.3_p1-r0 | 10.3_p1-r1 | /lib/apk/db/installed |
| HIGH | CVE-2026-89161 | pcre2 | 10.47-r1 | 10.48-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-76957 | libexpat | 2.8.3-r0 | 2.8.4-r0 | /lib/apk/db/installed |
| HIGH | GO-2026-5026 | stdlib | go1.26.2 | 1.25.13, 1.26.6, 1.27.0-rc.3 | The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com". — /usr/local/bin/supercronic-linux-amd64 |
| HIGH | CVE-2026-80231 | libcurl | 8.21.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | GHSA-q339-8rmv-2mhv | erb | 4.0.4 | 4.0.4.1 | ERB has an @_init deserialization guard bypass via def_module / def_method / def_class — /usr/lib/ruby/gems/3.4.0/specifications/default/erb-4.0.4.gemspec |
| HIGH | CVE-2026-66046 | libexpat | 2.8.3-r0 | 2.8.4-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-85091 | zlib | 1.3.2-r0 | 1.3.2-r1 | /lib/apk/db/installed |
| HIGH | GO-2026-4918 | stdlib | go1.26.2 | 1.25.10, 1.26.3 | When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0. — /usr/local/bin/supercronic-linux-amd64 |
| HIGH | GO-2026-4971 | stdlib | go1.26.2 | 1.25.10, 1.26.3 | The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0). — /usr/local/bin/supercronic-linux-amd64 |
| HIGH | CVE-2026-60000 | openssh-client-common | 10.3_p1-r0 | 10.3_p1-r1 | /lib/apk/db/installed |
| HIGH | CVE-2026-60000 | openssh-client-default | 10.3_p1-r0 | 10.3_p1-r1 | /lib/apk/db/installed |
| HIGH | CVE-2026-60000 | openssh-keygen | 10.3_p1-r0 | 10.3_p1-r1 | /lib/apk/db/installed |
| HIGH | GO-2026-5037 | stdlib | go1.26.2 | 1.25.11, 1.26.4 | (*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates. — /usr/local/bin/supercronic-linux-amd64 |
| HIGH | GO-2026-6090 | stdlib | go1.26.2 | 1.25.13, 1.26.6, 1.27.0-rc.3 | Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely. — /usr/local/bin/supercronic-linux-amd64 |
| HIGH | GO-2026-5972 | stdlib | go1.26.2 | 1.25.13, 1.26.6, 1.27.0-rc.3 | Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures. — /usr/local/bin/supercronic-linux-amd64 |
| HIGH | GO-2026-6089 | stdlib | go1.26.2 | 1.25.13, 1.26.6, 1.27.0-rc.3 | When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this. — /usr/local/bin/supercronic-linux-amd64 |
| HIGH | CVE-2026-80229 | curl | 8.21.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-80229 | libcurl | 8.21.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-80255 | curl | 8.21.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-80255 | libcurl | 8.21.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-13608 | curl | 8.21.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| HIGH | CVE-2026-13608 | libcurl | 8.21.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-59995 | openssh-keygen | 10.3_p1-r0 | 10.3_p1-r1 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-59998 | openssh-client-common | 10.3_p1-r0 | 10.3_p1-r1 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-59998 | openssh-client-default | 10.3_p1-r0 | 10.3_p1-r1 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-59998 | openssh-keygen | 10.3_p1-r0 | 10.3_p1-r1 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-59997 | openssh-client-common | 10.3_p1-r0 | 10.3_p1-r1 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-59997 | openssh-client-default | 10.3_p1-r0 | 10.3_p1-r1 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-59997 | openssh-keygen | 10.3_p1-r0 | 10.3_p1-r1 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-73282 | openssh-client-common | 10.3_p1-r0 | 10.3_p1-r1 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-73282 | openssh-client-default | 10.3_p1-r0 | 10.3_p1-r1 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-73282 | openssh-keygen | 10.3_p1-r0 | 10.3_p1-r1 | /lib/apk/db/installed |
| MEDIUM | GO-2026-6218 | stdlib | go1.26.2 | 1.25.13, 1.26.6, 1.27.0-rc.3 | Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations. — /usr/local/bin/supercronic-linux-amd64 |
| MEDIUM | GO-2026-5039 | stdlib | go1.26.2 | 1.25.11, 1.26.4 | When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or logged. — /usr/local/bin/supercronic-linux-amd64 |
| MEDIUM | GO-2026-5856 | stdlib | go1.26.2 | 1.25.12, 1.26.5, 1.27.0-rc.2 | Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello. — /usr/local/bin/supercronic-linux-amd64 |
| MEDIUM | CVE-2026-58055 | nghttp2-libs | 1.69.0-r0 | 1.70.0-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-60001 | openssh-client-common | 10.3_p1-r0 | 10.3_p1-r1 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-60001 | openssh-client-default | 10.3_p1-r0 | 10.3_p1-r1 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-60001 | openssh-keygen | 10.3_p1-r0 | 10.3_p1-r1 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-89156 | pcre2 | 10.47-r1 | 10.48-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-89160 | pcre2 | 10.47-r1 | 10.48-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-89158 | pcre2 | 10.47-r1 | 10.48-r0 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-59996 | openssh-client-common | 10.3_p1-r0 | 10.3_p1-r1 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-59996 | openssh-client-default | 10.3_p1-r0 | 10.3_p1-r1 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-59996 | openssh-keygen | 10.3_p1-r0 | 10.3_p1-r1 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-59995 | openssh-client-common | 10.3_p1-r0 | 10.3_p1-r1 | /lib/apk/db/installed |
| MEDIUM | CVE-2026-59995 | openssh-client-default | 10.3_p1-r0 | 10.3_p1-r1 | /lib/apk/db/installed |
| LOW | CVE-2026-73283 | openssh-keygen | 10.3_p1-r0 | 10.3_p1-r1 | /lib/apk/db/installed |
| LOW | CVE-2026-73283 | openssh-client-default | 10.3_p1-r0 | 10.3_p1-r1 | /lib/apk/db/installed |
| LOW | CVE-2026-73283 | openssh-client-common | 10.3_p1-r0 | 10.3_p1-r1 | /lib/apk/db/installed |
| LOW | CVE-2026-89162 | pcre2 | 10.47-r1 | 10.48-r0 | /lib/apk/db/installed |
| LOW | CVE-2026-73281 | openssh-keygen | 10.3_p1-r0 | 10.3_p1-r1 | /lib/apk/db/installed |
| LOW | CVE-2026-73281 | openssh-client-default | 10.3_p1-r0 | 10.3_p1-r1 | /lib/apk/db/installed |
| LOW | CVE-2026-73281 | openssh-client-common | 10.3_p1-r0 | 10.3_p1-r1 | /lib/apk/db/installed |
| LOW | GHSA-x2f5-4prf-w687 | json | 2.9.1 | 2.19.9 | Ruby json: JSON generator heap buffer overflow when streaming to an IO — /usr/lib/ruby/gems/3.4.0/specifications/default/json-2.9.1.gemspec |
| UNKNOWN | CVE-2026-80256 | curl | 8.21.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
| UNKNOWN | CVE-2026-80256 | libcurl | 8.21.0-r0 | 8.22.0-r0 | /lib/apk/db/installed |
Filtered NVD/CPE matches (43)
These broad CPE matches are unconfirmed for the distribution package and excluded from scanner totals.
| Severity | ID | Package | Installed | Fixed | Title / target |
|---|---|---|---|---|---|
| HIGH | CVE-2026-72897 | libssl3 | 3.5.8-r0 | Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a connection to a different SSL_CTX part way through a handshake may access memory beyond the end of an internal array if the replacement context knows about more provider signature algorithms than the context the connection was created from. Applications which never call SSL_set_SSL_CTX() are not affected. Impact summary: A remote peer may be able to cause a small out-of-bounds read, and in some circumstances a fixed-value out-of-bounds write, on the server heap. This may lead to a Denial of Service. CWE: CWE-787: Out-of-bounds Write Description: A TLS connection records how many certificate slots it has when it is created, taken from the SSL_CTX that created it: the built-in certificate types plus one slot for each provider TLS-SIGALG entry that context was aware of. That count sizes an internal array of per-slot certificate validity flags. An application may replace a connection's SSL_CTX part way through the handshake by calling SSL_set_SSL_CTX(), most commonly from a servername callback in order to serve a different virtual host. Doing so did not refresh the recorded count. A provider signature algorithm's slot index is its position in the list of whichever context resolves it, so if the replacement context is aware of more of them than the original, an algorithm offered by the peer can resolve to an index beyond the end of the array. Processing the peer's signature algorithms then reads one four byte word past the end for each such algorithm and, where the word read is zero, writes a fixed value over it. A peer offering many of them can corrupt heap metadata and abort the process. Only provider signature algorithms which occupy one of the excess slots, and which the server also has configured, have this effect. Codepoints the replacement context does not recognise are discarded without being resolved to a slot, and provider signature algorithms are usable only from TLS 1.3. The two contexts must therefore be aware of different numbers of provider signature algorithms, which requires separate library contexts, a provider loaded between the two being created, or providers which differ in what they advertise - in 4.0, for example, the default provider advertises SM2 where the FIPS provider does not. A deployment meeting the condition is also unable to negotiate the affected algorithms with legitimate clients, since the same stale count hides the corresponding certificates, so the misconfiguration is likely to be noticed. For that reason, and because the configuration is not the default, this issue has been assessed as Low severity. FIPS impact: no No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| HIGH | CVE-2026-72897 | libcrypto3 | 3.5.8-r0 | Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a connection to a different SSL_CTX part way through a handshake may access memory beyond the end of an internal array if the replacement context knows about more provider signature algorithms than the context the connection was created from. Applications which never call SSL_set_SSL_CTX() are not affected. Impact summary: A remote peer may be able to cause a small out-of-bounds read, and in some circumstances a fixed-value out-of-bounds write, on the server heap. This may lead to a Denial of Service. CWE: CWE-787: Out-of-bounds Write Description: A TLS connection records how many certificate slots it has when it is created, taken from the SSL_CTX that created it: the built-in certificate types plus one slot for each provider TLS-SIGALG entry that context was aware of. That count sizes an internal array of per-slot certificate validity flags. An application may replace a connection's SSL_CTX part way through the handshake by calling SSL_set_SSL_CTX(), most commonly from a servername callback in order to serve a different virtual host. Doing so did not refresh the recorded count. A provider signature algorithm's slot index is its position in the list of whichever context resolves it, so if the replacement context is aware of more of them than the original, an algorithm offered by the peer can resolve to an index beyond the end of the array. Processing the peer's signature algorithms then reads one four byte word past the end for each such algorithm and, where the word read is zero, writes a fixed value over it. A peer offering many of them can corrupt heap metadata and abort the process. Only provider signature algorithms which occupy one of the excess slots, and which the server also has configured, have this effect. Codepoints the replacement context does not recognise are discarded without being resolved to a slot, and provider signature algorithms are usable only from TLS 1.3. The two contexts must therefore be aware of different numbers of provider signature algorithms, which requires separate library contexts, a provider loaded between the two being created, or providers which differ in what they advertise - in 4.0, for example, the default provider advertises SM2 where the FIPS provider does not. A deployment meeting the condition is also unable to negotiate the affected algorithms with legitimate clients, since the same stale count hides the corresponding certificates, so the misconfiguration is likely to be noticed. For that reason, and because the configuration is not the default, this issue has been assessed as Low severity. FIPS impact: no No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| HIGH | CVE-2026-58051 | libssh2 | 1.11.1-r3 | libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsing populates them, so a parse failure reaching the cleanup path leaves libssh2_publickey_list_free operating on an uninitialized entry. A malicious SSH server offering the publickey subsystem can use a malformed response to make cleanup free an uninitialized, attacker-influenceable attrs pointer in a connecting libssh2 client. — /lib/apk/db/installed | |
| HIGH | CVE-2026-59850 | libssh2 | 1.11.1-r3 | A flaw was found in libssh. If data packets are processed after a channel is closed, channel data callbacks can be invoked after the associated data has already been freed, leading to crashes or possible use-after-free conditions. — /lib/apk/db/installed | |
| HIGH | CVE-2026-84784 | libssl3 | 3.5.8-r0 | Issue summary: A malicious remote peer may flood the local QUIC stack with NEW_CONNECTION_ID frames by avoiding a limit check on how many connection IDs the remote QUIC stack can use. Impact summary: The local QUIC stack sends a RETIRE_CONN_ID frame for every NEW_CONNECTION_ID frame it receives. The RETIRE_CONN_ID frame is dispatched via the Control Frame Queue (CFQ). If the remote peer also withholds ACKs, then it can force the local stack to allocate ~400MB (depending on ACK delay). CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: RFC 9000 sections 5.1.1 and 5.1.2 [1] describe the mechanism by which a remote peer can notify the local QUIC stack to change the destination connection ID (a.k.a. CID) the local stack uses to identify the connection at the remote peer. Each CID is associated with a sequence number. The sequence number is transmitted in NEW_CONNECTION_ID and RETIRE_CONNECTION_ID frames to identify the CID which is being either associated with a connection or retired. The remote peer sends a NEW_CONNECTION_ID frame to let the local stack know a new CID is being associated with an existing connection. The NEW_CONNECTION_ID frame carries the new CID, its sequence number, and the retire-prior-to number. The retire-prior-to identifies existing CIDs that are to be retired. The local QUIC stack must send a RETIRE_CONNECTION_ID for every destination CID whose sequence number is less than retire-prior-to. The CID becomes retired after the local stack receives an ACK for its RETIRE_CONNECTION_ID frame. Although the OpenSSL QUIC stack supports at most one destination CID for every connection, it can be tricked into processing more than one RETIRE_CONNECTION_ID frame per connection. The OpenSSL QUIC stack currently retires the destination CID as soon as it receives the NEW_CONNECTION_ID, while in fact the destination CID must be retired after an ACK for the RETIRE_CONNECTION_ID frame is received. Correcting the flawed logic also fixes the backlog growth. [1] https://datatracker.ietf.org/doc/html/rfc9000#name-issuing-connection-ids FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| HIGH | CVE-2026-84784 | libcrypto3 | 3.5.8-r0 | Issue summary: A malicious remote peer may flood the local QUIC stack with NEW_CONNECTION_ID frames by avoiding a limit check on how many connection IDs the remote QUIC stack can use. Impact summary: The local QUIC stack sends a RETIRE_CONN_ID frame for every NEW_CONNECTION_ID frame it receives. The RETIRE_CONN_ID frame is dispatched via the Control Frame Queue (CFQ). If the remote peer also withholds ACKs, then it can force the local stack to allocate ~400MB (depending on ACK delay). CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: RFC 9000 sections 5.1.1 and 5.1.2 [1] describe the mechanism by which a remote peer can notify the local QUIC stack to change the destination connection ID (a.k.a. CID) the local stack uses to identify the connection at the remote peer. Each CID is associated with a sequence number. The sequence number is transmitted in NEW_CONNECTION_ID and RETIRE_CONNECTION_ID frames to identify the CID which is being either associated with a connection or retired. The remote peer sends a NEW_CONNECTION_ID frame to let the local stack know a new CID is being associated with an existing connection. The NEW_CONNECTION_ID frame carries the new CID, its sequence number, and the retire-prior-to number. The retire-prior-to identifies existing CIDs that are to be retired. The local QUIC stack must send a RETIRE_CONNECTION_ID for every destination CID whose sequence number is less than retire-prior-to. The CID becomes retired after the local stack receives an ACK for its RETIRE_CONNECTION_ID frame. Although the OpenSSL QUIC stack supports at most one destination CID for every connection, it can be tricked into processing more than one RETIRE_CONNECTION_ID frame per connection. The OpenSSL QUIC stack currently retires the destination CID as soon as it receives the NEW_CONNECTION_ID, while in fact the destination CID must be retired after an ACK for the RETIRE_CONNECTION_ID frame is received. Correcting the flawed logic also fixes the backlog growth. [1] https://datatracker.ietf.org/doc/html/rfc9000#name-issuing-connection-ids FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| HIGH | CVE-2026-66034 | libssh2 | 1.11.1-r3 | libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitrary-length heap out-of-bounds read and a free of an uninitialized pointer via the publickey subsystem. In libssh2_publickey_list_fetch(), the version 1 response parser reads a server-controlled comment_len value and advances the parse pointer without verifying sufficient bytes remain in the buffer, causing the out-of-bounds read to leak heap pointers from adjacent allocations defeating ASLR, followed by heap allocator state corruption when the error cleanup path frees an uninitialized pointer from a non-zeroed realloc() region. — /lib/apk/db/installed | |
| HIGH | CVE-2026-84782 | libssl3 | 3.5.8-r0 | Issue summary: The DTLS retransmission logic does not correctly handle a handshake message write that is suspended part-way through. The retransmitted message can be read past the message buffer and the retransmission overwrites the internal state the suspended write needs to resume correctly. Impact summary: The retransmitted message can disclose a heap memory to the peer as plaintext handshake data or cause a crash and a Denial of Service when the read reaches an unmapped memory region. CWE: CWE-125: Out-of-bounds Read Description: DTLS handshake messages can be written out in multiple fragments, and a write can suspend mid-message (returning WANT_WRITE) if the underlying transport temporarily cannot accept more data. While such a write is suspended, the DTLS retransmission timer may independently fire and ask the retransmission logic to resend an earlier, already-acknowledged-as-sent message from its retransmit queue. The retransmission logic reused the same internal buffer and position tracking as the message that was still being written, without resetting the position back to the start of the message being retransmitted. As a result the retransmission was read starting from wherever the suspended write had left off, producing a mislabelled message whose body was leftover bytes from the other, larger message still in flight - content that was never meant to be sent at that point, and which could run past the end of the allocated buffer. Separately, even when the retransmission is positioned correctly, allowing it to run to completion while another write is suspended overwrites the same shared bookkeeping that the suspended write depends on to resume. When the application later resumes the suspended write (via a subsequent SSL_read(), SSL_write(), SSL_accept(), or SSL_connect() call), it finds that bookkeeping in a state inconsistent with the message and aborts the process in a debugging build. The fix resets the retransmission's read position to the start of the message before resending, and skips retransmission entirely whenever a handshake write is still suspended, deferring to the next call that resumes it instead. FIPS impact: no The affected code is outside the FIPS module boundary. — /lib/apk/db/installed | |
| HIGH | CVE-2026-84782 | libcrypto3 | 3.5.8-r0 | Issue summary: The DTLS retransmission logic does not correctly handle a handshake message write that is suspended part-way through. The retransmitted message can be read past the message buffer and the retransmission overwrites the internal state the suspended write needs to resume correctly. Impact summary: The retransmitted message can disclose a heap memory to the peer as plaintext handshake data or cause a crash and a Denial of Service when the read reaches an unmapped memory region. CWE: CWE-125: Out-of-bounds Read Description: DTLS handshake messages can be written out in multiple fragments, and a write can suspend mid-message (returning WANT_WRITE) if the underlying transport temporarily cannot accept more data. While such a write is suspended, the DTLS retransmission timer may independently fire and ask the retransmission logic to resend an earlier, already-acknowledged-as-sent message from its retransmit queue. The retransmission logic reused the same internal buffer and position tracking as the message that was still being written, without resetting the position back to the start of the message being retransmitted. As a result the retransmission was read starting from wherever the suspended write had left off, producing a mislabelled message whose body was leftover bytes from the other, larger message still in flight - content that was never meant to be sent at that point, and which could run past the end of the allocated buffer. Separately, even when the retransmission is positioned correctly, allowing it to run to completion while another write is suspended overwrites the same shared bookkeeping that the suspended write depends on to resume. When the application later resumes the suspended write (via a subsequent SSL_read(), SSL_write(), SSL_accept(), or SSL_connect() call), it finds that bookkeeping in a state inconsistent with the message and aborts the process in a debugging build. The fix resets the retransmission's read position to the start of the message before resending, and skips retransmission entirely whenever a handshake write is still suspended, deferring to the next call that resumes it instead. FIPS impact: no The affected code is outside the FIPS module boundary. — /lib/apk/db/installed | |
| HIGH | CVE-2026-58050 | libssh2 | 1.11.1-r3 | libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attrs * sizeof(libssh2_publickey_attribute) without bounds checking, so on 32-bit platforms the multiplication overflows to an undersized buffer. A malicious SSH server can then drive the attribute-parsing loop to write past the allocation, causing a heap buffer overflow in a connecting libssh2 client. — /lib/apk/db/installed | |
| HIGH | CVE-2026-54873 | libssl3 | 3.5.8-r0 | Issue summary: QUIC process may keep memory for QUIC packet buffer for much longer period than necessary. Impact summary: Remote peer can exploit this vulnerability by sending maliciously crafted packets, making the local QUIC stack to keep the memory for packet buffers allocated. The time for which the memory remains allocated is entirely under the control of the potentially malicious remote peer. CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: To save copy operation from the packet buffer to the stream reassemble buffer the QUIC stack leaves the stream data on the packet buffer waiting to be copied to a buffer provided by the local receiving application. The QUIC stack releases a reference to the packet buffer only after the data are copied to the application buffer. This design is more efficient for legitimate data transfers but enables an attacker to allocate a lot more memory than actually required by the data kept in the receiving stream buffer. To mitigate the vulnerability, the QUIC stack now calculates and monitors memory overhead for every stream. The memory overhead for a single stream frame is calculated as a difference between the size of the whole packet that carries the stream frame and the size of the stream frame itself. The memory overhead for a single stream frame is added to the total (cumulative) memory overhead QUIC stack keeps for each stream. Once the cumulative memory overhead exceeds 64kB, the QUIC stack moves the stream frame data from the packet buffer to the stream buffer, starting with the next packet received. FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| HIGH | CVE-2026-54873 | libcrypto3 | 3.5.8-r0 | Issue summary: QUIC process may keep memory for QUIC packet buffer for much longer period than necessary. Impact summary: Remote peer can exploit this vulnerability by sending maliciously crafted packets, making the local QUIC stack to keep the memory for packet buffers allocated. The time for which the memory remains allocated is entirely under the control of the potentially malicious remote peer. CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: To save copy operation from the packet buffer to the stream reassemble buffer the QUIC stack leaves the stream data on the packet buffer waiting to be copied to a buffer provided by the local receiving application. The QUIC stack releases a reference to the packet buffer only after the data are copied to the application buffer. This design is more efficient for legitimate data transfers but enables an attacker to allocate a lot more memory than actually required by the data kept in the receiving stream buffer. To mitigate the vulnerability, the QUIC stack now calculates and monitors memory overhead for every stream. The memory overhead for a single stream frame is calculated as a difference between the size of the whole packet that carries the stream frame and the size of the stream frame itself. The memory overhead for a single stream frame is added to the total (cumulative) memory overhead QUIC stack keeps for each stream. Once the cumulative memory overhead exceeds 64kB, the QUIC stack moves the stream frame data from the packet buffer to the stream buffer, starting with the next packet received. FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| HIGH | CVE-2026-66032 | libssh2 | 1.11.1-r3 | libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt the heap of any authenticated client opening an SFTP session. When a server responds to SSH_FXP_OPEN with SSH_FXP_STATUS containing FX_OK, the response data buffer is freed, and if a subsequent sftp_packet_require() call returns a specific error such as LIBSSH2_ERROR_CHANNEL_PACKET_EXCEEDED, the same pointer is freed a second time, enabling tcache dup conditions on glibc systems that allow overlapping allocations and function pointer overwrites. — /lib/apk/db/installed | |
| HIGH | CVE-2026-59851 | libssh2 | 1.11.1-r3 | A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssapi-keyex path does not verify whether the authenticated Kerberos principal is authorized for the requested local user, allowing authenticated clients to log in as arbitrary users. — /lib/apk/db/installed | |
| HIGH | CVE-2026-66035 | libssh2 | 1.11.1-r3 | libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that allows a malicious SSH server to corrupt heap metadata in any connecting client by sending a packet with a packet_length smaller than the cipher's block size during Encrypt-then-MAC cipher negotiation. In the fullpacket() function in src/transport.c, the ETM path allocates a buffer of packet_length bytes but copies blocksize minus one bytes via memcpy, causing an overflow that on 32-bit glibc writes attacker-controlled bytes into an adjacent chunk's SIZE field, enabling tcache bin confusion, overlapping live objects, and function pointer overwrite during the session handshake before authentication. — /lib/apk/db/installed | |
| HIGH | CVE-2026-66033 | libssh2 | 1.11.1-r3 | libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in src/openssl.c that allows a malicious SSH server to crash any connecting client by negotiating AES-GCM ciphers during handshake. Attackers can exploit the underflow in the expression computing blocksize minus aadlen minus authentication tag length to trigger an out-of-bounds read and a memcpy call with a near-SIZE_MAX length argument, causing immediate process crash before any authentication occurs. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-75805 | libcrypto3 | 3.5.8-r0 | Issue summary: A CMP client that requests certificate revocation on the basis of a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when processing a crafted revocation response. Impact summary: The NULL pointer dereference happens on a read which leads to a crash and a Denial of Service for the affected client application. CWE: CWE-476: NULL-pointer dereference Description: A CMP client revoking a certificate has to tell the server which certificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the certificate itself or its issuer name and serial number. This is 'openssl cmp -cmd rr -csr <file>' on the command line, or OSSL_CMP_exec_RR_ses() with the certificate supplied via OSSL_CMP_CTX_set1_p10CSR() through the API. A CSR does not contain the issuer name and serial number of the certificate, so the client does not send them. A server may optionally name the certificate it revoked in its response, and the client then compares that name against what it sent. Having sent neither an issuer name nor a serial number, it has nothing to compare against, and a server returning a specially crafted name causes the client to read from a NULL pointer and crash. The revocation response is checked for valid message protection before the affected code is reached, so an attacker must be a malicious or compromised CMP server, or a man-in-the-middle in possession of the secret used for message protection. Clients that identify the certificate to be revoked by a certificate or by issuer and serial number rather than by a PKCS#10 CSR are not affected. FIPS impact: no No FIPS modules are affected by this issue, as the CMP protocol implementation is outside the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-75805 | libssl3 | 3.5.8-r0 | Issue summary: A CMP client that requests certificate revocation on the basis of a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when processing a crafted revocation response. Impact summary: The NULL pointer dereference happens on a read which leads to a crash and a Denial of Service for the affected client application. CWE: CWE-476: NULL-pointer dereference Description: A CMP client revoking a certificate has to tell the server which certificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the certificate itself or its issuer name and serial number. This is 'openssl cmp -cmd rr -csr <file>' on the command line, or OSSL_CMP_exec_RR_ses() with the certificate supplied via OSSL_CMP_CTX_set1_p10CSR() through the API. A CSR does not contain the issuer name and serial number of the certificate, so the client does not send them. A server may optionally name the certificate it revoked in its response, and the client then compares that name against what it sent. Having sent neither an issuer name nor a serial number, it has nothing to compare against, and a server returning a specially crafted name causes the client to read from a NULL pointer and crash. The revocation response is checked for valid message protection before the affected code is reached, so an attacker must be a malicious or compromised CMP server, or a man-in-the-middle in possession of the secret used for message protection. Clients that identify the certificate to be revoked by a certificate or by issuer and serial number rather than by a PKCS#10 CSR are not affected. FIPS impact: no No FIPS modules are affected by this issue, as the CMP protocol implementation is outside the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-59845 | libssh2 | 1.11.1-r3 | A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may then be sent across the caller's accessible process tree, leading to local denial of service. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-35189 | libssl3 | 3.5.8-r0 | Issue summary: A certificate with many nameRelativeToCRLIssuer CRL distribution points causes disproportionate heap growth when OpenSSL caches X.509 extensions. Impact summary: Receiving a crafted certificate from a malicious peer can lead to significant memory pressure and possible Denial of Service in clients or in servers that solicit client certificates. CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: A certificate or a set of certificates that fits under the limit for size of certificates accepted from the peer (~100 KiB) can result in allocation of several hundred MiB of resident memory on the receiving side during a normal TLS handshake. This may be enough to crash the client or server, if multiple concurrent connections lead to similarly large memory allocations. The fix postpones processing of the CRL distribution points extensions in certificates to the time when the processed value is required for CRL processing. This avoids keeping large memory allocations for a long time when such certificates are received. FIPS impact: no The affected code is outside the FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-35189 | libcrypto3 | 3.5.8-r0 | Issue summary: A certificate with many nameRelativeToCRLIssuer CRL distribution points causes disproportionate heap growth when OpenSSL caches X.509 extensions. Impact summary: Receiving a crafted certificate from a malicious peer can lead to significant memory pressure and possible Denial of Service in clients or in servers that solicit client certificates. CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: A certificate or a set of certificates that fits under the limit for size of certificates accepted from the peer (~100 KiB) can result in allocation of several hundred MiB of resident memory on the receiving side during a normal TLS handshake. This may be enough to crash the client or server, if multiple concurrent connections lead to similarly large memory allocations. The fix postpones processing of the CRL distribution points extensions in certificates to the time when the processed value is required for CRL processing. This avoids keeping large memory allocations for a long time when such certificates are received. FIPS impact: no The affected code is outside the FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-60876 | ssl_client | 1.37.0-r31 | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-60876 | busybox-binsh | 1.37.0-r31 | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-60876 | busybox | 1.37.0-r31 | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-42772 | libssl3 | 3.5.8-r0 | Issue summary: The QUIC stream reassembly algorithm performance deteriorates progressively as packets are arriving out of order. The worst case has a quadratic complexity proportional to the number of stream frames kept in the buffer for the received stream data. Impact summary: A remote QUIC peer that completes the handshake can create a connection-scoped CPU pressure and potentially a Denial of Service using compliant STREAM frames inside the advertised receive window, with low attacker bandwidth. CWE: CWE-407: Inefficient Algorithmic Complexity Description: OpenSSL manages received QUIC stream fragments using a doubly-linked list. While it optimizes for append operations (at the end of the list), it falls back to a head-to-tail linear search for any fragment that does not immediately follow the current `tail`. By manipulating the sequence of offsets, an attacker can force the server to perform O(n^2) operations, consuming excessive CPU time for the QUIC process. FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-59843 | libssh2 | 1.11.1-r3 | A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel writes to loop indefinitely and consume CPU, leading to denial of service. — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-15661 | libssh2 | 1.11.1-r3 | libssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bounds heap read vulnerability in the sftp_symlink() function in src/sftp.c that allows a malicious SSH server or man-in-the-middle attacker to disclose heap memory contents or cause a crash by sending a crafted SSH_FXP_NAME response. Attackers can supply a link_len value larger than the actual packet data in SSH_FXP_NAME responses for SFTP READLINK and REALPATH operations, triggering a heap buffer over-read of up to target_len minus one bytes due to the missing validation of available packet buffer size before the memcpy operation. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-59844 | libssh2 | 1.11.1-r3 | A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large length, causing a libssh SFTP server to allocate excessive memory and potentially exhaust it through repeated requests. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-75806 | libcrypto3 | 3.5.8-r0 | Issue summary: An established DTLS 1.2 association using an AEAD cipher suite can be terminated by a single unauthenticated datagram whose encrypted fragment is shorter than the mandatory explicit IV and authentication tag overhead. Impact summary: An attacker who can send a datagram that is routed to an existing DTLS 1.2 association can tear that association down without knowing any key material. This is a Denial of Service limited to the targeted association. There is no memory safety or confidentiality impact. CWE: CWE-1284: Improper Validation of Specified Quantity in Input Description: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher suite carries an explicit IV followed by the ciphertext and an authentication tag. When decrypting such a record the record layer passed the record length to the cipher implementation before checking that the record was long enough to contain the explicit IV and the tag. For a record shorter than that overhead the cipher implementation rejected the impossible length, and the record layer treated this as an internal failure and raised a fatal internal_error alert instead of treating the record as one that failed authentication. In TLS 1.2 the same record causes a fatal internal_error alert instead of the expected bad_record_mac alert. Since any undecryptable record already terminates a TLS connection, this is a protocol conformance issue rather than a security issue in TLS. The fix validates the record length against the explicit IV and tag length before any AEAD processing, so that TLS reports bad_record_mac and DTLS silently discards the record. FIPS impact: no The affected code is outside the FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-75806 | libssl3 | 3.5.8-r0 | Issue summary: An established DTLS 1.2 association using an AEAD cipher suite can be terminated by a single unauthenticated datagram whose encrypted fragment is shorter than the mandatory explicit IV and authentication tag overhead. Impact summary: An attacker who can send a datagram that is routed to an existing DTLS 1.2 association can tear that association down without knowing any key material. This is a Denial of Service limited to the targeted association. There is no memory safety or confidentiality impact. CWE: CWE-1284: Improper Validation of Specified Quantity in Input Description: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher suite carries an explicit IV followed by the ciphertext and an authentication tag. When decrypting such a record the record layer passed the record length to the cipher implementation before checking that the record was long enough to contain the explicit IV and the tag. For a record shorter than that overhead the cipher implementation rejected the impossible length, and the record layer treated this as an internal failure and raised a fatal internal_error alert instead of treating the record as one that failed authentication. In TLS 1.2 the same record causes a fatal internal_error alert instead of the expected bad_record_mac alert. Since any undecryptable record already terminates a TLS connection, this is a protocol conformance issue rather than a security issue in TLS. The fix validates the record length against the explicit IV and tag length before any AEAD processing, so that TLS reports bad_record_mac and DTLS silently discards the record. FIPS impact: no The affected code is outside the FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-75804 | libcrypto3 | 3.5.8-r0 | Issue summary: OpenSSL QUIC stack does not enforce connection level flow control for streams. Remote peers may send more bytes as long as they fit within the stream flow control limits. Impact summary: A malicious remote peer may exploit the lack of connection flow control for streams to make the QUIC stack receive ~100MB of memory instead of 768 KiB (default flow control window size). CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: The local QUIC stack advertises two flow control limits to its remote peer: stream flow control limit and connection flow control limit. The remote peer must follow both limits when transmitting stream data. Whenever the local QUIC stack receives a stream frame, it validates that the size of the received stream frame stays within flow control limits. If either limit is exceeded (stream level or connection level), then the QUIC stack must close the connection with a flow control error. The vulnerable OpenSSL QUIC stack enforces the stream-level but not the connection-level limit. To exploit the issue, three conditions must be met: - the remote peer opens several streams - each stream must stay within the stream-level flow control limit - there must be no zero-offset byte sent on any of the streams (to prevent the vulnerable QUIC stack from consuming data). By meeting the conditions above, the remote peer may make the local stack allocate 2 x MAX_STREAMS x (stream flow control limit) bytes of memory. MAX_STREAMS defaults to 100, and the limit applies to both bidirectional and unidirectional streams, making it 200 in total. The default flow control window for a stream is 512kB. The remote peer may force the vulnerable QUIC stack to allocate 100MB of heap per connection. FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-75804 | libssl3 | 3.5.8-r0 | Issue summary: OpenSSL QUIC stack does not enforce connection level flow control for streams. Remote peers may send more bytes as long as they fit within the stream flow control limits. Impact summary: A malicious remote peer may exploit the lack of connection flow control for streams to make the QUIC stack receive ~100MB of memory instead of 768 KiB (default flow control window size). CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: The local QUIC stack advertises two flow control limits to its remote peer: stream flow control limit and connection flow control limit. The remote peer must follow both limits when transmitting stream data. Whenever the local QUIC stack receives a stream frame, it validates that the size of the received stream frame stays within flow control limits. If either limit is exceeded (stream level or connection level), then the QUIC stack must close the connection with a flow control error. The vulnerable OpenSSL QUIC stack enforces the stream-level but not the connection-level limit. To exploit the issue, three conditions must be met: - the remote peer opens several streams - each stream must stay within the stream-level flow control limit - there must be no zero-offset byte sent on any of the streams (to prevent the vulnerable QUIC stack from consuming data). By meeting the conditions above, the remote peer may make the local stack allocate 2 x MAX_STREAMS x (stream flow control limit) bytes of memory. MAX_STREAMS defaults to 100, and the limit applies to both bidirectional and unidirectional streams, making it 200 in total. The default flow control window for a stream is 512kB. The remote peer may force the vulnerable QUIC stack to allocate 100MB of heap per connection. FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-59848 | libssh2 | 1.11.1-r3 | A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh clients keep queued indefinitely, causing unbounded memory growth and client-side denial of service. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-42772 | libcrypto3 | 3.5.8-r0 | Issue summary: The QUIC stream reassembly algorithm performance deteriorates progressively as packets are arriving out of order. The worst case has a quadratic complexity proportional to the number of stream frames kept in the buffer for the received stream data. Impact summary: A remote QUIC peer that completes the handshake can create a connection-scoped CPU pressure and potentially a Denial of Service using compliant STREAM frames inside the advertised receive window, with low attacker bandwidth. CWE: CWE-407: Inefficient Algorithmic Complexity Description: OpenSSL manages received QUIC stream fragments using a doubly-linked list. While it optimizes for append operations (at the end of the list), it falls back to a head-to-tail linear search for any fragment that does not immediately follow the current `tail`. By manipulating the sequence of offsets, an attacker can force the server to perform O(n^2) operations, consuming excessive CPU time for the QUIC process. FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| LOW | CVE-2026-35191 | libcrypto3 | 3.5.8-r0 | Issue summary: The OpenSSL QUIC server, when configured to not preform address validation, can be forced to count incoming packets multiple times in its unvalidated credit computation, leading to a violation of the RFC 9000 unvalidated connection amplification limit of 3 times the amount of data received. Impact summary: A remote attacker able to spoof packets to a server using the OpenSSL QUIC implementation might use the server for an amplification of a DDoS attack. CWE: CWE-440: Expected Behavior Violation Description: OpenSSL's QUIC stack, when operating as a server, enforces client address validation (RFC 9000, Section 8), to confirm the peer address is not used for a traffic amplification attack. If this feature is disabled on the server, the QUIC stack limits the amount of server data that can be sent to 3 times the amount of data received from the peer address, until such time as the TLS handshake is completed. The OpenSSL QUIC server, when operating in non-validation mode, adds the length of the whole datagram received to the unvalidated credit limit when processing each QUIC packet in the datagram. A remote peer may, after establishing a connection with an initial client hello frame, send a subsequent datagram containing multiple QUIC packets, leading the server to account the entire datagram length for each packet in the datagram, resulting in the server believing that the peer has sent more data than it actually has, thereby violating the 3x amplification limit mandated by the RFC. FIPS impact: no As the QUIC stack lives outside the FIPS module boundary, no FIPS modules are affected by this CVE. — /lib/apk/db/installed | |
| LOW | CVE-2026-35191 | libssl3 | 3.5.8-r0 | Issue summary: The OpenSSL QUIC server, when configured to not preform address validation, can be forced to count incoming packets multiple times in its unvalidated credit computation, leading to a violation of the RFC 9000 unvalidated connection amplification limit of 3 times the amount of data received. Impact summary: A remote attacker able to spoof packets to a server using the OpenSSL QUIC implementation might use the server for an amplification of a DDoS attack. CWE: CWE-440: Expected Behavior Violation Description: OpenSSL's QUIC stack, when operating as a server, enforces client address validation (RFC 9000, Section 8), to confirm the peer address is not used for a traffic amplification attack. If this feature is disabled on the server, the QUIC stack limits the amount of server data that can be sent to 3 times the amount of data received from the peer address, until such time as the TLS handshake is completed. The OpenSSL QUIC server, when operating in non-validation mode, adds the length of the whole datagram received to the unvalidated credit limit when processing each QUIC packet in the datagram. A remote peer may, after establishing a connection with an initial client hello frame, send a subsequent datagram containing multiple QUIC packets, leading the server to account the entire datagram length for each packet in the datagram, resulting in the server believing that the peer has sent more data than it actually has, thereby violating the 3x amplification limit mandated by the RFC. FIPS impact: no As the QUIC stack lives outside the FIPS module boundary, no FIPS modules are affected by this CVE. — /lib/apk/db/installed | |
| LOW | CVE-2026-54875 | libcrypto3 | 3.5.8-r0 | Issue summary: A non-constant-time optimized implementation of scalar point multiplication is used for SM2 private key operations on ARM64 and RISC-V platforms. Impact summary: An attacker able to measure the time taken by, or to observe the cache-line access pattern of SM2 signing or decryption on an affected platform can learn information about the secret scalar. CWE: CWE-208: Observable Timing Discrepancy Description: On ARM64 and RISC-V processors, the SM2 curve uses an optimized scalar multiplication implementation whose conditional branches and table look ups are chosen according to the bits of the secret scalar. The execution time and the cache-access pattern therefore depend on the long-term private key (during SM2 decryption) or the per-signature nonce (during SM2 signature generation), forming a timing and cache side-channel. FIPS Impact: no SM2 is not a FIPS algorithm and the optimized SM2 implementation is not part of the FIPS module. OpenSSL 4.0, 3.6, 3.5 and 3.4 are vulnerable to this issue on AArch64 and RISC-V. OpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue. OpenSSL 4.0 users should upgrade to OpenSSL 4.0.3. OpenSSL 3.6 users should upgrade to OpenSSL 3.6.5. OpenSSL 3.5 users should upgrade to OpenSSL 3.5.9. OpenSSL 3.4 users should upgrade to OpenSSL 3.4.8. This issue was reported on 2 May 2026 by Abhinav Agarwal. It was independently reported on 6 June 2026 by Feng Xue. The fix was developed by Igor Ustinov. -- cut (non-publishing metadata for internal use) -- Reported by: Abhinav Agarwal, Feng Xue Fixed by: Igor Ustinov — /lib/apk/db/installed | |
| LOW | CVE-2026-54875 | libssl3 | 3.5.8-r0 | Issue summary: A non-constant-time optimized implementation of scalar point multiplication is used for SM2 private key operations on ARM64 and RISC-V platforms. Impact summary: An attacker able to measure the time taken by, or to observe the cache-line access pattern of SM2 signing or decryption on an affected platform can learn information about the secret scalar. CWE: CWE-208: Observable Timing Discrepancy Description: On ARM64 and RISC-V processors, the SM2 curve uses an optimized scalar multiplication implementation whose conditional branches and table look ups are chosen according to the bits of the secret scalar. The execution time and the cache-access pattern therefore depend on the long-term private key (during SM2 decryption) or the per-signature nonce (during SM2 signature generation), forming a timing and cache side-channel. FIPS Impact: no SM2 is not a FIPS algorithm and the optimized SM2 implementation is not part of the FIPS module. OpenSSL 4.0, 3.6, 3.5 and 3.4 are vulnerable to this issue on AArch64 and RISC-V. OpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue. OpenSSL 4.0 users should upgrade to OpenSSL 4.0.3. OpenSSL 3.6 users should upgrade to OpenSSL 3.6.5. OpenSSL 3.5 users should upgrade to OpenSSL 3.5.9. OpenSSL 3.4 users should upgrade to OpenSSL 3.4.8. This issue was reported on 2 May 2026 by Abhinav Agarwal. It was independently reported on 6 June 2026 by Feng Xue. The fix was developed by Igor Ustinov. -- cut (non-publishing metadata for internal use) -- Reported by: Abhinav Agarwal, Feng Xue Fixed by: Igor Ustinov — /lib/apk/db/installed | |
| LOW | CVE-2026-54872 | libcrypto3 | 3.5.8-r0 | Issue summary: The generic elliptic-curve scalar multiplication used for ECDSA and SM2 signature operations with curves that do not have a dedicated implementation leaks information about the secret nonce through timing. Impact summary: An attacker able to measure signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key. CWE: CWE-208: Observable Timing Discrepancy Description: The generic elliptic-curve scalar multiplication used for curves that do not have a dedicated constant-time implementation pads the secret scalar with non-constant-time BIGNUM operations, so the time taken depends on the value of the secret scalar derived from the ECDSA and SM2 nonce. The leak is very small; observing it requires a large number of measurements. The effect is largest for curves whose group order lies on a machine-word boundary, such as brainpoolP384r1. Applications using ECDSA signing over the Brainpool and other generic prime curves, and SM2 signing on platforms that use the generic implementation, are vulnerable to this issue. The NIST curves P-256, P-384 and P-521 use dedicated constant-time implementations and are not affected. FIPS Impact: no The FIPS modules are not affected: the approved NIST curves used in the FIPS provider have dedicated constant-time implementations and do not use the affected code path. — /lib/apk/db/installed | |
| LOW | CVE-2026-54872 | libssl3 | 3.5.8-r0 | Issue summary: The generic elliptic-curve scalar multiplication used for ECDSA and SM2 signature operations with curves that do not have a dedicated implementation leaks information about the secret nonce through timing. Impact summary: An attacker able to measure signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key. CWE: CWE-208: Observable Timing Discrepancy Description: The generic elliptic-curve scalar multiplication used for curves that do not have a dedicated constant-time implementation pads the secret scalar with non-constant-time BIGNUM operations, so the time taken depends on the value of the secret scalar derived from the ECDSA and SM2 nonce. The leak is very small; observing it requires a large number of measurements. The effect is largest for curves whose group order lies on a machine-word boundary, such as brainpoolP384r1. Applications using ECDSA signing over the Brainpool and other generic prime curves, and SM2 signing on platforms that use the generic implementation, are vulnerable to this issue. The NIST curves P-256, P-384 and P-521 use dedicated constant-time implementations and are not affected. FIPS Impact: no The FIPS modules are not affected: the approved NIST curves used in the FIPS provider have dedicated constant-time implementations and do not use the affected code path. — /lib/apk/db/installed | |
| LOW | CVE-2026-77696 | libcrypto3 | 3.5.8-r0 | Issue summary: SM2 signature generation uses non-constant-time arithmetic on secret values, forming a timing side-channel. Impact summary: An attacker able to measure SM2 signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key. CWE: CWE-208: Observable Timing Discrepancy Description: SM2 signature generation computes the signature value using variable-time BIGNUM operations on the secret nonce and the private key, so the time taken to produce an SM2 signature depends on these secret values, forming a timing side-channel. Applications performing SM2 signature generation are affected on all platforms. FIPS Impact: no SM2 is not a FIPS algorithm. — /lib/apk/db/installed | |
| LOW | CVE-2026-77696 | libssl3 | 3.5.8-r0 | Issue summary: SM2 signature generation uses non-constant-time arithmetic on secret values, forming a timing side-channel. Impact summary: An attacker able to measure SM2 signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key. CWE: CWE-208: Observable Timing Discrepancy Description: SM2 signature generation computes the signature value using variable-time BIGNUM operations on the secret nonce and the private key, so the time taken to produce an SM2 signature depends on these secret values, forming a timing side-channel. Applications performing SM2 signature generation are affected on all platforms. FIPS Impact: no SM2 is not a FIPS algorithm. — /lib/apk/db/installed | |
| LOW | CVE-2026-59846 | libssh2 | 1.11.1-r3 | A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing unintended shell behavior. — /lib/apk/db/installed |
ghcr.io/voxpupuli/renovate
Downloads
ghcr.io/voxpupuli/renovate:latest (2026-10-08)
Trivy
CRITICAL 2
HIGH 9
MEDIUM 14
LOW 1
| Severity | ID | Package | Installed | Fixed | Title / target |
|---|---|---|---|---|---|
| CRITICAL | CVE-2026-106445 | handlebars | 4.7.9 | 4.7.10 | Handlebars provides the power necessary to let users build semantic te ... — Node.js |
| CRITICAL | CVE-2026-106446 | handlebars | 4.7.9 | 4.7.10 | Handlebars provides the power necessary to let users build semantic te ... — Node.js |
| HIGH | CVE-2026-102276 | brace-expansion | 5.0.7 | 5.0.10, 3.0.7, 2.1.5, 1.1.19 | brace-expansion: brace-expansion: Denial of Service via stack exhaustion from crafted brace patterns — Node.js |
| HIGH | CVE-2026-102278 | brace-expansion | 5.0.7 | 5.0.11, 3.0.8, 2.1.6, 1.1.20 | brace-expansion: brace-expansion: Denial of Service via uncontrolled recursion in nested brace patterns — Node.js |
| HIGH | CVE-2026-14257 | brace-expansion | 5.0.7 | 5.0.8, 3.0.3, 2.1.3, 1.1.17 | brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function — Node.js |
| HIGH | CVE-2026-69152 | brace-expansion | 5.0.7 | 1.1.18, 2.1.4, 3.0.6, 5.0.9 | brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation — Node.js |
| HIGH | CVE-2026-93687 | braces | 3.0.3 | braces: braces: Denial of Service via Stack Overflow from Deeply Nested Patterns — Node.js | |
| HIGH | CVE-2026-93748 | http-cache-semantics | 4.2.0 | http-cache-semantics: http-cache-semantics: Information Disclosure via max-stale directive — Node.js | |
| HIGH | CVE-2026-69192 | ip-address | 10.2.0 | 10.3.1 | ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass — Node.js |
| HIGH | CVE-2026-73566 | tar | 7.5.19 | 7.5.21 | tar: node-tar: Denial of Service via crafted long-path tar archive — Node.js |
| HIGH | CVE-2026-19534 | undici | 6.27.0 | 6.28.1, 7.29.1, 8.10.2 | undici: undici: Denial of Service via unrequested WebSocket subprotocol — Node.js |
| MEDIUM | CVE-2026-104844 | postcss-selector-parser | 7.1.4 | 7.1.6 | postcss-selector-parser: postcss-selector-parser: Denial of Service via crafted CSS selectors — Node.js |
| MEDIUM | CVE-2026-97058 | sprintf-js | 1.1.3 | sprintf-js: sprintf-js: Denial of Service via unbounded precision specifiers — Node.js | |
| MEDIUM | CVE-2026-15157 | undici | 6.27.0 | 6.28.0, 7.29.0, 8.9.0 | undici: undici: HTTP header injection via unvalidated blob-like body type property — Node.js |
| MEDIUM | CVE-2026-16728 | undici | 6.27.0 | 6.28.0, 7.29.0, 8.9.0 | undici: undici: Response desynchronization via retry interceptor with mismatched Content-Length — Node.js |
| MEDIUM | CVE-2026-16729 | undici | 6.27.0 | 6.28.0, 7.29.0, 8.9.0 | undici: Undici: Cookie attribute injection allows bypassing security protections — Node.js |
| MEDIUM | CVE-2026-85024 | undici | 6.27.0 | 6.28.1, 7.29.1, 8.10.2 | undici: undici: Denial of Service via unhandled error in WebSocket permessage-deflate decompression — Node.js |
| MEDIUM | CVE-2026-69198 | ip-address | 10.2.0 | 10.2.2 | ip-address: ip-address: Server-Side Request Forgery (SSRF) and trust-boundary bypass — Node.js |
| MEDIUM | CVE-2026-54272 | ip-address | 10.2.0 | 10.2.1 | ip-address: ip-address: Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification — Node.js |
| MEDIUM | CVE-2026-101913 | ip-address | 10.2.0 | 10.5.1 | ip-address: ip-address: Security bypass via incomplete IPv6 link-local address validation — Node.js |
| MEDIUM | CVE-2026-101912 | ip-address | 10.2.0 | 10.7.1 | ip-address: ip-address: Access control bypass via cross-family subnet comparison — Node.js |
| MEDIUM | CVE-2026-101911 | ip-address | 10.2.0 | 10.7.1 | ip-address: ip-address: Denial of Service via unbounded IPv6 address parsing — Node.js |
| MEDIUM | CVE-2026-101910 | ip-address | 10.2.0 | 10.5.1 | ip-address: ip-address: Security boundary bypass via unclassified NAT64 local-use address range — Node.js |
| MEDIUM | CVE-2026-106444 | handlebars | 4.7.9 | 4.7.10 | handlebars: Handlebars: Cross-Site Scripting via unescaped closing script tags in precompiled templates — Node.js |
| MEDIUM | CVE-2026-102277 | brace-expansion | 5.0.7 | 5.0.12, 3.0.9, 2.1.7, 1.1.21 | brace-expansion: brace-expansion: Denial of Service via crafted brace patterns — Node.js |
| LOW | CVE-2026-18540 | undici | 6.27.0 | 6.28.1, 7.29.1, 8.10.2 | undici: undici: HTTP response splitting via retry interceptor — Node.js |
Grype
HIGH 9
MEDIUM 13
LOW 1
NVD/CPE filtered 3
| Severity | ID | Package | Installed | Fixed | Title / target |
|---|---|---|---|---|---|
| HIGH | GHSA-vfj7-8cjw-p6xm | braces | 3.0.3 | braces vulnerable to stack-exhaustion denial of service through deeply nested patterns — /npm/node_modules/braces/package.json | |
| HIGH | GHSA-mwp4-54f8-5fhr | ip-address | 10.2.0 | 10.3.1 | ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass — /usr/local/lib/node_modules/npm/node_modules/ip-address/package.json |
| HIGH | GHSA-rgw5-rvv9-x895 | brace-expansion | 5.0.7 | 5.0.9 | brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation — /usr/local/lib/node_modules/npm/node_modules/brace-expansion/package.json |
| HIGH | GHSA-mh99-v99m-4gvg | brace-expansion | 5.0.7 | 5.0.8 | brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash — /usr/local/lib/node_modules/npm/node_modules/brace-expansion/package.json |
| HIGH | GHSA-ch52-4w7c-c8xp | http-cache-semantics | 4.2.0 | http-cache-semantics max-stale handling can disclose cross-user cached responses — /usr/local/lib/node_modules/npm/node_modules/http-cache-semantics/package.json | |
| HIGH | GHSA-r292-9mhp-454m | tar | 7.5.19 | 7.5.21 | node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection — /usr/local/lib/node_modules/npm/node_modules/tar/package.json |
| HIGH | GHSA-rfgv-xxqx-mfg5 | undici | 6.27.0 | 6.28.1 | undici vulnerable to Denial of Service via unrequested WebSocket subprotocol — /usr/local/lib/node_modules/npm/node_modules/undici/package.json |
| HIGH | GHSA-qhr7-859c-m2p7 | brace-expansion | 5.0.7 | 5.0.11 | brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion — /usr/local/lib/node_modules/npm/node_modules/brace-expansion/package.json |
| HIGH | GHSA-6j4f-fj2g-mc7p | brace-expansion | 5.0.7 | 5.0.10 | brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion — /usr/local/lib/node_modules/npm/node_modules/brace-expansion/package.json |
| MEDIUM | GHSA-8xcm-r25x-g524 | undici | 6.27.0 | 6.28.0 | undici vulnerable to downstream response desynchronization via retry interceptor — /usr/local/lib/node_modules/npm/node_modules/undici/package.json |
| MEDIUM | GHSA-m8rv-5g2x-5cg5 | undici | 6.27.0 | 6.28.0 | undici vulnerable to CRLF Injection via blob-like body 'type' property — /usr/local/lib/node_modules/npm/node_modules/undici/package.json |
| MEDIUM | GHSA-v3r7-h72x-cjcm | undici | 6.27.0 | 6.28.0 | undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields — /usr/local/lib/node_modules/npm/node_modules/undici/package.json |
| MEDIUM | GHSA-q2hr-2g5m-vwhr | brace-expansion | 5.0.7 | 5.0.12 | brace-expansion: Quadratic-time expansion of the `{a},b}` rewrite causes CPU denial of service — /usr/local/lib/node_modules/npm/node_modules/brace-expansion/package.json |
| MEDIUM | GHSA-h3mg-xc3c-68pw | ip-address | 10.2.0 | 10.7.1 | ip-address: Address6 builds a parse diagnostic proportional to the input with no length bound, allowing a single long string to stall or crash the process — /usr/local/lib/node_modules/npm/node_modules/ip-address/package.json |
| MEDIUM | GHSA-hp3w-g68c-fv3c | sprintf-js | 1.1.3 | sprintf-js vulnerable to denial of service through unbounded precision specifiers — /npm/node_modules/sprintf-js/package.json | |
| MEDIUM | GHSA-j6r3-76f7-8jcv | ip-address | 10.2.0 | 10.7.1 | ip-address: isInSubnet() and isHostInSubnet() compare addresses of different families as if they shared an address space, allowing an allowlist check to admit an address outside its range — /usr/local/lib/node_modules/npm/node_modules/ip-address/package.json |
| MEDIUM | GHSA-rj75-hqrm-r3gf | postcss-selector-parser | 7.1.4 | 7.1.6 | PostCSS: Quadratic complexity in flat selector parsing allows CPU exhaustion — /usr/local/lib/node_modules/npm/node_modules/postcss-selector-parser/package.json |
| MEDIUM | GHSA-rpw4-54j3-4h4q | ip-address | 10.2.0 | 10.5.1 | ip-address: Address6.isLinkLocal() recognizes fe80::/64 rather than fe80::/10, allowing SSRF and trust-boundary bypass to on-link hosts — /usr/local/lib/node_modules/npm/node_modules/ip-address/package.json |
| MEDIUM | GHSA-3wwx-pv8p-q78v | undici | 6.27.0 | 6.28.1 | undici vulnerable to Denial of Service via unhandled error in WebSocket permessage-deflate decompression — /usr/local/lib/node_modules/npm/node_modules/undici/package.json |
| MEDIUM | GHSA-2vr4-cq9g-pvrc | ip-address | 10.2.0 | 10.5.1 | ip-address: no classifier recognizes the NAT64 local-use range 64:ff9b:1::/48, allowing SSRF and trust-boundary bypass — /usr/local/lib/node_modules/npm/node_modules/ip-address/package.json |
| MEDIUM | GHSA-22jq-vg5j-6vgg | ip-address | 10.2.0 | 10.2.1 | ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSRF and trust-boundary checks — /usr/local/lib/node_modules/npm/node_modules/ip-address/package.json |
| MEDIUM | GHSA-4xrf-jv44-h6hh | ip-address | 10.2.0 | 10.2.2 | ip-address: a CIDR suffix on the parsed address suppresses special-use classification and can bypass SSRF and trust-boundary checks — /usr/local/lib/node_modules/npm/node_modules/ip-address/package.json |
| LOW | GHSA-r53p-7pc4-xj5r | undici | 6.27.0 | 6.28.1 | undici vulnerable to downstream response splitting via retry interceptor — /usr/local/lib/node_modules/npm/node_modules/undici/package.json |
Filtered NVD/CPE matches (3)
These broad CPE matches are unconfirmed for the distribution package and excluded from scanner totals.
| Severity | ID | Package | Installed | Fixed | Title / target |
|---|---|---|---|---|---|
| MEDIUM | CVE-2025-60876 | busybox | 1.37.0-r31 | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-60876 | busybox-binsh | 1.37.0-r31 | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-60876 | ssl_client | 1.37.0-r31 | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed |
ghcr.io/voxpupuli/semantic-release
Downloads
ghcr.io/voxpupuli/semantic-release:latest (2026-09-23)
Trivy
HIGH 26
MEDIUM 29
LOW 2
UNKNOWN 14
| Severity | ID | Package | Installed | Fixed | Title / target |
|---|---|---|---|---|---|
| HIGH | CVE-2026-73566 | tar | 7.5.19 | 7.5.21 | tar: node-tar: Denial of Service via crafted long-path tar archive — Node.js |
| HIGH | CVE-2026-19534 | undici | 6.27.0 | 6.28.1, 7.29.1, 8.10.2 | undici: undici: Denial of Service via unrequested WebSocket subprotocol — Node.js |
| HIGH | CVE-2026-19534 | undici | 6.28.0 | 6.28.1, 7.29.1, 8.10.2 | undici: undici: Denial of Service via unrequested WebSocket subprotocol — Node.js |
| HIGH | CVE-2026-56852 | golang.org/x/text | v0.38.0 | 0.39.0 | golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc |
| HIGH | CVE-2026-69192 | ip-address | 10.2.0 | 10.3.1 | ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass — Node.js |
| HIGH | CVE-2026-93748 | http-cache-semantics | 4.2.0 | http-cache-semantics: http-cache-semantics: Information Disclosure via max-stale directive — Node.js | |
| HIGH | CVE-2026-93748 | http-cache-semantics | 4.2.0 | http-cache-semantics: http-cache-semantics: Information Disclosure via max-stale directive — Node.js | |
| HIGH | CVE-2026-93748 | http-cache-semantics | 4.2.0 | http-cache-semantics: http-cache-semantics: Information Disclosure via max-stale directive — Node.js | |
| HIGH | CVE-2026-93687 | braces | 3.0.3 | braces: braces: Denial of Service via Stack Overflow from Deeply Nested Patterns — Node.js | |
| HIGH | CVE-2026-33818 | stdlib | v1.26.4 | 1.25.13, 1.26.6, 1.27.0-rc.3 | encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc |
| HIGH | CVE-2026-102278 | brace-expansion | 5.0.9 | 5.0.11, 3.0.8, 2.1.6, 1.1.20 | brace-expansion: brace-expansion: Denial of Service via uncontrolled recursion in nested brace patterns — Node.js |
| HIGH | CVE-2026-102276 | brace-expansion | 5.0.9 | 5.0.10, 3.0.7, 2.1.5, 1.1.19 | brace-expansion: brace-expansion: Denial of Service via stack exhaustion from crafted brace patterns — Node.js |
| HIGH | CVE-2026-39821 | stdlib | v1.26.4 | 1.25.13, 1.26.6, 1.27.0-rc.3 | golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc |
| HIGH | CVE-2026-93990 | libexpat | 2.8.4-r0 | 2.8.5-r0 | expat: Expat: XML Injection via Malformed UTF-16 Input — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.2) |
| HIGH | CVE-2026-103111 | pcre2 | 10.48-r0 | 10.49-r0 | pcre2: pcre2: Out-of-bounds write via crafted regular expression — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.2) |
| HIGH | CVE-2026-56862 | stdlib | v1.26.4 | 1.25.13, 1.26.6, 1.27.0-rc.3 | crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc |
| HIGH | CVE-2026-56860 | stdlib | v1.26.4 | 1.25.13, 1.26.6, 1.27.0-rc.3 | net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc |
| HIGH | CVE-2026-56859 | stdlib | v1.26.4 | 1.25.13, 1.26.6, 1.27.0-rc.3 | encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc |
| HIGH | CVE-2026-56858 | stdlib | v1.26.4 | 1.25.13, 1.26.6, 1.27.0-rc.3 | html/template: golang: Go html/template: Cross-Site Scripting via pathological input — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc |
| HIGH | CVE-2026-56853 | stdlib | v1.26.4 | 1.25.13, 1.26.6, 1.27.0-rc.3 | net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc |
| HIGH | CVE-2026-46600 | stdlib | v1.26.4 | 1.26.6, 1.27.0-rc.3 | golang.org/x/net/dns/dnsmessage: golang.org/x/net/dns/dnsmessage: Denial of Service via invalid DNS record parsing — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc |
| HIGH | CVE-2026-39822 | stdlib | v1.26.4 | 1.25.12, 1.26.5, 1.27.0-rc.2 | golang: Go os.Root: Symlink following vulnerability allows directory traversal — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc |
| HIGH | CVE-2026-102276 | brace-expansion | 5.0.7 | 5.0.10, 3.0.7, 2.1.5, 1.1.19 | brace-expansion: brace-expansion: Denial of Service via stack exhaustion from crafted brace patterns — Node.js |
| HIGH | CVE-2026-102278 | brace-expansion | 5.0.7 | 5.0.11, 3.0.8, 2.1.6, 1.1.20 | brace-expansion: brace-expansion: Denial of Service via uncontrolled recursion in nested brace patterns — Node.js |
| HIGH | CVE-2026-14257 | brace-expansion | 5.0.7 | 5.0.8, 3.0.3, 2.1.3, 1.1.17 | brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function — Node.js |
| HIGH | CVE-2026-69152 | brace-expansion | 5.0.7 | 1.1.18, 2.1.4, 3.0.6, 5.0.9 | brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation — Node.js |
| MEDIUM | CVE-2026-85024 | undici | 6.28.0 | 6.28.1, 7.29.1, 8.10.2 | undici: undici: Denial of Service via unhandled error in WebSocket permessage-deflate decompression — Node.js |
| MEDIUM | CVE-2026-85024 | undici | 6.27.0 | 6.28.1, 7.29.1, 8.10.2 | undici: undici: Denial of Service via unhandled error in WebSocket permessage-deflate decompression — Node.js |
| MEDIUM | CVE-2026-16729 | undici | 6.27.0 | 6.28.0, 7.29.0, 8.9.0 | undici: Undici: Cookie attribute injection allows bypassing security protections — Node.js |
| MEDIUM | CVE-2026-16728 | undici | 6.27.0 | 6.28.0, 7.29.0, 8.9.0 | undici: undici: Response desynchronization via retry interceptor with mismatched Content-Length — Node.js |
| MEDIUM | CVE-2026-15157 | undici | 6.27.0 | 6.28.0, 7.29.0, 8.9.0 | undici: undici: HTTP header injection via unvalidated blob-like body type property — Node.js |
| MEDIUM | CVE-2026-42505 | stdlib | v1.26.4 | 1.25.12, 1.26.5, 1.27.0-rc.2 | crypto/tls: golang: Go crypto/tls: Information disclosure in Encrypted Client Hello — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc |
| MEDIUM | CVE-2026-97058 | sprintf-js | 1.0.3 | sprintf-js: sprintf-js: Denial of Service via unbounded precision specifiers — Node.js | |
| MEDIUM | CVE-2026-104844 | postcss-selector-parser | 7.1.4 | 7.1.6 | postcss-selector-parser: postcss-selector-parser: Denial of Service via crafted CSS selectors — Node.js |
| MEDIUM | CVE-2026-58055 | nghttp2-libs | 1.69.0-r0 | 1.70.0-r0 | nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.2) |
| MEDIUM | CVE-2026-85091 | zlib | 1.3.2-r0 | 1.3.2-r1 | zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vul ... — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.2) |
| MEDIUM | CVE-2025-25288 | @octokit/plugin-paginate-rest | 2.21.3 | 11.4.1, 9.2.2 | octokit/plugin-paginate-rest: @octokit/plugin-paginate-rest has a Regular Expression in iterator that Leads to ReDoS Vulnerability Due to Catastrophic Backtracking — Node.js |
| MEDIUM | CVE-2025-25288 | @octokit/plugin-paginate-rest | 6.1.2 | 11.4.1, 9.2.2 | octokit/plugin-paginate-rest: @octokit/plugin-paginate-rest has a Regular Expression in iterator that Leads to ReDoS Vulnerability Due to Catastrophic Backtracking — Node.js |
| MEDIUM | CVE-2025-25290 | @octokit/request | 5.6.3 | 9.2.1, 8.4.1 | octokit/request: @octokit/request has a Regular Expression in fetchWrapper that Leads to ReDoS Vulnerability Due to Catastrophic Backtracking — Node.js |
| MEDIUM | CVE-2025-25290 | @octokit/request | 6.2.8 | 9.2.1, 8.4.1 | octokit/request: @octokit/request has a Regular Expression in fetchWrapper that Leads to ReDoS Vulnerability Due to Catastrophic Backtracking — Node.js |
| MEDIUM | CVE-2025-25289 | @octokit/request-error | 2.1.0 | 5.1.1, 6.1.7 | @octokit/request-error: @octokit/request-error has a Regular Expression in index that Leads to ReDoS Vulnerability Due to Catastrophic Backtracking — Node.js |
| MEDIUM | CVE-2025-25289 | @octokit/request-error | 3.0.3 | 5.1.1, 6.1.7 | @octokit/request-error: @octokit/request-error has a Regular Expression in index that Leads to ReDoS Vulnerability Due to Catastrophic Backtracking — Node.js |
| MEDIUM | CVE-2026-102277 | brace-expansion | 5.0.7 | 5.0.12, 3.0.9, 2.1.7, 1.1.21 | brace-expansion: brace-expansion: Denial of Service via crafted brace patterns — Node.js |
| MEDIUM | CVE-2026-102277 | brace-expansion | 5.0.9 | 5.0.12, 3.0.9, 2.1.7, 1.1.21 | brace-expansion: brace-expansion: Denial of Service via crafted brace patterns — Node.js |
| MEDIUM | CVE-2026-101910 | ip-address | 10.2.0 | 10.5.1 | ip-address: ip-address: Security boundary bypass via unclassified NAT64 local-use address range — Node.js |
| MEDIUM | CVE-2026-104844 | postcss-selector-parser | 7.1.4 | 7.1.6 | postcss-selector-parser: postcss-selector-parser: Denial of Service via crafted CSS selectors — Node.js |
| MEDIUM | CVE-2026-101911 | ip-address | 10.2.0 | 10.7.1 | ip-address: ip-address: Denial of Service via unbounded IPv6 address parsing — Node.js |
| MEDIUM | CVE-2026-101913 | ip-address | 10.5.0 | 10.5.1 | ip-address: ip-address: Security bypass via incomplete IPv6 link-local address validation — Node.js |
| MEDIUM | CVE-2026-101912 | ip-address | 10.2.0 | 10.7.1 | ip-address: ip-address: Access control bypass via cross-family subnet comparison — Node.js |
| MEDIUM | CVE-2026-101912 | ip-address | 10.5.0 | 10.7.1 | ip-address: ip-address: Access control bypass via cross-family subnet comparison — Node.js |
| MEDIUM | CVE-2026-101913 | ip-address | 10.2.0 | 10.5.1 | ip-address: ip-address: Security bypass via incomplete IPv6 link-local address validation — Node.js |
| MEDIUM | CVE-2026-54272 | ip-address | 10.2.0 | 10.2.1 | ip-address: ip-address: Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification — Node.js |
| MEDIUM | CVE-2026-69198 | ip-address | 10.2.0 | 10.2.2 | ip-address: ip-address: Server-Side Request Forgery (SSRF) and trust-boundary bypass — Node.js |
| MEDIUM | CVE-2026-101910 | ip-address | 10.5.0 | 10.5.1 | ip-address: ip-address: Security boundary bypass via unclassified NAT64 local-use address range — Node.js |
| MEDIUM | CVE-2026-101911 | ip-address | 10.5.0 | 10.7.1 | ip-address: ip-address: Denial of Service via unbounded IPv6 address parsing — Node.js |
| LOW | CVE-2026-18540 | undici | 6.27.0 | 6.28.1, 7.29.1, 8.10.2 | undici: undici: HTTP response splitting via retry interceptor — Node.js |
| LOW | CVE-2026-18540 | undici | 6.28.0 | 6.28.1, 7.29.1, 8.10.2 | undici: undici: HTTP response splitting via retry interceptor — Node.js |
| UNKNOWN | CVE-2026-97032 | stdlib | v1.26.4 | 1.26.9, 1.27.2 | HTTP/2 server crash due to HPACK encoder race in net/http — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc |
| UNKNOWN | CVE-2026-97031 | stdlib | v1.26.4 | 1.26.9, 1.27.2 | Reject malformed ECH outer extension references in crypto/tls — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc |
| UNKNOWN | CVE-2026-97030 | stdlib | v1.26.4 | 1.26.9, 1.27.2 | Recognize yield as regexp preceder keyword in html/template — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc |
| UNKNOWN | CVE-2026-94448 | stdlib | v1.26.4 | 1.26.9, 1.27.2 | Reset context tracking on consecutive template expressions in html/template — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc |
| UNKNOWN | CVE-2026-94440 | stdlib | v1.26.4 | 1.26.9, 1.27.2 | Memory limit bypass when parsing MIME headers in net/textproto, mime/multipart — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc |
| UNKNOWN | CVE-2026-94439 | stdlib | v1.26.4 | 1.26.9, 1.27.2 | HTTP/1 server connection desynchronization after 2xx CONNECT response in net/http — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc |
| UNKNOWN | CVE-2026-78669 | stdlib | v1.26.4 | 1.26.9, 1.27.2 | Excessive CPU consumption from repeated initial window changes in net/http — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc |
| UNKNOWN | CVE-2026-78667 | stdlib | v1.26.4 | 1.26.9, 1.27.2 | Lack of limit on size of parsed Range headers in net/http — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc |
| UNKNOWN | CVE-2026-78663 | stdlib | v1.26.4 | 1.26.9, 1.27.2 | Double flow control refund on HTTP/2 server streams in net/http — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc |
| UNKNOWN | CVE-2026-78660 | stdlib | v1.26.4 | 1.26.9, 1.27.2 | HTTP/2 transport accepts malformed framing-related headers in net/http — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc |
| UNKNOWN | CVE-2026-78659 | stdlib | v1.26.4 | 1.26.9, 1.27.2 | HTTP/2 server memory exhaustion due to Trailer headers in net/http — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc |
| UNKNOWN | CVE-2026-56866 | stdlib | v1.26.4 | 1.26.9, 1.27.2 | HTTP/1 client connection desynchronization after CONNECT rejection in net/http — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc |
| UNKNOWN | CVE-2026-56857 | stdlib | v1.26.4 | 1.26.9, 1.27.2 | Root.Mkdir(All) can follow junctions out of the root on Windows in os — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc |
| UNKNOWN | CVE-2026-56851 | golang.org/x/text | v0.38.0 | 0.41.0 | The Nickname profile can panic with an out-of-bounds slice error when ... — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc |
Grype
HIGH 18
MEDIUM 27
LOW 2
NVD/CPE filtered 29
| Severity | ID | Package | Installed | Fixed | Title / target |
|---|---|---|---|---|---|
| HIGH | CVE-2026-103111 | pcre2 | 10.48-r0 | 10.49-r0 | /lib/apk/db/installed |
| HIGH | GHSA-6j4f-fj2g-mc7p | brace-expansion | 5.0.9 | 5.0.10 | brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion — /npm/node_modules/npm/node_modules/brace-expansion/package.json |
| HIGH | GHSA-6j4f-fj2g-mc7p | brace-expansion | 5.0.7 | 5.0.10 | brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion — /usr/local/lib/node_modules/npm/node_modules/brace-expansion/package.json |
| HIGH | GHSA-qhr7-859c-m2p7 | brace-expansion | 5.0.9 | 5.0.11 | brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion — /npm/node_modules/npm/node_modules/brace-expansion/package.json |
| HIGH | GHSA-qhr7-859c-m2p7 | brace-expansion | 5.0.7 | 5.0.11 | brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion — /usr/local/lib/node_modules/npm/node_modules/brace-expansion/package.json |
| HIGH | GHSA-rfgv-xxqx-mfg5 | undici | 6.28.0 | 6.28.1 | undici vulnerable to Denial of Service via unrequested WebSocket subprotocol — /npm/node_modules/npm/node_modules/undici/package.json |
| HIGH | GHSA-rfgv-xxqx-mfg5 | undici | 6.27.0 | 6.28.1 | undici vulnerable to Denial of Service via unrequested WebSocket subprotocol — /usr/local/lib/node_modules/npm/node_modules/undici/package.json |
| HIGH | CVE-2026-93990 | libexpat | 2.8.4-r0 | 2.8.5-r0 | /lib/apk/db/installed |
| HIGH | GO-2026-5970 | golang.org/x/text | v0.38.0 | 0.39.0 | A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes. — /npm/node_modules/@typescript/typescript-linux-x64/lib/tsc |
| HIGH | GHSA-r292-9mhp-454m | tar | 7.5.19 | 7.5.21 | node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection — /usr/local/lib/node_modules/npm/node_modules/tar/package.json |
| HIGH | GHSA-ch52-4w7c-c8xp | http-cache-semantics | 4.2.0 | http-cache-semantics max-stale handling can disclose cross-user cached responses — /usr/local/lib/node_modules/npm/node_modules/http-cache-semantics/package.json | |
| HIGH | GHSA-vfj7-8cjw-p6xm | braces | 3.0.3 | braces vulnerable to stack-exhaustion denial of service through deeply nested patterns — /npm/node_modules/braces/package.json | |
| HIGH | GHSA-ch52-4w7c-c8xp | http-cache-semantics | 4.2.0 | http-cache-semantics max-stale handling can disclose cross-user cached responses — /npm/node_modules/npm/node_modules/http-cache-semantics/package.json | |
| HIGH | GHSA-ch52-4w7c-c8xp | http-cache-semantics | 4.2.0 | http-cache-semantics max-stale handling can disclose cross-user cached responses — /npm/node_modules/http-cache-semantics/package.json | |
| HIGH | CVE-2026-85091 | zlib | 1.3.2-r0 | 1.3.2-r1 | /lib/apk/db/installed |
| HIGH | GHSA-mh99-v99m-4gvg | brace-expansion | 5.0.7 | 5.0.8 | brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash — /usr/local/lib/node_modules/npm/node_modules/brace-expansion/package.json |
| HIGH | GHSA-rgw5-rvv9-x895 | brace-expansion | 5.0.7 | 5.0.9 | brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation — /usr/local/lib/node_modules/npm/node_modules/brace-expansion/package.json |
| HIGH | GHSA-mwp4-54f8-5fhr | ip-address | 10.2.0 | 10.3.1 | ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass — /usr/local/lib/node_modules/npm/node_modules/ip-address/package.json |
| MEDIUM | GHSA-rj75-hqrm-r3gf | postcss-selector-parser | 7.1.4 | 7.1.6 | PostCSS: Quadratic complexity in flat selector parsing allows CPU exhaustion — /usr/local/lib/node_modules/npm/node_modules/postcss-selector-parser/package.json |
| MEDIUM | GHSA-rj75-hqrm-r3gf | postcss-selector-parser | 7.1.4 | 7.1.6 | PostCSS: Quadratic complexity in flat selector parsing allows CPU exhaustion — /npm/node_modules/npm/node_modules/postcss-selector-parser/package.json |
| MEDIUM | GHSA-j6r3-76f7-8jcv | ip-address | 10.2.0 | 10.7.1 | ip-address: isInSubnet() and isHostInSubnet() compare addresses of different families as if they shared an address space, allowing an allowlist check to admit an address outside its range — /usr/local/lib/node_modules/npm/node_modules/ip-address/package.json |
| MEDIUM | GHSA-j6r3-76f7-8jcv | ip-address | 10.5.0 | 10.7.1 | ip-address: isInSubnet() and isHostInSubnet() compare addresses of different families as if they shared an address space, allowing an allowlist check to admit an address outside its range — /npm/node_modules/npm/node_modules/ip-address/package.json |
| MEDIUM | GHSA-hp3w-g68c-fv3c | sprintf-js | 1.0.3 | sprintf-js vulnerable to denial of service through unbounded precision specifiers — /npm/node_modules/sprintf-js/package.json | |
| MEDIUM | CVE-2026-58055 | nghttp2-libs | 1.69.0-r0 | 1.70.0-r0 | /lib/apk/db/installed |
| MEDIUM | GHSA-h3mg-xc3c-68pw | ip-address | 10.2.0 | 10.7.1 | ip-address: Address6 builds a parse diagnostic proportional to the input with no length bound, allowing a single long string to stall or crash the process — /usr/local/lib/node_modules/npm/node_modules/ip-address/package.json |
| MEDIUM | GHSA-h3mg-xc3c-68pw | ip-address | 10.5.0 | 10.7.1 | ip-address: Address6 builds a parse diagnostic proportional to the input with no length bound, allowing a single long string to stall or crash the process — /npm/node_modules/npm/node_modules/ip-address/package.json |
| MEDIUM | GHSA-q2hr-2g5m-vwhr | brace-expansion | 5.0.7 | 5.0.12 | brace-expansion: Quadratic-time expansion of the `{a},b}` rewrite causes CPU denial of service — /usr/local/lib/node_modules/npm/node_modules/brace-expansion/package.json |
| MEDIUM | GHSA-q2hr-2g5m-vwhr | brace-expansion | 5.0.9 | 5.0.12 | brace-expansion: Quadratic-time expansion of the `{a},b}` rewrite causes CPU denial of service — /npm/node_modules/npm/node_modules/brace-expansion/package.json |
| MEDIUM | GHSA-v3r7-h72x-cjcm | undici | 6.27.0 | 6.28.0 | undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields — /usr/local/lib/node_modules/npm/node_modules/undici/package.json |
| MEDIUM | GHSA-m8rv-5g2x-5cg5 | undici | 6.27.0 | 6.28.0 | undici vulnerable to CRLF Injection via blob-like body 'type' property — /usr/local/lib/node_modules/npm/node_modules/undici/package.json |
| MEDIUM | GHSA-8xcm-r25x-g524 | undici | 6.27.0 | 6.28.0 | undici vulnerable to downstream response desynchronization via retry interceptor — /usr/local/lib/node_modules/npm/node_modules/undici/package.json |
| MEDIUM | GHSA-rpw4-54j3-4h4q | ip-address | 10.5.0 | 10.5.1 | ip-address: Address6.isLinkLocal() recognizes fe80::/64 rather than fe80::/10, allowing SSRF and trust-boundary bypass to on-link hosts — /npm/node_modules/npm/node_modules/ip-address/package.json |
| MEDIUM | GHSA-rpw4-54j3-4h4q | ip-address | 10.2.0 | 10.5.1 | ip-address: Address6.isLinkLocal() recognizes fe80::/64 rather than fe80::/10, allowing SSRF and trust-boundary bypass to on-link hosts — /usr/local/lib/node_modules/npm/node_modules/ip-address/package.json |
| MEDIUM | GHSA-3wwx-pv8p-q78v | undici | 6.28.0 | 6.28.1 | undici vulnerable to Denial of Service via unhandled error in WebSocket permessage-deflate decompression — /npm/node_modules/npm/node_modules/undici/package.json |
| MEDIUM | GHSA-3wwx-pv8p-q78v | undici | 6.27.0 | 6.28.1 | undici vulnerable to Denial of Service via unhandled error in WebSocket permessage-deflate decompression — /usr/local/lib/node_modules/npm/node_modules/undici/package.json |
| MEDIUM | GHSA-2vr4-cq9g-pvrc | ip-address | 10.5.0 | 10.5.1 | ip-address: no classifier recognizes the NAT64 local-use range 64:ff9b:1::/48, allowing SSRF and trust-boundary bypass — /npm/node_modules/npm/node_modules/ip-address/package.json |
| MEDIUM | GHSA-2vr4-cq9g-pvrc | ip-address | 10.2.0 | 10.5.1 | ip-address: no classifier recognizes the NAT64 local-use range 64:ff9b:1::/48, allowing SSRF and trust-boundary bypass — /usr/local/lib/node_modules/npm/node_modules/ip-address/package.json |
| MEDIUM | GHSA-22jq-vg5j-6vgg | ip-address | 10.2.0 | 10.2.1 | ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSRF and trust-boundary checks — /usr/local/lib/node_modules/npm/node_modules/ip-address/package.json |
| MEDIUM | GHSA-4xrf-jv44-h6hh | ip-address | 10.2.0 | 10.2.2 | ip-address: a CIDR suffix on the parsed address suppresses special-use classification and can bypass SSRF and trust-boundary checks — /usr/local/lib/node_modules/npm/node_modules/ip-address/package.json |
| MEDIUM | GHSA-xx4v-prfh-6cgc | @octokit/request-error | 3.0.3 | 5.1.1 | @octokit/request-error has a Regular Expression in index that Leads to ReDoS Vulnerability Due to Catastrophic Backtracking — /npm/node_modules/semantic-release-github-pullrequest/node_modules/@octokit/request-error/package.json |
| MEDIUM | GHSA-xx4v-prfh-6cgc | @octokit/request-error | 2.1.0 | 5.1.1 | @octokit/request-error has a Regular Expression in index that Leads to ReDoS Vulnerability Due to Catastrophic Backtracking — /npm/node_modules/@octokit/rest/node_modules/@octokit/request-error/package.json |
| MEDIUM | GHSA-h5c3-5r3r-rr8q | @octokit/plugin-paginate-rest | 6.1.2 | 9.2.2 | @octokit/plugin-paginate-rest has a Regular Expression in iterator Leads to ReDoS Vulnerability Due to Catastrophic Backtracking — /npm/node_modules/semantic-release-github-pullrequest/node_modules/@octokit/plugin-paginate-rest/package.json |
| MEDIUM | GHSA-h5c3-5r3r-rr8q | @octokit/plugin-paginate-rest | 2.21.3 | 9.2.2 | @octokit/plugin-paginate-rest has a Regular Expression in iterator Leads to ReDoS Vulnerability Due to Catastrophic Backtracking — /npm/node_modules/@octokit/rest/node_modules/@octokit/plugin-paginate-rest/package.json |
| MEDIUM | GHSA-rmvr-2pp2-xj38 | @octokit/request | 5.6.3 | 8.4.1 | @octokit/request has a Regular Expression in fetchWrapper that Leads to ReDoS Vulnerability Due to Catastrophic Backtracking — /npm/node_modules/@octokit/rest/node_modules/@octokit/request/package.json |
| MEDIUM | GHSA-rmvr-2pp2-xj38 | @octokit/request | 6.2.8 | 8.4.1 | @octokit/request has a Regular Expression in fetchWrapper that Leads to ReDoS Vulnerability Due to Catastrophic Backtracking — /npm/node_modules/semantic-release-github-pullrequest/node_modules/@octokit/request/package.json |
| LOW | GHSA-r53p-7pc4-xj5r | undici | 6.27.0 | 6.28.1 | undici vulnerable to downstream response splitting via retry interceptor — /usr/local/lib/node_modules/npm/node_modules/undici/package.json |
| LOW | GHSA-r53p-7pc4-xj5r | undici | 6.28.0 | 6.28.1 | undici vulnerable to downstream response splitting via retry interceptor — /npm/node_modules/npm/node_modules/undici/package.json |
Filtered NVD/CPE matches (29)
These broad CPE matches are unconfirmed for the distribution package and excluded from scanner totals.
| Severity | ID | Package | Installed | Fixed | Title / target |
|---|---|---|---|---|---|
| HIGH | CVE-2026-54873 | libcrypto3 | 3.5.8-r0 | Issue summary: QUIC process may keep memory for QUIC packet buffer for much longer period than necessary. Impact summary: Remote peer can exploit this vulnerability by sending maliciously crafted packets, making the local QUIC stack to keep the memory for packet buffers allocated. The time for which the memory remains allocated is entirely under the control of the potentially malicious remote peer. CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: To save copy operation from the packet buffer to the stream reassemble buffer the QUIC stack leaves the stream data on the packet buffer waiting to be copied to a buffer provided by the local receiving application. The QUIC stack releases a reference to the packet buffer only after the data are copied to the application buffer. This design is more efficient for legitimate data transfers but enables an attacker to allocate a lot more memory than actually required by the data kept in the receiving stream buffer. To mitigate the vulnerability, the QUIC stack now calculates and monitors memory overhead for every stream. The memory overhead for a single stream frame is calculated as a difference between the size of the whole packet that carries the stream frame and the size of the stream frame itself. The memory overhead for a single stream frame is added to the total (cumulative) memory overhead QUIC stack keeps for each stream. Once the cumulative memory overhead exceeds 64kB, the QUIC stack moves the stream frame data from the packet buffer to the stream buffer, starting with the next packet received. FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| HIGH | CVE-2026-54873 | libssl3 | 3.5.8-r0 | Issue summary: QUIC process may keep memory for QUIC packet buffer for much longer period than necessary. Impact summary: Remote peer can exploit this vulnerability by sending maliciously crafted packets, making the local QUIC stack to keep the memory for packet buffers allocated. The time for which the memory remains allocated is entirely under the control of the potentially malicious remote peer. CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: To save copy operation from the packet buffer to the stream reassemble buffer the QUIC stack leaves the stream data on the packet buffer waiting to be copied to a buffer provided by the local receiving application. The QUIC stack releases a reference to the packet buffer only after the data are copied to the application buffer. This design is more efficient for legitimate data transfers but enables an attacker to allocate a lot more memory than actually required by the data kept in the receiving stream buffer. To mitigate the vulnerability, the QUIC stack now calculates and monitors memory overhead for every stream. The memory overhead for a single stream frame is calculated as a difference between the size of the whole packet that carries the stream frame and the size of the stream frame itself. The memory overhead for a single stream frame is added to the total (cumulative) memory overhead QUIC stack keeps for each stream. Once the cumulative memory overhead exceeds 64kB, the QUIC stack moves the stream frame data from the packet buffer to the stream buffer, starting with the next packet received. FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| HIGH | CVE-2026-84782 | libcrypto3 | 3.5.8-r0 | Issue summary: The DTLS retransmission logic does not correctly handle a handshake message write that is suspended part-way through. The retransmitted message can be read past the message buffer and the retransmission overwrites the internal state the suspended write needs to resume correctly. Impact summary: The retransmitted message can disclose a heap memory to the peer as plaintext handshake data or cause a crash and a Denial of Service when the read reaches an unmapped memory region. CWE: CWE-125: Out-of-bounds Read Description: DTLS handshake messages can be written out in multiple fragments, and a write can suspend mid-message (returning WANT_WRITE) if the underlying transport temporarily cannot accept more data. While such a write is suspended, the DTLS retransmission timer may independently fire and ask the retransmission logic to resend an earlier, already-acknowledged-as-sent message from its retransmit queue. The retransmission logic reused the same internal buffer and position tracking as the message that was still being written, without resetting the position back to the start of the message being retransmitted. As a result the retransmission was read starting from wherever the suspended write had left off, producing a mislabelled message whose body was leftover bytes from the other, larger message still in flight - content that was never meant to be sent at that point, and which could run past the end of the allocated buffer. Separately, even when the retransmission is positioned correctly, allowing it to run to completion while another write is suspended overwrites the same shared bookkeeping that the suspended write depends on to resume. When the application later resumes the suspended write (via a subsequent SSL_read(), SSL_write(), SSL_accept(), or SSL_connect() call), it finds that bookkeeping in a state inconsistent with the message and aborts the process in a debugging build. The fix resets the retransmission's read position to the start of the message before resending, and skips retransmission entirely whenever a handshake write is still suspended, deferring to the next call that resumes it instead. FIPS impact: no The affected code is outside the FIPS module boundary. — /lib/apk/db/installed | |
| HIGH | CVE-2026-84782 | libssl3 | 3.5.8-r0 | Issue summary: The DTLS retransmission logic does not correctly handle a handshake message write that is suspended part-way through. The retransmitted message can be read past the message buffer and the retransmission overwrites the internal state the suspended write needs to resume correctly. Impact summary: The retransmitted message can disclose a heap memory to the peer as plaintext handshake data or cause a crash and a Denial of Service when the read reaches an unmapped memory region. CWE: CWE-125: Out-of-bounds Read Description: DTLS handshake messages can be written out in multiple fragments, and a write can suspend mid-message (returning WANT_WRITE) if the underlying transport temporarily cannot accept more data. While such a write is suspended, the DTLS retransmission timer may independently fire and ask the retransmission logic to resend an earlier, already-acknowledged-as-sent message from its retransmit queue. The retransmission logic reused the same internal buffer and position tracking as the message that was still being written, without resetting the position back to the start of the message being retransmitted. As a result the retransmission was read starting from wherever the suspended write had left off, producing a mislabelled message whose body was leftover bytes from the other, larger message still in flight - content that was never meant to be sent at that point, and which could run past the end of the allocated buffer. Separately, even when the retransmission is positioned correctly, allowing it to run to completion while another write is suspended overwrites the same shared bookkeeping that the suspended write depends on to resume. When the application later resumes the suspended write (via a subsequent SSL_read(), SSL_write(), SSL_accept(), or SSL_connect() call), it finds that bookkeeping in a state inconsistent with the message and aborts the process in a debugging build. The fix resets the retransmission's read position to the start of the message before resending, and skips retransmission entirely whenever a handshake write is still suspended, deferring to the next call that resumes it instead. FIPS impact: no The affected code is outside the FIPS module boundary. — /lib/apk/db/installed | |
| HIGH | CVE-2026-84784 | libcrypto3 | 3.5.8-r0 | Issue summary: A malicious remote peer may flood the local QUIC stack with NEW_CONNECTION_ID frames by avoiding a limit check on how many connection IDs the remote QUIC stack can use. Impact summary: The local QUIC stack sends a RETIRE_CONN_ID frame for every NEW_CONNECTION_ID frame it receives. The RETIRE_CONN_ID frame is dispatched via the Control Frame Queue (CFQ). If the remote peer also withholds ACKs, then it can force the local stack to allocate ~400MB (depending on ACK delay). CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: RFC 9000 sections 5.1.1 and 5.1.2 [1] describe the mechanism by which a remote peer can notify the local QUIC stack to change the destination connection ID (a.k.a. CID) the local stack uses to identify the connection at the remote peer. Each CID is associated with a sequence number. The sequence number is transmitted in NEW_CONNECTION_ID and RETIRE_CONNECTION_ID frames to identify the CID which is being either associated with a connection or retired. The remote peer sends a NEW_CONNECTION_ID frame to let the local stack know a new CID is being associated with an existing connection. The NEW_CONNECTION_ID frame carries the new CID, its sequence number, and the retire-prior-to number. The retire-prior-to identifies existing CIDs that are to be retired. The local QUIC stack must send a RETIRE_CONNECTION_ID for every destination CID whose sequence number is less than retire-prior-to. The CID becomes retired after the local stack receives an ACK for its RETIRE_CONNECTION_ID frame. Although the OpenSSL QUIC stack supports at most one destination CID for every connection, it can be tricked into processing more than one RETIRE_CONNECTION_ID frame per connection. The OpenSSL QUIC stack currently retires the destination CID as soon as it receives the NEW_CONNECTION_ID, while in fact the destination CID must be retired after an ACK for the RETIRE_CONNECTION_ID frame is received. Correcting the flawed logic also fixes the backlog growth. [1] https://datatracker.ietf.org/doc/html/rfc9000#name-issuing-connection-ids FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| HIGH | CVE-2026-84784 | libssl3 | 3.5.8-r0 | Issue summary: A malicious remote peer may flood the local QUIC stack with NEW_CONNECTION_ID frames by avoiding a limit check on how many connection IDs the remote QUIC stack can use. Impact summary: The local QUIC stack sends a RETIRE_CONN_ID frame for every NEW_CONNECTION_ID frame it receives. The RETIRE_CONN_ID frame is dispatched via the Control Frame Queue (CFQ). If the remote peer also withholds ACKs, then it can force the local stack to allocate ~400MB (depending on ACK delay). CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: RFC 9000 sections 5.1.1 and 5.1.2 [1] describe the mechanism by which a remote peer can notify the local QUIC stack to change the destination connection ID (a.k.a. CID) the local stack uses to identify the connection at the remote peer. Each CID is associated with a sequence number. The sequence number is transmitted in NEW_CONNECTION_ID and RETIRE_CONNECTION_ID frames to identify the CID which is being either associated with a connection or retired. The remote peer sends a NEW_CONNECTION_ID frame to let the local stack know a new CID is being associated with an existing connection. The NEW_CONNECTION_ID frame carries the new CID, its sequence number, and the retire-prior-to number. The retire-prior-to identifies existing CIDs that are to be retired. The local QUIC stack must send a RETIRE_CONNECTION_ID for every destination CID whose sequence number is less than retire-prior-to. The CID becomes retired after the local stack receives an ACK for its RETIRE_CONNECTION_ID frame. Although the OpenSSL QUIC stack supports at most one destination CID for every connection, it can be tricked into processing more than one RETIRE_CONNECTION_ID frame per connection. The OpenSSL QUIC stack currently retires the destination CID as soon as it receives the NEW_CONNECTION_ID, while in fact the destination CID must be retired after an ACK for the RETIRE_CONNECTION_ID frame is received. Correcting the flawed logic also fixes the backlog growth. [1] https://datatracker.ietf.org/doc/html/rfc9000#name-issuing-connection-ids FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| HIGH | CVE-2026-72897 | libcrypto3 | 3.5.8-r0 | Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a connection to a different SSL_CTX part way through a handshake may access memory beyond the end of an internal array if the replacement context knows about more provider signature algorithms than the context the connection was created from. Applications which never call SSL_set_SSL_CTX() are not affected. Impact summary: A remote peer may be able to cause a small out-of-bounds read, and in some circumstances a fixed-value out-of-bounds write, on the server heap. This may lead to a Denial of Service. CWE: CWE-787: Out-of-bounds Write Description: A TLS connection records how many certificate slots it has when it is created, taken from the SSL_CTX that created it: the built-in certificate types plus one slot for each provider TLS-SIGALG entry that context was aware of. That count sizes an internal array of per-slot certificate validity flags. An application may replace a connection's SSL_CTX part way through the handshake by calling SSL_set_SSL_CTX(), most commonly from a servername callback in order to serve a different virtual host. Doing so did not refresh the recorded count. A provider signature algorithm's slot index is its position in the list of whichever context resolves it, so if the replacement context is aware of more of them than the original, an algorithm offered by the peer can resolve to an index beyond the end of the array. Processing the peer's signature algorithms then reads one four byte word past the end for each such algorithm and, where the word read is zero, writes a fixed value over it. A peer offering many of them can corrupt heap metadata and abort the process. Only provider signature algorithms which occupy one of the excess slots, and which the server also has configured, have this effect. Codepoints the replacement context does not recognise are discarded without being resolved to a slot, and provider signature algorithms are usable only from TLS 1.3. The two contexts must therefore be aware of different numbers of provider signature algorithms, which requires separate library contexts, a provider loaded between the two being created, or providers which differ in what they advertise - in 4.0, for example, the default provider advertises SM2 where the FIPS provider does not. A deployment meeting the condition is also unable to negotiate the affected algorithms with legitimate clients, since the same stale count hides the corresponding certificates, so the misconfiguration is likely to be noticed. For that reason, and because the configuration is not the default, this issue has been assessed as Low severity. FIPS impact: no No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| HIGH | CVE-2026-72897 | libssl3 | 3.5.8-r0 | Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a connection to a different SSL_CTX part way through a handshake may access memory beyond the end of an internal array if the replacement context knows about more provider signature algorithms than the context the connection was created from. Applications which never call SSL_set_SSL_CTX() are not affected. Impact summary: A remote peer may be able to cause a small out-of-bounds read, and in some circumstances a fixed-value out-of-bounds write, on the server heap. This may lead to a Denial of Service. CWE: CWE-787: Out-of-bounds Write Description: A TLS connection records how many certificate slots it has when it is created, taken from the SSL_CTX that created it: the built-in certificate types plus one slot for each provider TLS-SIGALG entry that context was aware of. That count sizes an internal array of per-slot certificate validity flags. An application may replace a connection's SSL_CTX part way through the handshake by calling SSL_set_SSL_CTX(), most commonly from a servername callback in order to serve a different virtual host. Doing so did not refresh the recorded count. A provider signature algorithm's slot index is its position in the list of whichever context resolves it, so if the replacement context is aware of more of them than the original, an algorithm offered by the peer can resolve to an index beyond the end of the array. Processing the peer's signature algorithms then reads one four byte word past the end for each such algorithm and, where the word read is zero, writes a fixed value over it. A peer offering many of them can corrupt heap metadata and abort the process. Only provider signature algorithms which occupy one of the excess slots, and which the server also has configured, have this effect. Codepoints the replacement context does not recognise are discarded without being resolved to a slot, and provider signature algorithms are usable only from TLS 1.3. The two contexts must therefore be aware of different numbers of provider signature algorithms, which requires separate library contexts, a provider loaded between the two being created, or providers which differ in what they advertise - in 4.0, for example, the default provider advertises SM2 where the FIPS provider does not. A deployment meeting the condition is also unable to negotiate the affected algorithms with legitimate clients, since the same stale count hides the corresponding certificates, so the misconfiguration is likely to be noticed. For that reason, and because the configuration is not the default, this issue has been assessed as Low severity. FIPS impact: no No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-75805 | libssl3 | 3.5.8-r0 | Issue summary: A CMP client that requests certificate revocation on the basis of a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when processing a crafted revocation response. Impact summary: The NULL pointer dereference happens on a read which leads to a crash and a Denial of Service for the affected client application. CWE: CWE-476: NULL-pointer dereference Description: A CMP client revoking a certificate has to tell the server which certificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the certificate itself or its issuer name and serial number. This is 'openssl cmp -cmd rr -csr <file>' on the command line, or OSSL_CMP_exec_RR_ses() with the certificate supplied via OSSL_CMP_CTX_set1_p10CSR() through the API. A CSR does not contain the issuer name and serial number of the certificate, so the client does not send them. A server may optionally name the certificate it revoked in its response, and the client then compares that name against what it sent. Having sent neither an issuer name nor a serial number, it has nothing to compare against, and a server returning a specially crafted name causes the client to read from a NULL pointer and crash. The revocation response is checked for valid message protection before the affected code is reached, so an attacker must be a malicious or compromised CMP server, or a man-in-the-middle in possession of the secret used for message protection. Clients that identify the certificate to be revoked by a certificate or by issuer and serial number rather than by a PKCS#10 CSR are not affected. FIPS impact: no No FIPS modules are affected by this issue, as the CMP protocol implementation is outside the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-75805 | libcrypto3 | 3.5.8-r0 | Issue summary: A CMP client that requests certificate revocation on the basis of a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when processing a crafted revocation response. Impact summary: The NULL pointer dereference happens on a read which leads to a crash and a Denial of Service for the affected client application. CWE: CWE-476: NULL-pointer dereference Description: A CMP client revoking a certificate has to tell the server which certificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the certificate itself or its issuer name and serial number. This is 'openssl cmp -cmd rr -csr <file>' on the command line, or OSSL_CMP_exec_RR_ses() with the certificate supplied via OSSL_CMP_CTX_set1_p10CSR() through the API. A CSR does not contain the issuer name and serial number of the certificate, so the client does not send them. A server may optionally name the certificate it revoked in its response, and the client then compares that name against what it sent. Having sent neither an issuer name nor a serial number, it has nothing to compare against, and a server returning a specially crafted name causes the client to read from a NULL pointer and crash. The revocation response is checked for valid message protection before the affected code is reached, so an attacker must be a malicious or compromised CMP server, or a man-in-the-middle in possession of the secret used for message protection. Clients that identify the certificate to be revoked by a certificate or by issuer and serial number rather than by a PKCS#10 CSR are not affected. FIPS impact: no No FIPS modules are affected by this issue, as the CMP protocol implementation is outside the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-35189 | libssl3 | 3.5.8-r0 | Issue summary: A certificate with many nameRelativeToCRLIssuer CRL distribution points causes disproportionate heap growth when OpenSSL caches X.509 extensions. Impact summary: Receiving a crafted certificate from a malicious peer can lead to significant memory pressure and possible Denial of Service in clients or in servers that solicit client certificates. CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: A certificate or a set of certificates that fits under the limit for size of certificates accepted from the peer (~100 KiB) can result in allocation of several hundred MiB of resident memory on the receiving side during a normal TLS handshake. This may be enough to crash the client or server, if multiple concurrent connections lead to similarly large memory allocations. The fix postpones processing of the CRL distribution points extensions in certificates to the time when the processed value is required for CRL processing. This avoids keeping large memory allocations for a long time when such certificates are received. FIPS impact: no The affected code is outside the FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-35189 | libcrypto3 | 3.5.8-r0 | Issue summary: A certificate with many nameRelativeToCRLIssuer CRL distribution points causes disproportionate heap growth when OpenSSL caches X.509 extensions. Impact summary: Receiving a crafted certificate from a malicious peer can lead to significant memory pressure and possible Denial of Service in clients or in servers that solicit client certificates. CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: A certificate or a set of certificates that fits under the limit for size of certificates accepted from the peer (~100 KiB) can result in allocation of several hundred MiB of resident memory on the receiving side during a normal TLS handshake. This may be enough to crash the client or server, if multiple concurrent connections lead to similarly large memory allocations. The fix postpones processing of the CRL distribution points extensions in certificates to the time when the processed value is required for CRL processing. This avoids keeping large memory allocations for a long time when such certificates are received. FIPS impact: no The affected code is outside the FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-60876 | ssl_client | 1.37.0-r31 | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-60876 | busybox-binsh | 1.37.0-r31 | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-60876 | busybox | 1.37.0-r31 | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-42772 | libssl3 | 3.5.8-r0 | Issue summary: The QUIC stream reassembly algorithm performance deteriorates progressively as packets are arriving out of order. The worst case has a quadratic complexity proportional to the number of stream frames kept in the buffer for the received stream data. Impact summary: A remote QUIC peer that completes the handshake can create a connection-scoped CPU pressure and potentially a Denial of Service using compliant STREAM frames inside the advertised receive window, with low attacker bandwidth. CWE: CWE-407: Inefficient Algorithmic Complexity Description: OpenSSL manages received QUIC stream fragments using a doubly-linked list. While it optimizes for append operations (at the end of the list), it falls back to a head-to-tail linear search for any fragment that does not immediately follow the current `tail`. By manipulating the sequence of offsets, an attacker can force the server to perform O(n^2) operations, consuming excessive CPU time for the QUIC process. FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-42772 | libcrypto3 | 3.5.8-r0 | Issue summary: The QUIC stream reassembly algorithm performance deteriorates progressively as packets are arriving out of order. The worst case has a quadratic complexity proportional to the number of stream frames kept in the buffer for the received stream data. Impact summary: A remote QUIC peer that completes the handshake can create a connection-scoped CPU pressure and potentially a Denial of Service using compliant STREAM frames inside the advertised receive window, with low attacker bandwidth. CWE: CWE-407: Inefficient Algorithmic Complexity Description: OpenSSL manages received QUIC stream fragments using a doubly-linked list. While it optimizes for append operations (at the end of the list), it falls back to a head-to-tail linear search for any fragment that does not immediately follow the current `tail`. By manipulating the sequence of offsets, an attacker can force the server to perform O(n^2) operations, consuming excessive CPU time for the QUIC process. FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-75804 | libssl3 | 3.5.8-r0 | Issue summary: OpenSSL QUIC stack does not enforce connection level flow control for streams. Remote peers may send more bytes as long as they fit within the stream flow control limits. Impact summary: A malicious remote peer may exploit the lack of connection flow control for streams to make the QUIC stack receive ~100MB of memory instead of 768 KiB (default flow control window size). CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: The local QUIC stack advertises two flow control limits to its remote peer: stream flow control limit and connection flow control limit. The remote peer must follow both limits when transmitting stream data. Whenever the local QUIC stack receives a stream frame, it validates that the size of the received stream frame stays within flow control limits. If either limit is exceeded (stream level or connection level), then the QUIC stack must close the connection with a flow control error. The vulnerable OpenSSL QUIC stack enforces the stream-level but not the connection-level limit. To exploit the issue, three conditions must be met: - the remote peer opens several streams - each stream must stay within the stream-level flow control limit - there must be no zero-offset byte sent on any of the streams (to prevent the vulnerable QUIC stack from consuming data). By meeting the conditions above, the remote peer may make the local stack allocate 2 x MAX_STREAMS x (stream flow control limit) bytes of memory. MAX_STREAMS defaults to 100, and the limit applies to both bidirectional and unidirectional streams, making it 200 in total. The default flow control window for a stream is 512kB. The remote peer may force the vulnerable QUIC stack to allocate 100MB of heap per connection. FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-75804 | libcrypto3 | 3.5.8-r0 | Issue summary: OpenSSL QUIC stack does not enforce connection level flow control for streams. Remote peers may send more bytes as long as they fit within the stream flow control limits. Impact summary: A malicious remote peer may exploit the lack of connection flow control for streams to make the QUIC stack receive ~100MB of memory instead of 768 KiB (default flow control window size). CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: The local QUIC stack advertises two flow control limits to its remote peer: stream flow control limit and connection flow control limit. The remote peer must follow both limits when transmitting stream data. Whenever the local QUIC stack receives a stream frame, it validates that the size of the received stream frame stays within flow control limits. If either limit is exceeded (stream level or connection level), then the QUIC stack must close the connection with a flow control error. The vulnerable OpenSSL QUIC stack enforces the stream-level but not the connection-level limit. To exploit the issue, three conditions must be met: - the remote peer opens several streams - each stream must stay within the stream-level flow control limit - there must be no zero-offset byte sent on any of the streams (to prevent the vulnerable QUIC stack from consuming data). By meeting the conditions above, the remote peer may make the local stack allocate 2 x MAX_STREAMS x (stream flow control limit) bytes of memory. MAX_STREAMS defaults to 100, and the limit applies to both bidirectional and unidirectional streams, making it 200 in total. The default flow control window for a stream is 512kB. The remote peer may force the vulnerable QUIC stack to allocate 100MB of heap per connection. FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-75806 | libssl3 | 3.5.8-r0 | Issue summary: An established DTLS 1.2 association using an AEAD cipher suite can be terminated by a single unauthenticated datagram whose encrypted fragment is shorter than the mandatory explicit IV and authentication tag overhead. Impact summary: An attacker who can send a datagram that is routed to an existing DTLS 1.2 association can tear that association down without knowing any key material. This is a Denial of Service limited to the targeted association. There is no memory safety or confidentiality impact. CWE: CWE-1284: Improper Validation of Specified Quantity in Input Description: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher suite carries an explicit IV followed by the ciphertext and an authentication tag. When decrypting such a record the record layer passed the record length to the cipher implementation before checking that the record was long enough to contain the explicit IV and the tag. For a record shorter than that overhead the cipher implementation rejected the impossible length, and the record layer treated this as an internal failure and raised a fatal internal_error alert instead of treating the record as one that failed authentication. In TLS 1.2 the same record causes a fatal internal_error alert instead of the expected bad_record_mac alert. Since any undecryptable record already terminates a TLS connection, this is a protocol conformance issue rather than a security issue in TLS. The fix validates the record length against the explicit IV and tag length before any AEAD processing, so that TLS reports bad_record_mac and DTLS silently discards the record. FIPS impact: no The affected code is outside the FIPS module boundary. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-75806 | libcrypto3 | 3.5.8-r0 | Issue summary: An established DTLS 1.2 association using an AEAD cipher suite can be terminated by a single unauthenticated datagram whose encrypted fragment is shorter than the mandatory explicit IV and authentication tag overhead. Impact summary: An attacker who can send a datagram that is routed to an existing DTLS 1.2 association can tear that association down without knowing any key material. This is a Denial of Service limited to the targeted association. There is no memory safety or confidentiality impact. CWE: CWE-1284: Improper Validation of Specified Quantity in Input Description: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher suite carries an explicit IV followed by the ciphertext and an authentication tag. When decrypting such a record the record layer passed the record length to the cipher implementation before checking that the record was long enough to contain the explicit IV and the tag. For a record shorter than that overhead the cipher implementation rejected the impossible length, and the record layer treated this as an internal failure and raised a fatal internal_error alert instead of treating the record as one that failed authentication. In TLS 1.2 the same record causes a fatal internal_error alert instead of the expected bad_record_mac alert. Since any undecryptable record already terminates a TLS connection, this is a protocol conformance issue rather than a security issue in TLS. The fix validates the record length against the explicit IV and tag length before any AEAD processing, so that TLS reports bad_record_mac and DTLS silently discards the record. FIPS impact: no The affected code is outside the FIPS module boundary. — /lib/apk/db/installed | |
| LOW | CVE-2026-35191 | libcrypto3 | 3.5.8-r0 | Issue summary: The OpenSSL QUIC server, when configured to not preform address validation, can be forced to count incoming packets multiple times in its unvalidated credit computation, leading to a violation of the RFC 9000 unvalidated connection amplification limit of 3 times the amount of data received. Impact summary: A remote attacker able to spoof packets to a server using the OpenSSL QUIC implementation might use the server for an amplification of a DDoS attack. CWE: CWE-440: Expected Behavior Violation Description: OpenSSL's QUIC stack, when operating as a server, enforces client address validation (RFC 9000, Section 8), to confirm the peer address is not used for a traffic amplification attack. If this feature is disabled on the server, the QUIC stack limits the amount of server data that can be sent to 3 times the amount of data received from the peer address, until such time as the TLS handshake is completed. The OpenSSL QUIC server, when operating in non-validation mode, adds the length of the whole datagram received to the unvalidated credit limit when processing each QUIC packet in the datagram. A remote peer may, after establishing a connection with an initial client hello frame, send a subsequent datagram containing multiple QUIC packets, leading the server to account the entire datagram length for each packet in the datagram, resulting in the server believing that the peer has sent more data than it actually has, thereby violating the 3x amplification limit mandated by the RFC. FIPS impact: no As the QUIC stack lives outside the FIPS module boundary, no FIPS modules are affected by this CVE. — /lib/apk/db/installed | |
| LOW | CVE-2026-35191 | libssl3 | 3.5.8-r0 | Issue summary: The OpenSSL QUIC server, when configured to not preform address validation, can be forced to count incoming packets multiple times in its unvalidated credit computation, leading to a violation of the RFC 9000 unvalidated connection amplification limit of 3 times the amount of data received. Impact summary: A remote attacker able to spoof packets to a server using the OpenSSL QUIC implementation might use the server for an amplification of a DDoS attack. CWE: CWE-440: Expected Behavior Violation Description: OpenSSL's QUIC stack, when operating as a server, enforces client address validation (RFC 9000, Section 8), to confirm the peer address is not used for a traffic amplification attack. If this feature is disabled on the server, the QUIC stack limits the amount of server data that can be sent to 3 times the amount of data received from the peer address, until such time as the TLS handshake is completed. The OpenSSL QUIC server, when operating in non-validation mode, adds the length of the whole datagram received to the unvalidated credit limit when processing each QUIC packet in the datagram. A remote peer may, after establishing a connection with an initial client hello frame, send a subsequent datagram containing multiple QUIC packets, leading the server to account the entire datagram length for each packet in the datagram, resulting in the server believing that the peer has sent more data than it actually has, thereby violating the 3x amplification limit mandated by the RFC. FIPS impact: no As the QUIC stack lives outside the FIPS module boundary, no FIPS modules are affected by this CVE. — /lib/apk/db/installed | |
| LOW | CVE-2026-54875 | libcrypto3 | 3.5.8-r0 | Issue summary: A non-constant-time optimized implementation of scalar point multiplication is used for SM2 private key operations on ARM64 and RISC-V platforms. Impact summary: An attacker able to measure the time taken by, or to observe the cache-line access pattern of SM2 signing or decryption on an affected platform can learn information about the secret scalar. CWE: CWE-208: Observable Timing Discrepancy Description: On ARM64 and RISC-V processors, the SM2 curve uses an optimized scalar multiplication implementation whose conditional branches and table look ups are chosen according to the bits of the secret scalar. The execution time and the cache-access pattern therefore depend on the long-term private key (during SM2 decryption) or the per-signature nonce (during SM2 signature generation), forming a timing and cache side-channel. FIPS Impact: no SM2 is not a FIPS algorithm and the optimized SM2 implementation is not part of the FIPS module. OpenSSL 4.0, 3.6, 3.5 and 3.4 are vulnerable to this issue on AArch64 and RISC-V. OpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue. OpenSSL 4.0 users should upgrade to OpenSSL 4.0.3. OpenSSL 3.6 users should upgrade to OpenSSL 3.6.5. OpenSSL 3.5 users should upgrade to OpenSSL 3.5.9. OpenSSL 3.4 users should upgrade to OpenSSL 3.4.8. This issue was reported on 2 May 2026 by Abhinav Agarwal. It was independently reported on 6 June 2026 by Feng Xue. The fix was developed by Igor Ustinov. -- cut (non-publishing metadata for internal use) -- Reported by: Abhinav Agarwal, Feng Xue Fixed by: Igor Ustinov — /lib/apk/db/installed | |
| LOW | CVE-2026-54875 | libssl3 | 3.5.8-r0 | Issue summary: A non-constant-time optimized implementation of scalar point multiplication is used for SM2 private key operations on ARM64 and RISC-V platforms. Impact summary: An attacker able to measure the time taken by, or to observe the cache-line access pattern of SM2 signing or decryption on an affected platform can learn information about the secret scalar. CWE: CWE-208: Observable Timing Discrepancy Description: On ARM64 and RISC-V processors, the SM2 curve uses an optimized scalar multiplication implementation whose conditional branches and table look ups are chosen according to the bits of the secret scalar. The execution time and the cache-access pattern therefore depend on the long-term private key (during SM2 decryption) or the per-signature nonce (during SM2 signature generation), forming a timing and cache side-channel. FIPS Impact: no SM2 is not a FIPS algorithm and the optimized SM2 implementation is not part of the FIPS module. OpenSSL 4.0, 3.6, 3.5 and 3.4 are vulnerable to this issue on AArch64 and RISC-V. OpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue. OpenSSL 4.0 users should upgrade to OpenSSL 4.0.3. OpenSSL 3.6 users should upgrade to OpenSSL 3.6.5. OpenSSL 3.5 users should upgrade to OpenSSL 3.5.9. OpenSSL 3.4 users should upgrade to OpenSSL 3.4.8. This issue was reported on 2 May 2026 by Abhinav Agarwal. It was independently reported on 6 June 2026 by Feng Xue. The fix was developed by Igor Ustinov. -- cut (non-publishing metadata for internal use) -- Reported by: Abhinav Agarwal, Feng Xue Fixed by: Igor Ustinov — /lib/apk/db/installed | |
| LOW | CVE-2026-54872 | libcrypto3 | 3.5.8-r0 | Issue summary: The generic elliptic-curve scalar multiplication used for ECDSA and SM2 signature operations with curves that do not have a dedicated implementation leaks information about the secret nonce through timing. Impact summary: An attacker able to measure signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key. CWE: CWE-208: Observable Timing Discrepancy Description: The generic elliptic-curve scalar multiplication used for curves that do not have a dedicated constant-time implementation pads the secret scalar with non-constant-time BIGNUM operations, so the time taken depends on the value of the secret scalar derived from the ECDSA and SM2 nonce. The leak is very small; observing it requires a large number of measurements. The effect is largest for curves whose group order lies on a machine-word boundary, such as brainpoolP384r1. Applications using ECDSA signing over the Brainpool and other generic prime curves, and SM2 signing on platforms that use the generic implementation, are vulnerable to this issue. The NIST curves P-256, P-384 and P-521 use dedicated constant-time implementations and are not affected. FIPS Impact: no The FIPS modules are not affected: the approved NIST curves used in the FIPS provider have dedicated constant-time implementations and do not use the affected code path. — /lib/apk/db/installed | |
| LOW | CVE-2026-54872 | libssl3 | 3.5.8-r0 | Issue summary: The generic elliptic-curve scalar multiplication used for ECDSA and SM2 signature operations with curves that do not have a dedicated implementation leaks information about the secret nonce through timing. Impact summary: An attacker able to measure signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key. CWE: CWE-208: Observable Timing Discrepancy Description: The generic elliptic-curve scalar multiplication used for curves that do not have a dedicated constant-time implementation pads the secret scalar with non-constant-time BIGNUM operations, so the time taken depends on the value of the secret scalar derived from the ECDSA and SM2 nonce. The leak is very small; observing it requires a large number of measurements. The effect is largest for curves whose group order lies on a machine-word boundary, such as brainpoolP384r1. Applications using ECDSA signing over the Brainpool and other generic prime curves, and SM2 signing on platforms that use the generic implementation, are vulnerable to this issue. The NIST curves P-256, P-384 and P-521 use dedicated constant-time implementations and are not affected. FIPS Impact: no The FIPS modules are not affected: the approved NIST curves used in the FIPS provider have dedicated constant-time implementations and do not use the affected code path. — /lib/apk/db/installed | |
| LOW | CVE-2026-77696 | libcrypto3 | 3.5.8-r0 | Issue summary: SM2 signature generation uses non-constant-time arithmetic on secret values, forming a timing side-channel. Impact summary: An attacker able to measure SM2 signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key. CWE: CWE-208: Observable Timing Discrepancy Description: SM2 signature generation computes the signature value using variable-time BIGNUM operations on the secret nonce and the private key, so the time taken to produce an SM2 signature depends on these secret values, forming a timing side-channel. Applications performing SM2 signature generation are affected on all platforms. FIPS Impact: no SM2 is not a FIPS algorithm. — /lib/apk/db/installed | |
| LOW | CVE-2026-77696 | libssl3 | 3.5.8-r0 | Issue summary: SM2 signature generation uses non-constant-time arithmetic on secret values, forming a timing side-channel. Impact summary: An attacker able to measure SM2 signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key. CWE: CWE-208: Observable Timing Discrepancy Description: SM2 signature generation computes the signature value using variable-time BIGNUM operations on the secret nonce and the private key, so the time taken to produce an SM2 signature depends on these secret values, forming a timing side-channel. Applications performing SM2 signature generation are affected on all platforms. FIPS Impact: no SM2 is not a FIPS algorithm. — /lib/apk/db/installed |
ghcr.io/voxpupuli/voxbox
Downloads
ghcr.io/voxpupuli/voxbox:latest (2026-10-08)
Trivy
HIGH 1
MEDIUM 1
UNKNOWN 19
| Severity | ID | Package | Installed | Fixed | Title / target |
|---|---|---|---|---|---|
| HIGH | CVE-2026-80212 | resolv | 0.2.3 | ~> 0.3.2, >= 0.7.2 | resolv: resolv gem: Denial of Service via uncontrolled memory growth from crafted DNS responses — Ruby |
| MEDIUM | CVE-2026-80213 | resolv | 0.2.3 | ~> 0.3.2, >= 0.7.2 | resolv: Resolv gem: DNS allowlist and egress bypass, and cache poisoning via crafted hostnames — Ruby |
| UNKNOWN | GO-2026-5932 | golang.org/x/crypto | v0.56.0 | The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues — usr/local/bin/jig | |
| UNKNOWN | CVE-2026-78659 | golang.org/x/net | v0.57.0 | 0.60.0 | HTTP/2 server memory exhaustion due to Trailer headers in net/http — usr/local/bin/jig |
| UNKNOWN | CVE-2026-78660 | golang.org/x/net | v0.57.0 | 0.60.0 | HTTP/2 transport accepts malformed framing-related headers in net/http — usr/local/bin/jig |
| UNKNOWN | CVE-2026-78663 | golang.org/x/net | v0.57.0 | 0.60.0 | Double flow control refund on HTTP/2 server streams in net/http — usr/local/bin/jig |
| UNKNOWN | CVE-2026-78669 | golang.org/x/net | v0.57.0 | 0.60.0 | Excessive CPU consumption from repeated initial window changes in net/http — usr/local/bin/jig |
| UNKNOWN | CVE-2026-97032 | golang.org/x/net | v0.57.0 | 0.60.0 | HTTP/2 server crash due to HPACK encoder race in net/http — usr/local/bin/jig |
| UNKNOWN | CVE-2026-56857 | stdlib | v1.27.1 | 1.26.9, 1.27.2 | Root.Mkdir(All) can follow junctions out of the root on Windows in os — usr/local/bin/jig |
| UNKNOWN | CVE-2026-56866 | stdlib | v1.27.1 | 1.26.9, 1.27.2 | HTTP/1 client connection desynchronization after CONNECT rejection in net/http — usr/local/bin/jig |
| UNKNOWN | CVE-2026-78659 | stdlib | v1.27.1 | 1.26.9, 1.27.2 | HTTP/2 server memory exhaustion due to Trailer headers in net/http — usr/local/bin/jig |
| UNKNOWN | CVE-2026-78660 | stdlib | v1.27.1 | 1.26.9, 1.27.2 | HTTP/2 transport accepts malformed framing-related headers in net/http — usr/local/bin/jig |
| UNKNOWN | CVE-2026-78663 | stdlib | v1.27.1 | 1.26.9, 1.27.2 | Double flow control refund on HTTP/2 server streams in net/http — usr/local/bin/jig |
| UNKNOWN | CVE-2026-78667 | stdlib | v1.27.1 | 1.26.9, 1.27.2 | Lack of limit on size of parsed Range headers in net/http — usr/local/bin/jig |
| UNKNOWN | CVE-2026-78669 | stdlib | v1.27.1 | 1.26.9, 1.27.2 | Excessive CPU consumption from repeated initial window changes in net/http — usr/local/bin/jig |
| UNKNOWN | CVE-2026-94439 | stdlib | v1.27.1 | 1.26.9, 1.27.2 | HTTP/1 server connection desynchronization after 2xx CONNECT response in net/http — usr/local/bin/jig |
| UNKNOWN | CVE-2026-94440 | stdlib | v1.27.1 | 1.26.9, 1.27.2 | Memory limit bypass when parsing MIME headers in net/textproto, mime/multipart — usr/local/bin/jig |
| UNKNOWN | CVE-2026-94448 | stdlib | v1.27.1 | 1.26.9, 1.27.2 | Reset context tracking on consecutive template expressions in html/template — usr/local/bin/jig |
| UNKNOWN | CVE-2026-97030 | stdlib | v1.27.1 | 1.26.9, 1.27.2 | Recognize yield as regexp preceder keyword in html/template — usr/local/bin/jig |
| UNKNOWN | CVE-2026-97031 | stdlib | v1.27.1 | 1.26.9, 1.27.2 | Reject malformed ECH outer extension references in crypto/tls — usr/local/bin/jig |
| UNKNOWN | CVE-2026-97032 | stdlib | v1.27.1 | 1.26.9, 1.27.2 | HTTP/2 server crash due to HPACK encoder race in net/http — usr/local/bin/jig |
Grype
NVD/CPE filtered 15
No confirmed findings.
Filtered NVD/CPE matches (15)
These broad CPE matches are unconfirmed for the distribution package and excluded from scanner totals.
| Severity | ID | Package | Installed | Fixed | Title / target |
|---|---|---|---|---|---|
| MEDIUM | CVE-2025-12781 | python3 | 3.12.15-r0 | When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the "base64" module the characters "+/" will always be accepted, regardless of the value of "altchars" parameter, typically used to establish an "alternative base64 alphabet" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues. This behavior can only be insecure if your application uses an alternate base64 alphabet (without "+/"). If your application does not use the "altchars" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet. The attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64 alphabet they are expecting or verify that their application would not be affected if the b64decode() functions accepted "+" or "/" outside of altchars. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-6019 | python3 | 3.12.15-r0 | http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value. — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-15366 | python3 | 3.12.15-r0 | The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters. — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-15367 | python3 | 3.12.15-r0 | The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-58055 | nghttp2-libs | 1.69.0-r0 | nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning. — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-60876 | busybox | 1.37.0-r30 | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-60876 | busybox-binsh | 1.37.0-r30 | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed | |
| MEDIUM | CVE-2025-60876 | ssl_client | 1.37.0-r30 | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-3446 | python3 | 3.12.15-r0 | When calling base64.b64decode() or related functions the decoding process would stop after encountering the first padded quad regardless of whether there was more information to be processed. This can lead to data being accepted which may be processed differently by other implementations. Use "validate=True" to enable stricter processing of base64 data. — /lib/apk/db/installed | |
| MEDIUM | CVE-2026-12345 | python3 | 3.12.15-r0 | The cleanup of tempfile.TemporaryDirectory is vulnerable to a race condition. An attacker who can modify the tree during cleanup can replace a directory with a symbolic link, causing files outside of the temporary directory to be deleted or have their permissions and file flags reset, with the privileges of the process performing the cleanup. Note that platforms where shutil.rmtree.avoids_symlink_attacks is false, remain affected, and file flags may still be reset outside of the tree on all platforms. — /lib/apk/db/installed | |
| LOW | CVE-2022-3219 | gnupg-dirmngr | 2.4.9-r0 | GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB. — /lib/apk/db/installed | |
| LOW | CVE-2022-3219 | gnupg-gpgconf | 2.4.9-r0 | GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB. — /lib/apk/db/installed | |
| LOW | CVE-2022-3219 | gnupg-keyboxd | 2.4.9-r0 | GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB. — /lib/apk/db/installed | |
| LOW | CVE-2022-3219 | gpg | 2.4.9-r0 | GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB. — /lib/apk/db/installed | |
| UNKNOWN | CVE-2026-3479 | python3 | 3.12.15-r0 | DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point. There is no vulnerability in the function if following the intended security model. pkgutil.get_data() did not validate the resource argument as documented, allowing path traversals. — /lib/apk/db/installed |