container statistics

11 container package(s) · generated 2026-09-18T04:50:31Z

581,133 combined downloads
11configured packages

ghcr.io/openvoxproject/openbolt

GitHub Container Registry

Downloads

1,724 downloads

ghcr.io/openvoxproject/openbolt:latest (2026-08-27)

Trivy

HIGH 2 MEDIUM 1
SeverityIDPackageInstalledFixedTitle / target
HIGH CVE-2026-80212resolv0.2.3 ~> 0.3.2, >= 0.7.2resolv: resolv gem: Denial of Service via uncontrolled memory growth from crafted DNS responses — Ruby
HIGH CVE-2026-85396rubyzip2.4.1 >= 3.4.0rubyzip: rubyzip: Arbitrary file write via path traversal — Ruby
MEDIUM CVE-2026-80213resolv0.2.3 ~> 0.3.2, >= 0.7.2resolv: Resolv gem: DNS allowlist and egress bypass, and cache poisoning via crafted hostnames — Ruby

Grype

NVD/CPE filtered 3

No confirmed findings.

Filtered NVD/CPE matches (3)

These broad CPE matches are unconfirmed for the distribution package and excluded from scanner totals.

SeverityIDPackageInstalledFixedTitle / target
MEDIUM CVE-2025-60876busybox1.37.0-r30 BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed
MEDIUM CVE-2025-60876busybox-binsh1.37.0-r30 BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed
MEDIUM CVE-2025-60876ssl_client1.37.0-r30 BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed

ghcr.io/openvoxproject/openvoxagent

GitHub Container Registry

Downloads

14,220 downloads

ghcr.io/openvoxproject/openvoxagent:latest (2026-08-27)

Trivy

HIGH 8 MEDIUM 109 LOW 12
SeverityIDPackageInstalledFixedTitle / target
HIGH CVE-2026-56862stdlibv1.26.5 1.25.13, 1.26.6, 1.27.0-rc.3crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages — usr/bin/pebble
HIGH CVE-2026-56860stdlibv1.26.5 1.25.13, 1.26.6, 1.27.0-rc.3net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution — usr/bin/pebble
HIGH CVE-2026-56859stdlibv1.26.5 1.25.13, 1.26.6, 1.27.0-rc.3encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue — usr/bin/pebble
HIGH CVE-2026-56858stdlibv1.26.5 1.25.13, 1.26.6, 1.27.0-rc.3html/template: golang: Go html/template: Cross-Site Scripting via pathological input — usr/bin/pebble
HIGH CVE-2026-56853stdlibv1.26.5 1.25.13, 1.26.6, 1.27.0-rc.3net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service — usr/bin/pebble
HIGH CVE-2026-46600stdlibv1.26.5 1.26.6, 1.27.0-rc.3golang.org/x/net/dns/dnsmessage: golang.org/x/net/dns/dnsmessage: Denial of Service via invalid DNS record parsing — usr/bin/pebble
HIGH CVE-2026-39821stdlibv1.26.5 1.25.13, 1.26.6, 1.27.0-rc.3golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing — usr/bin/pebble
HIGH CVE-2026-33818stdlibv1.26.5 1.25.13, 1.26.6, 1.27.0-rc.3encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal — usr/bin/pebble
MEDIUM CVE-2026-3184mount2.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: Access control bypass due to improper hostname canonicalization — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-53612mount2.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: TOCTOU in the mount program when applying post-mount ownership/mode changes — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-53613mount2.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-53614mount2.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: SUID mount(8) allows nosuid/noexec bypass via LIBMOUNT_FORCE_MOUNT2 — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-53615mount2.41.3-3ubuntu2 2.41.3-3ubuntu2.2[Integer Overflow or Wraparound in libblkid/src/partitions/dos.c] — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-12087perl-base5.40.1-7ubuntu0.1 5.40.1-7ubuntu0.3perl-Socket: perl-Socket: Information Disclosure due to Out-of-Bounds Read — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-13221perl-base5.40.1-7ubuntu0.1 5.40.1-7ubuntu0.3perl: Perl: Incorrect regular expression processing via large regular expressions — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-15534perl-base5.40.1-7ubuntu0.1 5.40.1-7ubuntu0.2perl: Perl: Arbitrary code execution via out-of-bounds memory access in regular expression engine. — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-19487perl-base5.40.1-7ubuntu0.1 5.40.1-7ubuntu0.2perl: Perl: Incorrect regular expression matching can lead to wrong access or filtering decisions. — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-57432perl-base5.40.1-7ubuntu0.1 5.40.1-7ubuntu0.3perl: Perl: Information disclosure via integer overflow in pack/unpack operations — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-57433perl-base5.40.1-7ubuntu0.1 5.40.1-7ubuntu0.3Storable: Storable: Denial of Service via signed integer overflow in deserialization — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-35341rust-coreutils0.8.0-0ubuntu3 A vulnerability in uutils coreutils mkfifo allows for the unauthorized ... — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-35344rust-coreutils0.8.0-0ubuntu3 The dd utility in uutils coreutils suppresses errors during file trunc ... — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-35345rust-coreutils0.8.0-0ubuntu3 A vulnerability in the tail utility of uutils coreutils allows for the ... — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-27456mount2.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: TOCTOU in the mount program when setting up loop devices — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-13595mount2.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: heap use-after-free in libblkid nested partition probing — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-53615login1:4.16.0-2+really2.41.3-3ubuntu2 2.41.3-3ubuntu2.2[Integer Overflow or Wraparound in libblkid/src/partitions/dos.c] — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-53614login1:4.16.0-2+really2.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: SUID mount(8) allows nosuid/noexec bypass via LIBMOUNT_FORCE_MOUNT2 — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-53613login1:4.16.0-2+really2.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-53612login1:4.16.0-2+really2.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: TOCTOU in the mount program when applying post-mount ownership/mode changes — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-3184login1:4.16.0-2+really2.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: Access control bypass due to improper hostname canonicalization — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-27456login1:4.16.0-2+really2.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: TOCTOU in the mount program when setting up loop devices — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-13595login1:4.16.0-2+really2.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: heap use-after-free in libblkid nested partition probing — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-53615libuuid12.41.3-3ubuntu2 2.41.3-3ubuntu2.2[Integer Overflow or Wraparound in libblkid/src/partitions/dos.c] — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-53614libuuid12.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: SUID mount(8) allows nosuid/noexec bypass via LIBMOUNT_FORCE_MOUNT2 — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-53613libuuid12.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-53612libuuid12.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: TOCTOU in the mount program when applying post-mount ownership/mode changes — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-85091zlib1g1:1.3.dfsg+really1.3.1-1ubuntu3 zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vul ... — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-53615util-linux2.41.3-3ubuntu2 2.41.3-3ubuntu2.2[Integer Overflow or Wraparound in libblkid/src/partitions/dos.c] — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-53614util-linux2.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: SUID mount(8) allows nosuid/noexec bypass via LIBMOUNT_FORCE_MOUNT2 — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-53613util-linux2.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-53612util-linux2.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: TOCTOU in the mount program when applying post-mount ownership/mode changes — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-3184util-linux2.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: Access control bypass due to improper hostname canonicalization — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-27456util-linux2.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: TOCTOU in the mount program when setting up loop devices — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-13595util-linux2.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: heap use-after-free in libblkid nested partition probing — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-18508tar1.35+dfsg-4ubuntu0.4 tar: tar: --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-18477tar1.35+dfsg-4ubuntu0.4 tar: tar: TOCTOU in incremental dumpdir 'X' rename handling allows restore path escape — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-35377rust-coreutils0.8.0-0ubuntu3 A logic error in the env utility of uutils coreutils causes a failure ... — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-35374rust-coreutils0.8.0-0ubuntu3 A Time-of-Check to Time-of-Use (TOCTOU) vulnerability exists in the sp ... — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-35373rust-coreutils0.8.0-0ubuntu3 A logic error in the ln utility of uutils coreutils causes the program ... — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-35371rust-coreutils0.8.0-0ubuntu3 The id utility in uutils coreutils exhibits incorrect behavior in its ... — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-35370rust-coreutils0.8.0-0ubuntu3 The id utility in uutils coreutils miscalculates the groups= section o ... — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-35368rust-coreutils0.8.0-0ubuntu3 A vulnerability exists in the chroot utility of uutils coreutils when ... — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-35367rust-coreutils0.8.0-0ubuntu3 The nohup utility in uutils coreutils creates its default output file, ... — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-35364rust-coreutils0.8.0-0ubuntu3 A Time-of-Check to Time-of-Use (TOCTOU) race condition exists in the m ... — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-35363rust-coreutils0.8.0-0ubuntu3 A vulnerability in the rm utility of uutils coreutils allows the bypas ... — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-35360rust-coreutils0.8.0-0ubuntu3 The touch utility in uutils coreutils is vulnerable to a Time-of-Check ... — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-35359rust-coreutils0.8.0-0ubuntu3 A Time-of-Check to Time-of-Use (TOCTOU) vulnerability in the cp utilit ... — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-35357rust-coreutils0.8.0-0ubuntu3 The cp utility in uutils coreutils is vulnerable to an information dis ... — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-35354rust-coreutils0.8.0-0ubuntu3 A Time-of-Check to Time-of-Use (TOCTOU) vulnerability exists in the mv ... — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-35352rust-coreutils0.8.0-0ubuntu3 A Time-of-Check to Time-of-Use (TOCTOU) race condition exists in the m ... — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-35351rust-coreutils0.8.0-0ubuntu3 The mv utility in uutils coreutils fails to preserve file ownership du ... — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-35350rust-coreutils0.8.0-0ubuntu3 The cp utility in uutils coreutils fails to properly handle setuid and ... — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-35348rust-coreutils0.8.0-0ubuntu3 The sort utility in uutils coreutils is vulnerable to a process panic ... — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-3184libuuid12.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: Access control bypass due to improper hostname canonicalization — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-80489libc-gconv-modules-extra2.43-2ubuntu2.3 2.43-2ubuntu2.4glibc: Non-progress DoS in EUC_JISX0213 -> UCS-4 conversion state — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-77117libc-gconv-modules-extra2.43-2ubuntu2.3 2.43-2ubuntu2.4glibc: Non-progress DoS in SHIFT_JISX0213 -&gt — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-6791libc-gconv-modules-extra2.43-2ubuntu2.3 2.43-2ubuntu2.4glibc: Glibc: Denial of Service via stack exhaustion during tilde expansion — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-6368libc-gconv-modules-extra2.43-2ubuntu2.3 2.43-2ubuntu2.4glibc: glibc: Process abort due to invalid memory in wordexp — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-19542libc-gconv-modules-extra2.43-2ubuntu2.3 2.43-2ubuntu2.4glibc: Fix out-of-bounds array write in tdelete — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-19499libc-gconv-modules-extra2.43-2ubuntu2.3 2.43-2ubuntu2.4glibc: Buffer Overflow in strfmon right-justification padding — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-18374libc-gconv-modules-extra2.43-2ubuntu2.3 glibc: glibc: Heap buffer overflow via attacker-controlled fopen mode string — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-80489libc-bin2.43-2ubuntu2.3 2.43-2ubuntu2.4glibc: Non-progress DoS in EUC_JISX0213 -> UCS-4 conversion state — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-77117libc-bin2.43-2ubuntu2.3 2.43-2ubuntu2.4glibc: Non-progress DoS in SHIFT_JISX0213 -&gt — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-6791libc-bin2.43-2ubuntu2.3 2.43-2ubuntu2.4glibc: Glibc: Denial of Service via stack exhaustion during tilde expansion — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-6368libc-bin2.43-2ubuntu2.3 2.43-2ubuntu2.4glibc: glibc: Process abort due to invalid memory in wordexp — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-19542libc-bin2.43-2ubuntu2.3 2.43-2ubuntu2.4glibc: Fix out-of-bounds array write in tdelete — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-19499libc-bin2.43-2ubuntu2.3 2.43-2ubuntu2.4glibc: Buffer Overflow in strfmon right-justification padding — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-18374libc-bin2.43-2ubuntu2.3 glibc: glibc: Heap buffer overflow via attacker-controlled fopen mode string — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-53615libblkid12.41.3-3ubuntu2 2.41.3-3ubuntu2.2[Integer Overflow or Wraparound in libblkid/src/partitions/dos.c] — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-53614libblkid12.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: SUID mount(8) allows nosuid/noexec bypass via LIBMOUNT_FORCE_MOUNT2 — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-53613libblkid12.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-53612libblkid12.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: TOCTOU in the mount program when applying post-mount ownership/mode changes — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-3184libblkid12.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: Access control bypass due to improper hostname canonicalization — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-27456libblkid12.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: TOCTOU in the mount program when setting up loop devices — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-13595libblkid12.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: heap use-after-free in libblkid nested partition probing — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-54371libattr11:2.5.2-4 1:2.5.2-4ubuntu0.1attr: attr: Symlink Traversal Privilege Escalation via getfattr and setfattr — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-56391gnu-coreutils9.7-3ubuntu2 9.7-3ubuntu2.1coreutils: GNU coreutils uniq: Denial of Service and information disclosure via out-of-bounds read with multibyte input — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-53910diffutils1:3.12-1 1:3.12-1ubuntu0.1diffutils: heap‑based buffer overflow due to multiple signed integer overflows in line‑mapping calculations — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-53615bsdutils1:2.41.3-3ubuntu2 2.41.3-3ubuntu2.2[Integer Overflow or Wraparound in libblkid/src/partitions/dos.c] — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-53614bsdutils1:2.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: SUID mount(8) allows nosuid/noexec bypass via LIBMOUNT_FORCE_MOUNT2 — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-53613bsdutils1:2.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-53612bsdutils1:2.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: TOCTOU in the mount program when applying post-mount ownership/mode changes — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-3184bsdutils1:2.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: Access control bypass due to improper hostname canonicalization — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-27456bsdutils1:2.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: TOCTOU in the mount program when setting up loop devices — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-13595bsdutils1:2.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: heap use-after-free in libblkid nested partition probing — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-27456libuuid12.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: TOCTOU in the mount program when setting up loop devices — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-13595libuuid12.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: heap use-after-free in libblkid nested partition probing — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-53615libsmartcols12.41.3-3ubuntu2 2.41.3-3ubuntu2.2[Integer Overflow or Wraparound in libblkid/src/partitions/dos.c] — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-53614libsmartcols12.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: SUID mount(8) allows nosuid/noexec bypass via LIBMOUNT_FORCE_MOUNT2 — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-53613libsmartcols12.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-53612libsmartcols12.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: TOCTOU in the mount program when applying post-mount ownership/mode changes — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-3184libsmartcols12.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: Access control bypass due to improper hostname canonicalization — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-27456libsmartcols12.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: TOCTOU in the mount program when setting up loop devices — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-13595libsmartcols12.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: heap use-after-free in libblkid nested partition probing — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-53615libmount12.41.3-3ubuntu2 2.41.3-3ubuntu2.2[Integer Overflow or Wraparound in libblkid/src/partitions/dos.c] — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-53614libmount12.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: SUID mount(8) allows nosuid/noexec bypass via LIBMOUNT_FORCE_MOUNT2 — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-53613libmount12.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-53612libmount12.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: TOCTOU in the mount program when applying post-mount ownership/mode changes — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-18374libc62.43-2ubuntu2.3 glibc: glibc: Heap buffer overflow via attacker-controlled fopen mode string — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-19499libc62.43-2ubuntu2.3 2.43-2ubuntu2.4glibc: Buffer Overflow in strfmon right-justification padding — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-19542libc62.43-2ubuntu2.3 2.43-2ubuntu2.4glibc: Fix out-of-bounds array write in tdelete — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-6368libc62.43-2ubuntu2.3 2.43-2ubuntu2.4glibc: glibc: Process abort due to invalid memory in wordexp — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-6791libc62.43-2ubuntu2.3 2.43-2ubuntu2.4glibc: Glibc: Denial of Service via stack exhaustion during tilde expansion — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-77117libc62.43-2ubuntu2.3 2.43-2ubuntu2.4glibc: Non-progress DoS in SHIFT_JISX0213 -&gt — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-80489libc62.43-2ubuntu2.3 2.43-2ubuntu2.4glibc: Non-progress DoS in EUC_JISX0213 -> UCS-4 conversion state — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-13595libmount12.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: heap use-after-free in libblkid nested partition probing — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-27456libmount12.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: TOCTOU in the mount program when setting up loop devices — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
MEDIUM CVE-2026-3184libmount12.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: Access control bypass due to improper hostname canonicalization — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
LOW CVE-2024-56433login.defs1:4.17.4-2ubuntu3 shadow-utils: Default subordinate ID configuration in /etc/login.defs could lead to compromise — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
LOW CVE-2024-2236libgcrypt201.12.0-2ubuntu1 1.12.0-2ubuntu1.1libgcrypt: vulnerable to Marvin Attack — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
LOW CVE-2026-57062gpgv2.4.8-4ubuntu3 2.4.8-4ubuntu3.1GnuPG: Incorrect cryptographic message parsing — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
LOW CVE-2025-5278gnu-coreutils9.7-3ubuntu2 9.7-3ubuntu2.1coreutils: Heap Buffer Under-Read in GNU Coreutils sort via Key Specification — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
LOW CVE-2026-27171zlib1g1:1.3.dfsg+really1.3.1-1ubuntu3 1:1.3.dfsg+really1.3.1-1ubuntu3.1zlib: zlib: Denial of Service via infinite loop in CRC32 combine functions — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
LOW CVE-2024-56433passwd1:4.17.4-2ubuntu3 shadow-utils: Default subordinate ID configuration in /etc/login.defs could lead to compromise — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
LOW CVE-2026-75803openssl-provider-legacy3.5.5-1ubuntu3.4 3.5.5-1ubuntu3.5openssl: openssl: AEAD forgeries possible with empty ciphertext in EVP_Cipher() — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
LOW CVE-2026-75803libssl3t643.5.5-1ubuntu3.4 3.5.5-1ubuntu3.5openssl: openssl: AEAD forgeries possible with empty ciphertext in EVP_Cipher() — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
LOW CVE-2026-40228libsystemd0259.5-0ubuntu3.4 systemd: systemd-journald: Unintended output to user terminals via logger command — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
LOW CVE-2026-40228libudev1259.5-0ubuntu3.4 systemd: systemd-journald: Unintended output to user terminals via logger command — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
LOW CVE-2026-75803openssl3.5.5-1ubuntu3.4 3.5.5-1ubuntu3.5openssl: openssl: AEAD forgeries possible with empty ciphertext in EVP_Cipher() — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)
LOW CVE-2026-42250libbz2-1.01.0.8-6build2 1.0.8-6ubuntu0.1bzip2: bzip2: Denial of Service in bzip2recover via a specially crafted file — ghcr.io/openvoxproject/openvoxagent:latest (ubuntu 26.04)

Grype

HIGH 4 MEDIUM 162 LOW 13
SeverityIDPackageInstalledFixedTitle / target
HIGH GO-2026-5026stdlibgo1.26.5 1.25.13, 1.26.6, 1.27.0-rc.3The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com". — /usr/bin/pebble
HIGH GO-2026-6090stdlibgo1.26.5 1.25.13, 1.26.6, 1.27.0-rc.3Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely. — /usr/bin/pebble
HIGH GO-2026-5972stdlibgo1.26.5 1.25.13, 1.26.6, 1.27.0-rc.3Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures. — /usr/bin/pebble
HIGH GO-2026-6089stdlibgo1.26.5 1.25.13, 1.26.6, 1.27.0-rc.3When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this. — /usr/bin/pebble
MEDIUM GO-2026-6218stdlibgo1.26.5 1.25.13, 1.26.6, 1.27.0-rc.3Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations. — /usr/bin/pebble
MEDIUM CVE-2026-78408libmount12.41.3-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-78408libsmartcols12.41.3-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-78408libuuid12.41.3-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-78408login1:4.16.0-2+really2.41.3-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-78408mount2.41.3-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-78408util-linux2.41.3-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-89161libpcre2-8-010.46-1build1 /var/lib/dpkg/status
MEDIUM CVE-2026-35370rust-coreutils0.8.0-0ubuntu3 /var/lib/dpkg/status
MEDIUM CVE-2026-6368libc-bin2.43-2ubuntu2.3 2.43-2ubuntu2.4/var/lib/dpkg/status
MEDIUM CVE-2026-6368libc-gconv-modules-extra2.43-2ubuntu2.3 2.43-2ubuntu2.4/var/lib/dpkg/status
MEDIUM CVE-2026-6368libc62.43-2ubuntu2.3 2.43-2ubuntu2.4/var/lib/dpkg/status
MEDIUM CVE-2026-35359rust-coreutils0.8.0-0ubuntu3 /var/lib/dpkg/status
MEDIUM CVE-2026-89162libpcre2-8-010.46-1build1 /var/lib/dpkg/status
MEDIUM CVE-2026-35360rust-coreutils0.8.0-0ubuntu3 /var/lib/dpkg/status
MEDIUM CVE-2026-89156libpcre2-8-010.46-1build1 /var/lib/dpkg/status
MEDIUM CVE-2026-89157libpcre2-8-010.46-1build1 /var/lib/dpkg/status
MEDIUM CVE-2026-35377rust-coreutils0.8.0-0ubuntu3 /var/lib/dpkg/status
MEDIUM CVE-2026-35345rust-coreutils0.8.0-0ubuntu3 /var/lib/dpkg/status
MEDIUM CVE-2026-78410bsdutils1:2.41.3-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-78410libblkid12.41.3-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-78410libmount12.41.3-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-78409libblkid12.41.3-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-78409libmount12.41.3-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-78409libsmartcols12.41.3-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-78409libuuid12.41.3-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-78409login1:4.16.0-2+really2.41.3-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-78409mount2.41.3-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-78409util-linux2.41.3-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-35371rust-coreutils0.8.0-0ubuntu3 /var/lib/dpkg/status
MEDIUM CVE-2026-35373rust-coreutils0.8.0-0ubuntu3 /var/lib/dpkg/status
MEDIUM CVE-2026-27456bsdutils1:2.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-27456libblkid12.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-27456libmount12.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-27456libsmartcols12.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-27456libuuid12.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-27456login1:4.16.0-2+really2.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-27456mount2.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-27456util-linux2.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-35344rust-coreutils0.8.0-0ubuntu3 /var/lib/dpkg/status
MEDIUM CVE-2026-35367rust-coreutils0.8.0-0ubuntu3 /var/lib/dpkg/status
MEDIUM CVE-2026-78408bsdutils1:2.41.3-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-78408libblkid12.41.3-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-78410libsmartcols12.41.3-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-53615libmount12.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-53612libsmartcols12.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-53613libsmartcols12.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-53614libsmartcols12.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-53615libsmartcols12.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-53612libuuid12.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-53613libuuid12.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-53614libuuid12.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-53615libuuid12.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-53612login1:4.16.0-2+really2.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-53613login1:4.16.0-2+really2.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-53614login1:4.16.0-2+really2.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-53615login1:4.16.0-2+really2.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-53612mount2.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-53613mount2.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-53614mount2.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-53615mount2.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-53612util-linux2.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-53613util-linux2.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-53614util-linux2.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-53615util-linux2.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-78410libuuid12.41.3-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-78410login1:4.16.0-2+really2.41.3-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-78410mount2.41.3-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-78410util-linux2.41.3-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-35354rust-coreutils0.8.0-0ubuntu3 /var/lib/dpkg/status
MEDIUM CVE-2026-35364rust-coreutils0.8.0-0ubuntu3 /var/lib/dpkg/status
MEDIUM CVE-2026-35357rust-coreutils0.8.0-0ubuntu3 /var/lib/dpkg/status
MEDIUM CVE-2026-54370libacl12.3.2-2 /var/lib/dpkg/status
MEDIUM CVE-2026-18477tar1.35+dfsg-4ubuntu0.4 /var/lib/dpkg/status
MEDIUM CVE-2026-35374rust-coreutils0.8.0-0ubuntu3 /var/lib/dpkg/status
MEDIUM CVE-2026-53612bsdutils1:2.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-53613bsdutils1:2.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-53614bsdutils1:2.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-53615bsdutils1:2.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-53612libblkid12.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-53613libblkid12.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-53614libblkid12.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-53615libblkid12.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-53612libmount12.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-53613libmount12.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-53614libmount12.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-19499libc62.43-2ubuntu2.3 2.43-2ubuntu2.4/var/lib/dpkg/status
MEDIUM CVE-2026-12087perl-base5.40.1-7ubuntu0.1 5.40.1-7ubuntu0.3/var/lib/dpkg/status
MEDIUM CVE-2026-48959perl-base5.40.1-7ubuntu0.1 /var/lib/dpkg/status
MEDIUM CVE-2026-86145libpcre2-8-010.46-1build1 /var/lib/dpkg/status
MEDIUM CVE-2026-57433perl-base5.40.1-7ubuntu0.1 5.40.1-7ubuntu0.3/var/lib/dpkg/status
MEDIUM CVE-2026-53910diffutils1:3.12-1 1:3.12-1ubuntu0.1/var/lib/dpkg/status
MEDIUM CVE-2026-48962perl-base5.40.1-7ubuntu0.1 /var/lib/dpkg/status
MEDIUM CVE-2026-19542libc-bin2.43-2ubuntu2.3 2.43-2ubuntu2.4/var/lib/dpkg/status
MEDIUM CVE-2026-19542libc-gconv-modules-extra2.43-2ubuntu2.3 2.43-2ubuntu2.4/var/lib/dpkg/status
MEDIUM CVE-2026-19542libc62.43-2ubuntu2.3 2.43-2ubuntu2.4/var/lib/dpkg/status
MEDIUM CVE-2026-48961perl-base5.40.1-7ubuntu0.1 /var/lib/dpkg/status
MEDIUM CVE-2026-7017perl-base5.40.1-7ubuntu0.1 /var/lib/dpkg/status
MEDIUM CVE-2026-89092libc-bin2.43-2ubuntu2.3 /var/lib/dpkg/status
MEDIUM CVE-2026-89092libc-gconv-modules-extra2.43-2ubuntu2.3 /var/lib/dpkg/status
MEDIUM CVE-2026-89092libc62.43-2ubuntu2.3 /var/lib/dpkg/status
MEDIUM CVE-2026-89158libpcre2-8-010.46-1build1 /var/lib/dpkg/status
MEDIUM CVE-2026-89160libpcre2-8-010.46-1build1 /var/lib/dpkg/status
MEDIUM CVE-2026-57432perl-base5.40.1-7ubuntu0.1 5.40.1-7ubuntu0.3/var/lib/dpkg/status
MEDIUM CVE-2026-6791libc-bin2.43-2ubuntu2.3 2.43-2ubuntu2.4/var/lib/dpkg/status
MEDIUM CVE-2026-6791libc-gconv-modules-extra2.43-2ubuntu2.3 2.43-2ubuntu2.4/var/lib/dpkg/status
MEDIUM CVE-2026-6791libc62.43-2ubuntu2.3 2.43-2ubuntu2.4/var/lib/dpkg/status
MEDIUM CVE-2026-9538perl-base5.40.1-7ubuntu0.1 /var/lib/dpkg/status
MEDIUM CVE-2026-85091zlib1g1:1.3.dfsg+really1.3.1-1ubuntu3 /var/lib/dpkg/status
MEDIUM CVE-2026-3184bsdutils1:2.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-3184libblkid12.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-3184libmount12.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-3184libsmartcols12.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-3184libuuid12.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-3184login1:4.16.0-2+really2.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-3184mount2.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-3184util-linux2.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-13221perl-base5.40.1-7ubuntu0.1 5.40.1-7ubuntu0.3/var/lib/dpkg/status
MEDIUM CVE-2026-19487perl-base5.40.1-7ubuntu0.1 5.40.1-7ubuntu0.2/var/lib/dpkg/status
MEDIUM CVE-2026-42497perl-base5.40.1-7ubuntu0.1 /var/lib/dpkg/status
MEDIUM CVE-2026-77117libc-bin2.43-2ubuntu2.3 2.43-2ubuntu2.4/var/lib/dpkg/status
MEDIUM CVE-2026-80489libc-bin2.43-2ubuntu2.3 2.43-2ubuntu2.4/var/lib/dpkg/status
MEDIUM CVE-2026-77117libc-gconv-modules-extra2.43-2ubuntu2.3 2.43-2ubuntu2.4/var/lib/dpkg/status
MEDIUM CVE-2026-80489libc-gconv-modules-extra2.43-2ubuntu2.3 2.43-2ubuntu2.4/var/lib/dpkg/status
MEDIUM CVE-2026-77117libc62.43-2ubuntu2.3 2.43-2ubuntu2.4/var/lib/dpkg/status
MEDIUM CVE-2026-80489libc62.43-2ubuntu2.3 2.43-2ubuntu2.4/var/lib/dpkg/status
MEDIUM CVE-2026-19499libc-bin2.43-2ubuntu2.3 2.43-2ubuntu2.4/var/lib/dpkg/status
MEDIUM CVE-2026-19499libc-gconv-modules-extra2.43-2ubuntu2.3 2.43-2ubuntu2.4/var/lib/dpkg/status
MEDIUM CVE-2026-13595login1:4.16.0-2+really2.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-13595mount2.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-13595util-linux2.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-15534perl-base5.40.1-7ubuntu0.1 5.40.1-7ubuntu0.2/var/lib/dpkg/status
MEDIUM CVE-2026-35363rust-coreutils0.8.0-0ubuntu3 /var/lib/dpkg/status
MEDIUM CVE-2026-35341rust-coreutils0.8.0-0ubuntu3 /var/lib/dpkg/status
MEDIUM CVE-2026-54369libacl12.3.2-2 /var/lib/dpkg/status
MEDIUM CVE-2026-18374libc-bin2.43-2ubuntu2.3 /var/lib/dpkg/status
MEDIUM CVE-2026-18374libc-gconv-modules-extra2.43-2ubuntu2.3 /var/lib/dpkg/status
MEDIUM CVE-2026-18374libc62.43-2ubuntu2.3 /var/lib/dpkg/status
MEDIUM CVE-2026-35352rust-coreutils0.8.0-0ubuntu3 /var/lib/dpkg/status
MEDIUM CVE-2026-54371libattr11:2.5.2-4 1:2.5.2-4ubuntu0.1/var/lib/dpkg/status
MEDIUM CVE-2026-18508tar1.35+dfsg-4ubuntu0.4 /var/lib/dpkg/status
MEDIUM CVE-2026-35368rust-coreutils0.8.0-0ubuntu3 /var/lib/dpkg/status
MEDIUM CVE-2026-35348rust-coreutils0.8.0-0ubuntu3 /var/lib/dpkg/status
MEDIUM CVE-2026-35351rust-coreutils0.8.0-0ubuntu3 /var/lib/dpkg/status
MEDIUM CVE-2026-56391coreutils9.5-1ubuntu2+0.0.0~ubuntu25 9.7-3ubuntu2.1/var/lib/dpkg/status
MEDIUM CVE-2026-56391gnu-coreutils9.7-3ubuntu2 9.7-3ubuntu2.1/var/lib/dpkg/status
MEDIUM CVE-2025-15649perl-base5.40.1-7ubuntu0.1 /var/lib/dpkg/status
MEDIUM CVE-2026-35350rust-coreutils0.8.0-0ubuntu3 /var/lib/dpkg/status
MEDIUM CVE-2026-78409bsdutils1:2.41.3-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-76642bsdutils1:2.41.3-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-76642libblkid12.41.3-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-76642libmount12.41.3-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-76642libsmartcols12.41.3-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-76642libuuid12.41.3-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-76642login1:4.16.0-2+really2.41.3-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-76642mount2.41.3-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-76642util-linux2.41.3-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-13595libuuid12.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-13595libsmartcols12.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-13595libmount12.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-13595libblkid12.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-13595bsdutils1:2.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
LOW CVE-2024-2236libgcrypt201.12.0-2ubuntu1 1.12.0-2ubuntu1.1/var/lib/dpkg/status
LOW CVE-2026-27171zlib1g1:1.3.dfsg+really1.3.1-1ubuntu3 1:1.3.dfsg+really1.3.1-1ubuntu3.1/var/lib/dpkg/status
LOW CVE-2026-40228libudev1259.5-0ubuntu3.4 /var/lib/dpkg/status
LOW CVE-2026-75803openssl-provider-legacy3.5.5-1ubuntu3.4 3.5.5-1ubuntu3.5/var/lib/dpkg/status
LOW CVE-2026-75803openssl3.5.5-1ubuntu3.4 3.5.5-1ubuntu3.5/var/lib/dpkg/status
LOW CVE-2026-75803libssl3t643.5.5-1ubuntu3.4 3.5.5-1ubuntu3.5/var/lib/dpkg/status
LOW CVE-2026-40228libsystemd0259.5-0ubuntu3.4 /var/lib/dpkg/status
LOW CVE-2025-5278gnu-coreutils9.7-3ubuntu2 9.7-3ubuntu2.1/var/lib/dpkg/status
LOW CVE-2025-5278coreutils9.5-1ubuntu2+0.0.0~ubuntu25 9.7-3ubuntu2.1/var/lib/dpkg/status
LOW CVE-2026-42250libbz2-1.01.0.8-6build2 1.0.8-6ubuntu0.1/var/lib/dpkg/status
LOW CVE-2024-56433passwd1:4.17.4-2ubuntu3 /var/lib/dpkg/status
LOW CVE-2024-56433login.defs1:4.17.4-2ubuntu3 /var/lib/dpkg/status
LOW CVE-2026-57062gpgv2.4.8-4ubuntu3 2.4.8-4ubuntu3.1/var/lib/dpkg/status

ghcr.io/openvoxproject/openvoxdb

GitHub Container Registry

Downloads

185,517 downloads

ghcr.io/openvoxproject/openvoxdb:latest (2026-08-27)

Trivy

HIGH 9 MEDIUM 146 LOW 14
SeverityIDPackageInstalledFixedTitle / target
HIGH CVE-2026-56862stdlibv1.26.5 1.25.13, 1.26.6, 1.27.0-rc.3crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages — usr/bin/pebble
HIGH CVE-2026-56860stdlibv1.26.5 1.25.13, 1.26.6, 1.27.0-rc.3net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution — usr/bin/pebble
HIGH CVE-2026-56859stdlibv1.26.5 1.25.13, 1.26.6, 1.27.0-rc.3encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue — usr/bin/pebble
HIGH CVE-2026-56858stdlibv1.26.5 1.25.13, 1.26.6, 1.27.0-rc.3html/template: golang: Go html/template: Cross-Site Scripting via pathological input — usr/bin/pebble
HIGH CVE-2026-56853stdlibv1.26.5 1.25.13, 1.26.6, 1.27.0-rc.3net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service — usr/bin/pebble
HIGH CVE-2026-46600stdlibv1.26.5 1.26.6, 1.27.0-rc.3golang.org/x/net/dns/dnsmessage: golang.org/x/net/dns/dnsmessage: Denial of Service via invalid DNS record parsing — usr/bin/pebble
HIGH CVE-2026-39821stdlibv1.26.5 1.25.13, 1.26.6, 1.27.0-rc.3golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing — usr/bin/pebble
HIGH CVE-2026-33818stdlibv1.26.5 1.25.13, 1.26.6, 1.27.0-rc.3encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal — usr/bin/pebble
HIGH CVE-2022-41404org.ini4j:ini4j0.5.4 org.ini4j: unspecified DoS — Java
MEDIUM CVE-2026-15534perl5.40.1-7ubuntu0.1 5.40.1-7ubuntu0.2perl: Perl: Arbitrary code execution via out-of-bounds memory access in regular expression engine. — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-13221perl5.40.1-7ubuntu0.1 5.40.1-7ubuntu0.3perl: Perl: Incorrect regular expression processing via large regular expressions — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-12087perl5.40.1-7ubuntu0.1 5.40.1-7ubuntu0.3perl-Socket: perl-Socket: Information Disclosure due to Out-of-Bounds Read — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-53615mount2.41.3-3ubuntu2 2.41.3-3ubuntu2.2[Integer Overflow or Wraparound in libblkid/src/partitions/dos.c] — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-53614mount2.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: SUID mount(8) allows nosuid/noexec bypass via LIBMOUNT_FORCE_MOUNT2 — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-53613mount2.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-53612mount2.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: TOCTOU in the mount program when applying post-mount ownership/mode changes — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-3184mount2.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: Access control bypass due to improper hostname canonicalization — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-27456mount2.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: TOCTOU in the mount program when setting up loop devices — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-19487perl5.40.1-7ubuntu0.1 5.40.1-7ubuntu0.2perl: Perl: Incorrect regular expression matching can lead to wrong access or filtering decisions. — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-57432perl5.40.1-7ubuntu0.1 5.40.1-7ubuntu0.3perl: Perl: Information disclosure via integer overflow in pack/unpack operations — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-57433perl5.40.1-7ubuntu0.1 5.40.1-7ubuntu0.3Storable: Storable: Denial of Service via signed integer overflow in deserialization — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-12087perl-base5.40.1-7ubuntu0.1 5.40.1-7ubuntu0.3perl-Socket: perl-Socket: Information Disclosure due to Out-of-Bounds Read — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-13221perl-base5.40.1-7ubuntu0.1 5.40.1-7ubuntu0.3perl: Perl: Incorrect regular expression processing via large regular expressions — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-15534perl-base5.40.1-7ubuntu0.1 5.40.1-7ubuntu0.2perl: Perl: Arbitrary code execution via out-of-bounds memory access in regular expression engine. — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-19487perl-base5.40.1-7ubuntu0.1 5.40.1-7ubuntu0.2perl: Perl: Incorrect regular expression matching can lead to wrong access or filtering decisions. — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-57432perl-base5.40.1-7ubuntu0.1 5.40.1-7ubuntu0.3perl: Perl: Information disclosure via integer overflow in pack/unpack operations — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-57433perl-base5.40.1-7ubuntu0.1 5.40.1-7ubuntu0.3Storable: Storable: Denial of Service via signed integer overflow in deserialization — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-53613libblkid12.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-66033libssh2-1t641.11.1-1ubuntu0.26.04.3 1.11.1-1ubuntu0.26.04.4libssh2: libssh2: Denial of Service via integer underflow in AES-GCM cipher negotiation — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-66035libssh2-1t641.11.1-1ubuntu0.26.04.3 1.11.1-1ubuntu0.26.04.4libssh2: libssh2: Arbitrary code execution via heap buffer overflow during SSH negotiation — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-13595libuuid12.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: heap use-after-free in libblkid nested partition probing — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-27456libuuid12.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: TOCTOU in the mount program when setting up loop devices — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-3184libuuid12.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: Access control bypass due to improper hostname canonicalization — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-53612libuuid12.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: TOCTOU in the mount program when applying post-mount ownership/mode changes — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-53613libuuid12.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-53614libuuid12.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: SUID mount(8) allows nosuid/noexec bypass via LIBMOUNT_FORCE_MOUNT2 — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-53615libuuid12.41.3-3ubuntu2 2.41.3-3ubuntu2.2[Integer Overflow or Wraparound in libblkid/src/partitions/dos.c] — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-13595login1:4.16.0-2+really2.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: heap use-after-free in libblkid nested partition probing — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-27456login1:4.16.0-2+really2.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: TOCTOU in the mount program when setting up loop devices — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-3184login1:4.16.0-2+really2.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: Access control bypass due to improper hostname canonicalization — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-53612login1:4.16.0-2+really2.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: TOCTOU in the mount program when applying post-mount ownership/mode changes — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-53613login1:4.16.0-2+really2.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-53614login1:4.16.0-2+really2.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: SUID mount(8) allows nosuid/noexec bypass via LIBMOUNT_FORCE_MOUNT2 — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-53615login1:4.16.0-2+really2.41.3-3ubuntu2 2.41.3-3ubuntu2.2[Integer Overflow or Wraparound in libblkid/src/partitions/dos.c] — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-13595mount2.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: heap use-after-free in libblkid nested partition probing — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-35364rust-coreutils0.8.0-0ubuntu3 A Time-of-Check to Time-of-Use (TOCTOU) race condition exists in the m ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-35367rust-coreutils0.8.0-0ubuntu3 The nohup utility in uutils coreutils creates its default output file, ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-35368rust-coreutils0.8.0-0ubuntu3 A vulnerability exists in the chroot utility of uutils coreutils when ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-35370rust-coreutils0.8.0-0ubuntu3 The id utility in uutils coreutils miscalculates the groups= section o ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-35371rust-coreutils0.8.0-0ubuntu3 The id utility in uutils coreutils exhibits incorrect behavior in its ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-35373rust-coreutils0.8.0-0ubuntu3 A logic error in the ln utility of uutils coreutils causes the program ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-35374rust-coreutils0.8.0-0ubuntu3 A Time-of-Check to Time-of-Use (TOCTOU) vulnerability exists in the sp ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-35377rust-coreutils0.8.0-0ubuntu3 A logic error in the env utility of uutils coreutils causes a failure ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-18477tar1.35+dfsg-4ubuntu0.4 tar: tar: TOCTOU in incremental dumpdir 'X' rename handling allows restore path escape — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-18508tar1.35+dfsg-4ubuntu0.4 tar: tar: --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-13595util-linux2.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: heap use-after-free in libblkid nested partition probing — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-27456util-linux2.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: TOCTOU in the mount program when setting up loop devices — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-3184util-linux2.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: Access control bypass due to improper hostname canonicalization — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-53612util-linux2.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: TOCTOU in the mount program when applying post-mount ownership/mode changes — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-53613util-linux2.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-53614util-linux2.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: SUID mount(8) allows nosuid/noexec bypass via LIBMOUNT_FORCE_MOUNT2 — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-53615util-linux2.41.3-3ubuntu2 2.41.3-3ubuntu2.2[Integer Overflow or Wraparound in libblkid/src/partitions/dos.c] — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-85091zlib1g1:1.3.dfsg+really1.3.1-1ubuntu3 zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vul ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-12087perl-modules-5.405.40.1-7ubuntu0.1 5.40.1-7ubuntu0.3perl-Socket: perl-Socket: Information Disclosure due to Out-of-Bounds Read — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-13221perl-modules-5.405.40.1-7ubuntu0.1 5.40.1-7ubuntu0.3perl: Perl: Incorrect regular expression processing via large regular expressions — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-15534perl-modules-5.405.40.1-7ubuntu0.1 5.40.1-7ubuntu0.2perl: Perl: Arbitrary code execution via out-of-bounds memory access in regular expression engine. — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-19487perl-modules-5.405.40.1-7ubuntu0.1 5.40.1-7ubuntu0.2perl: Perl: Incorrect regular expression matching can lead to wrong access or filtering decisions. — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-57432perl-modules-5.405.40.1-7ubuntu0.1 5.40.1-7ubuntu0.3perl: Perl: Information disclosure via integer overflow in pack/unpack operations — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-57433perl-modules-5.405.40.1-7ubuntu0.1 5.40.1-7ubuntu0.3Storable: Storable: Denial of Service via signed integer overflow in deserialization — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-35341rust-coreutils0.8.0-0ubuntu3 A vulnerability in uutils coreutils mkfifo allows for the unauthorized ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-35344rust-coreutils0.8.0-0ubuntu3 The dd utility in uutils coreutils suppresses errors during file trunc ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-35345rust-coreutils0.8.0-0ubuntu3 A vulnerability in the tail utility of uutils coreutils allows for the ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-35348rust-coreutils0.8.0-0ubuntu3 The sort utility in uutils coreutils is vulnerable to a process panic ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-35350rust-coreutils0.8.0-0ubuntu3 The cp utility in uutils coreutils fails to properly handle setuid and ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-35351rust-coreutils0.8.0-0ubuntu3 The mv utility in uutils coreutils fails to preserve file ownership du ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-35352rust-coreutils0.8.0-0ubuntu3 A Time-of-Check to Time-of-Use (TOCTOU) race condition exists in the m ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-35354rust-coreutils0.8.0-0ubuntu3 A Time-of-Check to Time-of-Use (TOCTOU) vulnerability exists in the mv ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-35357rust-coreutils0.8.0-0ubuntu3 The cp utility in uutils coreutils is vulnerable to an information dis ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-35359rust-coreutils0.8.0-0ubuntu3 A Time-of-Check to Time-of-Use (TOCTOU) vulnerability in the cp utilit ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-35360rust-coreutils0.8.0-0ubuntu3 The touch utility in uutils coreutils is vulnerable to a Time-of-Check ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-35363rust-coreutils0.8.0-0ubuntu3 A vulnerability in the rm utility of uutils coreutils allows the bypas ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-53614libblkid12.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: SUID mount(8) allows nosuid/noexec bypass via LIBMOUNT_FORCE_MOUNT2 — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-53615libblkid12.41.3-3ubuntu2 2.41.3-3ubuntu2.2[Integer Overflow or Wraparound in libblkid/src/partitions/dos.c] — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-18374libc-bin2.43-2ubuntu2.3 glibc: glibc: Heap buffer overflow via attacker-controlled fopen mode string — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-19499libc-bin2.43-2ubuntu2.3 2.43-2ubuntu2.4glibc: Buffer Overflow in strfmon right-justification padding — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-19542libc-bin2.43-2ubuntu2.3 2.43-2ubuntu2.4glibc: Fix out-of-bounds array write in tdelete — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-6368libc-bin2.43-2ubuntu2.3 2.43-2ubuntu2.4glibc: glibc: Process abort due to invalid memory in wordexp — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-6791libc-bin2.43-2ubuntu2.3 2.43-2ubuntu2.4glibc: Glibc: Denial of Service via stack exhaustion during tilde expansion — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-77117libc-bin2.43-2ubuntu2.3 2.43-2ubuntu2.4glibc: Non-progress DoS in SHIFT_JISX0213 -&gt — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-80489libc-bin2.43-2ubuntu2.3 2.43-2ubuntu2.4glibc: Non-progress DoS in EUC_JISX0213 -> UCS-4 conversion state — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-18374libc-gconv-modules-extra2.43-2ubuntu2.3 glibc: glibc: Heap buffer overflow via attacker-controlled fopen mode string — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-19499libc-gconv-modules-extra2.43-2ubuntu2.3 2.43-2ubuntu2.4glibc: Buffer Overflow in strfmon right-justification padding — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-19542libc-gconv-modules-extra2.43-2ubuntu2.3 2.43-2ubuntu2.4glibc: Fix out-of-bounds array write in tdelete — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-6368libc-gconv-modules-extra2.43-2ubuntu2.3 2.43-2ubuntu2.4glibc: glibc: Process abort due to invalid memory in wordexp — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-6791libc-gconv-modules-extra2.43-2ubuntu2.3 2.43-2ubuntu2.4glibc: Glibc: Denial of Service via stack exhaustion during tilde expansion — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-77117libc-gconv-modules-extra2.43-2ubuntu2.3 2.43-2ubuntu2.4glibc: Non-progress DoS in SHIFT_JISX0213 -&gt — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-80489libc-gconv-modules-extra2.43-2ubuntu2.3 2.43-2ubuntu2.4glibc: Non-progress DoS in EUC_JISX0213 -> UCS-4 conversion state — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-18374libc62.43-2ubuntu2.3 glibc: glibc: Heap buffer overflow via attacker-controlled fopen mode string — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-19499libc62.43-2ubuntu2.3 2.43-2ubuntu2.4glibc: Buffer Overflow in strfmon right-justification padding — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-19542libc62.43-2ubuntu2.3 2.43-2ubuntu2.4glibc: Fix out-of-bounds array write in tdelete — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-6368libc62.43-2ubuntu2.3 2.43-2ubuntu2.4glibc: glibc: Process abort due to invalid memory in wordexp — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-13595bsdutils1:2.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: heap use-after-free in libblkid nested partition probing — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-27456bsdutils1:2.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: TOCTOU in the mount program when setting up loop devices — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-3184bsdutils1:2.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: Access control bypass due to improper hostname canonicalization — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-53612bsdutils1:2.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: TOCTOU in the mount program when applying post-mount ownership/mode changes — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-53613bsdutils1:2.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-53614bsdutils1:2.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: SUID mount(8) allows nosuid/noexec bypass via LIBMOUNT_FORCE_MOUNT2 — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-53615bsdutils1:2.41.3-3ubuntu2 2.41.3-3ubuntu2.2[Integer Overflow or Wraparound in libblkid/src/partitions/dos.c] — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-13608curl8.18.0-1ubuntu2.4 A flaw in the libcurl SASL negotiation for LDAP authentication allows ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-18924curl8.18.0-1ubuntu2.4 curl: libcurl: Use-after-free in HTTP/2 Server Push with shared connections — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-19931curl8.18.0-1ubuntu2.4 curl: libcurl: Information disclosure via incorrect connection reuse with Negotiate authentication — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-80229curl8.18.0-1ubuntu2.4 When performing transfers via libcurl\u2019s multi interface, pooled T ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-80230curl8.18.0-1ubuntu2.4 When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that di ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-80255curl8.18.0-1ubuntu2.4 A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instea ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-82209curl8.18.0-1ubuntu2.4 When libpsl support is enabled, libcurl fails to enforce the Public Su ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-53910diffutils1:3.12-1 1:3.12-1ubuntu0.1diffutils: heap‑based buffer overflow due to multiple signed integer overflows in line‑mapping calculations — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-56391gnu-coreutils9.7-3ubuntu2 9.7-3ubuntu2.1coreutils: GNU coreutils uniq: Denial of Service and information disclosure via out-of-bounds read with multibyte input — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-54371libattr11:2.5.2-4 1:2.5.2-4ubuntu0.1attr: attr: Symlink Traversal Privilege Escalation via getfattr and setfattr — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-13595libblkid12.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: heap use-after-free in libblkid nested partition probing — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-27456libblkid12.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: TOCTOU in the mount program when setting up loop devices — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-3184libblkid12.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: Access control bypass due to improper hostname canonicalization — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-53612libblkid12.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: TOCTOU in the mount program when applying post-mount ownership/mode changes — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-6791libc62.43-2ubuntu2.3 2.43-2ubuntu2.4glibc: Glibc: Denial of Service via stack exhaustion during tilde expansion — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-53613libmount12.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-53614libmount12.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: SUID mount(8) allows nosuid/noexec bypass via LIBMOUNT_FORCE_MOUNT2 — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-53615libmount12.41.3-3ubuntu2 2.41.3-3ubuntu2.2[Integer Overflow or Wraparound in libblkid/src/partitions/dos.c] — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-13757libp11-kit00.26.2-2 p11-kit: Stack exhaustion via unbounded recursion in RPC attribute parsing — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-12087libperl5.405.40.1-7ubuntu0.1 5.40.1-7ubuntu0.3perl-Socket: perl-Socket: Information Disclosure due to Out-of-Bounds Read — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-13221libperl5.405.40.1-7ubuntu0.1 5.40.1-7ubuntu0.3perl: Perl: Incorrect regular expression processing via large regular expressions — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-15534libperl5.405.40.1-7ubuntu0.1 5.40.1-7ubuntu0.2perl: Perl: Arbitrary code execution via out-of-bounds memory access in regular expression engine. — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-19487libperl5.405.40.1-7ubuntu0.1 5.40.1-7ubuntu0.2perl: Perl: Incorrect regular expression matching can lead to wrong access or filtering decisions. — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-57432libperl5.405.40.1-7ubuntu0.1 5.40.1-7ubuntu0.3perl: Perl: Information disclosure via integer overflow in pack/unpack operations — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-57433libperl5.405.40.1-7ubuntu0.1 5.40.1-7ubuntu0.3Storable: Storable: Denial of Service via signed integer overflow in deserialization — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-13595libsmartcols12.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: heap use-after-free in libblkid nested partition probing — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-27456libsmartcols12.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: TOCTOU in the mount program when setting up loop devices — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-3184libsmartcols12.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: Access control bypass due to improper hostname canonicalization — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-53612libsmartcols12.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: TOCTOU in the mount program when applying post-mount ownership/mode changes — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-53613libsmartcols12.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-53614libsmartcols12.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: SUID mount(8) allows nosuid/noexec bypass via LIBMOUNT_FORCE_MOUNT2 — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-53615libsmartcols12.41.3-3ubuntu2 2.41.3-3ubuntu2.2[Integer Overflow or Wraparound in libblkid/src/partitions/dos.c] — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-39113libsqlite3-03.46.1-9ubuntu0.2 3.46.1-9ubuntu0.3Buffer Overflow vulnerability in SQLite affected version source s ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-66032libssh2-1t641.11.1-1ubuntu0.26.04.3 1.11.1-1ubuntu0.26.04.4libssh2: libssh2: Arbitrary code execution via double-free in SFTP session — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-77117libc62.43-2ubuntu2.3 2.43-2ubuntu2.4glibc: Non-progress DoS in SHIFT_JISX0213 -&gt — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-80489libc62.43-2ubuntu2.3 2.43-2ubuntu2.4glibc: Non-progress DoS in EUC_JISX0213 -> UCS-4 conversion state — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-13608libcurl4t648.18.0-1ubuntu2.4 A flaw in the libcurl SASL negotiation for LDAP authentication allows ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-18924libcurl4t648.18.0-1ubuntu2.4 curl: libcurl: Use-after-free in HTTP/2 Server Push with shared connections — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-19931libcurl4t648.18.0-1ubuntu2.4 curl: libcurl: Information disclosure via incorrect connection reuse with Negotiate authentication — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-80229libcurl4t648.18.0-1ubuntu2.4 When performing transfers via libcurl\u2019s multi interface, pooled T ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-80230libcurl4t648.18.0-1ubuntu2.4 When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that di ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-80255libcurl4t648.18.0-1ubuntu2.4 A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instea ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-82209libcurl4t648.18.0-1ubuntu2.4 When libpsl support is enabled, libcurl fails to enforce the Public Su ... — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-53612libmount12.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: TOCTOU in the mount program when applying post-mount ownership/mode changes — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-3184libmount12.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: Access control bypass due to improper hostname canonicalization — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-27456libmount12.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: TOCTOU in the mount program when setting up loop devices — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
MEDIUM CVE-2026-13595libmount12.41.3-3ubuntu2 2.41.3-3ubuntu2.2util-linux: util-linux: heap use-after-free in libblkid nested partition probing — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
LOW CVE-2025-5278gnu-coreutils9.7-3ubuntu2 9.7-3ubuntu2.1coreutils: Heap Buffer Under-Read in GNU Coreutils sort via Key Specification — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
LOW CVE-2026-57062gpgv2.4.8-4ubuntu3 2.4.8-4ubuntu3.1GnuPG: Incorrect cryptographic message parsing — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
LOW CVE-2026-75803openssl3.5.5-1ubuntu3.4 3.5.5-1ubuntu3.5openssl: openssl: AEAD forgeries possible with empty ciphertext in EVP_Cipher() — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
LOW CVE-2024-2236libgcrypt201.12.0-2ubuntu1 1.12.0-2ubuntu1.1libgcrypt: vulnerable to Marvin Attack — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
LOW CVE-2026-27171zlib1g1:1.3.dfsg+really1.3.1-1ubuntu3 1:1.3.dfsg+really1.3.1-1ubuntu3.1zlib: zlib: Denial of Service via infinite loop in CRC32 combine functions — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
LOW CVE-2026-8932libcurl4t648.18.0-1ubuntu2.4 8.18.0-1ubuntu2.5libcurl: libcurl: Security feature bypass due to improper mTLS connection reuse — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
LOW CVE-2026-8932curl8.18.0-1ubuntu2.4 8.18.0-1ubuntu2.5libcurl: libcurl: Security feature bypass due to improper mTLS connection reuse — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
LOW CVE-2024-56433login.defs1:4.17.4-2ubuntu3 shadow-utils: Default subordinate ID configuration in /etc/login.defs could lead to compromise — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
LOW CVE-2026-40228libudev1259.5-0ubuntu3.4 systemd: systemd-journald: Unintended output to user terminals via logger command — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
LOW CVE-2026-40228libsystemd0259.5-0ubuntu3.4 systemd: systemd-journald: Unintended output to user terminals via logger command — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
LOW CVE-2026-75803libssl3t643.5.5-1ubuntu3.4 3.5.5-1ubuntu3.5openssl: openssl: AEAD forgeries possible with empty ciphertext in EVP_Cipher() — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
LOW CVE-2024-56433passwd1:4.17.4-2ubuntu3 shadow-utils: Default subordinate ID configuration in /etc/login.defs could lead to compromise — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
LOW CVE-2026-42250libbz2-1.01.0.8-6build2 1.0.8-6ubuntu0.1bzip2: bzip2: Denial of Service in bzip2recover via a specially crafted file — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)
LOW CVE-2026-75803openssl-provider-legacy3.5.5-1ubuntu3.4 3.5.5-1ubuntu3.5openssl: openssl: AEAD forgeries possible with empty ciphertext in EVP_Cipher() — ghcr.io/openvoxproject/openvoxdb:latest (ubuntu 26.04)

Grype

HIGH 5 MEDIUM 227 LOW 16
SeverityIDPackageInstalledFixedTitle / target
HIGH GO-2026-6089stdlibgo1.26.5 1.25.13, 1.26.6, 1.27.0-rc.3When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this. — /usr/bin/pebble
HIGH GO-2026-5972stdlibgo1.26.5 1.25.13, 1.26.6, 1.27.0-rc.3Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures. — /usr/bin/pebble
HIGH GO-2026-6090stdlibgo1.26.5 1.25.13, 1.26.6, 1.27.0-rc.3Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely. — /usr/bin/pebble
HIGH GO-2026-5026stdlibgo1.26.5 1.25.13, 1.26.6, 1.27.0-rc.3The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com". — /usr/bin/pebble
HIGH GHSA-jr6h-r7vg-f9mcini4j0.5.4 org.ini4j allows attackers to cause a Denial of Service (DoS) — /opt/puppetlabs/server/apps/puppetdb/puppetdb.jar
MEDIUM CVE-2026-78409bsdutils1:2.41.3-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-78409libblkid12.41.3-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-78409libmount12.41.3-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-78409libsmartcols12.41.3-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-78409libuuid12.41.3-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-35350rust-coreutils0.8.0-0ubuntu3 /var/lib/dpkg/status
MEDIUM CVE-2026-3184mount2.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-78409login1:4.16.0-2+really2.41.3-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-78409mount2.41.3-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-78409util-linux2.41.3-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-35371rust-coreutils0.8.0-0ubuntu3 /var/lib/dpkg/status
MEDIUM CVE-2026-35373rust-coreutils0.8.0-0ubuntu3 /var/lib/dpkg/status
MEDIUM CVE-2026-27456bsdutils1:2.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-27456libblkid12.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-27456libmount12.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-27456libsmartcols12.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-27456libuuid12.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-27456login1:4.16.0-2+really2.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-27456mount2.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-27456util-linux2.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-35344rust-coreutils0.8.0-0ubuntu3 /var/lib/dpkg/status
MEDIUM CVE-2026-35367rust-coreutils0.8.0-0ubuntu3 /var/lib/dpkg/status
MEDIUM CVE-2026-78408bsdutils1:2.41.3-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-78408libblkid12.41.3-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-78408libmount12.41.3-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-78408libsmartcols12.41.3-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-78408libuuid12.41.3-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-78408login1:4.16.0-2+really2.41.3-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-78408mount2.41.3-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-78408util-linux2.41.3-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-13595libmount12.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-13595libsmartcols12.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-13595libuuid12.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-13595login1:4.16.0-2+really2.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-13595mount2.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-13595util-linux2.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-15534libperl5.405.40.1-7ubuntu0.1 5.40.1-7ubuntu0.2/var/lib/dpkg/status
MEDIUM CVE-2026-15534perl5.40.1-7ubuntu0.1 5.40.1-7ubuntu0.2/var/lib/dpkg/status
MEDIUM CVE-2026-15534perl-base5.40.1-7ubuntu0.1 5.40.1-7ubuntu0.2/var/lib/dpkg/status
MEDIUM CVE-2026-15534perl-modules-5.405.40.1-7ubuntu0.1 5.40.1-7ubuntu0.2/var/lib/dpkg/status
MEDIUM CVE-2026-35363rust-coreutils0.8.0-0ubuntu3 /var/lib/dpkg/status
MEDIUM CVE-2026-35341rust-coreutils0.8.0-0ubuntu3 /var/lib/dpkg/status
MEDIUM CVE-2026-54369libacl12.3.2-2 /var/lib/dpkg/status
MEDIUM CVE-2026-18374libc-bin2.43-2ubuntu2.3 /var/lib/dpkg/status
MEDIUM CVE-2026-18374libc-gconv-modules-extra2.43-2ubuntu2.3 /var/lib/dpkg/status
MEDIUM CVE-2026-18374libc62.43-2ubuntu2.3 /var/lib/dpkg/status
MEDIUM CVE-2026-13757libp11-kit00.26.2-2 /var/lib/dpkg/status
MEDIUM CVE-2026-35352rust-coreutils0.8.0-0ubuntu3 /var/lib/dpkg/status
MEDIUM CVE-2026-54371libattr11:2.5.2-4 1:2.5.2-4ubuntu0.1/var/lib/dpkg/status
MEDIUM CVE-2026-18508tar1.35+dfsg-4ubuntu0.4 /var/lib/dpkg/status
MEDIUM CVE-2026-35368rust-coreutils0.8.0-0ubuntu3 /var/lib/dpkg/status
MEDIUM CVE-2026-35348rust-coreutils0.8.0-0ubuntu3 /var/lib/dpkg/status
MEDIUM CVE-2026-35351rust-coreutils0.8.0-0ubuntu3 /var/lib/dpkg/status
MEDIUM CVE-2026-56391coreutils9.5-1ubuntu2+0.0.0~ubuntu25 9.7-3ubuntu2.1/var/lib/dpkg/status
MEDIUM CVE-2026-56391gnu-coreutils9.7-3ubuntu2 9.7-3ubuntu2.1/var/lib/dpkg/status
MEDIUM CVE-2025-15649libperl5.405.40.1-7ubuntu0.1 /var/lib/dpkg/status
MEDIUM CVE-2025-15649perl5.40.1-7ubuntu0.1 /var/lib/dpkg/status
MEDIUM CVE-2025-15649perl-base5.40.1-7ubuntu0.1 /var/lib/dpkg/status
MEDIUM CVE-2025-15649perl-modules-5.405.40.1-7ubuntu0.1 /var/lib/dpkg/status
MEDIUM CVE-2026-89161libpcre2-8-010.46-1build1 /var/lib/dpkg/status
MEDIUM CVE-2026-53615bsdutils1:2.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-53612libblkid12.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-53613libblkid12.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-53614libblkid12.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-53615libblkid12.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-53612libmount12.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-53613libmount12.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-53614libmount12.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-53615libmount12.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-53612libsmartcols12.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-53613libsmartcols12.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-53614libsmartcols12.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-53615libsmartcols12.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-53612libuuid12.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-53613libuuid12.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-53614libuuid12.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-53615libuuid12.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-53612login1:4.16.0-2+really2.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-53613login1:4.16.0-2+really2.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-53614login1:4.16.0-2+really2.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-53615login1:4.16.0-2+really2.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-53612mount2.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-53613mount2.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-53614mount2.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-53615mount2.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-53612util-linux2.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-53613util-linux2.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-53614util-linux2.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-53615util-linux2.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-35370rust-coreutils0.8.0-0ubuntu3 /var/lib/dpkg/status
MEDIUM CVE-2026-6368libc-bin2.43-2ubuntu2.3 2.43-2ubuntu2.4/var/lib/dpkg/status
MEDIUM CVE-2026-6368libc-gconv-modules-extra2.43-2ubuntu2.3 2.43-2ubuntu2.4/var/lib/dpkg/status
MEDIUM CVE-2026-6368libc62.43-2ubuntu2.3 2.43-2ubuntu2.4/var/lib/dpkg/status
MEDIUM CVE-2026-18938libp11-kit00.26.2-2 /var/lib/dpkg/status
MEDIUM CVE-2026-35359rust-coreutils0.8.0-0ubuntu3 /var/lib/dpkg/status
MEDIUM CVE-2026-89162libpcre2-8-010.46-1build1 /var/lib/dpkg/status
MEDIUM CVE-2026-35360rust-coreutils0.8.0-0ubuntu3 /var/lib/dpkg/status
MEDIUM CVE-2026-89156libpcre2-8-010.46-1build1 /var/lib/dpkg/status
MEDIUM CVE-2026-89157libpcre2-8-010.46-1build1 /var/lib/dpkg/status
MEDIUM CVE-2026-35377rust-coreutils0.8.0-0ubuntu3 /var/lib/dpkg/status
MEDIUM CVE-2026-35345rust-coreutils0.8.0-0ubuntu3 /var/lib/dpkg/status
MEDIUM CVE-2026-78410bsdutils1:2.41.3-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-78410libblkid12.41.3-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-78410libmount12.41.3-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-78410libsmartcols12.41.3-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-78410libuuid12.41.3-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-78410login1:4.16.0-2+really2.41.3-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-78410mount2.41.3-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-78410util-linux2.41.3-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-35354rust-coreutils0.8.0-0ubuntu3 /var/lib/dpkg/status
MEDIUM CVE-2026-35364rust-coreutils0.8.0-0ubuntu3 /var/lib/dpkg/status
MEDIUM CVE-2026-35357rust-coreutils0.8.0-0ubuntu3 /var/lib/dpkg/status
MEDIUM CVE-2026-54370libacl12.3.2-2 /var/lib/dpkg/status
MEDIUM CVE-2026-18477tar1.35+dfsg-4ubuntu0.4 /var/lib/dpkg/status
MEDIUM CVE-2026-35374rust-coreutils0.8.0-0ubuntu3 /var/lib/dpkg/status
MEDIUM CVE-2026-53612bsdutils1:2.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-53613bsdutils1:2.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-53614bsdutils1:2.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-3184util-linux2.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-13221libperl5.405.40.1-7ubuntu0.1 5.40.1-7ubuntu0.3/var/lib/dpkg/status
MEDIUM CVE-2026-13221perl5.40.1-7ubuntu0.1 5.40.1-7ubuntu0.3/var/lib/dpkg/status
MEDIUM CVE-2026-13221perl-base5.40.1-7ubuntu0.1 5.40.1-7ubuntu0.3/var/lib/dpkg/status
MEDIUM CVE-2026-13221perl-modules-5.405.40.1-7ubuntu0.1 5.40.1-7ubuntu0.3/var/lib/dpkg/status
MEDIUM CVE-2026-19487libperl5.405.40.1-7ubuntu0.1 5.40.1-7ubuntu0.2/var/lib/dpkg/status
MEDIUM CVE-2026-19487perl5.40.1-7ubuntu0.1 5.40.1-7ubuntu0.2/var/lib/dpkg/status
MEDIUM CVE-2026-19487perl-base5.40.1-7ubuntu0.1 5.40.1-7ubuntu0.2/var/lib/dpkg/status
MEDIUM CVE-2026-19487perl-modules-5.405.40.1-7ubuntu0.1 5.40.1-7ubuntu0.2/var/lib/dpkg/status
MEDIUM CVE-2026-42497libperl5.405.40.1-7ubuntu0.1 /var/lib/dpkg/status
MEDIUM CVE-2026-42497perl5.40.1-7ubuntu0.1 /var/lib/dpkg/status
MEDIUM CVE-2026-42497perl-base5.40.1-7ubuntu0.1 /var/lib/dpkg/status
MEDIUM CVE-2026-42497perl-modules-5.405.40.1-7ubuntu0.1 /var/lib/dpkg/status
MEDIUM CVE-2026-77117libc-bin2.43-2ubuntu2.3 2.43-2ubuntu2.4/var/lib/dpkg/status
MEDIUM CVE-2026-80489libc-bin2.43-2ubuntu2.3 2.43-2ubuntu2.4/var/lib/dpkg/status
MEDIUM CVE-2026-77117libc-gconv-modules-extra2.43-2ubuntu2.3 2.43-2ubuntu2.4/var/lib/dpkg/status
MEDIUM CVE-2026-80489libc-gconv-modules-extra2.43-2ubuntu2.3 2.43-2ubuntu2.4/var/lib/dpkg/status
MEDIUM CVE-2026-77117libc62.43-2ubuntu2.3 2.43-2ubuntu2.4/var/lib/dpkg/status
MEDIUM CVE-2026-80489libc62.43-2ubuntu2.3 2.43-2ubuntu2.4/var/lib/dpkg/status
MEDIUM CVE-2026-19499libc-bin2.43-2ubuntu2.3 2.43-2ubuntu2.4/var/lib/dpkg/status
MEDIUM CVE-2026-19499libc-gconv-modules-extra2.43-2ubuntu2.3 2.43-2ubuntu2.4/var/lib/dpkg/status
MEDIUM CVE-2026-19499libc62.43-2ubuntu2.3 2.43-2ubuntu2.4/var/lib/dpkg/status
MEDIUM CVE-2026-12087libperl5.405.40.1-7ubuntu0.1 5.40.1-7ubuntu0.3/var/lib/dpkg/status
MEDIUM CVE-2026-12087perl5.40.1-7ubuntu0.1 5.40.1-7ubuntu0.3/var/lib/dpkg/status
MEDIUM CVE-2026-12087perl-base5.40.1-7ubuntu0.1 5.40.1-7ubuntu0.3/var/lib/dpkg/status
MEDIUM CVE-2026-12087perl-modules-5.405.40.1-7ubuntu0.1 5.40.1-7ubuntu0.3/var/lib/dpkg/status
MEDIUM CVE-2026-48959libperl5.405.40.1-7ubuntu0.1 /var/lib/dpkg/status
MEDIUM CVE-2026-48959perl5.40.1-7ubuntu0.1 /var/lib/dpkg/status
MEDIUM CVE-2026-48959perl-base5.40.1-7ubuntu0.1 /var/lib/dpkg/status
MEDIUM CVE-2026-19931curl8.18.0-1ubuntu2.4 /var/lib/dpkg/status
MEDIUM CVE-2026-19931libcurl4t648.18.0-1ubuntu2.4 /var/lib/dpkg/status
MEDIUM CVE-2026-80229curl8.18.0-1ubuntu2.4 /var/lib/dpkg/status
MEDIUM CVE-2026-80229libcurl4t648.18.0-1ubuntu2.4 /var/lib/dpkg/status
MEDIUM CVE-2026-18924curl8.18.0-1ubuntu2.4 /var/lib/dpkg/status
MEDIUM CVE-2026-18924libcurl4t648.18.0-1ubuntu2.4 /var/lib/dpkg/status
MEDIUM CVE-2026-80255curl8.18.0-1ubuntu2.4 /var/lib/dpkg/status
MEDIUM CVE-2026-80255libcurl4t648.18.0-1ubuntu2.4 /var/lib/dpkg/status
MEDIUM CVE-2026-13608curl8.18.0-1ubuntu2.4 /var/lib/dpkg/status
MEDIUM CVE-2026-13608libcurl4t648.18.0-1ubuntu2.4 /var/lib/dpkg/status
MEDIUM CVE-2026-66033libssh2-1t641.11.1-1ubuntu0.26.04.3 1.11.1-1ubuntu0.26.04.4/var/lib/dpkg/status
MEDIUM CVE-2026-80230curl8.18.0-1ubuntu2.4 /var/lib/dpkg/status
MEDIUM CVE-2026-80230libcurl4t648.18.0-1ubuntu2.4 /var/lib/dpkg/status
MEDIUM GO-2026-6218stdlibgo1.26.5 1.25.13, 1.26.6, 1.27.0-rc.3Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations. — /usr/bin/pebble
MEDIUM CVE-2026-82209curl8.18.0-1ubuntu2.4 /var/lib/dpkg/status
MEDIUM CVE-2026-82209libcurl4t648.18.0-1ubuntu2.4 /var/lib/dpkg/status
MEDIUM CVE-2026-66035libssh2-1t641.11.1-1ubuntu0.26.04.3 1.11.1-1ubuntu0.26.04.4/var/lib/dpkg/status
MEDIUM CVE-2026-47057openjdk-21-jre-headless21.0.12+8-1~26.04 /var/lib/dpkg/status
MEDIUM CVE-2026-9538libperl5.405.40.1-7ubuntu0.1 /var/lib/dpkg/status
MEDIUM CVE-2026-9538perl5.40.1-7ubuntu0.1 /var/lib/dpkg/status
MEDIUM CVE-2026-9538perl-base5.40.1-7ubuntu0.1 /var/lib/dpkg/status
MEDIUM CVE-2026-9538perl-modules-5.405.40.1-7ubuntu0.1 /var/lib/dpkg/status
MEDIUM CVE-2026-66032libssh2-1t641.11.1-1ubuntu0.26.04.3 1.11.1-1ubuntu0.26.04.4/var/lib/dpkg/status
MEDIUM CVE-2026-85091zlib1g1:1.3.dfsg+really1.3.1-1ubuntu3 /var/lib/dpkg/status
MEDIUM CVE-2026-3184bsdutils1:2.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-3184libblkid12.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-3184libmount12.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-3184libsmartcols12.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-3184libuuid12.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-3184login1:4.16.0-2+really2.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-7017perl5.40.1-7ubuntu0.1 /var/lib/dpkg/status
MEDIUM CVE-2026-7017perl-base5.40.1-7ubuntu0.1 /var/lib/dpkg/status
MEDIUM CVE-2026-7017perl-modules-5.405.40.1-7ubuntu0.1 /var/lib/dpkg/status
MEDIUM CVE-2026-89092libc-bin2.43-2ubuntu2.3 /var/lib/dpkg/status
MEDIUM CVE-2026-89092libc-gconv-modules-extra2.43-2ubuntu2.3 /var/lib/dpkg/status
MEDIUM CVE-2026-89092libc62.43-2ubuntu2.3 /var/lib/dpkg/status
MEDIUM CVE-2026-89158libpcre2-8-010.46-1build1 /var/lib/dpkg/status
MEDIUM CVE-2026-89160libpcre2-8-010.46-1build1 /var/lib/dpkg/status
MEDIUM CVE-2026-39113libsqlite3-03.46.1-9ubuntu0.2 /var/lib/dpkg/status
MEDIUM CVE-2026-57432libperl5.405.40.1-7ubuntu0.1 5.40.1-7ubuntu0.3/var/lib/dpkg/status
MEDIUM CVE-2026-57432perl5.40.1-7ubuntu0.1 5.40.1-7ubuntu0.3/var/lib/dpkg/status
MEDIUM CVE-2026-57432perl-base5.40.1-7ubuntu0.1 5.40.1-7ubuntu0.3/var/lib/dpkg/status
MEDIUM CVE-2026-57432perl-modules-5.405.40.1-7ubuntu0.1 5.40.1-7ubuntu0.3/var/lib/dpkg/status
MEDIUM CVE-2026-6791libc-bin2.43-2ubuntu2.3 2.43-2ubuntu2.4/var/lib/dpkg/status
MEDIUM CVE-2026-6791libc-gconv-modules-extra2.43-2ubuntu2.3 2.43-2ubuntu2.4/var/lib/dpkg/status
MEDIUM CVE-2026-6791libc62.43-2ubuntu2.3 2.43-2ubuntu2.4/var/lib/dpkg/status
MEDIUM CVE-2026-75466libjpeg-turbo82.1.5-4ubuntu4 /var/lib/dpkg/status
MEDIUM CVE-2026-76642bsdutils1:2.41.3-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-76642libblkid12.41.3-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-76642libmount12.41.3-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-76642libsmartcols12.41.3-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-76642libuuid12.41.3-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-76642login1:4.16.0-2+really2.41.3-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-76642mount2.41.3-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-76642util-linux2.41.3-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-13595bsdutils1:2.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-13595libblkid12.41.3-3ubuntu2 2.41.3-3ubuntu2.2/var/lib/dpkg/status
MEDIUM CVE-2026-7017libperl5.405.40.1-7ubuntu0.1 /var/lib/dpkg/status
MEDIUM CVE-2026-19542libc-gconv-modules-extra2.43-2ubuntu2.3 2.43-2ubuntu2.4/var/lib/dpkg/status
MEDIUM CVE-2026-19542libc-bin2.43-2ubuntu2.3 2.43-2ubuntu2.4/var/lib/dpkg/status
MEDIUM CVE-2026-70907openjdk-21-jre-headless21.0.12+8-1~26.04 /var/lib/dpkg/status
MEDIUM CVE-2026-48962perl-modules-5.405.40.1-7ubuntu0.1 /var/lib/dpkg/status
MEDIUM CVE-2026-48962perl-base5.40.1-7ubuntu0.1 /var/lib/dpkg/status
MEDIUM CVE-2026-48962perl5.40.1-7ubuntu0.1 /var/lib/dpkg/status
MEDIUM CVE-2026-48962libperl5.405.40.1-7ubuntu0.1 /var/lib/dpkg/status
MEDIUM CVE-2026-61308openjdk-21-jre-headless21.0.12+8-1~26.04 /var/lib/dpkg/status
MEDIUM CVE-2026-53910diffutils1:3.12-1 1:3.12-1ubuntu0.1/var/lib/dpkg/status
MEDIUM CVE-2026-57433perl-modules-5.405.40.1-7ubuntu0.1 5.40.1-7ubuntu0.3/var/lib/dpkg/status
MEDIUM CVE-2026-57433perl-base5.40.1-7ubuntu0.1 5.40.1-7ubuntu0.3/var/lib/dpkg/status
MEDIUM CVE-2026-57433perl5.40.1-7ubuntu0.1 5.40.1-7ubuntu0.3/var/lib/dpkg/status
MEDIUM CVE-2026-57433libperl5.405.40.1-7ubuntu0.1 5.40.1-7ubuntu0.3/var/lib/dpkg/status
MEDIUM CVE-2026-47058openjdk-21-jre-headless21.0.12+8-1~26.04 /var/lib/dpkg/status
MEDIUM CVE-2026-86145libpcre2-8-010.46-1build1 /var/lib/dpkg/status
MEDIUM CVE-2026-48959perl-modules-5.405.40.1-7ubuntu0.1 /var/lib/dpkg/status
MEDIUM CVE-2026-48961perl-modules-5.405.40.1-7ubuntu0.1 /var/lib/dpkg/status
MEDIUM CVE-2026-48961perl-base5.40.1-7ubuntu0.1 /var/lib/dpkg/status
MEDIUM CVE-2026-48961perl5.40.1-7ubuntu0.1 /var/lib/dpkg/status
MEDIUM CVE-2026-19542libc62.43-2ubuntu2.3 2.43-2ubuntu2.4/var/lib/dpkg/status
MEDIUM CVE-2026-60589openjdk-21-jre-headless21.0.12+8-1~26.04 /var/lib/dpkg/status
MEDIUM CVE-2026-48961libperl5.405.40.1-7ubuntu0.1 /var/lib/dpkg/status
LOW CVE-2024-56433passwd1:4.17.4-2ubuntu3 /var/lib/dpkg/status
LOW CVE-2018-10126libjpeg-turbo82.1.5-4ubuntu4 /var/lib/dpkg/status
LOW CVE-2025-5278gnu-coreutils9.7-3ubuntu2 9.7-3ubuntu2.1/var/lib/dpkg/status
LOW CVE-2025-5278coreutils9.5-1ubuntu2+0.0.0~ubuntu25 9.7-3ubuntu2.1/var/lib/dpkg/status
LOW CVE-2024-56433login.defs1:4.17.4-2ubuntu3 /var/lib/dpkg/status
LOW CVE-2026-57062gpgv2.4.8-4ubuntu3 2.4.8-4ubuntu3.1/var/lib/dpkg/status
LOW CVE-2026-42250libbz2-1.01.0.8-6build2 1.0.8-6ubuntu0.1/var/lib/dpkg/status
LOW CVE-2024-2236libgcrypt201.12.0-2ubuntu1 1.12.0-2ubuntu1.1/var/lib/dpkg/status
LOW CVE-2026-27171zlib1g1:1.3.dfsg+really1.3.1-1ubuntu3 1:1.3.dfsg+really1.3.1-1ubuntu3.1/var/lib/dpkg/status
LOW CVE-2026-75803libssl3t643.5.5-1ubuntu3.4 3.5.5-1ubuntu3.5/var/lib/dpkg/status
LOW CVE-2026-8932curl8.18.0-1ubuntu2.4 8.18.0-1ubuntu2.5/var/lib/dpkg/status
LOW CVE-2026-8932libcurl4t648.18.0-1ubuntu2.4 8.18.0-1ubuntu2.5/var/lib/dpkg/status
LOW CVE-2026-75803openssl-provider-legacy3.5.5-1ubuntu3.4 3.5.5-1ubuntu3.5/var/lib/dpkg/status
LOW CVE-2026-40228libsystemd0259.5-0ubuntu3.4 /var/lib/dpkg/status
LOW CVE-2026-40228libudev1259.5-0ubuntu3.4 /var/lib/dpkg/status
LOW CVE-2026-75803openssl3.5.5-1ubuntu3.4 3.5.5-1ubuntu3.5/var/lib/dpkg/status

ghcr.io/openvoxproject/openvoxdb:latest-alpine (2026-08-27)

Trivy

HIGH 8 MEDIUM 13 LOW 2 UNKNOWN 6
SeverityIDPackageInstalledFixedTitle / target
HIGH CVE-2022-41404org.ini4j:ini4j0.5.4 org.ini4j: unspecified DoS — Java
HIGH CVE-2026-78410runuser2.42.1-r0 2.42.3-r0util-linux: util-linux: restricted bind mounts do not pin the source, allowing X-mount.owner/group/mode redirection — ghcr.io/openvoxproject/openvoxdb:latest-alpine (alpine 3.24.1)
HIGH CVE-2026-78409runuser2.42.1-r0 2.42.3-r0util-linux: util-linux: X-mount.subdir detached-tree resolution can escape via intermediate symlinks — ghcr.io/openvoxproject/openvoxdb:latest-alpine (alpine 3.24.1)
HIGH CVE-2026-78408runuser2.42.1-r0 2.42.3-r1util-linux: util-linux: nsenter --join-cgroup leaks root cgroup migration authority — ghcr.io/openvoxproject/openvoxdb:latest-alpine (alpine 3.24.1)
HIGH CVE-2026-76642runuser2.42.1-r0 2.42.3-r0util-linux: util-linux: failed external mount helper still runs privileged X-mount post-hooks — ghcr.io/openvoxproject/openvoxdb:latest-alpine (alpine 3.24.1)
HIGH CVE-2026-53614runuser2.42.1-r0 2.42.3-r0util-linux: util-linux: SUID mount(8) allows nosuid/noexec bypass via LIBMOUNT_FORCE_MOUNT2 — ghcr.io/openvoxproject/openvoxdb:latest-alpine (alpine 3.24.1)
HIGH CVE-2026-53613runuser2.42.1-r0 2.42.3-r0util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path — ghcr.io/openvoxproject/openvoxdb:latest-alpine (alpine 3.24.1)
HIGH CVE-2026-53612runuser2.42.1-r0 2.42.3-r0util-linux: util-linux: TOCTOU in the mount program when applying post-mount ownership/mode changes — ghcr.io/openvoxproject/openvoxdb:latest-alpine (alpine 3.24.1)
MEDIUM CVE-2026-27456runuser2.42.1-r0 2.42.3-r0util-linux: TOCTOU in the mount program when setting up loop devices — ghcr.io/openvoxproject/openvoxdb:latest-alpine (alpine 3.24.1)
MEDIUM CVE-2026-82209libcurl8.21.0-r0 8.22.0-r0When libpsl support is enabled, libcurl fails to enforce the Public Su ... — ghcr.io/openvoxproject/openvoxdb:latest-alpine (alpine 3.24.1)
MEDIUM CVE-2026-80255libcurl8.21.0-r0 8.22.0-r0A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instea ... — ghcr.io/openvoxproject/openvoxdb:latest-alpine (alpine 3.24.1)
MEDIUM CVE-2026-80230libcurl8.21.0-r0 8.22.0-r0When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that di ... — ghcr.io/openvoxproject/openvoxdb:latest-alpine (alpine 3.24.1)
MEDIUM CVE-2026-13608curl8.21.0-r0 8.22.0-r0A flaw in the libcurl SASL negotiation for LDAP authentication allows ... — ghcr.io/openvoxproject/openvoxdb:latest-alpine (alpine 3.24.1)
MEDIUM CVE-2026-19931curl8.21.0-r0 8.22.0-r0curl: libcurl: Information disclosure via incorrect connection reuse with Negotiate authentication — ghcr.io/openvoxproject/openvoxdb:latest-alpine (alpine 3.24.1)
MEDIUM CVE-2026-80229curl8.21.0-r0 8.22.0-r0When performing transfers via libcurl\u2019s multi interface, pooled T ... — ghcr.io/openvoxproject/openvoxdb:latest-alpine (alpine 3.24.1)
MEDIUM CVE-2026-80230curl8.21.0-r0 8.22.0-r0When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that di ... — ghcr.io/openvoxproject/openvoxdb:latest-alpine (alpine 3.24.1)
MEDIUM CVE-2026-80255curl8.21.0-r0 8.22.0-r0A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instea ... — ghcr.io/openvoxproject/openvoxdb:latest-alpine (alpine 3.24.1)
MEDIUM CVE-2026-82209curl8.21.0-r0 8.22.0-r0When libpsl support is enabled, libcurl fails to enforce the Public Su ... — ghcr.io/openvoxproject/openvoxdb:latest-alpine (alpine 3.24.1)
MEDIUM CVE-2026-13608libcurl8.21.0-r0 8.22.0-r0A flaw in the libcurl SASL negotiation for LDAP authentication allows ... — ghcr.io/openvoxproject/openvoxdb:latest-alpine (alpine 3.24.1)
MEDIUM CVE-2026-19931libcurl8.21.0-r0 8.22.0-r0curl: libcurl: Information disclosure via incorrect connection reuse with Negotiate authentication — ghcr.io/openvoxproject/openvoxdb:latest-alpine (alpine 3.24.1)
MEDIUM CVE-2026-80229libcurl8.21.0-r0 8.22.0-r0When performing transfers via libcurl\u2019s multi interface, pooled T ... — ghcr.io/openvoxproject/openvoxdb:latest-alpine (alpine 3.24.1)
LOW CVE-2026-18924curl8.21.0-r0 8.22.0-r0curl: libcurl: Use-after-free in HTTP/2 Server Push with shared connections — ghcr.io/openvoxproject/openvoxdb:latest-alpine (alpine 3.24.1)
LOW CVE-2026-18924libcurl8.21.0-r0 8.22.0-r0curl: libcurl: Use-after-free in HTTP/2 Server Push with shared connections — ghcr.io/openvoxproject/openvoxdb:latest-alpine (alpine 3.24.1)
UNKNOWN CVE-2026-80256libcurl8.21.0-r0 8.22.0-r0ghcr.io/openvoxproject/openvoxdb:latest-alpine (alpine 3.24.1)
UNKNOWN CVE-2026-82208libcurl8.21.0-r0 8.22.0-r0With the wolfSSL backend, when CA caching is enabled and an `CURLOPT_S ... — ghcr.io/openvoxproject/openvoxdb:latest-alpine (alpine 3.24.1)
UNKNOWN CVE-2026-80256curl8.21.0-r0 8.22.0-r0ghcr.io/openvoxproject/openvoxdb:latest-alpine (alpine 3.24.1)
UNKNOWN CVE-2026-80231curl8.21.0-r0 8.22.0-r0native CA store conn reuse — ghcr.io/openvoxproject/openvoxdb:latest-alpine (alpine 3.24.1)
UNKNOWN CVE-2026-80231libcurl8.21.0-r0 8.22.0-r0native CA store conn reuse — ghcr.io/openvoxproject/openvoxdb:latest-alpine (alpine 3.24.1)
UNKNOWN CVE-2026-82208curl8.21.0-r0 8.22.0-r0With the wolfSSL backend, when CA caching is enabled and an `CURLOPT_S ... — ghcr.io/openvoxproject/openvoxdb:latest-alpine (alpine 3.24.1)

Grype

CRITICAL 4 HIGH 19 MEDIUM 1 UNKNOWN 5 NVD/CPE filtered 19
SeverityIDPackageInstalledFixedTitle / target
CRITICAL CVE-2026-19931curl8.21.0-r0 8.22.0-r0/lib/apk/db/installed
CRITICAL CVE-2026-19931libcurl8.21.0-r0 8.22.0-r0/lib/apk/db/installed
CRITICAL CVE-2026-18924curl8.21.0-r0 8.22.0-r0/lib/apk/db/installed
CRITICAL CVE-2026-18924libcurl8.21.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-78410runuser2.42.1-r0 2.42.3-r0/lib/apk/db/installed
HIGH CVE-2026-78408runuser2.42.1-r0 2.42.3-r1/lib/apk/db/installed
HIGH CVE-2026-78409runuser2.42.1-r0 2.42.3-r0/lib/apk/db/installed
HIGH CVE-2026-76642runuser2.42.1-r0 2.42.3-r0/lib/apk/db/installed
HIGH CVE-2026-82208libcurl8.21.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-82208curl8.21.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-82209libcurl8.21.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-82209curl8.21.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-80230libcurl8.21.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-80230curl8.21.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-13608libcurl8.21.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-13608curl8.21.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-80255libcurl8.21.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-80255curl8.21.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-80229libcurl8.21.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-80229curl8.21.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-80231libcurl8.21.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-80231curl8.21.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH GHSA-jr6h-r7vg-f9mcini4j0.5.4 org.ini4j allows attackers to cause a Denial of Service (DoS) — /opt/puppetlabs/server/apps/puppetdb/puppetdb.jar
MEDIUM CVE-2026-27456runuser2.42.1-r0 2.41.4-r0, 2.42.3-r0/lib/apk/db/installed
UNKNOWN CVE-2026-80256curl8.21.0-r0 8.22.0-r0/lib/apk/db/installed
UNKNOWN CVE-2026-80256libcurl8.21.0-r0 8.22.0-r0/lib/apk/db/installed
UNKNOWN CVE-2026-53612runuser2.42.1-r0 2.42.3-r0/lib/apk/db/installed
UNKNOWN CVE-2026-53613runuser2.42.1-r0 2.42.3-r0/lib/apk/db/installed
UNKNOWN CVE-2026-53614runuser2.42.1-r0 2.42.3-r0/lib/apk/db/installed
Filtered NVD/CPE matches (19)

These broad CPE matches are unconfirmed for the distribution package and excluded from scanner totals.

SeverityIDPackageInstalledFixedTitle / target
MEDIUM CVE-2026-5704tar1.35-r5 A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection. — /lib/apk/db/installed
MEDIUM CVE-2016-2781coreutils9.11-r0 chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer. — /lib/apk/db/installed
MEDIUM CVE-2016-2781coreutils-env9.11-r0 chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer. — /lib/apk/db/installed
MEDIUM CVE-2016-2781coreutils-fmt9.11-r0 chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer. — /lib/apk/db/installed
MEDIUM CVE-2016-2781coreutils-sha512sum9.11-r0 chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer. — /lib/apk/db/installed
MEDIUM CVE-2025-60876busybox1.37.0-r31 BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed
MEDIUM CVE-2025-60876busybox-binsh1.37.0-r31 BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed
MEDIUM CVE-2025-60876ssl_client1.37.0-r31 BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed
MEDIUM CVE-2026-58055nghttp2-libs1.69.0-r0 nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning. — /lib/apk/db/installed
MEDIUM CVE-2026-56391coreutils9.11-r0 GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. This incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input. When running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure. This issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371. — /lib/apk/db/installed
MEDIUM CVE-2026-56391coreutils-env9.11-r0 GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. This incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input. When running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure. This issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371. — /lib/apk/db/installed
MEDIUM CVE-2026-56391coreutils-fmt9.11-r0 GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. This incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input. When running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure. This issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371. — /lib/apk/db/installed
MEDIUM CVE-2026-56391coreutils-sha512sum9.11-r0 GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. This incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input. When running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure. This issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371. — /lib/apk/db/installed
MEDIUM CVE-2026-18508tar1.35-r5 A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction. — /lib/apk/db/installed
MEDIUM CVE-2026-56392coreutils9.11-r0 GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer. When processing crafted input, subsequent writes exceed the allocated memory, leading to an out‑of‑bounds heap write. When running GNU coreutils unexpand with attacker-provided large tab stop (-t) arguments, this behavior leads to a crash and potentially achieve a heap write primitive depending on memory layout. This issue has been fixed in the commit b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d — /lib/apk/db/installed
MEDIUM CVE-2026-56392coreutils-env9.11-r0 GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer. When processing crafted input, subsequent writes exceed the allocated memory, leading to an out‑of‑bounds heap write. When running GNU coreutils unexpand with attacker-provided large tab stop (-t) arguments, this behavior leads to a crash and potentially achieve a heap write primitive depending on memory layout. This issue has been fixed in the commit b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d — /lib/apk/db/installed
MEDIUM CVE-2026-56392coreutils-fmt9.11-r0 GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer. When processing crafted input, subsequent writes exceed the allocated memory, leading to an out‑of‑bounds heap write. When running GNU coreutils unexpand with attacker-provided large tab stop (-t) arguments, this behavior leads to a crash and potentially achieve a heap write primitive depending on memory layout. This issue has been fixed in the commit b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d — /lib/apk/db/installed
MEDIUM CVE-2026-56392coreutils-sha512sum9.11-r0 GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer. When processing crafted input, subsequent writes exceed the allocated memory, leading to an out‑of‑bounds heap write. When running GNU coreutils unexpand with attacker-provided large tab stop (-t) arguments, this behavior leads to a crash and potentially achieve a heap write primitive depending on memory layout. This issue has been fixed in the commit b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d — /lib/apk/db/installed
MEDIUM CVE-2026-18477tar1.35-r5 A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. This could lead to unauthorized file modification or, in some cases, privilege escalation. Exploitation does not require the attacker to modify or craft the archive, and standard backup and restore workflows—including extracting into a newly created directory without using the -P option do not mitigate the issue. — /lib/apk/db/installed

ghcr.io/openvoxproject/openvoxserver

GitHub Container Registry

Downloads

172,136 downloads

ghcr.io/openvoxproject/openvoxserver:latest (2026-09-09)

Trivy

CRITICAL 4 HIGH 95 MEDIUM 2378 LOW 152
SeverityIDPackageInstalledFixedTitle / target
CRITICAL CVE-2026-74394linux-libc-dev7.0.0-31.31 kernel: RDMA/srpt: fix integer overflow in immediate data length check — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
CRITICAL CVE-2026-72287linux-libc-dev7.0.0-31.31 kernel: KVM: nVMX: Move vTPR vs. TPR Threshold consistency check into "normal" checks — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
CRITICAL CVE-2026-64564linux-libc-dev7.0.0-31.31 kernel: sctp: don't free the ASCONF's own transport in DEL-IP processing — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
CRITICAL CVE-2026-64535linux-libc-dev7.0.0-31.31 kernel: nvmet-tcp: Fix potential UAF when ddgst mismatch — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-68399linux-libc-dev7.0.0-31.31 kernel: bpf: Fix UAF in sock clone early bailouts — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-68442linux-libc-dev7.0.0-31.31 kernel: btrfs: don't propagate EXTENT_FLAG_LOGGING to split extent maps — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-68446linux-libc-dev7.0.0-31.31 kernel: drm/vmwgfx: Validate vmw_surface_metadata::array_size — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-68451linux-libc-dev7.0.0-31.31 kernel: s390/zcrypt: Validate length for CCA ECC private key requests — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-68470linux-libc-dev7.0.0-31.31 kernel: wifi: mac80211: validate extension-frame layout before RX — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-72003linux-libc-dev7.0.0-31.31 kernel: wifi: brcmfmac: cyw: fix heap overflow on a short auth frame — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-72024linux-libc-dev7.0.0-31.31 kernel: mac802154: remove interfaces with RCU list deletion — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-72110linux-libc-dev7.0.0-31.31 kernel: bpf,fork: wipe ->bpf_storage before bailouts that access it — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-72111linux-libc-dev7.0.0-31.31 kernel: bpf: Reset register bounds before narrowing retval range in check_mem_access() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-72123linux-libc-dev7.0.0-31.31 kernel: can: bcm: thrtimer use-after-free during RX operation teardown — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-72124linux-libc-dev7.0.0-31.31 kernel: can: isotp: serialize TX state transitions under so->rx_lock — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-72135linux-libc-dev7.0.0-31.31 kernel: tpm: Make the TPM character devices non-seekable — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-72151linux-libc-dev7.0.0-31.31 kernel: tpm: tpm2-sessions: wait for async KPP completion in tpm_buf_append_salt — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-72195linux-libc-dev7.0.0-31.31 kernel: fs/ntfs3: bound attr_off in UpdateResidentValue against data_off — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-72288linux-libc-dev7.0.0-31.31 kernel: KVM: arm64: vgic: Handle race between interrupt affinity change and LPI disabling — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-72331linux-libc-dev7.0.0-31.31 kernel: accel/amdxdna: Fix VMA access race — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-72338linux-libc-dev7.0.0-31.31 kernel: net/sched: act_pedit: fix TOCTOU heap OOB write in tc offload — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-72372linux-libc-dev7.0.0-31.31 kernel: afs: Fix lack of locking around modifications of net->cells_dyn_ino — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-74534linux-libc-dev7.0.0-31.31 kernel: Bluetooth: ISO: fix refcounting of iso_conn — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-64567linux-libc-dev7.0.0-31.31 kernel: btrfs: reject free space cache with more entries than pages — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-68098linux-libc-dev7.0.0-31.31 kernel: ksmbd: bound DACL dedup walk to copied ACEs — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-68117linux-libc-dev7.0.0-31.31 kernel: tipc: clear sock->sk on the failed-insert path in tipc_sk_create() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-68121linux-libc-dev7.0.0-31.31 kernel: Linux kernel: PPPoE memory corruption via stale pointer — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-68147linux-libc-dev7.0.0-31.31 kernel: fscrypt: Avoid dynamic allocation in fscrypt_get_devices() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-68162linux-libc-dev7.0.0-31.31 kernel: sctp: avoid auth_enable sysctl UAF during netns teardown — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-68189linux-libc-dev7.0.0-31.31 kernel: Bluetooth: hci_sync: Protect UUID list traversal — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-68196linux-libc-dev7.0.0-31.31 kernel: wifi: wilc1000: validate assoc response length before subtracting header — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-68198linux-libc-dev7.0.0-31.31 kernel: Linux kernel: Use-after-free in ath6kl Wi-Fi driver leading to denial of service — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-68199linux-libc-dev7.0.0-31.31 kernel: wifi: ath6kl: fix OOB access from firmware ADDBA window size — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-68201linux-libc-dev7.0.0-31.31 kernel: ALSA: timer: drain a slave's callback before its master detaches it — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-68204linux-libc-dev7.0.0-31.31 kernel: media: vivid: check for vb2_is_busy() when toggling caps — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-68236linux-libc-dev7.0.0-31.31 kernel: drm/amd/display: set new_stream to NULL after release — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-68257linux-libc-dev7.0.0-31.31 kernel: drm/amdkfd: fix 32-bit overflow in CWSR total size calculation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-68284linux-libc-dev7.0.0-31.31 kernel: Linux kernel: bpf/sockmap use-after-free vulnerability leading to denial of service — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-68323linux-libc-dev7.0.0-31.31 kernel: tipc: serialize udp bearer replicast list updates — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-68329linux-libc-dev7.0.0-31.31 kernel: iommu/amd: Wait for completion instead of returning early in iommu_completion_wait() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-68380linux-libc-dev7.0.0-31.31 kernel: accel/amdxdna: Fix use-after-free of mm_struct in job scheduler — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-68393linux-libc-dev7.0.0-31.31 kernel: Bluetooth: hci_sync: extend conn_hash lookup critical sections — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-74535linux-libc-dev7.0.0-31.31 kernel: Bluetooth: ISO: avoid deadlocks in iso_sock_timeout — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-80631linux-libc-dev7.0.0-31.31 kernel: btrfs: lzo: reject compressed segment that overflows the compressed input — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-80634linux-libc-dev7.0.0-31.31 kernel: netfilter: flowtable: avoid num_encaps underflow on bridge VLAN untag — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-80637linux-libc-dev7.0.0-31.31 kernel: netfilter: synproxy: fix unaligned memory access in timestamp adjustment — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-80644linux-libc-dev7.0.0-31.31 kernel: ocfs2: don't BUG_ON an invalid journal dinode — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-80665linux-libc-dev7.0.0-31.31 kernel: KVM: arm64: nv: Inject SEA if kvm_translate_vncr() can't resolve PFN — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-80668linux-libc-dev7.0.0-31.31 kernel: netfilter: nf_conntrack_expect: use conntrack GC to reap expectations — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-80671linux-libc-dev7.0.0-31.31 kernel: perf sched: Fix register_pid() overflow, strcpy, and BUG_ON — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-80681linux-libc-dev7.0.0-31.31 kernel: vxlan: re-fetch eth header after route_shortcircuit() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-80683linux-libc-dev7.0.0-31.31 kernel: Bluetooth: SCO: give the socket its own sco_conn reference — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-80691linux-libc-dev7.0.0-31.31 kernel: scsi: target: iblock: Fix wrong PR ops NULL check for PREEMPT/RELEASE — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-80692linux-libc-dev7.0.0-31.31 kernel: Bluetooth: hci_sync: hold conn in hci_connect_acl/le_sync() callbacks — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-80693linux-libc-dev7.0.0-31.31 kernel: idpf: bound interrupt-vector register fill to the allocated array — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-80700linux-libc-dev7.0.0-31.31 kernel: drm/vmwgfx: validate external BO copy bounds for both stride paths — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-80702linux-libc-dev7.0.0-31.31 kernel: drm/vmwgfx: fix guest_memory_dirty bitfield clobbered as size — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-80710linux-libc-dev7.0.0-31.31 kernel: s390/dasd: Fix undersized format-check buffer — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-80714linux-libc-dev7.0.0-31.31 kernel: ipvs: do not propagate one-packet flag to synced conns — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-80716linux-libc-dev7.0.0-31.31 kernel: ALSA: pcm: wake linked drain waiters on unlink — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-80718linux-libc-dev7.0.0-31.31 kernel: mm/percpu-km: fix bitmap overflow and accounting in pcpu_create_chunk() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-80721linux-libc-dev7.0.0-31.31 kernel: Bluetooth: ISO: ensure no dangling hcon references in iso_conn — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-72390linux-libc-dev7.0.0-31.31 kernel: net/sched: sch_teql: Introduce slaves_lock to avoid race condition and UAF — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-72461linux-libc-dev7.0.0-31.31 kernel: apparmor: fix refcount leak when updating the sk_ctx — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-72462linux-libc-dev7.0.0-31.31 kernel: apparmor: fix race in unix socket mediation when peer_path is used — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-72472linux-libc-dev7.0.0-31.31 kernel: nfs: use nfsi->rwsem to protect traversal of the file lock list — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-72478linux-libc-dev7.0.0-31.31 kernel: fs/ntfs3: add bounds check to run_get_highest_vcn() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-74268linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: t ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-74317linux-libc-dev7.0.0-31.31 kernel: ixgbe: do not configure xps for XDP queues — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-74334linux-libc-dev7.0.0-31.31 kernel: RDMA/nldev: Fix locking when accessing mr->pd — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-74341linux-libc-dev7.0.0-31.31 kernel: wifi: wcn36xx: fix heap overflow from oversized firmware HAL response — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-74363linux-libc-dev7.0.0-31.31 kernel: bpf: fix UAF by restoring RCU-delayed inode freeing in bpffs — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-74378linux-libc-dev7.0.0-31.31 kernel: RDMA/rxe: Fix TOCTOU heap overflow in get_srq_wqe — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-74390linux-libc-dev7.0.0-31.31 kernel: RDMA/irdma: Fix out-of-bounds write in irdma_copy_user_pgaddrs — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-74411linux-libc-dev7.0.0-31.31 kernel: wifi: rtw89: Correct data type for scan index to avoid infinite loop — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-74427linux-libc-dev7.0.0-31.31 kernel: afs: Fix netns teardown to cancel the preallocation charger — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-74438linux-libc-dev7.0.0-31.31 kernel: crypto: sun4i-ss - Remove insecure and unused rng_alg — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-74446linux-libc-dev7.0.0-31.31 kernel: drm/amdkfd: hold event_mutex while checkpointing CRIU events — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-74465linux-libc-dev7.0.0-31.31 kernel: net: openvswitch: fix potential UAF on meter attach failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-74470linux-libc-dev7.0.0-31.31 kernel: scsi: scsi_debug: Fix REPORT ZONES alloc_len underflow OOB write — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-74506linux-libc-dev7.0.0-31.31 kernel: afs: Fix UAF when sending a message — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-74510linux-libc-dev7.0.0-31.31 kernel: Bluetooth: mgmt: fix UAF in pair command cancellation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-74529linux-libc-dev7.0.0-31.31 kernel: Bluetooth: hci_sync: hold conn in hci_connect_pa_sync() callback — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2022-41404org.ini4j:ini4j0.5.4 org.ini4j: unspecified DoS — Java
HIGH CVE-2026-33818stdlibv1.26.5 1.25.13, 1.26.6, 1.27.0-rc.3encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal — usr/bin/pebble
HIGH CVE-2026-39821stdlibv1.26.5 1.25.13, 1.26.6, 1.27.0-rc.3golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing — usr/bin/pebble
HIGH CVE-2026-46600stdlibv1.26.5 1.26.6, 1.27.0-rc.3golang.org/x/net/dns/dnsmessage: golang.org/x/net/dns/dnsmessage: Denial of Service via invalid DNS record parsing — usr/bin/pebble
HIGH CVE-2026-56853stdlibv1.26.5 1.25.13, 1.26.6, 1.27.0-rc.3net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service — usr/bin/pebble
HIGH CVE-2026-56858stdlibv1.26.5 1.25.13, 1.26.6, 1.27.0-rc.3html/template: golang: Go html/template: Cross-Site Scripting via pathological input — usr/bin/pebble
HIGH CVE-2026-56859stdlibv1.26.5 1.25.13, 1.26.6, 1.27.0-rc.3encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue — usr/bin/pebble
HIGH CVE-2026-56860stdlibv1.26.5 1.25.13, 1.26.6, 1.27.0-rc.3net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution — usr/bin/pebble
HIGH CVE-2026-56862stdlibv1.26.5 1.25.13, 1.26.6, 1.27.0-rc.3crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages — usr/bin/pebble
HIGH CVE-2026-64562linux-libc-dev7.0.0-31.31 kernel: KVM: nVMX: Hide shadow VMCS right after VMCLEAR — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-64558linux-libc-dev7.0.0-31.31 kernel: s390/pkey: Check length in pkey_pckmo handler implementation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-64557linux-libc-dev7.0.0-31.31 kernel: Bluetooth: L2CAP: Fix use-after-free in l2cap_sock_new_connection_cb() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-64554linux-libc-dev7.0.0-31.31 kernel: netfilter: bridge: fix stale prevhdr pointer in br_ip6_fragment() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-64548linux-libc-dev7.0.0-31.31 kernel: bpf, sockmap: reject overflowing copy + len in bpf_msg_push_data() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2026-64543linux-libc-dev7.0.0-31.31 kernel: tipc: fix use-after-free of the discoverer in tipc_disc_rcv() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
HIGH CVE-2025-40190linux-libc-dev7.0.0-31.31 kernel: ext4: guard against EA inode refcount underflow in xattr update — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80823linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80838linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: v ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80839linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80840linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80841linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80842linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80843linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: x ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80844linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: x ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80845linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: x ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80846linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: x ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80847linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: t ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80848linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: x ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80849linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80850linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: t ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80851linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: g ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80852linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: t ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80854linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: u ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80824linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: u ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80825linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80826linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: U ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80827linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: U ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80828linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: A ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80829linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: A ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80830linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: u ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80831linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: c ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80832linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: c ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80822linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80790linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80833linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: c ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80834linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: c ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80835linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: c ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80836linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: c ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80837linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80877linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: a ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80878linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: a ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80879linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: o ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80880linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: I ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80881linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: o ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80882linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: c ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80883linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80884linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80885linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: a ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80886linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80887linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80888linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80889linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: c ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80890linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80891linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: K ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80892linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: e ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80893linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80894linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80895linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80896linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80897linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80855linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80856linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80857linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80858linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80859linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80860linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80861linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: u ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80862linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80863linux-libc-dev7.0.0-31.31 kernel: RDMA/rxe: Fix OOB in free_rd_atomic_resources() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80864linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: R ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80865linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80866linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: t ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80867linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: a ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80868linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80870linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80871linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: c ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80872linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: A ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80873linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: K ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80874linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: a ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80875linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80876linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: r ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80789linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80788linux-libc-dev7.0.0-31.31 kernel: nvmet-tcp: Do not WARN on remotely-controlled oversized SGL allocations — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80787linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80786linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80785linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80784linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80783linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: H ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80782linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: H ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80781linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: H ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80780linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: H ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80779linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80778linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80777linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80776linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80775linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80774linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: H ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80772linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: H ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80752linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: I ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80809linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: o ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80808linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: e ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80807linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80806linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: e ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80805linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: x ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80804linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: x ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80803linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80802linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80801linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80800linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80799linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80798linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80797linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80796linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80795linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80794linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80793linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80792linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80791linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80751linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: p ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80750linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: p ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80749linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80748linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80747linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80745linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: r ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80810linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80811linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80812linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: A ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80813linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80814linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: r ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80815linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: A ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80816linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: A ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80817linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80818linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80819linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: B ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80820linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: x ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80821linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80771linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: H ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80770linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: H ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80769linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: H ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80768linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: H ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80767linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: H ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80766linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: H ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80765linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: H ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80764linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: B ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80763linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: B ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80762linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: B ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80761linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: B ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80760linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: B ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80759linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: B ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80758linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80757linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80756linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80755linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80754linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: I ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80753linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: o ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80992linux-libc-dev7.0.0-31.31 kernel: net: ravb: avoid dereferencing an invalid PTP clock — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80993linux-libc-dev7.0.0-31.31 kernel: net: phylink: correctly validate returned PCS in phylink_inband_caps — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80994linux-libc-dev7.0.0-31.31 kernel: net: openvswitch: fix flow mask use-after-free on flow deletion — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80996linux-libc-dev7.0.0-31.31 kernel: net: l2tp: do not propagate multicast notification errors — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80997linux-libc-dev7.0.0-31.31 kernel: net: ipa: fix stalled modem TX queue after runtime resume — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80999linux-libc-dev7.0.0-31.31 kernel: net: dsa: realtek: use gpiod_set_value_cansleep for reset GPIO — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-81000linux-libc-dev7.0.0-31.31 kernel: net: tun: bound receive headroom — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-81001linux-libc-dev7.0.0-31.31 kernel: slip: fix use-after-free in sl_sync() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-81002linux-libc-dev7.0.0-31.31 kernel: xdp: fix zero-copy frame layout — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-81003linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-81004linux-libc-dev7.0.0-31.31 kernel: ipmi:msghandler: Cancel work cleanly on an error — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-81005linux-libc-dev7.0.0-31.31 kernel: ipmi: si: Fix NULL pointer dereference after failed registration — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-81006linux-libc-dev7.0.0-31.31 kernel: ipmi: Remove all sysfs files on registration failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-81007linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-81008linux-libc-dev7.0.0-31.31 kernel: interconnect: Fix use after free in icc_get() and of_icc_get_by_index() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-81009linux-libc-dev7.0.0-31.31 kernel: io_uring/query: cap user size passed to copy_struct_to_user — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-81010linux-libc-dev7.0.0-31.31 kernel: io_uring/waitid: honor task_work cancellation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-81011linux-libc-dev7.0.0-31.31 kernel: platform/x86: hp-bioscfg: pass validated element count to package parsers — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89449linux-libc-dev7.0.0-31.31 kernel: Linux kernel: Memory leak in IOMMU subsystem can lead to denial of service — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80917linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: P ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80974linux-libc-dev7.0.0-31.31 kernel: mfd: sm501: Fix potential memory leaks during remove — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80975linux-libc-dev7.0.0-31.31 kernel: mfd: qnap-mcu: keep the reply buffer alive past a command timeout — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80976linux-libc-dev7.0.0-31.31 kernel: seg6: reset IP6CB after IPv6 decapsulation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80977linux-libc-dev7.0.0-31.31 kernel: net: skbuff: don't touch shared zerocopy state in skb_tx_error() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80978linux-libc-dev7.0.0-31.31 kernel: net: cap advertised IP tunnel headroom — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80979linux-libc-dev7.0.0-31.31 kernel: net/smc: unregister the connection before draining the rx tasklet — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80980linux-libc-dev7.0.0-31.31 kernel: net/smc: stop killed, freed and out_of_sync sharing a byte — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80981linux-libc-dev7.0.0-31.31 kernel: net/smc: fix use-after-free of the LLC qentry in smc_llc_srv_add_link() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80982linux-libc-dev7.0.0-31.31 kernel: net/smc: fix use-after-free in smc_rx_pipe_buf_release() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80983linux-libc-dev7.0.0-31.31 kernel: net/smc: fix socket refcount leak in smc_switch_conns() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80984linux-libc-dev7.0.0-31.31 kernel: net/smc: do not dereference an unset send buffer on the SMC-D teardown path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80985linux-libc-dev7.0.0-31.31 kernel: net/smc: carry oversized SMC-Rv2 LLC messages in the queue entry — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80986linux-libc-dev7.0.0-31.31 kernel: net/smc: bound the peer rkey counts in SMC-Rv2 LLC messages — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80987linux-libc-dev7.0.0-31.31 kernel: NTB: ntb_transport: Reject oversized TX buffers — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80988linux-libc-dev7.0.0-31.31 kernel: NTB: ntb_transport: Fail TX enqueue when the QP link is down — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80989linux-libc-dev7.0.0-31.31 kernel: net: thunderbolt: Mark the connection down when bringing it up fails — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80990linux-libc-dev7.0.0-31.31 kernel: net: thunderbolt: Release the Rx HopID that was handed out on mismatch — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80991linux-libc-dev7.0.0-31.31 kernel: net: ravb: serialize PTP clock teardown — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89450linux-libc-dev7.0.0-31.31 kernel: iommu/tegra241-cmdqv: Reject a vSID wider than the SID_MATCH field — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89451linux-libc-dev7.0.0-31.31 kernel: Linux kernel: iommu/sva null pointer dereference via race condition — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89452linux-libc-dev7.0.0-31.31 kernel: iommu/msm: Unwind probe state on registration failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89453linux-libc-dev7.0.0-31.31 kernel: iommu/amd: Put PCI device after handling PPR faults — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89454linux-libc-dev7.0.0-31.31 kernel: Linux Kernel: PCI PLDA driver resource leak via IRQ domain initialization failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89455linux-libc-dev7.0.0-31.31 kernel: Linux kernel PCI PLDA driver: Use-after-free vulnerability during IRQ teardown — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89456linux-libc-dev7.0.0-31.31 kernel: Linux kernel: Information disclosure in s390/dasd via incorrect data tracking — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89457linux-libc-dev7.0.0-31.31 kernel: s390/dasd: Guard sysfs discipline callbacks against unallocated private data — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89458linux-libc-dev7.0.0-31.31 kernel: s390/dasd: Do not complete a failed ESE read as successful — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89460linux-libc-dev7.0.0-31.31 kernel: s390/cpum_cf: Handle CPU hotplug via prepare/dead callbacks — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89461linux-libc-dev7.0.0-31.31 kernel: Linux kernel: max17040 driver resource management issue during system suspend — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89462linux-libc-dev7.0.0-31.31 kernel: power: supply: max17040: propagate register read errors — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89463linux-libc-dev7.0.0-31.31 kernel: power: supply: ucs1002: fix use-after-free on remove — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89464linux-libc-dev7.0.0-31.31 kernel: Linux kernel: twl4030_charger: Use-after-free vulnerability leading to denial of service — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89465linux-libc-dev7.0.0-31.31 kernel: Linux kernel: Use-after-free in rt9455 power supply driver can lead to system crash or privilege escalation. — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89466linux-libc-dev7.0.0-31.31 kernel: Linux kernel: Information disclosure in qcom_battmgr due to improper string termination — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89467linux-libc-dev7.0.0-31.31 kernel: Linux kernel: `qcom_battmgr` use-after-free vulnerability — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89876linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-81012linux-libc-dev7.0.0-31.31 kernel: platform/x86: hp-bioscfg: fix off-by-one write in hp_get_string_from_buffer() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-81013linux-libc-dev7.0.0-31.31 kernel: platform/x86: hp-bioscfg: fix heap OOB read on empty password write — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-81014linux-libc-dev7.0.0-31.31 kernel: platform/x86: hp-bioscfg: fix heap OOB read in sk_store() and kek_store() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-81015linux-libc-dev7.0.0-31.31 kernel: platform/x86/amd/pmc: Fix LPS0 and debugfs leaks when STB init fails — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-81016linux-libc-dev7.0.0-31.31 kernel: platform/x86/amd/pmc: Propagate SMU errors and validate S2D address — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-81017linux-libc-dev7.0.0-31.31 kernel: platform/chrome: sensorhub: Bound the EC-reported sensor number — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-81018linux-libc-dev7.0.0-31.31 kernel: platform/x86: think-lmi: Free system certificate signatures — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89437linux-libc-dev7.0.0-31.31 kernel: platform/x86: int1092: Fix potential memory leak in sar_probe() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89438linux-libc-dev7.0.0-31.31 kernel: platform/x86: ISST: Validate logical CPU id and clos id — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89439linux-libc-dev7.0.0-31.31 kernel: platform/x86: ISST: Add a NULL check for sst_inst[] — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89440linux-libc-dev7.0.0-31.31 kernel: mmc: via-sdmmc: stop card-detect handling on probe failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89441linux-libc-dev7.0.0-31.31 kernel: mmc: via-sdmmc: cancel card-detect work on remove — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89442linux-libc-dev7.0.0-31.31 kernel: platform/x86: ISST: Validate socket ID in clos_assoc ioctl — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89443linux-libc-dev7.0.0-31.31 kernel: platform/x86: ISST: Validate level in perf mask ioctls — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89444linux-libc-dev7.0.0-31.31 kernel: Linux kernel: dell-wmi-sysman driver discloses plaintext admin password in kernel logs — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89445linux-libc-dev7.0.0-31.31 kernel: Linux Kernel: Use-After-Free vulnerability in iommufd selftest — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89446linux-libc-dev7.0.0-31.31 kernel: Linux kernel iommufd: Resource leak due to improper IOAS release — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89447linux-libc-dev7.0.0-31.31 kernel: Linux kernel (iommufd): Object reference leak via incorrect unmap handling — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89448linux-libc-dev7.0.0-31.31 kernel: Linux kernel: IOMMU misconfiguration when tboot is enabled — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80918linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: H ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80920linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80921linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: K ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80922linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: c ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80923linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: x ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80924linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: c ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80925linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: v ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80926linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: k ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80927linux-libc-dev7.0.0-31.31 kernel: timekeeping: Check the return value of tk_get_aux_ts64 in __do_adjtimex() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80928linux-libc-dev7.0.0-31.31 kernel: smack: fix cred UAF in smack_file_send_sigiotask() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80929linux-libc-dev7.0.0-31.31 kernel: sysctl: move the "cad_pid" entry from pid_table[] to kern_reboot_table[] — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80930linux-libc-dev7.0.0-31.31 kernel: tpm: tpm_i2c_nuvoton: disable IRQ on wait timeout — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80931linux-libc-dev7.0.0-31.31 kernel: w1: ds28e17: reject an oversize length on an I2C block read — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80932linux-libc-dev7.0.0-31.31 kernel: vsock/virtio: flush works in dependency order — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80933linux-libc-dev7.0.0-31.31 kernel: wifi: mt76: mt7996: validate default EEPROM firmware size — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80934linux-libc-dev7.0.0-31.31 kernel: wifi: mt76: mt7996: fix TX DMA mapping leak for AddBA req frames — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80935linux-libc-dev7.0.0-31.31 kernel: wifi: mt76: mt7996: bound the device EEPROM address before the EFUSE copy — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80955linux-libc-dev7.0.0-31.31 kernel: dm-pcache: fix use-after-free and invalid seg operations in kset_replay() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80898linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80899linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: e ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80900linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: A ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80901linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80902linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80903linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80904linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80905linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80906linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80907linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80908linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80909linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80910linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: A ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80911linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: A ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80912linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80913linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80914linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: B ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80915linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80916linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: k ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80956linux-libc-dev7.0.0-31.31 kernel: dm-pcache: only hand out initialized cache segments — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80957linux-libc-dev7.0.0-31.31 kernel: dm-pcache: detect a cycle in the last-kset chain during replay — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80958linux-libc-dev7.0.0-31.31 kernel: dm-pcache: clamp the tail kset read to the segment data region — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80959linux-libc-dev7.0.0-31.31 kernel: dm-pcache: bound the persisted tail-position offset — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80960linux-libc-dev7.0.0-31.31 kernel: dm-pcache: validate on-media seg_num against the cache device size — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80961linux-libc-dev7.0.0-31.31 kernel: dm-pcache: validate kset key_num and intra-segment bounds — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80962linux-libc-dev7.0.0-31.31 kernel: dm-pcache: validate geometry fields from on-disk cache_info — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80963linux-libc-dev7.0.0-31.31 kernel: dm-stats: fix a crash if allocation of per-cpu data fails — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80964linux-libc-dev7.0.0-31.31 kernel: ALSA: virmidi: Check card index validity at probe — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80965linux-libc-dev7.0.0-31.31 kernel: ALSA: serial-u16550: Check card index validity at probe — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80966linux-libc-dev7.0.0-31.31 kernel: ALSA: portman2x4: Check card index validity at probe — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80967linux-libc-dev7.0.0-31.31 kernel: ALSA: pcxhr: initialize mutexes before requesting threaded IRQ — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80968linux-libc-dev7.0.0-31.31 kernel: ALSA: mts64: Check card index validity at probe — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80969linux-libc-dev7.0.0-31.31 kernel: ALSA: mpu401: Check card index validity at probe — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80970linux-libc-dev7.0.0-31.31 kernel: ALSA: FCP: do not copy out an uninitialised init response — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80971linux-libc-dev7.0.0-31.31 kernel: ALSA: bcd2000: clear the URB pointers on disconnect — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80972linux-libc-dev7.0.0-31.31 kernel: ALSA: aloop: Check card index validity at probe — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80973linux-libc-dev7.0.0-31.31 kernel: ALSA: 6fire: bound the MIDI event length from the device — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80936linux-libc-dev7.0.0-31.31 kernel: wifi: mt76: mt7925: cancel mlo_pm_work on stop — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80937linux-libc-dev7.0.0-31.31 kernel: wifi: mt76: mt7915: bound the device EEPROM address before the EFUSE copy — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80938linux-libc-dev7.0.0-31.31 kernel: wifi: mt76: mt7615: avoid waiting for mac work under the mt76 mutex — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80939linux-libc-dev7.0.0-31.31 kernel: wifi: rtw89: pci: add .shutdown callback to stop rfkill polling on reboot — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80940linux-libc-dev7.0.0-31.31 kernel: wifi: rtw88: pci: fix resource leak on failed NAPI setup — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80941linux-libc-dev7.0.0-31.31 kernel: wifi: rtw88: Fix potential memory leak in rtw_txq_push_skb() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80942linux-libc-dev7.0.0-31.31 kernel: wifi: rtlwifi: rtl8192du: Fix possible memory leak in rtl92du_init_sw_vars() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80943linux-libc-dev7.0.0-31.31 kernel: wifi: rtlwifi: rtl8192du: check QoS TID before indexing tids — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80944linux-libc-dev7.0.0-31.31 kernel: wifi: mwifiex: Detach sync cmd buffer on interrupted wait — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80945linux-libc-dev7.0.0-31.31 kernel: crypto: iaa - unmap dst before software fallback on decompress — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80946linux-libc-dev7.0.0-31.31 kernel: fuse: copy request headers via a stack buffer for io-uring — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80947linux-libc-dev7.0.0-31.31 kernel: wifi: rtl8xxxu: fix use-after-free from rx_urb_wq on stop — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80948linux-libc-dev7.0.0-31.31 kernel: wifi: iwlwifi: dvm: fix memory leak in iwl_op_mode_dvm_start() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80949linux-libc-dev7.0.0-31.31 kernel: wifi: brcmfmac: Fix memory leak in brcmf_sdio_read_control() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80950linux-libc-dev7.0.0-31.31 kernel: i3c: renesas: Check that the transfer is valid before accessing it — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80951linux-libc-dev7.0.0-31.31 kernel: i3c: master: svc: bound IBI payload to the requested max_payload_len — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80952linux-libc-dev7.0.0-31.31 kernel: i3c: master: Fix info leak and UAF in device unregister path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80953linux-libc-dev7.0.0-31.31 kernel: i3c: master: adi: initialize the lock before enabling interrupts — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80954linux-libc-dev7.0.0-31.31 kernel: i3c: Fix unlocked dereference of dev->desc in i3c_device_get_supported_xfer_mode() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74690linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74691linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74692linux-libc-dev7.0.0-31.31 kernel: net/smc: fix TOCTOU race between smc_listen_out() and listener close — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74693linux-libc-dev7.0.0-31.31 kernel: net: prestera: validate firmware header length — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74694linux-libc-dev7.0.0-31.31 kernel: net/ncsi: fix heap OOB read in NCSI_CMD_SEND_CMD payload length — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74695linux-libc-dev7.0.0-31.31 kernel: netfilter: nf_flow_table: drop existing skb dst before skb_dst_set_noref() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74696linux-libc-dev7.0.0-31.31 kernel: tcp: fix TFO max_qlen accounting across reuseport migration — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74697linux-libc-dev7.0.0-31.31 kernel: bnxt_en: Disable EOP for TPA on all chips to prevent data corruption — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74698linux-libc-dev7.0.0-31.31 kernel: net/mlx5e: fix BQL reset on SQ re-activation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74699linux-libc-dev7.0.0-31.31 kernel: drm/xe: Fix memory leak in exec_queue_set_hang_replay_state() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74700linux-libc-dev7.0.0-31.31 kernel: net/sched: cls_api: Always acquire rtnl_lock when destroying locked classifiers — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74701linux-libc-dev7.0.0-31.31 kernel: net/openvswitch: check Ethernet header length in key_extract() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74702linux-libc-dev7.0.0-31.31 kernel: vhost-scsi: reject feature changes after endpoint — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74703linux-libc-dev7.0.0-31.31 kernel: vhost-scsi: Validate T10 PI scatterlist counts — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74704linux-libc-dev7.0.0-31.31 kernel: net/sched: sch_cake: drop WARN_ON(1) for malformed packets in ACK filter — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74705linux-libc-dev7.0.0-31.31 kernel: udp: fix potential use-after-free in tunnel segmentation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74706linux-libc-dev7.0.0-31.31 kernel: bnge: Fix NULL pointer dereference in aux device release — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74707linux-libc-dev7.0.0-31.31 kernel: xsk: validate metadata when processing requests — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74727linux-libc-dev7.0.0-31.31 kernel: ovpn: skip rehash for peers already removed from by_id — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74615linux-libc-dev7.0.0-31.31 kernel: vxlan: do not arm the ageing timer on a device that is down — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74672linux-libc-dev7.0.0-31.31 kernel: mm/vmalloc: acquire init_mm lock on huge vmap to avoid ptdump UAF — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74673linux-libc-dev7.0.0-31.31 kernel: Input: evdev - fix information leak in evdev_pass_values() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74674linux-libc-dev7.0.0-31.31 kernel: mm: fix incorrect flush address in direct page table reclaim — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74675linux-libc-dev7.0.0-31.31 kernel: vt: stabilize tty reference in kbd_keycode with tty_port_tty_get — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74676linux-libc-dev7.0.0-31.31 kernel: vt: add permission check for KDSKBMETA ioctl — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74677linux-libc-dev7.0.0-31.31 kernel: net: usb: ipheth: fix carrier_work UAF on disconnect — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74678linux-libc-dev7.0.0-31.31 kernel: net: usb: ax88179_178a: fix skb leak in ax88179_tx_fixup() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74679linux-libc-dev7.0.0-31.31 kernel: usb: gadget: f_ncm: Use unsigned int for ndp_index — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74680linux-libc-dev7.0.0-31.31 kernel: usb: atm: cxacru: properly kill rcv_urb on error in cxacru_cm() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74681linux-libc-dev7.0.0-31.31 kernel: usb: misc: usbio: check ibuf_len against rxbuf_len in bulk msg — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74682linux-libc-dev7.0.0-31.31 kernel: ALSA: usb-audio: fix OOB write on Type II inbound URBs — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74683linux-libc-dev7.0.0-31.31 kernel: Input: evdev - sanitize event type index when fetching event masks — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74684linux-libc-dev7.0.0-31.31 kernel: net: tap: set skb->dev before parsing virtio net header in tap_get_user_xdp() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74685linux-libc-dev7.0.0-31.31 kernel: hwmon: (ltc4282) Clamp negative current limits — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74686linux-libc-dev7.0.0-31.31 kernel: rqspinlock: Reset tail when preserving queue on deadlock — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74687linux-libc-dev7.0.0-31.31 kernel: watchdog: at91sam9_wdt: prevent timer rearm during teardown — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74688linux-libc-dev7.0.0-31.31 kernel: sctp: clear control chunk transport if it is being removed — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74689linux-libc-dev7.0.0-31.31 kernel: net/atm: fix slab-out-of-bounds read in vcc_setsockopt() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74728linux-libc-dev7.0.0-31.31 kernel: xfs: handle NULL b_addr in xfs_buf_free — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74729linux-libc-dev7.0.0-31.31 kernel: soc: aspeed: lpc-snoop: Fix usercopy overflow in snoop_file_read — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74730linux-libc-dev7.0.0-31.31 kernel: NFS: Pin the 'struct nfs_server' during a FREE_STATEID call — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74733linux-libc-dev7.0.0-31.31 kernel: gpio: pca953x: fix pca953x_irq_bus_sync_unlock regmap lock — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74734linux-libc-dev7.0.0-31.31 kernel: firewire: ohci: fix NULL pointer dereference in ar_context_release — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74735linux-libc-dev7.0.0-31.31 kernel: l2tp: fix tunnel and session refcount leak on seq_file release — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74736linux-libc-dev7.0.0-31.31 kernel: net/sched: cls_bpf: reject dev-bound programs bound to a different device — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74737linux-libc-dev7.0.0-31.31 kernel: net: ethernet: ti: am65-cpsw-nuss: Fix port_id extraction from SRC TAG — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74738linux-libc-dev7.0.0-31.31 kernel: regmap: sdw-mbq: don't call an unset readable_reg callback — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74739linux-libc-dev7.0.0-31.31 kernel: net/sched: cls_u32: skip hash tables in u32_bind_class() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74740linux-libc-dev7.0.0-31.31 kernel: net/sched: act_api: fix TOCTOU NULL deref on a->goto_chain — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74741linux-libc-dev7.0.0-31.31 kernel: net: ngbe: fix NULL pointer dereference in non-MSI-X interrupt enabling — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74742linux-libc-dev7.0.0-31.31 kernel: veth: fix queue index used to wake the peer txq in veth_poll — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74743linux-libc-dev7.0.0-31.31 kernel: macvlan: inherit needed_headroom and needed_tailroom from lowerdev — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74744linux-libc-dev7.0.0-31.31 kernel: ipvlan: inherit needed_headroom and needed_tailroom from phy_dev — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74745linux-libc-dev7.0.0-31.31 kernel: eth: bnxt: avoid deadlock when canceling IRQ affinity notifier — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74746linux-libc-dev7.0.0-31.31 kernel: netfilter: flowtable: publish GC-visible tuple last — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74747linux-libc-dev7.0.0-31.31 kernel: ipvs: revalidate ihl to prevent out-of-bounds access — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74708linux-libc-dev7.0.0-31.31 kernel: xsk: validate launch-time metadata size — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74709linux-libc-dev7.0.0-31.31 kernel: xsk: clear metadata pointer when no timestamp is requested — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74710linux-libc-dev7.0.0-31.31 kernel: xsk: require at least 16 bytes of TX metadata — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74711linux-libc-dev7.0.0-31.31 kernel: hwmon: (pmbus) Fix type confusion in notification logic — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74712linux-libc-dev7.0.0-31.31 kernel: vdpa/mlx5: Fix buffer length in create_direct_keys() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74713linux-libc-dev7.0.0-31.31 kernel: vhost_iotlb: bound map allocation in add_range — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74714linux-libc-dev7.0.0-31.31 kernel: bpf: tcp: Fix use-after-free in bpf_iter_tcp_established_batch() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74715linux-libc-dev7.0.0-31.31 kernel: bpf: Fix netns reference imbalance in conntrack kfuncs — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74716linux-libc-dev7.0.0-31.31 kernel: accel/amdxdna: Fix locally exploitable BUG_ON in amdxdna_insert_pages() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74717linux-libc-dev7.0.0-31.31 kernel: net/mlx5: fw_tracer, return NULL on create error — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74718linux-libc-dev7.0.0-31.31 kernel: devlink: fix net namespace reference leak in reload — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74719linux-libc-dev7.0.0-31.31 kernel: net/smc: fix qentry overwrite for CONFIRM_LINK and ADD_LINK_CONT in smc_llc_event_handler() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74720linux-libc-dev7.0.0-31.31 kernel: bpf: Preserve pointer state for commuted arithmetic — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74721linux-libc-dev7.0.0-31.31 kernel: accel/amxdna: Fix page-insertion errors in amdxdna_insert_pages() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74722linux-libc-dev7.0.0-31.31 kernel: btrfs: fix memory leak in btrfs_do_encoded_write() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74723linux-libc-dev7.0.0-31.31 kernel: btrfs: lzo: reject inline extents without valid headers — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74724linux-libc-dev7.0.0-31.31 kernel: ipvs: avoid out-of-bounds write in ip_vs_nat_icmp — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74725linux-libc-dev7.0.0-31.31 kernel: enic: fix tx_hang_reset use-after-free on device removal — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74726linux-libc-dev7.0.0-31.31 kernel: bonding: alb: re-check primary_is_promisc under RTNL in bond_alb_monitor — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74616linux-libc-dev7.0.0-31.31 kernel: xdp: reject clones that overrun skb_shared_info tailroom — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74617linux-libc-dev7.0.0-31.31 kernel: dibs: initialise dibs->lock in dibs_dev_alloc() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74618linux-libc-dev7.0.0-31.31 kernel: binfmt_misc: don't warn when the mount is completed from another user namespace — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74619linux-libc-dev7.0.0-31.31 kernel: ovl: don't warn when the mount is completed from another user namespace — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74620linux-libc-dev7.0.0-31.31 kernel: net/sched: act_gact, act_police: range check the fallback control action — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74621linux-libc-dev7.0.0-31.31 kernel: net/sched: act_ct: fix sk_buff leak when the header checks reject a packet — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74622linux-libc-dev7.0.0-31.31 kernel: net: atlantic: free RX pages of consumed but not refilled buffers — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74623linux-libc-dev7.0.0-31.31 kernel: net: atlantic: free stranded TX buffers on ring deinit — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74624linux-libc-dev7.0.0-31.31 kernel: netfilter: nf_conntrack: defer invalid log until after unlock — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74625linux-libc-dev7.0.0-31.31 kernel: netfilter: bridge: release template ct on non-IP path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74626linux-libc-dev7.0.0-31.31 kernel: NTB: ntb_netdev: Preserve RX queue depth on allocation failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74627linux-libc-dev7.0.0-31.31 kernel: net: devmem: prevent net-iov / page mixing — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74628linux-libc-dev7.0.0-31.31 kernel: net/x25: fix use-after-free of the socket by its timers — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74629linux-libc-dev7.0.0-31.31 kernel: net/dibs: Correct freeing of dmb_clientid_arr — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74630linux-libc-dev7.0.0-31.31 kernel: ipv6: prevent in6_dev_get() from resurrecting inet6_dev — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74631linux-libc-dev7.0.0-31.31 kernel: net: smc: fix splice entry lifetime imbalance in smc_rx_splice — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74632linux-libc-dev7.0.0-31.31 kernel: mm/huge_memory: fix huge_zero_pfn race — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74653linux-libc-dev7.0.0-31.31 kernel: serial: 8250_of: clear stuck empty-FIFO RX-timeout on LPC32xx — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68373linux-libc-dev7.0.0-31.31 kernel: Linux kernel: Out-of-bounds read in wifi driver due to length underflow — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74597linux-libc-dev7.0.0-31.31 kernel: ip6_tunnel: clear skb2->cb[] in ip6ip6_err() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74598linux-libc-dev7.0.0-31.31 kernel: ipv6: fix Route Information option length validation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74599linux-libc-dev7.0.0-31.31 kernel: mm/ptdump: always stabilise against page table freeing using init_mm — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74600linux-libc-dev7.0.0-31.31 kernel: mm/page_table_check: skip special zero mappings — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74601linux-libc-dev7.0.0-31.31 kernel: ring-buffer: Use current_context for safe per-CPU buffer swap — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74602linux-libc-dev7.0.0-31.31 kernel: ring-buffer: Initialise reader page order in rb_allocate_cpu_buffer() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74603linux-libc-dev7.0.0-31.31 kernel: ptp: ocp: Fix board ID over-read — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74604linux-libc-dev7.0.0-31.31 kernel: Revert "thermal/drivers/hwmon: Cleanup coding style a bit" — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74605linux-libc-dev7.0.0-31.31 kernel: eventfs: Use children field for rcu head and add memory barriers — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74606linux-libc-dev7.0.0-31.31 kernel: eventfs: Fix use-after-free in eventfs_remove_rec() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74607linux-libc-dev7.0.0-31.31 kernel: KVM: SVM: Serialize accesses to the owner and mirror list with separate lock — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74608linux-libc-dev7.0.0-31.31 kernel: smb: client: Fix use-after-free in cifs_try_adding_channels() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74609linux-libc-dev7.0.0-31.31 kernel: tipc: read le->link under the node lock in tipc_node_link_down() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74610linux-libc-dev7.0.0-31.31 kernel: tls: don't leave a full plaintext sk_msg ring unpushed — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74611linux-libc-dev7.0.0-31.31 kernel: tls: rx: restore msg_iter before TLS 1.3 optimistic retry — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74612linux-libc-dev7.0.0-31.31 kernel: veth: fix skb length accounting after XDP frag adjustment — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74613linux-libc-dev7.0.0-31.31 kernel: vsock/virtio: avoid refilling the RX queue after teardown — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74614linux-libc-dev7.0.0-31.31 kernel: vsock/virtio: read virtqueues under worker locks — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74654linux-libc-dev7.0.0-31.31 kernel: serial: 8250_dma: Clear stale RX state on shutdown — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74655linux-libc-dev7.0.0-31.31 kernel: serial: qcom-geni: fix TX DMA buffer flush — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74656linux-libc-dev7.0.0-31.31 kernel: ipv4: fix use-after-free in fib_nhc_update_mtu() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74657linux-libc-dev7.0.0-31.31 kernel: ipv4: Fix fib_nlmsg_size() for RTA_VIA nexthops — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74658linux-libc-dev7.0.0-31.31 kernel: futex: Prevent robust futex exit race some more — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74659linux-libc-dev7.0.0-31.31 kernel: net: bridge: mrp: fix uninitialised bytes on the wire — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74660linux-libc-dev7.0.0-31.31 kernel: netfilter: ebt_nflog: pin the NFLOG backend — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74661linux-libc-dev7.0.0-31.31 kernel: mac802154: fix netdev use-after-free in beacon worker — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74662linux-libc-dev7.0.0-31.31 kernel: inet: frags: publish queues before arming timer — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74663linux-libc-dev7.0.0-31.31 kernel: net/sched: reject overly deep qdisc hierarchies — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74664linux-libc-dev7.0.0-31.31 kernel: net: openvswitch: reallocate update replies for mismatched IDs — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74665linux-libc-dev7.0.0-31.31 kernel: net: fix skb length accounting after generic XDP frag adjustment — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74666linux-libc-dev7.0.0-31.31 kernel: packet: synchronize pressure clearing with ring reconfiguration — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74667linux-libc-dev7.0.0-31.31 kernel: net/packet: reset the MAC header on the packet-socket transmit path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74668linux-libc-dev7.0.0-31.31 kernel: packet: use consistent hard_header_len in TX_RING send path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74669linux-libc-dev7.0.0-31.31 kernel: ipvs: clear IPv4 options after rebasing tunnel ICMP errors — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74670linux-libc-dev7.0.0-31.31 kernel: ipvs: stop estimator after disabled calc phase — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74671linux-libc-dev7.0.0-31.31 kernel: ima: fix out-of-bounds read in xattr_verify() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74633linux-libc-dev7.0.0-31.31 kernel: tracing: Fix NULL pointer dereference in module event cache removal — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74634linux-libc-dev7.0.0-31.31 kernel: ring-buffer: Prevent subbuf order change when resizing is disabled — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74635linux-libc-dev7.0.0-31.31 kernel: fbdev: bitblit: bound-check glyph index in bit_cursor() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74636linux-libc-dev7.0.0-31.31 kernel: tracing: Fix race between update_event_fields and, event_define_fields — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74637linux-libc-dev7.0.0-31.31 kernel: perf/core: Fix group leader use-after-free after sibling detach — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74638linux-libc-dev7.0.0-31.31 kernel: drm/v3d: Serialize the scheduler timeout handlers — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74639linux-libc-dev7.0.0-31.31 kernel: ALSA: us144mkii: re-anchor capture URBs on resubmission — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74640linux-libc-dev7.0.0-31.31 kernel: ALSA: FCP: fix OOB write in fcp_meter_ctl_get() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74641linux-libc-dev7.0.0-31.31 kernel: ALSA: usx2y: bound the hwdep mmap fault offset — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74643linux-libc-dev7.0.0-31.31 kernel: samples/damon/mtier: error out for zero quota goal target values — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74644linux-libc-dev7.0.0-31.31 kernel: mm/damon/ops-common: putback folios on invalid migrate nid — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74645linux-libc-dev7.0.0-31.31 kernel: mm/damon/lru_sort: error out for >10000 active_mem_bp — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74646linux-libc-dev7.0.0-31.31 kernel: misc: fastrpc: take fl->lock when moving mmaps on interrupted invoke — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74647linux-libc-dev7.0.0-31.31 kernel: misc: fastrpc: Remove buffer from list prior to unmap operation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74648linux-libc-dev7.0.0-31.31 kernel: staging: rtl8723bs: validate monitor transmit frame lengths — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74649linux-libc-dev7.0.0-31.31 kernel: staging: rtl8723bs: fix missing shared-key auth challenge length check — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74650linux-libc-dev7.0.0-31.31 kernel: staging: rtl8723bs: fix OOB read in WMM_param_handler() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74651linux-libc-dev7.0.0-31.31 kernel: staging: rtl8723bs: fix OOB read in rtw_get_wpa_ie() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74652linux-libc-dev7.0.0-31.31 kernel: serial: amba-pl011: cancel RS485 hrtimers after freeing IRQ — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80612linux-libc-dev7.0.0-31.31 kernel: net: lwtunnel: Drop skb metadata before LWT encapsulation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80613linux-libc-dev7.0.0-31.31 kernel: veth: fix NAPI leak in XDP enable error path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80614linux-libc-dev7.0.0-31.31 kernel: net: emac: Fix NULL pointer dereference in emac_probe — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80615linux-libc-dev7.0.0-31.31 kernel: net: dst_metadata: fix false-positive memcpy overflow in tun_dst_unclone — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80616linux-libc-dev7.0.0-31.31 kernel: ieee802154: Avoid calling WARN_ON() on -ENOMEM in cfg802154_switch_netns() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80617linux-libc-dev7.0.0-31.31 kernel: net: airoha: fix foe_check_time allocation size — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80618linux-libc-dev7.0.0-31.31 kernel: drm/amdkfd: Avoid double-unpin of DOORBELL/MMIO BOs on free — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80619linux-libc-dev7.0.0-31.31 kernel: apparmor: fix potential UAF in aa_replace_profiles — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80620linux-libc-dev7.0.0-31.31 kernel: Revert "PCI/MSI: Unmap MSI-X region on error" — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80621linux-libc-dev7.0.0-31.31 kernel: PCI: dwc: Avoid dwc_pcie_rasdes_debugfs_deinit() NULL dereference when no RAS DES capability — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80626linux-libc-dev7.0.0-31.31 kernel: powerpc/perf: fix preempt count underflow in fsl_emb_pmu_del — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80630linux-libc-dev7.0.0-31.31 kernel: net/sched: sch_fq_codel: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80638linux-libc-dev7.0.0-31.31 kernel: ocfs2: fix out-of-bounds write in ocfs2_remove_refcount_extent — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80641linux-libc-dev7.0.0-31.31 kernel: wifi: wlcore: enable the right set of ciphers — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80646linux-libc-dev7.0.0-31.31 kernel: ipv6: guard against possible NULL deref in __in6_dev_stats_get() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80659linux-libc-dev7.0.0-31.31 kernel: mmc: vub300: defer reset until cmd_mutex is unlocked — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80663linux-libc-dev7.0.0-31.31 kernel: tools/power/x86/intel-speed-select: Harden daemon pidfile open — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80664linux-libc-dev7.0.0-31.31 kernel: netfilter: xt_nat: reject unsupported target families — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80722linux-libc-dev7.0.0-31.31 kernel: wifi: mac80211: validate individual TWT params before driver setup — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80533linux-libc-dev7.0.0-31.31 kernel: xfs: don't walk off the end of a null sc->sa.agi_bp in AGI repair — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80594linux-libc-dev7.0.0-31.31 kernel: Input: ims-pcu - fix potential infinite loop in CDC union descriptor parsing — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80595linux-libc-dev7.0.0-31.31 kernel: Input: ims-pcu - add response length checks — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80596linux-libc-dev7.0.0-31.31 kernel: Input: ims-pcu - only expose sysfs attributes on control interface — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80597linux-libc-dev7.0.0-31.31 kernel: mtd: maps: vmu-flash: fix NULL pointer dereference in initialization — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80598linux-libc-dev7.0.0-31.31 kernel: ntfs3: fix out-of-bounds read in decompress_lznt — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80599linux-libc-dev7.0.0-31.31 kernel: batman-adv: dat: ensure accessible eth_hdr proto field — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80600linux-libc-dev7.0.0-31.31 kernel: batman-adv: dat: acquire ARP hw source only after skb realloc — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80601linux-libc-dev7.0.0-31.31 kernel: batman-adv: gw: acquire ethernet header only after skb realloc — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80602linux-libc-dev7.0.0-31.31 kernel: perf/x86/amd/lbr: Fix kernel address leakage — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80603linux-libc-dev7.0.0-31.31 kernel: netfilter: nf_conntrack_irc: fix parse_dcc() off-by-one OOB read — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80604linux-libc-dev7.0.0-31.31 kernel: HID: core: Fix OOB read in hid_get_report for numbered reports — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80605linux-libc-dev7.0.0-31.31 kernel: HID: picolcd: prevent NULL pointer dereference in picolcd_send_and_wait() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80606linux-libc-dev7.0.0-31.31 kernel: drm/xe/userptr: Hold notifier_lock for write on inject test path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80607linux-libc-dev7.0.0-31.31 kernel: tracing/probes: Remove WARN_ON_ONCE from parse_btf_arg — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80608linux-libc-dev7.0.0-31.31 kernel: accel/amdxdna: Fix iommu domain lifetime race during device removal — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80609linux-libc-dev7.0.0-31.31 kernel: qede: fix out-of-bounds check for cqe->len_list[] — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80610linux-libc-dev7.0.0-31.31 kernel: net: enetc: fix potential divide-by-zero when num_vsi is zero — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80611linux-libc-dev7.0.0-31.31 kernel: ACPI: processor_idle: Mark LPI enter functions as __cpuidle — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80726linux-libc-dev7.0.0-31.31 kernel: KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80727linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: x ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80729linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80730linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: r ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80731linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80732linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: a ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80733linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80734linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80735linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: o ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80736linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: t ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80737linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80738linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80739linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80740linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80741linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80742linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: a ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80743linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: A ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80744linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80666linux-libc-dev7.0.0-31.31 kernel: Bluetooth: sco: Fix a race condition in sco_sock_timeout() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80667linux-libc-dev7.0.0-31.31 kernel: net/mlx5: LAG, MPESW, Fix missing complete() on devcom error — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80669linux-libc-dev7.0.0-31.31 kernel: bpf: Disable xfrm_decode_session hook attachment — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80670linux-libc-dev7.0.0-31.31 kernel: perf tools: Use perf_env__get_cpu_topology() in machine__resolve() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80675linux-libc-dev7.0.0-31.31 kernel: libbpf: Reject non-exclusive metadata maps in the signed loader — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80684linux-libc-dev7.0.0-31.31 kernel: KVM: s390: pci: Fix NULL dereference on AIBV allocation failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80686linux-libc-dev7.0.0-31.31 kernel: mm: migrate_device: fix pte_pfn/pte_dirty called on non-present PTE — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80694linux-libc-dev7.0.0-31.31 kernel: net: ethernet: mtk_eth_soc: pass eth to mtk_handle_irq_rx in poll_controller — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80695linux-libc-dev7.0.0-31.31 kernel: hwmon: (sht3x) Fix unaligned accesses — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80697linux-libc-dev7.0.0-31.31 kernel: erofs: ensure valid f_path for page cache sharing — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80699linux-libc-dev7.0.0-31.31 kernel: KVM: arm64: vgic: Avoid double-deactivate of IRQs in the nested context — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80701linux-libc-dev7.0.0-31.31 kernel: drm/vmwgfx: enforce cursor size limits for MOB cursors — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80703linux-libc-dev7.0.0-31.31 kernel: drm/amdkfd: Fix missing authorization check in KFD_IOC_DBG_TRAP_DISABLE — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80705linux-libc-dev7.0.0-31.31 kernel: drm/amd/display: check if dml21_add_phantom_plane() is successful — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80707linux-libc-dev7.0.0-31.31 kernel: can: j1939: transport: j1939_session_fresh_new(): initialize receive buffer — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80713linux-libc-dev7.0.0-31.31 kernel: io_uring: preserve task restrictions across exec — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80715linux-libc-dev7.0.0-31.31 kernel: igc: remove napi_synchronize() in igc_down() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80717linux-libc-dev7.0.0-31.31 kernel: sctp: validate Adaptation Indication parameter length — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80720linux-libc-dev7.0.0-31.31 kernel: iomap: add a separate bio_set for iomap_split_ioend — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80534linux-libc-dev7.0.0-31.31 kernel: xfs: fix ilock leak on error in xfs_dq_get_next_id — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80535linux-libc-dev7.0.0-31.31 kernel: xfs: don't double-lock when deleting a self-referential directory — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80536linux-libc-dev7.0.0-31.31 kernel: xfs: bounds-check buffer log item's dirty bitmap — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80537linux-libc-dev7.0.0-31.31 kernel: xfs: fix off-by-one in rtrefcount btree root level validation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80538linux-libc-dev7.0.0-31.31 kernel: xfs: propagate errors from xfs_rtginode_load — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80539linux-libc-dev7.0.0-31.31 kernel: drm/amdgpu: disallow multiple FENCE chunks in one submit — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80540linux-libc-dev7.0.0-31.31 kernel: drm/amdgpu: Fix UVD decode image min size calculation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80541linux-libc-dev7.0.0-31.31 kernel: drm/amdgpu: validate GEM_CREATE domain combinations — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80542linux-libc-dev7.0.0-31.31 kernel: drm/amd/display: Fix NULL pointer dereference in amdgpu_dm_crtc_set_vblank() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80547linux-libc-dev7.0.0-31.31 kernel: s390/vfio_ccw: Implement a crw lock — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80548linux-libc-dev7.0.0-31.31 kernel: s390/vfio_ccw: Selectively expand io_mutex — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80549linux-libc-dev7.0.0-31.31 kernel: s390/vfio_ccw: Move cp cleanup out of not operational — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80550linux-libc-dev7.0.0-31.31 kernel: s390/vfio_ccw: Fix out of bounds check on CCW array — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80551linux-libc-dev7.0.0-31.31 kernel: s390/vfio_ccw: Ensure first IDAW remains constant — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80552linux-libc-dev7.0.0-31.31 kernel: s390/vfio_ccw: Ensure index for read/write regions are within range — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80553linux-libc-dev7.0.0-31.31 kernel: s390/vfio_ccw: Cancel existing workqueues — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80554linux-libc-dev7.0.0-31.31 kernel: s390/vfio_ccw: Limit the number of channel program segments — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80574linux-libc-dev7.0.0-31.31 kernel: Input: focaltech - fix array out-of-bounds in focaltech_process_rel_packet — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74748linux-libc-dev7.0.0-31.31 kernel: netfilter: ipset: fix refcount race between list:set GC and swap — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74750linux-libc-dev7.0.0-31.31 kernel: ovpn: defer key slot crypto freeing to workqueue — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74752linux-libc-dev7.0.0-31.31 kernel: sctp: validate cookie AUTH state before use — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74753linux-libc-dev7.0.0-31.31 kernel: perf: Reject exited events as group leaders — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74754linux-libc-dev7.0.0-31.31 kernel: scsi: core: pair EH runtime PM get and put — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80519linux-libc-dev7.0.0-31.31 kernel: ovpn: finish crypto callback cleanup before peer release — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80520linux-libc-dev7.0.0-31.31 kernel: ovpn: fix NULL dereference when killing missing key — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80521linux-libc-dev7.0.0-31.31 kernel: af_unix: Unlink scc_entry in unix_del_edge() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80522linux-libc-dev7.0.0-31.31 kernel: crypto: tegra - fix rctx->cryptlen calculation in tegra_gcm_do_one_req() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80523linux-libc-dev7.0.0-31.31 kernel: clk: spacemit: k3: set hdma clock as critical — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80524linux-libc-dev7.0.0-31.31 kernel: optee: ffa: Add NULL check in optee_ffa_lend_protmem — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80525linux-libc-dev7.0.0-31.31 kernel: ASoC: SOF: ipc4-topology: Refresh copier IPC payload before widget setup — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80526linux-libc-dev7.0.0-31.31 kernel: ASoC: tas2562: Validate values for volume writes — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80527linux-libc-dev7.0.0-31.31 kernel: ceph: fix hanging __ceph_get_caps() with stale mds_wanted — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80528linux-libc-dev7.0.0-31.31 kernel: ceph: avoid fs reclaim while using current->journal_info — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80529linux-libc-dev7.0.0-31.31 kernel: xfs: don't swallow dquot recovery verification errors — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80530linux-libc-dev7.0.0-31.31 kernel: xfs: fix exchange-range reflink flag clearing issue with INO1_WRITTEN — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80531linux-libc-dev7.0.0-31.31 kernel: xfs: avoid UAF on sc->tempip in xrep_tempfile_create — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80532linux-libc-dev7.0.0-31.31 kernel: xfs: fix another iunlink infinite loop bug in online fsck — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80575linux-libc-dev7.0.0-31.31 kernel: Input: cs40l50-vibra - validate custom data from user space — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80576linux-libc-dev7.0.0-31.31 kernel: drm/amdgpu: reject oversized IBs with per-ring packet limits — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80577linux-libc-dev7.0.0-31.31 kernel: drm/panthor: skip zero-sized firmware sections — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80578linux-libc-dev7.0.0-31.31 kernel: fbdev: core: Fix pointer desynchronization in fb_io_read() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80579linux-libc-dev7.0.0-31.31 kernel: fbdev: clear fb_info->mode before deleting a videomode — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80580linux-libc-dev7.0.0-31.31 kernel: fbdev: bound mode sysfs output to the sysfs buffer — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80581linux-libc-dev7.0.0-31.31 kernel: ASoC: SOF: ipc4-pcm: Continue the pipeline trigger in case of IPC timeout — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80582linux-libc-dev7.0.0-31.31 kernel: drm/shmem_helper: Check VMA boundaries for PMD mappings — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80583linux-libc-dev7.0.0-31.31 kernel: ASoC: codecs: lpass-tx-macro: Fix enum kcontrol accesses — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80584linux-libc-dev7.0.0-31.31 kernel: s390/qeth: validate user buffer length in SNMP and ARP query ioctls — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80585linux-libc-dev7.0.0-31.31 kernel: mptcp: fastopen: only mark MPTFO subflows with SYN data — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80586linux-libc-dev7.0.0-31.31 kernel: mptcp: options: reset DSS fields in case of unexpected size — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80587linux-libc-dev7.0.0-31.31 kernel: mptcp: avoid combining some incoming suboptions — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80588linux-libc-dev7.0.0-31.31 kernel: mptcp: reclaim forward-allocated memory on RX path errors — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80589linux-libc-dev7.0.0-31.31 kernel: block: stop the timeout timer when releasing a never added disk — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80590linux-libc-dev7.0.0-31.31 kernel: inet: frags: strip GSO state from fragments before reassembly — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80592linux-libc-dev7.0.0-31.31 kernel: samples/damon/mtier: fail early if address range parameters are invalid — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80593linux-libc-dev7.0.0-31.31 kernel: hwmon: (asus_atk0110) Check package count before accessing element — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80555linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80556linux-libc-dev7.0.0-31.31 kernel: mmc: atmel-mci: Fix use-after-free in atmci_remove due to race condition — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80557linux-libc-dev7.0.0-31.31 kernel: libceph: fix OOB read in decode_watchers() via missing bounds check — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80558linux-libc-dev7.0.0-31.31 kernel: libceph: Avoid using invalid osd indices from primary_temp — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80559linux-libc-dev7.0.0-31.31 kernel: Input: sur40 - fix input device registration ordering — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80560linux-libc-dev7.0.0-31.31 kernel: openrisc: signal: do not restore privileged SR bits on sigreturn — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80561linux-libc-dev7.0.0-31.31 kernel: libceph: fix multiple unsafe decodes in decode_locker() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80562linux-libc-dev7.0.0-31.31 kernel: gpio: ml-ioh: use raw_spinlock_t for the register lock — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80563linux-libc-dev7.0.0-31.31 kernel: gpio: sloppy-logic-analyzer: fix use-after-free via debugfs trigger on unbind — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80564linux-libc-dev7.0.0-31.31 kernel: gve: fix NULL dereference due to missing ptp adjfine — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80565linux-libc-dev7.0.0-31.31 kernel: crypto: qce - fix error path in devm_qce_register_algs — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80566linux-libc-dev7.0.0-31.31 kernel: Input: hynitron_cstxxx - validate touch count and finger IDs — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80567linux-libc-dev7.0.0-31.31 kernel: Input: synaptics-rmi4 - propagate F54 worker errors to V4L2 queue — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80568linux-libc-dev7.0.0-31.31 kernel: Input: synaptics-rmi4 - block s_input when F54 queue is busy — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80569linux-libc-dev7.0.0-31.31 kernel: Input: synaptics-rmi4 - bound the F54 report size to the allocated buffer — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80570linux-libc-dev7.0.0-31.31 kernel: Input: synaptics-rmi4 - zero report size on F54 work error — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80571linux-libc-dev7.0.0-31.31 kernel: powerpc/pseries: papr-phy-attest - validate cmd.length, plug mem leak — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80572linux-libc-dev7.0.0-31.31 kernel: Input: byd - synchronize timer deletion before freeing private data — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80573linux-libc-dev7.0.0-31.31 kernel: Input: iforce - validate input packet lengths — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89877linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89878linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89879linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89880linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89881linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89882linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89883linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89884linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89885linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89886linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89887linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89888linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89889linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89890linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89891linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89892linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89893linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89915linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: K ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89802linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89858linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89859linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89860linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89861linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89862linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89863linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89864linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89865linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89866linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89867linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89868linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89869linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89870linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89871linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89872linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89873linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89874linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89875linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89916linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: K ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89917linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: K ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89918linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: K ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89919linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: K ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89920linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: K ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89921linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: K ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89922linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: K ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89923linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: K ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89924linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: K ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89925linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: K ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89926linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: K ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89927linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: K ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89928linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: K ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89929linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: K ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89930linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: K ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89931linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: K ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89932linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: K ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89933linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89894linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89895linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89896linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89897linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89898linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89899linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89901linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89902linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: L ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89903linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: L ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89904linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: L ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89905linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: L ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89906linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: L ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89907linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: L ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89908linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: L ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89909linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: L ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89911linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: K ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89912linux-libc-dev7.0.0-31.31 kernel: KVM: arm64: vgic-its: Don't dereference a NULL collection on ITT save — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89913linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: K ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89914linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: K ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89803linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89804linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89805linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89806linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89807linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89808linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89809linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89810linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89811linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89812linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89813linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89814linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89815linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89816linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89817linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89818linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89819linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89839linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89783linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: x ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89784linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: S ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89785linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89786linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: e ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89787linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: e ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89788linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: k ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89789linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: g ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89790linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89791linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: p ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89792linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: k ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89793linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: u ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89794linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: k ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89795linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: P ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89796linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89797linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: p ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89798linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: r ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89799linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89800linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89801linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89840linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89841linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89842linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89843linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89844linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89845linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89846linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89847linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89848linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89849linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89850linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89851linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89852linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89853linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89854linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89855linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89856linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89857linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89820linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89821linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89822linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89823linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89824linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89825linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89826linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89827linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89828linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89829linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89830linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89831linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89832linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89833linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89834linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89835linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89836linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89837linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89838linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-90031linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: u ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-90032linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-90033linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: A ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-90034linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: u ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-90035linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-90036linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: N ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-90037linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: N ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-90039linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: N ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-90040linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: K ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-90041linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: H ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-90042linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: c ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-90043linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: z ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-90044linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: u ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-90045linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: U ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-90046linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-90047linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-90048linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-90049linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-35351rust-coreutils0.8.0-0ubuntu3 The mv utility in uutils coreutils fails to preserve file ownership du ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89953linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-90013linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: t ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-90014linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: t ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-90015linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: x ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-90016linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-90017linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-90018linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-90019linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: u ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-90020linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: U ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-90021linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: u ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-90022linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: u ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-90023linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: u ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-90024linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: u ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-90025linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: u ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-90026linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: u ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-90027linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: u ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-90028linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: u ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-90029linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: u ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-90030linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: u ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-35352rust-coreutils0.8.0-0ubuntu3 A Time-of-Check to Time-of-Use (TOCTOU) race condition exists in the m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-35354rust-coreutils0.8.0-0ubuntu3 A Time-of-Check to Time-of-Use (TOCTOU) vulnerability exists in the mv ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-35357rust-coreutils0.8.0-0ubuntu3 The cp utility in uutils coreutils is vulnerable to an information dis ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-35359rust-coreutils0.8.0-0ubuntu3 A Time-of-Check to Time-of-Use (TOCTOU) vulnerability in the cp utilit ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-35360rust-coreutils0.8.0-0ubuntu3 The touch utility in uutils coreutils is vulnerable to a Time-of-Check ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-35363rust-coreutils0.8.0-0ubuntu3 A vulnerability in the rm utility of uutils coreutils allows the bypas ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-35364rust-coreutils0.8.0-0ubuntu3 A Time-of-Check to Time-of-Use (TOCTOU) race condition exists in the m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-35367rust-coreutils0.8.0-0ubuntu3 The nohup utility in uutils coreutils creates its default output file, ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-35368rust-coreutils0.8.0-0ubuntu3 A vulnerability exists in the chroot utility of uutils coreutils when ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-35370rust-coreutils0.8.0-0ubuntu3 The id utility in uutils coreutils miscalculates the groups= section o ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-35371rust-coreutils0.8.0-0ubuntu3 The id utility in uutils coreutils exhibits incorrect behavior in its ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-35373rust-coreutils0.8.0-0ubuntu3 A logic error in the ln utility of uutils coreutils causes the program ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-35374rust-coreutils0.8.0-0ubuntu3 A Time-of-Check to Time-of-Use (TOCTOU) vulnerability exists in the sp ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-35377rust-coreutils0.8.0-0ubuntu3 A logic error in the env utility of uutils coreutils causes a failure ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-18477tar1.35+dfsg-4ubuntu0.4 tar: tar: TOCTOU in incremental dumpdir 'X' rename handling allows restore path escape — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-18508tar1.35+dfsg-4ubuntu0.4 tar: tar: --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-85091zlib1g1:1.3.dfsg+really1.3.1-1ubuntu3.1 zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vul ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-85091zlib1g-dev1:1.3.dfsg+really1.3.1-1ubuntu3.1 zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vul ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-12087perl5.40.1-7ubuntu0.2 5.40.1-7ubuntu0.3perl-Socket: perl-Socket: Information Disclosure due to Out-of-Bounds Read — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-13221perl5.40.1-7ubuntu0.2 5.40.1-7ubuntu0.3perl: Perl: Incorrect regular expression processing via large regular expressions — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-57432perl5.40.1-7ubuntu0.2 5.40.1-7ubuntu0.3perl: Perl: Information disclosure via integer overflow in pack/unpack operations — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-57433perl5.40.1-7ubuntu0.2 5.40.1-7ubuntu0.3Storable: Storable: Denial of Service via signed integer overflow in deserialization — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-12087perl-base5.40.1-7ubuntu0.2 5.40.1-7ubuntu0.3perl-Socket: perl-Socket: Information Disclosure due to Out-of-Bounds Read — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-13221perl-base5.40.1-7ubuntu0.2 5.40.1-7ubuntu0.3perl: Perl: Incorrect regular expression processing via large regular expressions — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-57432perl-base5.40.1-7ubuntu0.2 5.40.1-7ubuntu0.3perl: Perl: Information disclosure via integer overflow in pack/unpack operations — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-57433perl-base5.40.1-7ubuntu0.2 5.40.1-7ubuntu0.3Storable: Storable: Denial of Service via signed integer overflow in deserialization — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-12087perl-modules-5.405.40.1-7ubuntu0.2 5.40.1-7ubuntu0.3perl-Socket: perl-Socket: Information Disclosure due to Out-of-Bounds Read — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-13221perl-modules-5.405.40.1-7ubuntu0.2 5.40.1-7ubuntu0.3perl: Perl: Incorrect regular expression processing via large regular expressions — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-57432perl-modules-5.405.40.1-7ubuntu0.2 5.40.1-7ubuntu0.3perl: Perl: Information disclosure via integer overflow in pack/unpack operations — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-57433perl-modules-5.405.40.1-7ubuntu0.2 5.40.1-7ubuntu0.3Storable: Storable: Denial of Service via signed integer overflow in deserialization — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2025-10990ruby3.33.3.8-2ubuntu3.1 rexml: REXML: Denial of Service via inefficient regex parsing — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2025-10990ruby3.3-dev3.3.8-2ubuntu3.1 rexml: REXML: Denial of Service via inefficient regex parsing — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-35341rust-coreutils0.8.0-0ubuntu3 A vulnerability in uutils coreutils mkfifo allows for the unauthorized ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-35344rust-coreutils0.8.0-0ubuntu3 The dd utility in uutils coreutils suppresses errors during file trunc ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-35345rust-coreutils0.8.0-0ubuntu3 A vulnerability in the tail utility of uutils coreutils allows for the ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-35348rust-coreutils0.8.0-0ubuntu3 The sort utility in uutils coreutils is vulnerable to a process panic ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-35350rust-coreutils0.8.0-0ubuntu3 The cp utility in uutils coreutils fails to properly handle setuid and ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89954linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89955linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89956linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89957linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89958linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89959linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89960linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89961linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: p ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89962linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: p ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89963linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: p ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89964linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: p ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89965linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89966linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89967linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89968linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89969linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89970linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89991linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89934linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89935linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89936linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89937linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89938linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89939linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89940linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89941linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89942linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89943linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: A ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89944linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: A ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89945linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: A ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89946linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: A ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89947linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: c ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89948linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89949linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89950linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89951linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: b ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89952linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89992linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: c ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89993linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89994linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89995linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89996linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89997linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89998linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89999linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: H ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-90000linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: H ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-90001linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: H ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-90002linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-90003linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-90005linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-90006linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-90007linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-90008linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-90011linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-90012linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89971linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89972linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89973linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89974linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89975linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89976linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: a ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89977linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: a ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89978linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: a ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89979linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: A ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89980linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: A ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89981linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: a ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89982linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89983linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89984linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: p ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89986linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89987linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: m ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89988linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: k ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89989linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89990linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: c ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89564linux-libc-dev7.0.0-31.31 kernel: ip: orphan prefetched skbs before multicast forwarding — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89565linux-libc-dev7.0.0-31.31 kernel: Linux kernel ipip: Memory leak in collect_md mode leading to Denial of Service — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89566linux-libc-dev7.0.0-31.31 kernel: jbd2: check need_resched() when skipping busy checkpoint buffers — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89567linux-libc-dev7.0.0-31.31 kernel: jbd2: bound shrinker scans by examined checkpoint buffers — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89568linux-libc-dev7.0.0-31.31 kernel: Linux kernel: Undefined behavior in memory reservation due to incorrect size calculation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89569linux-libc-dev7.0.0-31.31 kernel: Bluetooth: RFCOMM: serialize security confirmation handling — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89570linux-libc-dev7.0.0-31.31 kernel: cxl/mce: Make the MCE notifier per-region — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89571linux-libc-dev7.0.0-31.31 kernel: Linux kernel: Out-of-bounds read in CXL features leads to denial of service — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89572linux-libc-dev7.0.0-31.31 kernel: Linux kernel: cpufreq apple-soc driver improper cleanup of OPP tables — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89573linux-libc-dev7.0.0-31.31 kernel: Linux kernel: dm array memory corruption from crafted metadata — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89574linux-libc-dev7.0.0-31.31 kernel: Linux kernel: dm array out-of-bounds read due to insufficient header validation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89575linux-libc-dev7.0.0-31.31 kernel: Linux kernel: Buffer overflow in dm-raid1 due to missing NUL-terminator — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89576linux-libc-dev7.0.0-31.31 kernel: Linux kernel dm-era: Denial of Service due to metadata block leak — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89577linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: d ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89578linux-libc-dev7.0.0-31.31 kernel: Linux Kernel: dm-io vulnerability leads to denial of service via I/O hang — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89579linux-libc-dev7.0.0-31.31 kernel: bpf: Harden bloom filter sizing and indexing on 32-bit kernels — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89580linux-libc-dev7.0.0-31.31 kernel: Linux kernel: Memory corruption in BPF due to improper handling of preemption — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89581linux-libc-dev7.0.0-31.31 kernel: Linux kernel: Denial of Service due to incorrect BPF per-CPU address resolution on x86 — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89601linux-libc-dev7.0.0-31.31 kernel: ext2: Fix lost inode updates for IS_SYNC inodes — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89487linux-libc-dev7.0.0-31.31 kernel: openvswitch: only skb_tx_error() a packet we are about to drop — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89546linux-libc-dev7.0.0-31.31 kernel: Linux Kernel: Resource management flaw in SUNRPC NFS callback service — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89547linux-libc-dev7.0.0-31.31 kernel: SUNRPC: Check svc pool percpu counter allocation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89548linux-libc-dev7.0.0-31.31 kernel: SUNRPC: always drain cache_cleaner before destroying a cache_detail — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89549linux-libc-dev7.0.0-31.31 kernel: Linux kernel: sunrpc connection hang due to threadless pool routing — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89550linux-libc-dev7.0.0-31.31 kernel: Linux kernel: Denial of Service in SUNRPC via crafted Kerberos token — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89551linux-libc-dev7.0.0-31.31 kernel: SUNRPC: xdr_buf_trim: clamp buf->len to avoid underflow — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89552linux-libc-dev7.0.0-31.31 kernel: Linux kernel: Denial of Service via NULL pointer dereference in parameter handling — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89553linux-libc-dev7.0.0-31.31 kernel: nouveau/gem: reserve the bo in the info ioctl around the vma lookup — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89554linux-libc-dev7.0.0-31.31 kernel: mptcp: fix uninitialized local_id in syncookie MP_JOIN reconstruction — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89555linux-libc-dev7.0.0-31.31 kernel: mpls: reload header after pskb_may_pull() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89556linux-libc-dev7.0.0-31.31 kernel: module: validate string table section types — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89557linux-libc-dev7.0.0-31.31 kernel: Linux kernel md driver: Denial of service via integer overflow in bad block handling — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89558linux-libc-dev7.0.0-31.31 kernel: Linux kernel md/raid10: Silent data corruption due to inverted degraded state during array recovery — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89559linux-libc-dev7.0.0-31.31 kernel: libnvdimm/labels: Prevent integer overflow in __nd_label_validate() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89560linux-libc-dev7.0.0-31.31 kernel: Linux kernel (Landlock): Security bypass via improper whiteout creation permissions — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89561linux-libc-dev7.0.0-31.31 kernel: ipv6: rpl: fix NULL dereference of idev in ipv6_rpl_srh_rcv() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89562linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89563linux-libc-dev7.0.0-31.31 kernel: Linux Kernel: Memory corruption in ip6_tunnel due to double-free vulnerability — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89602linux-libc-dev7.0.0-31.31 kernel: Linux kernel: erofs memory corruption during global buffer resizing — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89603linux-libc-dev7.0.0-31.31 kernel: entry: Fix seccomp bypass after ptrace with TSYNC — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89604linux-libc-dev7.0.0-31.31 kernel: efivarfs: Rate limit statfs() handler — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89605linux-libc-dev7.0.0-31.31 kernel: Linux kernel ecryptfs: Denial of Service due to message context leak on send failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89606linux-libc-dev7.0.0-31.31 kernel: ecryptfs: Denial of Service via malformed tag 70 packets — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89607linux-libc-dev7.0.0-31.31 kernel: ecryptfs: reject oversized encrypted_key_size in parse_tag_3_packet — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89608linux-libc-dev7.0.0-31.31 kernel: Linux kernel: ecryptfs buffer size miscalculation vulnerability — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89609linux-libc-dev7.0.0-31.31 kernel: Linux Kernel: eCryptfs race condition in daemon queue cleanup — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89615linux-libc-dev7.0.0-31.31 kernel: Linux kernel: NTFS3 driver buffer overflow via crafted log record — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89616linux-libc-dev7.0.0-31.31 kernel: Linux kernel: Information leak in NTFS3 filesystem due to partial LZNT decompression — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89617linux-libc-dev7.0.0-31.31 kernel: Linux kernel: NTFS3 filesystem vulnerable to memory corruption via crafted log replay — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89618linux-libc-dev7.0.0-31.31 kernel: Linux kernel: eventfs false warning due to uninitialized data — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89619linux-libc-dev7.0.0-31.31 kernel: Linux kernel: Buffer overflow in intel-quickspi driver via oversized HID report — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89620linux-libc-dev7.0.0-31.31 kernel: HID: intel-thc-hid: intel-quickspi: validate report size before copy — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89621linux-libc-dev7.0.0-31.31 kernel: Linux kernel: Information disclosure in HID mcp2221 driver via crafted USB report — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89622linux-libc-dev7.0.0-31.31 kernel: HID: mcp2221: clear rxbuf after I2C/SMBus transfer completes — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89624linux-libc-dev7.0.0-31.31 kernel: HID: universal-pidff: stop the device when force-feedback init fails — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89625linux-libc-dev7.0.0-31.31 kernel: HID: sony: fix UAF of ghl_poke_timer / ghl_urb at driver unbind — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89582linux-libc-dev7.0.0-31.31 kernel: bnx2x: Double Free Vulnerability in Linux Kernel leading to Denial of Service or Code Execution — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89583linux-libc-dev7.0.0-31.31 kernel: Bluetooth: eir: Fix OOB read in eir_get_service_data() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89584linux-libc-dev7.0.0-31.31 kernel: Linux Kernel: Denial of Service due to improper user space vector validation in block layer — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89585linux-libc-dev7.0.0-31.31 kernel: Linux kernel: Use-after-free in auxdisplay charlcd component — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89586linux-libc-dev7.0.0-31.31 kernel: ata: libata-scsi: fix DSM TRIM for sector sizes larger than 2048 bytes — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89587linux-libc-dev7.0.0-31.31 kernel: Linux kernel: Stack buffer overflow in ACPI pfr_update can lead to memory corruption. — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89588linux-libc-dev7.0.0-31.31 kernel: ACPI: APEI: GHES: fix ARM section length accounting after header — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89589linux-libc-dev7.0.0-31.31 kernel: Linux kernel: Denial of Service in ACPI/APEI/GHES due to spinlock deadlock — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89590linux-libc-dev7.0.0-31.31 kernel: accel/rocket: Fix error path handling in rocket_job_run() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89591linux-libc-dev7.0.0-31.31 kernel: Linux kernel: NULL pointer dereference in accel/rocket module — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89592linux-libc-dev7.0.0-31.31 kernel: Linux kernel: accel/rocket NULL dereference and integer overflow — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89593linux-libc-dev7.0.0-31.31 kernel: hugetlb: only adjust reservation during unmapping if mapcount is 0 — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89594linux-libc-dev7.0.0-31.31 kernel: hsi: omap_ssi_core: fix missing DMA mask setup for SSI controller device — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89595linux-libc-dev7.0.0-31.31 kernel: fsnotify: Fix stale object mask after concurrent mark updates — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89596linux-libc-dev7.0.0-31.31 kernel: Linux kernel forcedeth driver: Out-of-bounds memory access can lead to kernel crash — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89597linux-libc-dev7.0.0-31.31 kernel: Linux kernel uvesafb: Resource leak due to improper callback unregistration — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89598linux-libc-dev7.0.0-31.31 kernel: fbdev: ssd1307fb: defer I2C transfers from damage callbacks — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89599linux-libc-dev7.0.0-31.31 kernel: Linux kernel: Denial of Service due to uninitialized mutex in `fbdev: omapfb: panel-dsi-cm` — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89600linux-libc-dev7.0.0-31.31 kernel: Linux Kernel: Information Disclosure via fanotify Use-After-Free — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89488linux-libc-dev7.0.0-31.31 kernel: Linux kernel: Open vSwitch use-after-free vulnerability leading to denial of service — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89489linux-libc-dev7.0.0-31.31 kernel: Linux kernel: Arbitrary code execution via or1k_atomic syscall — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89490linux-libc-dev7.0.0-31.31 kernel: ocfs2: ocfs2: Denial of Service via readdir position truncation on 32-bit kernels — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89491linux-libc-dev7.0.0-31.31 kernel: ocfs2: cluster: don't sleep while holding o2hb_live_lock in o2hb_region_pin() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89492linux-libc-dev7.0.0-31.31 kernel: ocfs2: validate directory-index entry counts when reading metadata — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89493linux-libc-dev7.0.0-31.31 kernel: ocfs2: Memory corruption due to insufficient refcount block validation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89494linux-libc-dev7.0.0-31.31 kernel: ocfs2: validate lengths in dlm_mig_lockres_handler — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89495linux-libc-dev7.0.0-31.31 kernel: ocfs2: Arbitrary code execution and Denial of Service via malformed Distributed Lock Manager messages — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89496linux-libc-dev7.0.0-31.31 kernel: ocfs2: always run deallocs on copy-on-write completion — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89497linux-libc-dev7.0.0-31.31 kernel: orangefs: skip leading spaces before parsing client debug masks — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89498linux-libc-dev7.0.0-31.31 kernel: orangefs: fix double-free of trailer_buf on readdir copy failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89500linux-libc-dev7.0.0-31.31 kernel: ring-buffer: Make cpu_buffer::free_page a buffer_data_read_page — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89501linux-libc-dev7.0.0-31.31 kernel: Linux kernel ring-buffer: Race condition can lead to system instability — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89502linux-libc-dev7.0.0-31.31 kernel: ring-buffer: Free cpu_buffer::free_page with subbuf_order — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89503linux-libc-dev7.0.0-31.31 kernel: ring-buffer: Fix subbuf resize race with ring_buffer_alloc_read_page() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89504linux-libc-dev7.0.0-31.31 kernel: Linux kernel: Dangling pointer in regulator subsystem can lead to denial of service. — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89506linux-libc-dev7.0.0-31.31 kernel: Linux kernel: RDMA/uverbs null pointer dereference leads to Denial of Service — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89527linux-libc-dev7.0.0-31.31 kernel: svcrdma: Use svc_xprt_put to free listener on create failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89468linux-libc-dev7.0.0-31.31 kernel: power: supply: lp8788-charger: fix use-after-free on remove — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89469linux-libc-dev7.0.0-31.31 kernel: Linux Kernel: Memory corruption in lp8727 power supply driver — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89470linux-libc-dev7.0.0-31.31 kernel: power: supply: cros_usbpd: Limit port counts to EC_USB_PD_MAX_PORTS — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89471linux-libc-dev7.0.0-31.31 kernel: Linux kernel: cros_usbpd-charger: Memory corruption from excessive EC port count — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89472linux-libc-dev7.0.0-31.31 kernel: power: supply: charger-manager: register regulators before exposing sysfs — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89473linux-libc-dev7.0.0-31.31 kernel: Linux Kernel: Denial of service via bq25890 driver reference leak. — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89474linux-libc-dev7.0.0-31.31 kernel: power: supply: bq256xx: drain usb_work before freeing the charger — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89475linux-libc-dev7.0.0-31.31 kernel: Linux kernel: Use-after-free in bq24257 power supply driver — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89476linux-libc-dev7.0.0-31.31 kernel: sctp: fix stream->outcnt underflow on duplicate RECONF responses — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89477linux-libc-dev7.0.0-31.31 kernel: Linux kernel: SCTP null pointer dereference leads to denial of service — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89478linux-libc-dev7.0.0-31.31 kernel: sctp: drop a chunk if its transport was removed — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89479linux-libc-dev7.0.0-31.31 kernel: Linux kernel (SCTP): Denial of service via use-after-free in packet processing — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89480linux-libc-dev7.0.0-31.31 kernel: Linux kernel: NVMe-TCP vulnerability allows information disclosure due to incomplete data transfer — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89481linux-libc-dev7.0.0-31.31 kernel: Linux kernel (nvme-tcp): Host memory disclosure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89482linux-libc-dev7.0.0-31.31 kernel: nvme-tcp: do not accept C2HData based on blk_rq_payload_bytes() alone — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89483linux-libc-dev7.0.0-31.31 kernel: nvme: zero the discard fallback page — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89484linux-libc-dev7.0.0-31.31 kernel: Linux kernel `lockd`: Denial of Service due to NULL dereference — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89485linux-libc-dev7.0.0-31.31 kernel: Linux kernel: lockd use-after-free vulnerability leading to system instability — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89486linux-libc-dev7.0.0-31.31 kernel: Linux kernel IPMI: Use-after-free vulnerability leading to system instability or privilege escalation. — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89528linux-libc-dev7.0.0-31.31 kernel: Linux kernel: Denial of Service in svcrdma due to page budget overflow — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89529linux-libc-dev7.0.0-31.31 kernel: svcrdma: Reject oversized Read segments at decode time — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89530linux-libc-dev7.0.0-31.31 kernel: Linux kernel: Memory corruption in svcrdma due to oversized network replies — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89531linux-libc-dev7.0.0-31.31 kernel: Linux kernel svcrdma: Denial of Service due to resource leak from failed connection attempts — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89532linux-libc-dev7.0.0-31.31 kernel: svcrdma: Fix pcl_for_each_segment for empty chunks — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89533linux-libc-dev7.0.0-31.31 kernel: svcrdma: Fix offset arithmetic in read_chunk_range — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89534linux-libc-dev7.0.0-31.31 kernel: svcrdma: Clear sc_cm_id when ADDR_CHANGE replacement fails — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89535linux-libc-dev7.0.0-31.31 kernel: svcrdma: Reorder rpcrdma_rn_unregister before rdma_destroy_id — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89536linux-libc-dev7.0.0-31.31 kernel: Linux kernel: Memory corruption in SUNRPC client TLS handshake — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89537linux-libc-dev7.0.0-31.31 kernel: Linux kernel: Memory corruption in SUNRPC due to short Kerberos MIC tokens — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89538linux-libc-dev7.0.0-31.31 kernel: Linux kernel: SUNRPC vulnerability in Kerberos v2 token processing — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89539linux-libc-dev7.0.0-31.31 kernel: Linux kernel: SUNRPC memory leak due to duplicate CREDS_VALUE options — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89540linux-libc-dev7.0.0-31.31 kernel: sunrpc: init gssp_lock before publishing proc entry — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89541linux-libc-dev7.0.0-31.31 kernel: Linux kernel (SUNRPC): Out-of-bounds read via crafted RPCSEC_GSS reply — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89542linux-libc-dev7.0.0-31.31 kernel: Linux kernel: SUNRPC memory corruption via crafted tokens — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89543linux-libc-dev7.0.0-31.31 kernel: sunrpc: fix use-after-free in __rpc_clnt_handle_event and __rpc_clnt_remove_pipedir — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89544linux-libc-dev7.0.0-31.31 kernel: SUNRPC: fix gssx_dec_option_array error path bugs — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89545linux-libc-dev7.0.0-31.31 kernel: Linux kernel: Use-after-free in sunrpc due to asynchronous memory deallocation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89507linux-libc-dev7.0.0-31.31 kernel: RDMA/ucma: Lock the handler in ucma_write_cm_event() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89508linux-libc-dev7.0.0-31.31 kernel: Linux kernel: RDMA/ucma use-after-free vulnerability leading to denial of service — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89509linux-libc-dev7.0.0-31.31 kernel: Linux kernel RDMA/ionic: NULL pointer dereference leading to Denial of Service — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89510linux-libc-dev7.0.0-31.31 kernel: RDMA/cxgb4: Cancel reg_work before freeing device on remove — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89511linux-libc-dev7.0.0-31.31 kernel: Linux Kernel qede driver: Kernel panic due to NULL pointer dereference — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89512linux-libc-dev7.0.0-31.31 kernel: remoteproc: scp: Fix device reference leak on failed lookup — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89513linux-libc-dev7.0.0-31.31 kernel: Linux kernel KVM (RISC-V): Memory corruption due to PMU event info array overflow — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89514linux-libc-dev7.0.0-31.31 kernel: scsi: fnic: Use GFP_ATOMIC for VLAN alloc under spinlock — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89515linux-libc-dev7.0.0-31.31 kernel: scsi: core: Fill in DMA padding bytes in scsi_alloc_sgtables() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89517linux-libc-dev7.0.0-31.31 kernel: Linux kernel: `sched_ext` core scheduling flaw leads to Denial of Service — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89518linux-libc-dev7.0.0-31.31 kernel: sched_ext: Fix this_rq() assumptions in dispatch kfuncs — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89519linux-libc-dev7.0.0-31.31 kernel: sched_ext: Replace SCX_RQ_BAL_KEEP with a dispatch verdict return — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89520linux-libc-dev7.0.0-31.31 kernel: Linux kernel: Core scheduling vulnerability leads to system instability — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89521linux-libc-dev7.0.0-31.31 kernel: Linux kernel: Denial of Service due to inconsistent core scheduling state — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89522linux-libc-dev7.0.0-31.31 kernel: media: staging/ipu7: fix async notifier UAF on probe error path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89523linux-libc-dev7.0.0-31.31 kernel: wifi: mt76: mt7925: cancel pending mlo_pm_work — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89524linux-libc-dev7.0.0-31.31 kernel: wifi: ath6kl: clamp assoc request/response lengths before subtracting IE offsets — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89525linux-libc-dev7.0.0-31.31 kernel: udf: reject VAT indexes equal to the entry count — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89526linux-libc-dev7.0.0-31.31 kernel: svcrdma: Validate Read chunk positions before reconstruction — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89724linux-libc-dev7.0.0-31.31 kernel: media: vicodec: fix out-of-bounds write in FWHT encoder — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89725linux-libc-dev7.0.0-31.31 kernel: media: cec: stm32: prevent out-of-bounds write on RX overflow — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89726linux-libc-dev7.0.0-31.31 kernel: Linux kernel: Out-of-bounds read in ucs2_strnlen() can lead to information disclosure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89727linux-libc-dev7.0.0-31.31 kernel: KVM: arm64: GICv2: Don't WARN on out-of-range GICV_DIR INTID — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89728linux-libc-dev7.0.0-31.31 kernel: i3c: renesas: Fix out-of-bounds access for newdevs mask — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89729linux-libc-dev7.0.0-31.31 kernel: HID: sensor-hub: Fix out-of-bounds write in sensor_hub_get_feature — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89730linux-libc-dev7.0.0-31.31 kernel: fpga: altera-cvp: Avoid out-of-bounds read in trailing byte write — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89731linux-libc-dev7.0.0-31.31 kernel: Linux kernel: Out-of-bounds read in CXL/RAS AER handling — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89732linux-libc-dev7.0.0-31.31 kernel: Kernel: USB FunctionFS deadlock via ep0 read loop — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89733linux-libc-dev7.0.0-31.31 kernel: Linux kernel: USB UVC gadget driver use-after-free vulnerability — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89734linux-libc-dev7.0.0-31.31 kernel: Linux kernel: Denial of Service due to null pointer dereference in USB Video Class gadget driver — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89735linux-libc-dev7.0.0-31.31 kernel: Linux kernel: USB gadget MIDI2 driver resource leak leads to denial of service — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89736linux-libc-dev7.0.0-31.31 kernel: Linux kernel USB audio gadget driver: Use-after-free leading to arbitrary code execution — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89737linux-libc-dev7.0.0-31.31 kernel: Linux kernel: Thunderbolt driver use-after-free vulnerability — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89738linux-libc-dev7.0.0-31.31 kernel: Linux kernel: USB gadget `at91_udc` driver use-after-free vulnerability — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89739linux-libc-dev7.0.0-31.31 kernel: usb: dwc3: gadget: Fix use-after-free in dwc3_gadget_free_endpoints due to race condition — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89740linux-libc-dev7.0.0-31.31 kernel: serial: imx: serialize imx_uart_ports[] lifetime — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89741linux-libc-dev7.0.0-31.31 kernel: Revert "media: v4l2-dev: fix error handling in __video_register_device()" — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89763linux-libc-dev7.0.0-31.31 kernel: Linux kernel: Use-after-free in TPM trusted keys due to incorrect teardown ordering — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89648linux-libc-dev7.0.0-31.31 kernel: ceph: cap delegated inode count in ceph_parse_deleg_inos() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89706linux-libc-dev7.0.0-31.31 kernel: nfsd: Reset write verifier when async COPY writeback fails — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89707linux-libc-dev7.0.0-31.31 kernel: nfsd: release path refs on follow_down() error — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89708linux-libc-dev7.0.0-31.31 kernel: nfsd: RCU-protect cl_cb_session to fix use-after-free on session teardown — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89709linux-libc-dev7.0.0-31.31 kernel: Linux kernel: lockd and nfsd denial of service vulnerability — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89710linux-libc-dev7.0.0-31.31 kernel: NFSv4.1: fix layout segment leak on the pnfs_layout_process() forget path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89711linux-libc-dev7.0.0-31.31 kernel: NFSD: remove flawed WARN_ON_ONCE from nfsd_mode_check — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89712linux-libc-dev7.0.0-31.31 kernel: Linux kernel NFSD: Denial of service via use-after-free — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89713linux-libc-dev7.0.0-31.31 kernel: Linux kernel NFSD: Unauthorized truncation of append-only files via TOCTOU vulnerability — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89714linux-libc-dev7.0.0-31.31 kernel: Linux kernel NFS: Denial of Service due to unbounded memory leak from failed mount attempts — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89715linux-libc-dev7.0.0-31.31 kernel: NFS/localio: fix ref leak on nfs_uuid_add_file failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89716linux-libc-dev7.0.0-31.31 kernel: Linux kernel zram: Denial of Service due to improper deflate parameter validation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89717linux-libc-dev7.0.0-31.31 kernel: zram: NULL pointer dereference due to invalid compressor state — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89718linux-libc-dev7.0.0-31.31 kernel: zram: fix out-of-bounds access in writeback_store() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89719linux-libc-dev7.0.0-31.31 kernel: Linux kernel: zram out-of-bounds access leading to system instability — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89720linux-libc-dev7.0.0-31.31 kernel: ubifs: fix out-of-bounds read in signature length check — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89721linux-libc-dev7.0.0-31.31 kernel: Linux kernel: `rockchip-samsung-dcphy` out-of-bounds read leads to denial of service — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89722linux-libc-dev7.0.0-31.31 kernel: PCI/sysfs: Fix out-of-bounds read in pci_write_legacy_io() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89723linux-libc-dev7.0.0-31.31 kernel: nilfs2: Linux kernel: nilfs2 slab-out-of-bounds due to improper node block handling — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89764linux-libc-dev7.0.0-31.31 kernel: Linux kernel (rust devres): Use-after-free due to race condition in concurrent resource revocation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89765linux-libc-dev7.0.0-31.31 kernel: Kernel: Information disclosure in timers/itimer due to uninitialized padding — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89766linux-libc-dev7.0.0-31.31 kernel: Linux kernel: Information disclosure in pidfd namespace handling — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89767linux-libc-dev7.0.0-31.31 kernel: ovl: fix double end_creating() on the casefold-mismatch path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89768linux-libc-dev7.0.0-31.31 kernel: Linux kernel: Information disclosure via incorrect path derivation in nested overlayfs — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89769linux-libc-dev7.0.0-31.31 kernel: Linux kernel: Use-after-free due to IRQ leak in NXP PIT clocksource driver — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89771linux-libc-dev7.0.0-31.31 kernel: ring-buffer: Fix subbuf resize race with ring buffer readers — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89772linux-libc-dev7.0.0-31.31 kernel: btrfs: write-protect folios during data writeback — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89773linux-libc-dev7.0.0-31.31 kernel: drm/amd/display: Skip Update HDCP Config In Transition State — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89774linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: B ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89775linux-libc-dev7.0.0-31.31 kernel: KVM: arm64: Handle negative S1 walk levels in VNCR TLB size evaluation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89776linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: v ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89777linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: v ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89778linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89779linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89780linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89781linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89782linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: f ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89742linux-libc-dev7.0.0-31.31 kernel: Linux kernel: Arbitrary code execution via use-after-free in RapidIO mport character device. — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89743linux-libc-dev7.0.0-31.31 kernel: Linux kernel: NSM information disclosure via out-of-bounds read — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89744linux-libc-dev7.0.0-31.31 kernel: device property: fix infinite loop in fwnode_for_each_child_node() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89745linux-libc-dev7.0.0-31.31 kernel: debugfs: Fix lockdown check for mmap_prepare — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89746linux-libc-dev7.0.0-31.31 kernel: Linux kernel tracing: Use-after-free leads to Denial of Service — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89747linux-libc-dev7.0.0-31.31 kernel: tracing: Fix use-after-free in trace_pipe read on sub-buffer order change — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89749linux-libc-dev7.0.0-31.31 kernel: tracing: Fix crash passing ERR_PTR to kthread_stop() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89750linux-libc-dev7.0.0-31.31 kernel: Linux kernel: Use-After-Free in tracing/user_events component — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89751linux-libc-dev7.0.0-31.31 kernel: Linux kernel (x86/tdx): Off-by-one error in port I/O handling — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89752linux-libc-dev7.0.0-31.31 kernel: Linux kernel: Denial of Service in memcg due to stale memory limit during reclaim — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89753linux-libc-dev7.0.0-31.31 kernel: mm/vmscan: report RCU-tasks quiescent states in shrink_lruvec() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89754linux-libc-dev7.0.0-31.31 kernel: Linux kernel: Memory corruption via out-of-bounds write in mm/pagewalk — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89755linux-libc-dev7.0.0-31.31 kernel: Linux kernel: System crash due to stale memory mapping in device migration — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89756linux-libc-dev7.0.0-31.31 kernel: mm/migrate: report RCU-tasks quiescent states in migrate_pages_batch() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89757linux-libc-dev7.0.0-31.31 kernel: mm/mglru: fix and remove redundant unevictable folio handling — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89758linux-libc-dev7.0.0-31.31 kernel: Linux kernel: Denial of Service due to improper handling of device-private PMDs in memory management — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89759linux-libc-dev7.0.0-31.31 kernel: mm/kmemleak: avoid soft lockup when scanning task stacks — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89761linux-libc-dev7.0.0-31.31 kernel: Kernel: AppArmor out-of-bounds write allows local denial of service or privilege escalation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89762linux-libc-dev7.0.0-31.31 kernel: apparmor: fix cred UAF caused by begin_current_label_crit_section() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89649linux-libc-dev7.0.0-31.31 kernel: ceph: Linux kernel CephFS: Information disclosure via out-of-bounds read in extended attribute handling — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89650linux-libc-dev7.0.0-31.31 kernel: Linux kernel (Ceph): Out-of-bounds read in client via crafted MDS map — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89651linux-libc-dev7.0.0-31.31 kernel: ceph: Linux kernel Ceph client: Out-of-bounds read leads to denial of service — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89652linux-libc-dev7.0.0-31.31 kernel: ceph: Linux kernel (Ceph): Buffer overflow leads to memory corruption in NFS export — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89653linux-libc-dev7.0.0-31.31 kernel: ceph: reject export_targets ranks >= CEPH_MAX_MDS in mdsmap decode — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89654linux-libc-dev7.0.0-31.31 kernel: ceph: fix UAF in check_new_map() on session freed during unlock — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89655linux-libc-dev7.0.0-31.31 kernel: ceph: fix UAF in __kick_flushing_caps() on cf entry freed during unlock — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89656linux-libc-dev7.0.0-31.31 kernel: libceph: reject buckets with mismatched CRUSH ids — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89657linux-libc-dev7.0.0-31.31 kernel: libceph: Denial of Service in Linux kernel via malformed sparse-read replies — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89658linux-libc-dev7.0.0-31.31 kernel: NFSD: Prevent client use-after-free during NFSv4.0 revoked-state cleanup — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89659linux-libc-dev7.0.0-31.31 kernel: NFSD: Prevent client use-after-free during delegation revoke — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89660linux-libc-dev7.0.0-31.31 kernel: Linux kernel: NFSD use-after-free during client state revocation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89661linux-libc-dev7.0.0-31.31 kernel: NFSD: Prevent post-shutdown use-after-free in unlock_filesystem — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89662linux-libc-dev7.0.0-31.31 kernel: NFSD: Prevent lock owner use-after-free during client teardown — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89663linux-libc-dev7.0.0-31.31 kernel: Linux kernel (nfsd): Use-after-free vulnerability in copy-notify stateid revocation. — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89664linux-libc-dev7.0.0-31.31 kernel: nfsd: release OPEN-decoded posix ACLs via op_release — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89665linux-libc-dev7.0.0-31.31 kernel: nfsd: reject out-of-range useconds in NFSv2 SETATTR/CREATE — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89687linux-libc-dev7.0.0-31.31 kernel: Linux Kernel (nfsd): Improper file handling could lead to system instability — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89626linux-libc-dev7.0.0-31.31 kernel: HID: sensor: custom: Fix field sysfs group cleanup on failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89627linux-libc-dev7.0.0-31.31 kernel: HID: roccat: free buffered reports when destroying device — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89628linux-libc-dev7.0.0-31.31 kernel: Linux kernel: HID picolcd driver information disclosure via out-of-bounds read — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89629linux-libc-dev7.0.0-31.31 kernel: HID: corsair-void: Check size of status and firmware events before reading them — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89630linux-libc-dev7.0.0-31.31 kernel: smb: client: restore the data_offset bound in is_valid_oplock_break() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89631linux-libc-dev7.0.0-31.31 kernel: Linux Kernel: Information disclosure in SMB client due to small byte count in tree connect response — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89633linux-libc-dev7.0.0-31.31 kernel: Linux kernel SMB client: Out-of-bounds read/write via unvalidated DataOffset — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89634linux-libc-dev7.0.0-31.31 kernel: smb: client: fix ALIGN() overflow in symlink_data() error context loop — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89636linux-libc-dev7.0.0-31.31 kernel: Linux kernel SMB client: Use-after-free vulnerability due to improper handling of freed structures — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89637linux-libc-dev7.0.0-31.31 kernel: Kernel: Use-After-Free vulnerability in SMB client due to malformed TRANSACT2 response — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89638linux-libc-dev7.0.0-31.31 kernel: smb: client: clear setuid/setgid bit on write with cifsacl/modefromsid/posix extensions — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89640linux-libc-dev7.0.0-31.31 kernel: cifs: fix loff_t underflow in cifs_remap_file_range() when len == 0 — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89641linux-libc-dev7.0.0-31.31 kernel: cifs: clear tcon after cifsFileInfo_put() in cifs_file_set_size() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89642linux-libc-dev7.0.0-31.31 kernel: Linux kernel: CIFS information disclosure via stale data exposure during file extension — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89643linux-libc-dev7.0.0-31.31 kernel: audit: avoid dropping live tree ref on fsnotify rule autoremove — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89644linux-libc-dev7.0.0-31.31 kernel: btrfs: fix extent map leak in NOCOW direct I/O write — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89645linux-libc-dev7.0.0-31.31 kernel: Linux kernel btrfs: Resource exhaustion due to improper relocation root cleanup — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89646linux-libc-dev7.0.0-31.31 kernel: ceph: fix leaked inode reference on writeback abort at umount — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89647linux-libc-dev7.0.0-31.31 kernel: ceph: Linux kernel Ceph: Excessive CPU utilization due to busy loop in dentry trimming — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89688linux-libc-dev7.0.0-31.31 kernel: nfsd: drop the stateid, not the stateowner, on seqid_op replay retry — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89689linux-libc-dev7.0.0-31.31 kernel: nfsd: don't free session slots that are still in use — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89690linux-libc-dev7.0.0-31.31 kernel: Linux kernel nfsd: Memory corruption via use-after-free in compound operations — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89691linux-libc-dev7.0.0-31.31 kernel: Linux Kernel nfsd: Information disclosure via out-of-bounds read in compound argument release — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89692linux-libc-dev7.0.0-31.31 kernel: nfsd: clear CALLBACK_RUNNING on failed delegation recall queue — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89693linux-libc-dev7.0.0-31.31 kernel: nfsd: check nfsd4_acl_to_attr() return value in nfsd4_create() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89694linux-libc-dev7.0.0-31.31 kernel: nfsd: check client ownership when cancelling a copy-notify stateid — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89695linux-libc-dev7.0.0-31.31 kernel: nfsd: cap decoded POSIX ACL count to bound sort cost — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89696linux-libc-dev7.0.0-31.31 kernel: Linux kernel (nfsd): Denial of Service via crafted NFS COMPOUND requests — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89697linux-libc-dev7.0.0-31.31 kernel: nfsd: add fh_want_write() for early-verified SETATTR in nfsd_proc_setattr() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89698linux-libc-dev7.0.0-31.31 kernel: Linux kernel (nfsd): Information disclosure via out-of-bounds read in address handling — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89699linux-libc-dev7.0.0-31.31 kernel: Linux kernel: nfsd vulnerable to denial of service via oversized NFSv4 symlink targets — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89700linux-libc-dev7.0.0-31.31 kernel: Linux kernel nfsd: Out-of-bounds read due to improper sockaddr length validation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89701linux-libc-dev7.0.0-31.31 kernel: Linux Kernel: Data integrity issue in nfsd due to improper timestamp validation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89702linux-libc-dev7.0.0-31.31 kernel: nfsd: size fh_verify server sockaddr slot by xpt_locallen — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89703linux-libc-dev7.0.0-31.31 kernel: nfsd: set SC_STATUS_FREED in nfsd4_drop_revoked_stid for delegations — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89704linux-libc-dev7.0.0-31.31 kernel: Linux kernel: nfsd silent data loss due to incorrect writeback error handling — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89705linux-libc-dev7.0.0-31.31 kernel: nfsd: restore rq_status_counter to even on all nfsd_dispatch() exit paths — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89666linux-libc-dev7.0.0-31.31 kernel: nfsd: reject out-of-range nseconds in NFSv3 SETATTR and create ops — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89667linux-libc-dev7.0.0-31.31 kernel: nfsd: close shrinker/GC/fsnotify vs per-net shutdown race in filecache — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89668linux-libc-dev7.0.0-31.31 kernel: nfsd: move nfsd_debugfs_init() after nfsd4_init_slabs() in init_nfsd() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89669linux-libc-dev7.0.0-31.31 kernel: Linux Kernel: nfsd use-after-free vulnerability via racing OFFLOAD_CANCEL — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89670linux-libc-dev7.0.0-31.31 kernel: Linux kernel: nfsd use-after-free vulnerability due to missing RCU lock — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89671linux-libc-dev7.0.0-31.31 kernel: Linux kernel: NFSv3 `nfsd` allows unauthorized ACL removal via crafted SETACL requests. — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89672linux-libc-dev7.0.0-31.31 kernel: nfsd: gate nfs2 setacl by argp->mask — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89674linux-libc-dev7.0.0-31.31 kernel: nfsd: fix XDR length calculation in nfsd4_ff_encode_layoutget — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89675linux-libc-dev7.0.0-31.31 kernel: nfsd: Linux kernel (nfsd): Use-After-Free vulnerability in asynchronous copy handling — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89676linux-libc-dev7.0.0-31.31 kernel: Linux kernel: Memory corruption in nfsd due to stale IDR entry in async COPY — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89677linux-libc-dev7.0.0-31.31 kernel: nfsd: fix possible fh_compose of wrong dentry in nfsd4_create_file() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89678linux-libc-dev7.0.0-31.31 kernel: Kernel: NFS daemon (nfsd) data corruption due to incorrect partial-write detection — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89679linux-libc-dev7.0.0-31.31 kernel: Linux kernel nfsd: Denial of Service via specially crafted SETATTR request — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89680linux-libc-dev7.0.0-31.31 kernel: Linux Kernel nfsd: Denial of Service via resource leak during inter-server COPY setup — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89682linux-libc-dev7.0.0-31.31 kernel: nfsd: fix fcache_disposal UAF by inlining dispose state into nfsd_net — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89683linux-libc-dev7.0.0-31.31 kernel: nfsd: fix dentry ref leak on V4ROOT export filehandle lookup — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89684linux-libc-dev7.0.0-31.31 kernel: Linux kernel: nfsd denial of service due to copy state notification race — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89685linux-libc-dev7.0.0-31.31 kernel: Linux kernel: NFS daemon denial of service via clock domain mismatch — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-89686linux-libc-dev7.0.0-31.31 kernel: Linux kernel (nfsd): Denial of Service due to a race condition in NFSv4 delegation revoke — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68374linux-libc-dev7.0.0-31.31 kernel: usb: core: sysfs: add lock to bos_descriptors_read() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68375linux-libc-dev7.0.0-31.31 kernel: bnxt_en: Handle partially initialized auxiliary devices — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68376linux-libc-dev7.0.0-31.31 kernel: sctp: fix auth_hmacs array size in struct sctp_cookie — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68377linux-libc-dev7.0.0-31.31 kernel: Linux kernel: Denial of Service due to use-after-free in act_tunnel_key — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68378linux-libc-dev7.0.0-31.31 kernel: dpll: fix NULL pointer dereference in dpll_msg_add_pin_ref_sync() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68379linux-libc-dev7.0.0-31.31 kernel: tcp: fix TIME_WAIT socket reference leak on PSP policy failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68381linux-libc-dev7.0.0-31.31 kernel: ksmbd: Use-after-free vulnerability due to race condition in connection handling — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68382linux-libc-dev7.0.0-31.31 kernel: drm/xe/guc: Hold device ref until queue teardown completes — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68383linux-libc-dev7.0.0-31.31 kernel: drm/xe/guc: Keep scheduler timeline name alive — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68384linux-libc-dev7.0.0-31.31 kernel: drm/xe/vf: Fix VF CCS attach/detach race with in-flight BO moves — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68385linux-libc-dev7.0.0-31.31 kernel: s390/checksum: Fix csum_partial() without vector facility — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68386linux-libc-dev7.0.0-31.31 kernel: bpf, sockmap: Reject unhashed UDP sockets on sockmap update — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68387linux-libc-dev7.0.0-31.31 kernel: can: raw: add locking for raw flags bitfield — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68388linux-libc-dev7.0.0-31.31 kernel: smb/client: handle overlapping allocated ranges in fallocate — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68389linux-libc-dev7.0.0-31.31 kernel: Bluetooth: hci_qca: Clear memdump state on invalid dump size — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68390linux-libc-dev7.0.0-31.31 kernel: Bluetooth: hci_sync: hold hdev->lock for hci_conn_params lookups — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68391linux-libc-dev7.0.0-31.31 kernel: Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68413linux-libc-dev7.0.0-31.31 kernel: memory leak in ipw2100_pci_init_one() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68290linux-libc-dev7.0.0-31.31 kernel: Kernel: Use-after-free vulnerability in RDS TCP can lead to system instability — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68354linux-libc-dev7.0.0-31.31 kernel: firewire: net: Fix fragmented datagram reassembly — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68355linux-libc-dev7.0.0-31.31 kernel: wifi: ath11k: fix potential buffer underflow in ath11k_hal_rx_msdu_list_get() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68356linux-libc-dev7.0.0-31.31 kernel: watchdog: airoha: Prevent division by zero when clock frequency is zero — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68357linux-libc-dev7.0.0-31.31 kernel: watchdog: pretimeout: Fix UAF in watchdog_unregister_governor() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68358linux-libc-dev7.0.0-31.31 kernel: hwmon: (nzxt-kraken3) Stop device IO before calling hid_hw_stop — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68359linux-libc-dev7.0.0-31.31 kernel: hwmon: (nzxt-smart2) Stop device IO before calling hid_hw_stop — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68360linux-libc-dev7.0.0-31.31 kernel: hwmon: (corsair-cpro) Stop device IO before calling hid_hw_stop — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68361linux-libc-dev7.0.0-31.31 kernel: hwmon: (corsair-psu) Stop device IO before calling hid_hw_stop — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68362linux-libc-dev7.0.0-31.31 kernel: wifi: ath11k: fix NULL pointer dereference in ath11k_hal_srng_access_begin — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68363linux-libc-dev7.0.0-31.31 kernel: Linux kernel: ath9k Wi-Fi driver use-after-free vulnerability leading to system crash — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68364linux-libc-dev7.0.0-31.31 kernel: drm/amd/display: Fix ISM dc_lock deadlock during suspend — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68365linux-libc-dev7.0.0-31.31 kernel: USB: serial: io_edgeport: cap received transmit credits — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68366linux-libc-dev7.0.0-31.31 kernel: usb: gadget: uvc: clamp SEND_RESPONSE length to the response buffer — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68367linux-libc-dev7.0.0-31.31 kernel: usb: gadget: f_tcm: synchronize delayed set_alt with teardown — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68368linux-libc-dev7.0.0-31.31 kernel: usb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68369linux-libc-dev7.0.0-31.31 kernel: usb: gadget: printer: fix infinite loop in printer_read() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68371linux-libc-dev7.0.0-31.31 kernel: usb: musb: omap2430: Do not put borrowed of_node in probe — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68372linux-libc-dev7.0.0-31.31 kernel: usb: core: port: Deattach Type-C connector on component unbind — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68414linux-libc-dev7.0.0-31.31 kernel: wifi: cfg80211: cancel sched scan results work on unregister — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68415linux-libc-dev7.0.0-31.31 kernel: xfrm: clear mode callbacks after failed mode setup — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68416linux-libc-dev7.0.0-31.31 kernel: mtd: fix double free and WARN_ON in add_mtd_device() error paths — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68417linux-libc-dev7.0.0-31.31 kernel: RDMA/siw: publish QP after initialization — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68418linux-libc-dev7.0.0-31.31 kernel: RDMA/irdma: Prevent user-triggered null deref on QP create — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68419linux-libc-dev7.0.0-31.31 kernel: RDMA/irdma: Prevent rereg_mr for non-mem regions — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68420linux-libc-dev7.0.0-31.31 kernel: xfrm: reject optional IPTFS templates in outbound policies — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68421linux-libc-dev7.0.0-31.31 kernel: sched_ext: Don't warn on core-sched forced idle in put_prev_task_scx() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68422linux-libc-dev7.0.0-31.31 kernel: btrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68425linux-libc-dev7.0.0-31.31 kernel: IB/mad: Drop unmatched RMPP responses before reassembly — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68426linux-libc-dev7.0.0-31.31 kernel: xfrm: fix stale skb->prev after async crypto steals a GSO segment — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68427linux-libc-dev7.0.0-31.31 kernel: gpu: host1x: Fix use-after-free in host1x_bo_clear_cached_mappings — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68428linux-libc-dev7.0.0-31.31 kernel: KVM: x86/mmu: Fix use-after-free on vendor module reload — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68429linux-libc-dev7.0.0-31.31 kernel: drm/dp_mst: Handle torn-down topology gracefully in drm_dp_mst_topology_queue_probe() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68430linux-libc-dev7.0.0-31.31 kernel: drm/amdgpu/gfx8: drop unecessary BUG_ON() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68431linux-libc-dev7.0.0-31.31 kernel: ksmbd: validate minimum PDU size for transform requests — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68433linux-libc-dev7.0.0-31.31 kernel: libceph: bound get_version reply decode to front len — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72068linux-libc-dev7.0.0-31.31 kernel: posix-cpu-timers: Use u64 multiplication in update_rlimit_cpu() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68392linux-libc-dev7.0.0-31.31 kernel: Bluetooth: mgmt: fix locking in unpair_device/disconnect_sync — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68394linux-libc-dev7.0.0-31.31 kernel: Bluetooth: MGMT: revalidate LOAD_CONN_PARAM queued update — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68395linux-libc-dev7.0.0-31.31 kernel: ata: sata_dwc_460ex: enable SATA interrupts only after IRQ handler is registered — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68396linux-libc-dev7.0.0-31.31 kernel: scsi: core: wake eh reliably when using scsi_schedule_eh — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68397linux-libc-dev7.0.0-31.31 kernel: net/iucv: take a reference on the socket found in afiucv_hs_rcv() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68398linux-libc-dev7.0.0-31.31 kernel: Linux kernel: PPP over L2TP Use-After-Free vulnerability — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68400linux-libc-dev7.0.0-31.31 kernel: firmware: arm_ffa: Fix Endpoint Memory Access Descriptor offset calculation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68401linux-libc-dev7.0.0-31.31 kernel: firmware: arm_ffa: Fix out-of-bound writes in ffa_setup_and_transmit() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68402linux-libc-dev7.0.0-31.31 kernel: Linux kernel: Wi-Fi subsystem out-of-bounds read via crafted frames — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68403linux-libc-dev7.0.0-31.31 kernel: wifi: brcmfmac: initialize SDIO data work before cleanup — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68404linux-libc-dev7.0.0-31.31 kernel: wifi: cfg80211: use wiphy work for socket owner autodisconnect — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68405linux-libc-dev7.0.0-31.31 kernel: wifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68406linux-libc-dev7.0.0-31.31 kernel: wifi: cfg80211: validate PMSR FTM preamble range — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68407linux-libc-dev7.0.0-31.31 kernel: wifi: nl80211: free RNR data on MBSSID mismatch — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68408linux-libc-dev7.0.0-31.31 kernel: wifi: cfg80211: convert pmsr_free_wk to wiphy_work to fix deadlock — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68409linux-libc-dev7.0.0-31.31 kernel: wifi: mac80211: defer link RX stats percpu free to RCU — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68410linux-libc-dev7.0.0-31.31 kernel: wifi: libertas: fix memory leak in helper_firmware_cb() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68411linux-libc-dev7.0.0-31.31 kernel: wifi: mac80211_hwsim: clamp virtio RX length before skb_put — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68412linux-libc-dev7.0.0-31.31 kernel: wifi: cfg80211: Fix an error handling path in cfg80211_wext_siwscan() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68291linux-libc-dev7.0.0-31.31 kernel: Linux kernel: idpf driver null pointer dereference leads to Denial of Service — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68292linux-libc-dev7.0.0-31.31 kernel: ice: prevent tstamp ring allocation for non-PF VSI types — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68293linux-libc-dev7.0.0-31.31 kernel: net/mlx5: Fix MCIA register buffer overflow on 32 dword reads — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68294linux-libc-dev7.0.0-31.31 kernel: net: qrtr: restrict socket creation to the initial network namespace — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68296linux-libc-dev7.0.0-31.31 kernel: net: gre: fix lltx regression for GRE tunnels with SEQ/CSUM — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68297linux-libc-dev7.0.0-31.31 kernel: tipc: fix u16 MTU truncation in media and bearer MTU validation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68298linux-libc-dev7.0.0-31.31 kernel: drm/xe/vm: Fix SVM leak on resv obj alloc failure in xe_vm_create() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68299linux-libc-dev7.0.0-31.31 kernel: vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68300linux-libc-dev7.0.0-31.31 kernel: sctp: auth: verify auth requirement when auth_chunk is NULL — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68301linux-libc-dev7.0.0-31.31 kernel: net: hsr: fix memory leak on slave unregistration by removing synced VLANs — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68302linux-libc-dev7.0.0-31.31 kernel: amt: re-read skb header pointers after every pull — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68303linux-libc-dev7.0.0-31.31 kernel: drm/vc4: hvs/v3d: Fix null dereference in unbind — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68304linux-libc-dev7.0.0-31.31 kernel: wifi: brcmfmac: fix 802.1X-SHA256 call trace warning — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68306linux-libc-dev7.0.0-31.31 kernel: wifi: mt76: mt7996: fix possible NULL-pointer deref in mt7996_mcu_sta_bfer_eht() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68307linux-libc-dev7.0.0-31.31 kernel: wifi: mt76: mt7925: fix crash in reset link replay — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68308linux-libc-dev7.0.0-31.31 kernel: wifi: mt76: mt7996: check pointer returned by mt76_connac_get_he_phy_cap() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68309linux-libc-dev7.0.0-31.31 kernel: wifi: mt76: connac: fix possible NULL-pointer deref in mt76_connac_mcu_uni_bss_he_tlv() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68333linux-libc-dev7.0.0-31.31 kernel: dpaa2-switch: put MAC endpoint device on disconnect — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68269linux-libc-dev7.0.0-31.31 kernel: drm/i915/gem: Add missing nospec on parallel submit slot — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68270linux-libc-dev7.0.0-31.31 kernel: drm/sysfb: Avoid possible truncation with calculating visible size — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68271linux-libc-dev7.0.0-31.31 kernel: drm/nouveau: fix reversed error cleanup order in ucopy functions — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68272linux-libc-dev7.0.0-31.31 kernel: drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1 — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68273linux-libc-dev7.0.0-31.31 kernel: drm/amdgpu: Fix context pstate override handling — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68274linux-libc-dev7.0.0-31.31 kernel: drm/xe/guc: Fix buffer overflow in steered register list allocation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68275linux-libc-dev7.0.0-31.31 kernel: drm/amdgpu: check amdgpu_vm_bo_find() result in GET_MAPPING_INFO — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68276linux-libc-dev7.0.0-31.31 kernel: drm/amdgpu/gfx: fix cleaner shader IB buffer overflow — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68277linux-libc-dev7.0.0-31.31 kernel: drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68278linux-libc-dev7.0.0-31.31 kernel: drm/dp/mst: fix buffer overflows in sideband chunk accumulation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68279linux-libc-dev7.0.0-31.31 kernel: drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68280linux-libc-dev7.0.0-31.31 kernel: drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68281linux-libc-dev7.0.0-31.31 kernel: drm/imagination: Count paired job fence as dependency in prepare_job() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68282linux-libc-dev7.0.0-31.31 kernel: drm/rockchip: analogix_dp: Add missing error check for platform_get_resource() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68283linux-libc-dev7.0.0-31.31 kernel: tracing: Fix use-after-free freeing trigger private data — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68286linux-libc-dev7.0.0-31.31 kernel: drop_monitor: perform u64_stats updates under IRQ-disabled section — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68287linux-libc-dev7.0.0-31.31 kernel: drop_monitor: fix size calculations for 64-bit attributes — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68288linux-libc-dev7.0.0-31.31 kernel: net: drop_monitor: fix info leak in NET_DM_ATTR_PAYLOAD — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68289linux-libc-dev7.0.0-31.31 kernel: tipc: fix integer overflow in tipc_recvmsg() and tipc_recvstream() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68334linux-libc-dev7.0.0-31.31 kernel: Linux kernel: `rxrpc` race condition causes Denial of Service — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68335linux-libc-dev7.0.0-31.31 kernel: rds: drop incoming messages that cross network namespace boundaries — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68336linux-libc-dev7.0.0-31.31 kernel: bonding: fix devconf_all NULL dereference when IPv6 is disabled — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68337linux-libc-dev7.0.0-31.31 kernel: Linux kernel: Denial of Service in BPF redirect helpers — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68338linux-libc-dev7.0.0-31.31 kernel: net/packet: avoid fanout hook re-registration after unregister — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68339linux-libc-dev7.0.0-31.31 kernel: Bluetooth: btusb: validate Realtek vendor event length — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68340linux-libc-dev7.0.0-31.31 kernel: hwmon: occ: validate poll response sensor blocks — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68341linux-libc-dev7.0.0-31.31 kernel: ovpn: fix use after free in unlock_ovpn() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68342linux-libc-dev7.0.0-31.31 kernel: ovpn: avoid putting unrelated P2P peer on socket release — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68343linux-libc-dev7.0.0-31.31 kernel: smb: client: validate DFS referral PathConsumed — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68345linux-libc-dev7.0.0-31.31 kernel: arm_mpam: guard MBWU state before adding it to garbage — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68346linux-libc-dev7.0.0-31.31 kernel: ALSA: hda: cs35l41: validate and free ACPI mute object — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68347linux-libc-dev7.0.0-31.31 kernel: iommu/amd: Fix IRQ unsafe locking in gdom allocation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68348linux-libc-dev7.0.0-31.31 kernel: ASoC: tas2781: bound firmware description string parsing — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68349linux-libc-dev7.0.0-31.31 kernel: wifi: carl9170: fix buffer overflow in rx_stream failover path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68350linux-libc-dev7.0.0-31.31 kernel: Linux kernel carl9170 Wi-Fi driver: Out-of-bounds read vulnerability — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68351linux-libc-dev7.0.0-31.31 kernel: wifi: carl9170: bound memcpy length in cmd callback to prevent OOB read — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68352linux-libc-dev7.0.0-31.31 kernel: wifi: ath6kl: fix OOB read from firmware IE lengths in connect event — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68310linux-libc-dev7.0.0-31.31 kernel: wifi: mt76: mt7915: guard HE capability lookups — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68311linux-libc-dev7.0.0-31.31 kernel: wifi: mt76: mt7925: guard link STA in decap offload — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68312linux-libc-dev7.0.0-31.31 kernel: cifs: fix cifsFileInfo leak on kmalloc failure in deferred close drain paths — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68313linux-libc-dev7.0.0-31.31 kernel: tipc: fix infinite loop in __tipc_nl_compat_dumpit — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68315linux-libc-dev7.0.0-31.31 kernel: sctp: validate stream count in sctp_process_strreset_inreq() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68316linux-libc-dev7.0.0-31.31 kernel: accel: ethosu: Fix element size accounting for cmd stream validation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68317linux-libc-dev7.0.0-31.31 kernel: pds_core: fix auxiliary device add/del races — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68318linux-libc-dev7.0.0-31.31 kernel: pds_core: fix use-after-free on workqueue during remove — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68319linux-libc-dev7.0.0-31.31 kernel: pds_core: fix deadlock between reset thread and remove — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68320linux-libc-dev7.0.0-31.31 kernel: sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68321linux-libc-dev7.0.0-31.31 kernel: net: txgbe: fix FDIR filter leak on remove — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68322linux-libc-dev7.0.0-31.31 kernel: rds: Fix inet6_addr_lst NULL dereference when IPv6 is disabled — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68324linux-libc-dev7.0.0-31.31 kernel: iommu/intel: Fix out-of-bounds memset in dmar_latency_disable() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68325linux-libc-dev7.0.0-31.31 kernel: iommu/amd: Bound the early ACPI HID map — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68326linux-libc-dev7.0.0-31.31 kernel: wifi: mwifiex: bound uAP association event IEs to the event buffer — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68327linux-libc-dev7.0.0-31.31 kernel: wan: wanxl: Only reset hardware after BAR mapping — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68328linux-libc-dev7.0.0-31.31 kernel: nfp: Check resource mutex allocation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68331linux-libc-dev7.0.0-31.31 kernel: dpaa2-eth: put MAC endpoint device on disconnect — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68332linux-libc-dev7.0.0-31.31 kernel: net: airoha: Fix potential use-after-free in airoha_ppe_deinit() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72069linux-libc-dev7.0.0-31.31 kernel: locking/rt: Fix the incorrect RCU protection in rt_spin_unlock() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72070linux-libc-dev7.0.0-31.31 kernel: wifi: libertas_tf: fix use-after-free in lbtf_free_adapter() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72072linux-libc-dev7.0.0-31.31 kernel: net/mlx5e: macsec: fix use-after-free of metadata_dst on RX SC delete — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72073linux-libc-dev7.0.0-31.31 kernel: mmc: vub300: fix use-after-free on probe failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72074linux-libc-dev7.0.0-31.31 kernel: Input: ims-pcu - fix type confusion in CDC union descriptor parsing — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72075linux-libc-dev7.0.0-31.31 kernel: Input: ims-pcu - fix race condition in reset_device sysfs callback — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72076linux-libc-dev7.0.0-31.31 kernel: Input: ims-pcu - fix out-of-bounds read in ims_pcu_irq() debug logging — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72077linux-libc-dev7.0.0-31.31 kernel: Input: ims-pcu - fix firmware leak in async update — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72078linux-libc-dev7.0.0-31.31 kernel: Input: ims-pcu - validate control endpoint type — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72079linux-libc-dev7.0.0-31.31 kernel: Input: ims-pcu - fix use-after-free and double-free in disconnect — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72080linux-libc-dev7.0.0-31.31 kernel: fs/resctrl: Fix use-after-free during unmount — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72081linux-libc-dev7.0.0-31.31 kernel: scsi: elx: efct: Fix I/O leak on unsupported additional CDB — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72082linux-libc-dev7.0.0-31.31 kernel: scsi: elx: efct: Fix refcount leak in efct_hw_io_abort() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72083linux-libc-dev7.0.0-31.31 kernel: scsi: target: core: Fix iSCSI ISID use-after-free in REGISTER AND MOVE — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72084linux-libc-dev7.0.0-31.31 kernel: scsi: target: Bound PR-OUT TransportID parsing to the received buffer — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72085linux-libc-dev7.0.0-31.31 kernel: scsi: xen: scsiback: Free unsubmitted command instead of double-putting it — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72086linux-libc-dev7.0.0-31.31 kernel: scsi: xen: scsiback: Free the command tag on the TMR submit-failure path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72113linux-libc-dev7.0.0-31.31 kernel: can: bcm: add missing device refcount for CAN filter removal — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68463linux-libc-dev7.0.0-31.31 kernel: mmc: sdhci-esdhc-imx: use pm_runtime_resume_and_get() in suspend — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72048linux-libc-dev7.0.0-31.31 kernel: ieee802154: ca8210: fix cas_ctl leak on spi_async failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72049linux-libc-dev7.0.0-31.31 kernel: ieee802154: admin-gate legacy LLSEC dump operations — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72050linux-libc-dev7.0.0-31.31 kernel: octeontx2-af: Free BPID bitmap on setup failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72052linux-libc-dev7.0.0-31.31 kernel: net: ip6_gre: require CAP_NET_ADMIN in the device netns for changelink — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72053linux-libc-dev7.0.0-31.31 kernel: net: ipip: require CAP_NET_ADMIN in the device netns for changelink — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72055linux-libc-dev7.0.0-31.31 kernel: net: ip6_vti: require CAP_NET_ADMIN in the device netns for changelink — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72056linux-libc-dev7.0.0-31.31 kernel: net: ena: clean up XDP TX queues when regular TX setup fails — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72057linux-libc-dev7.0.0-31.31 kernel: net/sched: act_ct: preserve tc_skb_cb across defragmentation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72058linux-libc-dev7.0.0-31.31 kernel: net: ixp4xx_hss: fix duplicate HDLC netdev allocation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72059linux-libc-dev7.0.0-31.31 kernel: net: wwan: t7xx: destroy DMA pool on CLDMA late init failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72060linux-libc-dev7.0.0-31.31 kernel: net: ethernet: ti: icssg: guard PA stat lookups — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72061linux-libc-dev7.0.0-31.31 kernel: net: sit: require CAP_NET_ADMIN in the device netns for changelink — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72062linux-libc-dev7.0.0-31.31 kernel: gpio: mt7621: avoid corruption of shared interrupt trigger state — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72063linux-libc-dev7.0.0-31.31 kernel: gpio: tegra: do not call pinctrl for GPIO direction — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72064linux-libc-dev7.0.0-31.31 kernel: net: mana: Sync page pool RX frags for CPU — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72065linux-libc-dev7.0.0-31.31 kernel: net: mana: Validate the packet length reported by the NIC — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72066linux-libc-dev7.0.0-31.31 kernel: cpu: hotplug: Bound hotplug states sysfs output — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72067linux-libc-dev7.0.0-31.31 kernel: cpu: hotplug: Preserve per instance callback errors — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72114linux-libc-dev7.0.0-31.31 kernel: can: bcm: validate frame length in bcm_rx_setup() for RTR replies — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72115linux-libc-dev7.0.0-31.31 kernel: can: bcm: track a single source interface for ANYDEV timeout/throttle ops — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72116linux-libc-dev7.0.0-31.31 kernel: can: bcm: fix stale rx/tx ops after device removal — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72117linux-libc-dev7.0.0-31.31 kernel: can: bcm: fix data race on rx_stamp/rx_ifindex in bcm_rx_handler() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72118linux-libc-dev7.0.0-31.31 kernel: can: bcm: fix CAN frame rx/tx statistics — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72119linux-libc-dev7.0.0-31.31 kernel: can: bcm: extend bcm_tx_lock usage for data and timer updates — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72120linux-libc-dev7.0.0-31.31 kernel: can: bcm: add missing rcu list annotations and operations — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72121linux-libc-dev7.0.0-31.31 kernel: can: bcm: add locking when updating filter and timer values — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72122linux-libc-dev7.0.0-31.31 kernel: can: bcm: fix lockless bound/ifindex race and silent RX_SETUP failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72125linux-libc-dev7.0.0-31.31 kernel: can: isotp: fix use-after-free race with concurrent NETDEV_UNREGISTER — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72126linux-libc-dev7.0.0-31.31 kernel: can: isotp: use unconditional synchronize_rcu() in isotp_release() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72127linux-libc-dev7.0.0-31.31 kernel: netdev-genl: report NAPI thread PID in the caller's pid namespace — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72128linux-libc-dev7.0.0-31.31 kernel: nvmet: fix refcount leak in nvmet_sq_create() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72129linux-libc-dev7.0.0-31.31 kernel: nvmet-rdma: handle inline data with a nonzero offset — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72130linux-libc-dev7.0.0-31.31 kernel: nvmet-auth: reject short AUTH_RECEIVE buffers — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72131linux-libc-dev7.0.0-31.31 kernel: nvme-apple: Prevent shared tags across queues on Apple A11 — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72132linux-libc-dev7.0.0-31.31 kernel: NFS: Charge unstable writes by request size, not folio size — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72133linux-libc-dev7.0.0-31.31 kernel: spi: uniphier: Fix completion initialization order before devm_request_irq() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72087linux-libc-dev7.0.0-31.31 kernel: scsi: lpfc: Fix memory leak in lpfc_sli4_driver_resource_setup() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72088linux-libc-dev7.0.0-31.31 kernel: scsi: hpsa: Fix DMA mapping leak on IOACCEL2 reset path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72089linux-libc-dev7.0.0-31.31 kernel: accel/ivpu: Reject firmware log with size smaller than header — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72091linux-libc-dev7.0.0-31.31 kernel: accel/amdxdna: reject user command submission without a command BO — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72092linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: a ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72093linux-libc-dev7.0.0-31.31 kernel: accel/amdxdna: Fix use-after-free in amdxdna_gem_dmabuf_mmap() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72095linux-libc-dev7.0.0-31.31 kernel: dma-fence: Make dma_fence_dedup_array() robust against 0-count input — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72096linux-libc-dev7.0.0-31.31 kernel: dm-verity: make error counter atomic — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72097linux-libc-dev7.0.0-31.31 kernel: dm-verity: fix a possible NULL pointer dereference — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72098linux-libc-dev7.0.0-31.31 kernel: dm-verity: fix buffer overflow in FEC calculation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72099linux-libc-dev7.0.0-31.31 kernel: dm-integrity: don't increment hash_offset twice — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72101linux-libc-dev7.0.0-31.31 kernel: dm-integrity: fix leaking uninitialized kernel memory — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72102linux-libc-dev7.0.0-31.31 kernel: dm_early_create: fix freeing used table on dm_resume failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72103linux-libc-dev7.0.0-31.31 kernel: dm: avoid leaking the caller's thread keyring via the table device file — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72104linux-libc-dev7.0.0-31.31 kernel: dm-pcache: reject option groups without values — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72105linux-libc-dev7.0.0-31.31 kernel: dm-log: fix a bitset_size overflow on 32bit machines — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72106linux-libc-dev7.0.0-31.31 kernel: dm-ioctl: fix a possible overflow in list_version_get_info — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72107linux-libc-dev7.0.0-31.31 kernel: dm era: fix out-of-bounds memory access for non-zero start sector — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72109linux-libc-dev7.0.0-31.31 kernel: net: sparx5: unregister blocking notifier on init failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68464linux-libc-dev7.0.0-31.31 kernel: mmc: sdhci-esdhc-imx: disable irq during suspend to fix unhandled interrupt — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68465linux-libc-dev7.0.0-31.31 kernel: mmc: sdhci-esdhc-imx: fix esdhc_change_pinstate() to allow default state restore — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68467linux-libc-dev7.0.0-31.31 kernel: mtd: mchp23k256: use SPI match data for chip caps — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68469linux-libc-dev7.0.0-31.31 kernel: wifi: mwifiex: fix permanently busy scans after multiple roam iterations — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68471linux-libc-dev7.0.0-31.31 kernel: wifi: ieee80211: validate MLE common info length — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68472linux-libc-dev7.0.0-31.31 kernel: wifi: cfg80211: validate EHT MLE before MLD ID read — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68473linux-libc-dev7.0.0-31.31 kernel: powerpc/uaccess: correct check for CONFIG_PPC_E500 in mask_user_address() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68474linux-libc-dev7.0.0-31.31 kernel: powerpc/spufs: fix out-of-bounds access in spufs_mem_mmap_access() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68475linux-libc-dev7.0.0-31.31 kernel: reset: sunxi: fix memory region leak on ioremap failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68476linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68477linux-libc-dev7.0.0-31.31 kernel: ipvs: fix more places with wrong ipv6 transport offsets — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68478linux-libc-dev7.0.0-31.31 kernel: memstick: ms_block: reject a card that reports too many blocks — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68479linux-libc-dev7.0.0-31.31 kernel: Bluetooth: btrtl: validate firmware patch bounds — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68480linux-libc-dev7.0.0-31.31 kernel: AMD-SN-7061: Safe RET Interrupt Vulnerability — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72004linux-libc-dev7.0.0-31.31 kernel: wifi: mac80211: fix memory leak in ieee80211_register_hw() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72005linux-libc-dev7.0.0-31.31 kernel: wifi: rt2x00: avoid full teardown before work setup in probe — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72006linux-libc-dev7.0.0-31.31 kernel: net/mlx5: free mlx5_st_idx_data on final dealloc — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72027linux-libc-dev7.0.0-31.31 kernel: mm/compaction: handle free_pages_prepare() properly in compaction_free() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68434linux-libc-dev7.0.0-31.31 kernel: serial: 8250_mid: Fix NULL function pointer dereference on DNV/ICX-D/SNR platforms — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68436linux-libc-dev7.0.0-31.31 kernel: drm/amd/display: use kvzalloc to allocate struct dc — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68437linux-libc-dev7.0.0-31.31 kernel: drm/imagination: Fit paired fragment job in the correct CCCB — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68439linux-libc-dev7.0.0-31.31 kernel: wifi: mt76: mt7925: fix possible NULL-pointer deref in mt7925_mcu_bss_he_tlv() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68440linux-libc-dev7.0.0-31.31 kernel: net: txgbe: fix heap overflow when reading module EEPROM — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68441linux-libc-dev7.0.0-31.31 kernel: net/sched: Handle TC_ACT_REDIRECT from qdisc filter chains — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68443linux-libc-dev7.0.0-31.31 kernel: hwmon: (gigabyte_waterforce) Stop device IO before calling hid_hw_stop — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68444linux-libc-dev7.0.0-31.31 kernel: firmware: arm_ffa: Fix NULL dereference in ffa_partition_info_get() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68445linux-libc-dev7.0.0-31.31 kernel: drm/vc4: Prevent shader BO mappings from becoming writable — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68447linux-libc-dev7.0.0-31.31 kernel: drm/amdkfd: clamp v9 CRIU control stack checkpoint copy to BO size — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68448linux-libc-dev7.0.0-31.31 kernel: ovl: check access to copy_file_range source with src mounter creds — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68449linux-libc-dev7.0.0-31.31 kernel: ata: sata_dwc_460ex: fix infinite loop in NCQ tag completion bit-scanning — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68450linux-libc-dev7.0.0-31.31 kernel: btrfs: free mapping node on duplicate reloc root insert — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68452linux-libc-dev7.0.0-31.31 kernel: s390/zcrypt: Validate length for CCA AES cipher key requests — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68453linux-libc-dev7.0.0-31.31 kernel: s390/zcrypt: Fix buffer over-read in cca_cipher2protkey — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68455linux-libc-dev7.0.0-31.31 kernel: liveupdate: validate session type before performing operation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68456linux-libc-dev7.0.0-31.31 kernel: usb: atm: ueagle-atm: wait for pre-firmware load in .disconnect() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68457linux-libc-dev7.0.0-31.31 kernel: ksmbd: use opener credentials for FSCTL mutations — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68458linux-libc-dev7.0.0-31.31 kernel: binder: cache secctx size before release zeroes it — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72028linux-libc-dev7.0.0-31.31 kernel: riscv: probes: save original sp in rethook trampoline — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72029linux-libc-dev7.0.0-31.31 kernel: net: wwan: iosm: bound device offsets in the MUX downlink decoder — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72030linux-libc-dev7.0.0-31.31 kernel: ata: libata-core: Reject an invalid concurrent positioning ranges count — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72031linux-libc-dev7.0.0-31.31 kernel: ata: libata-core: Add NOLPM quirk for PNY CS900 1TB SSD — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72032linux-libc-dev7.0.0-31.31 kernel: net/mlx5: HWS, fix matcher leak on resize target setup failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72033linux-libc-dev7.0.0-31.31 kernel: orangefs: keep the readdir entry size 64-bit in fill_from_part() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72034linux-libc-dev7.0.0-31.31 kernel: fhandle: reject detached mounts in capable_wrt_mount() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72035linux-libc-dev7.0.0-31.31 kernel: net/sched: sch_taprio: Replace direct dequeue call with peek and qdisc_dequeue_peeked — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72036linux-libc-dev7.0.0-31.31 kernel: net/sched: sch_multiq: Replace direct dequeue call with peek and qdisc_dequeue_peeked — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72037linux-libc-dev7.0.0-31.31 kernel: net: lan743x: Initialize eth_syslock spinlock before use — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72038linux-libc-dev7.0.0-31.31 kernel: net: liquidio: fix BAR resource leak on PF number failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72039linux-libc-dev7.0.0-31.31 kernel: bnx2x: fix potential memory leak in bnx2x_alloc_mem_bp() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72040linux-libc-dev7.0.0-31.31 kernel: ipmi: fix refcount leak in i_ipmi_request() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72041linux-libc-dev7.0.0-31.31 kernel: espintcp: use sk_msg_free_partial to fix partial send — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72042linux-libc-dev7.0.0-31.31 kernel: ipmi: Fix user refcount underflow in event delivery — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72045linux-libc-dev7.0.0-31.31 kernel: octeontx2-af: cn10k: restrict VF LMTLINE sharing to its own PF — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72046linux-libc-dev7.0.0-31.31 kernel: gve: fix header buffer corruption with header-split and HW-GRO — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72047linux-libc-dev7.0.0-31.31 kernel: ieee802154: ca8210: fix pointer truncation in kfifo on 64-bit — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72007linux-libc-dev7.0.0-31.31 kernel: pmdomain: imx: Fix i.MX8MP VC8000E power up sequence — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72008linux-libc-dev7.0.0-31.31 kernel: pmdomain: mediatek: Fix possible nullptr KP in HWV cleanup/on-check — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72009linux-libc-dev7.0.0-31.31 kernel: pmdomain: imx93-blk-ctrl: Extract PHY as shared domain for DSI/CSI — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72010linux-libc-dev7.0.0-31.31 kernel: cgroup/cpuset: rebind mm mempolicy to effective_mems, not mems_allowed — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72011linux-libc-dev7.0.0-31.31 kernel: s390/diag: Add missing array_index_nospec() call to memtop_get_page_count() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72012linux-libc-dev7.0.0-31.31 kernel: tracing/osnoise: Call synchronize_rcu() when unregistering — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72013linux-libc-dev7.0.0-31.31 kernel: riscv: Prevent NULL pointer dereference in machine_kexec_prepare() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72014linux-libc-dev7.0.0-31.31 kernel: drbd: reject data replies with an out-of-range payload size — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72015linux-libc-dev7.0.0-31.31 kernel: fs/resctrl: Fix double-add of pseudo-locked region's RMID to free list — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72016linux-libc-dev7.0.0-31.31 kernel: cpu/hotplug: Fix NULL kobject warning in cpuhp_smt_enable() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72017linux-libc-dev7.0.0-31.31 kernel: net: macb: drop in-flight Tx SKBs on close — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72018linux-libc-dev7.0.0-31.31 kernel: dibs: loopback: validate offset and size in move_data() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72019linux-libc-dev7.0.0-31.31 kernel: macsec: don't read an unset MAC header in macsec_encrypt() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72020linux-libc-dev7.0.0-31.31 kernel: ipvs: reset full ip_vs_seq structs in ip_vs_conn_new — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72021linux-libc-dev7.0.0-31.31 kernel: ipvs: use parsed transport offset in SCTP state lookup — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72022linux-libc-dev7.0.0-31.31 kernel: llc: fix SAP refcount leak in llc_ui_autobind() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72023linux-libc-dev7.0.0-31.31 kernel: octeontx2-pf: fix SQB pointer leak on init failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72025linux-libc-dev7.0.0-31.31 kernel: s390/monwriter: Reject buffer reuse with different data length — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72026linux-libc-dev7.0.0-31.31 kernel: irqchip/irq-riscv-imsic-early: Fix fwnode leak on state setup failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2023-54190linux-libc-dev7.0.0-31.31 kernel: Kernel: Denial of Service via reference count leak in LED core — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2024-35895linux-libc-dev7.0.0-31.31 kernel: bpf, sockmap: Prevent lock inversion deadlock in map delete elem — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2024-35995linux-libc-dev7.0.0-31.31 kernel: ACPI: CPPC: Use access_width over bit_width for system memory accesses — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2025-21988linux-libc-dev7.0.0-31.31 kernel: fs/netfs/read_collect: add to next->prev_donated — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-46055linux-libc-dev7.0.0-31.31 kernel: apparmor: Fix string overrun due to missing termination — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-64190linux-libc-dev7.0.0-31.31 kernel: net: team: fix NULL pointer dereference in team_xmit during mode change — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-64349linux-libc-dev7.0.0-31.31 kernel: usb: dwc3: fix dwc3_readl() and dwc3_writel() calls in dwc3_ulpi_setup() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-64530linux-libc-dev7.0.0-31.31 kernel: net: sched: UAF via missing handler for TC_ACT_CONSUMED in tcf_qevent_handle — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-64532linux-libc-dev7.0.0-31.31 kernel: fs/ntfs3: bound NTFS_DE view.data_off in UpdateRecordData{Root,Allocation} — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-64533linux-libc-dev7.0.0-31.31 kernel: fs/ntfs3: validate lcns_follow in log_replay conversion — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-64534linux-libc-dev7.0.0-31.31 kernel: nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-64537linux-libc-dev7.0.0-31.31 kernel: bridge: cfm: reject invalid CCM interval at configuration time — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-64538linux-libc-dev7.0.0-31.31 kernel: ipv6: Fix null-ptr-deref in fib6_nh_mtu_change() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-64539linux-libc-dev7.0.0-31.31 kernel: Bluetooth: eir: Fix stack OOB write when prepending the Flags AD — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-64540linux-libc-dev7.0.0-31.31 kernel: usbnet: gl620a: fix out-of-bounds read in genelink_rx_fixup() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-64541linux-libc-dev7.0.0-31.31 kernel: net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-64542linux-libc-dev7.0.0-31.31 kernel: ipv6: ndisc: fix NULL deref in accept_untracked_na() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-64544linux-libc-dev7.0.0-31.31 kernel: crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-64572linux-libc-dev7.0.0-31.31 kernel: ipv4: fib: free fib_alias with kfree_rcu() on insert error path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80255libcurl3t64-gnutls8.18.0-1ubuntu2.5 A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instea ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2022-48929linux-libc-dev7.0.0-31.31 kernel: bpf: Fix crash due to out of bounds access into reg2btf_ids. — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2022-49940linux-libc-dev7.0.0-31.31 kernel: tty: n_gsm: add sanity check for gsm->receive in gsm_receive_buf() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2022-50090linux-libc-dev7.0.0-31.31 kernel: btrfs: replace BTRFS_MAX_EXTENT_SIZE with fs_info->max_extent_size — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2022-50230linux-libc-dev7.0.0-31.31 kernel: arm64: set UXN on swapper page tables — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2022-50232linux-libc-dev7.0.0-31.31 kernel: arm64: set UXN on swapper page tables — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2022-50240linux-libc-dev7.0.0-31.31 kernel: binder: fix UAF of alloc->vma in race with munmap() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2022-50332linux-libc-dev7.0.0-31.31 kernel: Linux kernel: Denial of Service due to improper PCI device handling in aperture driver — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2022-50380linux-libc-dev7.0.0-31.31 kernel: mm: /proc/pid/smaps_rollup: fix no vma's null-deref — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2022-50551linux-libc-dev7.0.0-31.31 kernel: wifi: brcmfmac: Fix potential shift-out-of-bounds in brcmf_fw_alloc_request() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2023-0030linux-libc-dev7.0.0-31.31 kernel: Use after Free in nvkm_vmm_pfn_map — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2023-0160linux-libc-dev7.0.0-31.31 kernel: possibility of deadlock in libbpf function sock_hash_delete_elem — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2023-1193linux-libc-dev7.0.0-31.31 kernel: use-after-free in setup_async_work() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2023-26242linux-libc-dev7.0.0-31.31 afu_mmio_region_get_by_offset in drivers/fpga/dfl-afu-region.c in the ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2023-31082linux-libc-dev7.0.0-31.31 kernel: sleeping function called from an invalid context in gsmld_write — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2023-52879linux-libc-dev7.0.0-31.31 kernel: tracing: Have trace_event_file have ref counters — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2023-53642linux-libc-dev7.0.0-31.31 kernel: x86: fix clear_user_rep_good() exception handling annotation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2023-54105linux-libc-dev7.0.0-31.31 kernel: can: isotp: check CAN address family in isotp_bind() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2023-54187linux-libc-dev7.0.0-31.31 kernel: Linux kernel (F2FS): Data corruption and denial of service when moving a directory — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-64573linux-libc-dev7.0.0-31.31 kernel: Bluetooth: qca: fix NVM tag length underflow in TLV parser — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-64575linux-libc-dev7.0.0-31.31 kernel: bpf: tcp: fix double sock release on batch realloc — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-64576linux-libc-dev7.0.0-31.31 kernel: nexthop: initialize extack in nh_res_bucket_migrate() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-64577linux-libc-dev7.0.0-31.31 kernel: gtp: check skb_pull_data() return in gtp1u_send_echo_resp() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-64578linux-libc-dev7.0.0-31.31 kernel: ksmbd: validate compound request size before reading StructureSize2 — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-64579linux-libc-dev7.0.0-31.31 kernel: xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-64580linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: x ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-64581linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: x ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-64582linux-libc-dev7.0.0-31.31 kernel: RDMA/rxe: Fix a use-after-free problem in rxe_mmap — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-64584linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: u ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-64585linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: c ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-64586linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68081linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: K ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68082linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: l ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68083linux-libc-dev7.0.0-31.31 kernel: ksmbd: fix path resolution in ksmbd_vfs_kern_path_create — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68086linux-libc-dev7.0.0-31.31 kernel: mm/khugepaged: write all dirty file folios when collapsing — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68093linux-libc-dev7.0.0-31.31 kernel: KVM: SVM: Bump asid_generation on CPU online to avoid ASID collision after hotplug — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68210linux-libc-dev7.0.0-31.31 kernel: media: stm32: dcmi: unregister notifier on probe failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-64545linux-libc-dev7.0.0-31.31 kernel: net, bpf: check master for NULL in xdp_master_redirect() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-64546linux-libc-dev7.0.0-31.31 kernel: drm/edid: fix OOB read in drm_parse_tiled_block() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-64547linux-libc-dev7.0.0-31.31 kernel: net: usb: net1080: validate packet_len before pad-byte access in rx_fixup — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-64549linux-libc-dev7.0.0-31.31 kernel: Bluetooth: bpa10x: avoid OOB read of revision string in bpa10x_setup() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-64550linux-libc-dev7.0.0-31.31 kernel: net: qualcomm: rmnet: validate MAP frame length before ingress parsing — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-64551linux-libc-dev7.0.0-31.31 kernel: sctp: validate STALE_COOKIE cause length before reading staleness — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-64552linux-libc-dev7.0.0-31.31 kernel: virtio-net: fix len check in receive_big() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-64553linux-libc-dev7.0.0-31.31 kernel: net: psample: fix info leak in PSAMPLE_ATTR_DATA — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-64555linux-libc-dev7.0.0-31.31 kernel: KVM: arm64: nv: Fix SPSR_EL2 restore in kvm_hyp_handle_mops() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-64559linux-libc-dev7.0.0-31.31 kernel: s390/pkey: Check length in PKEY_VERIFYPROTK ioctl — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-64560linux-libc-dev7.0.0-31.31 kernel: posix-cpu-timers: Prevent UAF caused by non-leader exec() race — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-64561linux-libc-dev7.0.0-31.31 kernel: KVM: x86: Check for invalid/obsolete root *after* making MMU pages available — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-64563linux-libc-dev7.0.0-31.31 kernel: rhashtable: clear stale iter->p on table restart — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-64565linux-libc-dev7.0.0-31.31 kernel: Input: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-64566linux-libc-dev7.0.0-31.31 kernel: xfrm: iptfs: propagate SKBFL_SHARED_FRAG in iptfs_skb_add_frags() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-64568linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-64569linux-libc-dev7.0.0-31.31 kernel: mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-64570linux-libc-dev7.0.0-31.31 kernel: wifi: mac80211: fix fils_discovery double free on alloc failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-64571linux-libc-dev7.0.0-31.31 kernel: wifi: p54: validate RX frame length in p54_rx_eeprom_readback() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-82209libcurl3t64-gnutls8.18.0-1ubuntu2.5 When libpsl support is enabled, libcurl fails to enforce the Public Su ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-13608libcurl4t648.18.0-1ubuntu2.5 A flaw in the libcurl SASL negotiation for LDAP authentication allows ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-18924libcurl4t648.18.0-1ubuntu2.5 curl: libcurl: Use-after-free in HTTP/2 Server Push with shared connections — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-19931libcurl4t648.18.0-1ubuntu2.5 curl: libcurl: Information disclosure via incorrect connection reuse with Negotiate authentication — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80229libcurl4t648.18.0-1ubuntu2.5 When performing transfers via libcurl\u2019s multi interface, pooled T ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80230libcurl4t648.18.0-1ubuntu2.5 When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that di ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80255libcurl4t648.18.0-1ubuntu2.5 A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instea ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-82209libcurl4t648.18.0-1ubuntu2.5 When libpsl support is enabled, libcurl fails to enforce the Public Su ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2025-66382libexpat12.7.4-1 libexpat: libexpat: Denial of service via crafted file processing — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-32776libexpat12.7.4-1 libexpat: libexpat: Denial of Service due to NULL pointer dereference — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-32777libexpat12.7.4-1 libexpat: libexpat: Denial of Service via infinite loop in DTD content parsing — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-32778libexpat12.7.4-1 libexpat: libexpat: Denial of Service via NULL pointer dereference after out-of-memory condition — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-41080libexpat12.7.4-1 libexpat: expat: libexpat: Denial of Service via hash flooding with crafted XML — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-45186libexpat12.7.4-1 libexpat: denial of service via crafted XML input — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-50219libexpat12.7.4-1 expat: libexpat: Use-after-free vulnerability due to improper handler call depth tracking — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-56131libexpat12.7.4-1 libexpat: libexpat: Use-after-free vulnerability due to insufficient handler call depth tracking — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-56132libexpat12.7.4-1 expat: libexpat: Arbitrary Code Execution via Heap-based Buffer Overflow — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2025-10990libruby3.33.3.8-2ubuntu3.1 rexml: REXML: Denial of Service via inefficient regex parsing — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-13608curl8.18.0-1ubuntu2.5 A flaw in the libcurl SASL negotiation for LDAP authentication allows ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-18924curl8.18.0-1ubuntu2.5 curl: libcurl: Use-after-free in HTTP/2 Server Push with shared connections — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-19931curl8.18.0-1ubuntu2.5 curl: libcurl: Information disclosure via incorrect connection reuse with Negotiate authentication — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80229curl8.18.0-1ubuntu2.5 When performing transfers via libcurl\u2019s multi interface, pooled T ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80230curl8.18.0-1ubuntu2.5 When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that di ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80255curl8.18.0-1ubuntu2.5 A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instea ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-82209curl8.18.0-1ubuntu2.5 When libpsl support is enabled, libcurl fails to enforce the Public Su ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2024-52005git1:2.53.0-1ubuntu1 git: The sideband payload is passed unfiltered to the terminal in git — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2024-52005git-man1:2.53.0-1ubuntu1 git: The sideband payload is passed unfiltered to the terminal in git — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-18374libc-bin2.43-2ubuntu2.4 glibc: glibc: Heap buffer overflow via attacker-controlled fopen mode string — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-18374libc-dev-bin2.43-2ubuntu2.4 glibc: glibc: Heap buffer overflow via attacker-controlled fopen mode string — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-18374libc-gconv-modules-extra2.43-2ubuntu2.4 glibc: glibc: Heap buffer overflow via attacker-controlled fopen mode string — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-18374libc62.43-2ubuntu2.4 glibc: glibc: Heap buffer overflow via attacker-controlled fopen mode string — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-18374libc6-dev2.43-2ubuntu2.4 glibc: glibc: Heap buffer overflow via attacker-controlled fopen mode string — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-13608libcurl3t64-gnutls8.18.0-1ubuntu2.5 A flaw in the libcurl SASL negotiation for LDAP authentication allows ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-18924libcurl3t64-gnutls8.18.0-1ubuntu2.5 curl: libcurl: Use-after-free in HTTP/2 Server Push with shared connections — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-19931libcurl3t64-gnutls8.18.0-1ubuntu2.5 curl: libcurl: Information disclosure via incorrect connection reuse with Negotiate authentication — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80229libcurl3t64-gnutls8.18.0-1ubuntu2.5 When performing transfers via libcurl\u2019s multi interface, pooled T ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-80230libcurl3t64-gnutls8.18.0-1ubuntu2.5 When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that di ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-39113libsqlite3-03.46.1-9ubuntu0.2 3.46.1-9ubuntu0.3Buffer Overflow vulnerability in SQLite affected version source s ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74860libxml2-162.15.2+dfsg-0.1ubuntu0.1 libxml2: double-free/UAF in libxml2 Python bindings — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-86140libxml2-162.15.2+dfsg-0.1ubuntu0.1 libxml2: libxml2: Arbitrary code execution via stack-based buffer overflow in xmlSnprintfElements — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2013-7445linux-libc-dev7.0.0-31.31 kernel: memory exhaustion via crafted Graphics Execution Manager (GEM) objects — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2015-7837linux-libc-dev7.0.0-31.31 kernel: securelevel disabled after kexec — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2016-8660linux-libc-dev7.0.0-31.31 kernel: xfs: local DoS due to a page lock order bug in the XFS seek hole/data implementation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2018-17977linux-libc-dev7.0.0-31.31 kernel: Mishandled interactions among XFRM Netlink messages, IPPROTO_AH packets, and IPPROTO_IP packets resulting in a denial of service — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2019-15794linux-libc-dev7.0.0-31.31 kernel: Overlayfs in the Linux kernel and shiftfs not restoring original value on error leading to a refcount underflow — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2021-3714linux-libc-dev7.0.0-31.31 kernel: Remote Page Deduplication Attacks — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2021-3864linux-libc-dev7.0.0-31.31 kernel: descendant's dumpable setting with certain SUID binaries — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2022-0400linux-libc-dev7.0.0-31.31 kernel: Out of bounds read in the smc protocol stack — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2022-0480linux-libc-dev7.0.0-31.31 kernel: memcg does not limit the number of POSIX file locks allowing memory exhaustion — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2022-1247linux-libc-dev7.0.0-31.31 kernel: A race condition bug in rose_connect() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2022-25836linux-libc-dev7.0.0-31.31 Bluetooth® Low Energy Pairing in Bluetooth Core Specification v4. ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2022-2961linux-libc-dev7.0.0-31.31 kernel: race condition in rose_bind() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2022-3238linux-libc-dev7.0.0-31.31 kernel: ntfs3 local privledge escalation if NTFS character set and remount and umount called simultaneously — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2022-4543linux-libc-dev7.0.0-31.31 kernel: KASLR Prefetch Bypass Breaks KPTI — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2022-48846linux-libc-dev7.0.0-31.31 kernel: block: release rq qos structures for queue without disk — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-56403libexpat12.7.4-1 libexpat: libexpat: Arbitrary code execution due to integer overflow in storeAtts — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-56404libexpat12.7.4-1 libexpat: libexpat: Arbitrary Code Execution via integer overflow in addBinding — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-56405libexpat12.7.4-1 libexpat: libexpat: Information disclosure and arbitrary code execution via integer overflow — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-56406libexpat12.7.4-1 libexpat: libexpat: Arbitrary code execution via integer overflow in XML_ParseBuffer — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-56407libexpat12.7.4-1 libexpat: libexpat: Arbitrary code execution due to integer overflow — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-56408libexpat12.7.4-1 libexpat before 2.8.2 has an integer overflow in copyString. — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-56409libexpat12.7.4-1 xmlwf in libexpat before 2.8.2 has an integer overflow for the output ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-56410libexpat12.7.4-1 libexpat: libexpat: Integer overflow in xmlwf can lead to information disclosure and arbitrary code execution. — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-56411libexpat12.7.4-1 expat: libexpat: Integer Overflow Vulnerability Leading to Information Disclosure or Code Execution — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-56412libexpat12.7.4-1 libexpat: libexpat: Use-after-free vulnerability due to improper handling of XML CDATA sections — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-66046libexpat12.7.4-1 expat: Expat: Denial of Service via quadratic complexity in attribute processing — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72522libexpat12.7.4-1 expat: libexpat: Denial of Service due to incorrect Unicode surrogate handling — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-76641libexpat12.7.4-1 CVE-2026-76641 affecting package expat for versions less than 2.8.3-2 — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-76957libexpat12.7.4-1 libexpat: libexpat: Memory corruption vulnerability allows arbitrary code execution or denial of service — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-13757libp11-kit00.26.2-2 p11-kit: Stack exhaustion via unbounded recursion in RPC attribute parsing — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-12087libperl5.405.40.1-7ubuntu0.2 5.40.1-7ubuntu0.3perl-Socket: perl-Socket: Information Disclosure due to Out-of-Bounds Read — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-13221libperl5.405.40.1-7ubuntu0.2 5.40.1-7ubuntu0.3perl: Perl: Incorrect regular expression processing via large regular expressions — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-57432libperl5.405.40.1-7ubuntu0.2 5.40.1-7ubuntu0.3perl: Perl: Information disclosure via integer overflow in pack/unpack operations — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-57433libperl5.405.40.1-7ubuntu0.2 5.40.1-7ubuntu0.3Storable: Storable: Denial of Service via signed integer overflow in deserialization — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68211linux-libc-dev7.0.0-31.31 kernel: media: stm32-dcmipp: Return queued buffers on start_streaming() failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68212linux-libc-dev7.0.0-31.31 kernel: media: saa7134: Fix a possible memory leak in saa7134_video_init1 — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68213linux-libc-dev7.0.0-31.31 kernel: media: rtl2832_sdr: Return queued buffers on start_streaming() failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68214linux-libc-dev7.0.0-31.31 kernel: media: rtl2832: fix use-after-free in rtl2832_remove() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68215linux-libc-dev7.0.0-31.31 kernel: media: radio-si476x: Unregister v4l2_device on probe failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68216linux-libc-dev7.0.0-31.31 kernel: media: pwc: Return queued buffers on start_streaming() failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68217linux-libc-dev7.0.0-31.31 kernel: media: pwc: Drain fill_buf on start_streaming() failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68218linux-libc-dev7.0.0-31.31 kernel: media: pci: dm1105: Free allocated workqueue — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68219linux-libc-dev7.0.0-31.31 kernel: media: nxp: imx8-isi: Fix potential out-of-bounds issues — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68220linux-libc-dev7.0.0-31.31 kernel: media: nxp: imx8-isi: Add missing v4l2_subdev_cleanup() in crossbar and pipe — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68221linux-libc-dev7.0.0-31.31 kernel: media: nuvoton: npcm-video: fix memory leaks in probe and remove — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68222linux-libc-dev7.0.0-31.31 kernel: media: msi2500: Return queued buffers on start_streaming() failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68223linux-libc-dev7.0.0-31.31 kernel: media: meson: vdec: Fix memory leak in error path of vdec_open — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68224linux-libc-dev7.0.0-31.31 kernel: media: mali-c55: Fix possible ERR_PTR in enable_streams — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68225linux-libc-dev7.0.0-31.31 kernel: media: i2c: alvium: fix critical pointer access in alvium_ctrl_init — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68226linux-libc-dev7.0.0-31.31 kernel: media: cx23885: add ioremap return check and cleanup — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68227linux-libc-dev7.0.0-31.31 kernel: media: cx231xx: fix devres lifetime — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68249linux-libc-dev7.0.0-31.31 kernel: drm/amdgpu/sdma5.0: replace BUG_ON() with WARN_ON() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68120linux-libc-dev7.0.0-31.31 kernel: rtase: Workaround for TX hang caused by hardware packet parsing — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68186linux-libc-dev7.0.0-31.31 kernel: binfmt_misc: set have_execfd only once the interpreter is opened — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68187linux-libc-dev7.0.0-31.31 kernel: exec: fix unsigned loop counter wrap in transfer_args_to_stack() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68188linux-libc-dev7.0.0-31.31 kernel: Linux kernel Bluetooth RFCOMM: Denial of Service via use-after-free in set_termios — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68190linux-libc-dev7.0.0-31.31 kernel: staging: rtl8723bs: fix OOB reads in rtw_get_wps_ie() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68191linux-libc-dev7.0.0-31.31 kernel: wifi: ath12k: fix NULL pointer dereference in rhash table destroy — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68192linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: w ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68193linux-libc-dev7.0.0-31.31 kernel: wifi: mt76: mt7925: drop TXRX_NOTIFY on non-mmio buses — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68194linux-libc-dev7.0.0-31.31 kernel: wifi: mt76: mt7921: drop TXRX_NOTIFY on non-mmio buses — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68195linux-libc-dev7.0.0-31.31 kernel: wifi: mt76: mt7615: drop TXRX_NOTIFY on non-mmio buses — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68197linux-libc-dev7.0.0-31.31 kernel: wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68200linux-libc-dev7.0.0-31.31 kernel: Linux kernel: ALSA timer use-after-free vulnerability allows privilege escalation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68202linux-libc-dev7.0.0-31.31 kernel: ALSA: seq: close a re-opened queue timer in the destructor — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68203linux-libc-dev7.0.0-31.31 kernel: media: vivid: fix cleanup bugs in vivid_init() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68205linux-libc-dev7.0.0-31.31 kernel: media: v4l2-fwnode: Fix subdev owner overwritten in v4l2_async_register_subdev_sensor() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68206linux-libc-dev7.0.0-31.31 kernel: media: v4l2-ctrls: validate HEVC active reference counts — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68207linux-libc-dev7.0.0-31.31 kernel: media: ti: vpe: unwind v4l2 device registration on probe error — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68208linux-libc-dev7.0.0-31.31 kernel: media: ti: vpe: Fix the error code of devm_kzalloc() in vip_probe_slice() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68209linux-libc-dev7.0.0-31.31 kernel: media: sun4i-csi: Return queued buffers on start_streaming() failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68250linux-libc-dev7.0.0-31.31 kernel: drm/amdgpu/sdma5.2: replace BUG_ON() with WARN_ON() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68251linux-libc-dev7.0.0-31.31 kernel: drm/amdgpu/sdma6.0: replace BUG_ON() with WARN_ON() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68252linux-libc-dev7.0.0-31.31 kernel: drm/amdgpu/sdma7.0: replace BUG_ON() with WARN_ON() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68253linux-libc-dev7.0.0-31.31 kernel: drm/i915/hdcp: check streams[] bounds before overflow — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68254linux-libc-dev7.0.0-31.31 kernel: drm/i915/vrr: require valid min/max vfreq for VRR — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68255linux-libc-dev7.0.0-31.31 kernel: drm/virtio: bound EDID block reads to the response buffer — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68256linux-libc-dev7.0.0-31.31 kernel: drm/amd/display: detect_link_and_local_sink: DP alt mode timeout path leaks prev_sink reference — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68258linux-libc-dev7.0.0-31.31 kernel: drm/amdkfd: Check bounds on CRIU restore queue type and mqd size — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68259linux-libc-dev7.0.0-31.31 kernel: drm/amdkfd: Check bounds in allocate_event_notification_slot — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68260linux-libc-dev7.0.0-31.31 kernel: drm/imagination: acquire vm_ctx->lock before mapping memory to GPU VM — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68261linux-libc-dev7.0.0-31.31 kernel: drm/imagination: fix error checking of pvr_vm_context_lookup() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68262linux-libc-dev7.0.0-31.31 kernel: drm/imagination: Fix user array stride in pvr_set_uobj_array() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68263linux-libc-dev7.0.0-31.31 kernel: Linux kernel: drm/imagination use-after-free vulnerability — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68264linux-libc-dev7.0.0-31.31 kernel: drm/xe/pt: Reset current_op in xe_pt_update_ops_init() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68265linux-libc-dev7.0.0-31.31 kernel: drm/xe/vm: Fix BO prefetch with CONSULT_MEM_ADVISE_PREF_LOC — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68266linux-libc-dev7.0.0-31.31 kernel: drm/xe: Hold a dma-buf reference for imported BOs — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68267linux-libc-dev7.0.0-31.31 kernel: drm/xe/rtp: Add RING_FORCE_TO_NONPRIV_DENY to OA whitelists — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68268linux-libc-dev7.0.0-31.31 kernel: drm/xe: Return error on non-migratable faults requiring devmem — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68228linux-libc-dev7.0.0-31.31 kernel: media: chips-media: wave5: Move src_buf Removal to finish_encode — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68229linux-libc-dev7.0.0-31.31 kernel: media: cedrus: skip invalid H.264 reference list entries — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68230linux-libc-dev7.0.0-31.31 kernel: media: amlogic-c3: Add validations for ae and awb config — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68231linux-libc-dev7.0.0-31.31 kernel: media: airspy: Return queued buffers on start_streaming() failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68232linux-libc-dev7.0.0-31.31 kernel: drm/gpusvm: Fix MM reference leak in drm_gpusvm_range_evict — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68233linux-libc-dev7.0.0-31.31 kernel: drm/vc4: Shut down BO cache timer before teardown — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68234linux-libc-dev7.0.0-31.31 kernel: drm/amdgpu: fix bo->pin leaking in amdgpu_bo_create_reserved — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68235linux-libc-dev7.0.0-31.31 kernel: drm/amd/display: dce100: skip non-DP stream encoders for DP MST — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68237linux-libc-dev7.0.0-31.31 kernel: drm/amdgpu/userq: fix indefinite fence wait during GPU reset — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68238linux-libc-dev7.0.0-31.31 kernel: drm/amdgpu: Release VFCT ACPI table reference — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68239linux-libc-dev7.0.0-31.31 kernel: drm/ttm: Account for NULL and handle pages in ttm_pool_backup — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68241linux-libc-dev7.0.0-31.31 kernel: drm/i915/mst: limit DP MST ESI service loop — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68242linux-libc-dev7.0.0-31.31 kernel: drm/i915/gt: Fix NULL deref on sched_engine alloc failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68243linux-libc-dev7.0.0-31.31 kernel: drm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEU — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68244linux-libc-dev7.0.0-31.31 kernel: drm/i915/gem: Do not leak siblings[] on proto context error — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68245linux-libc-dev7.0.0-31.31 kernel: drm/amdgpu: fix lifetime issue of amdgpu_vm_get_task_info_pasid() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68246linux-libc-dev7.0.0-31.31 kernel: drm/amdgpu/gfx11: replace BUG_ON() with WARN_ON() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68247linux-libc-dev7.0.0-31.31 kernel: drm/i915/bios: range check LFP Data Block panel_type2 — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68248linux-libc-dev7.0.0-31.31 kernel: drm/i915: Return NULL on error in active_instance — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68122linux-libc-dev7.0.0-31.31 kernel: ovpn: fix peer refcount leak in TCP error paths — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68123linux-libc-dev7.0.0-31.31 kernel: openvswitch: fix GSO userspace truncation underflow — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68125linux-libc-dev7.0.0-31.31 kernel: mac802154: llsec: reject frames shorter than the authentication tag — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68126linux-libc-dev7.0.0-31.31 kernel: mac802154: hold an interface reference across the scan worker — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68127linux-libc-dev7.0.0-31.31 kernel: ila: reload IPv6 header after pskb_may_pull in checksum adjust — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68128linux-libc-dev7.0.0-31.31 kernel: Linux kernel (ice): Denial of Service via out-of-range ptype in VIRTCHNL — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68129linux-libc-dev7.0.0-31.31 kernel: gve: fix Rx queue stall on alloc failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68130linux-libc-dev7.0.0-31.31 kernel: ksmbd: defer destroy_previous_session() until after NTLM authentication — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68131linux-libc-dev7.0.0-31.31 kernel: rbd: Reset positive result codes to zero in object map update path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68132linux-libc-dev7.0.0-31.31 kernel: super: fix emergency thaw deadlock on frozen block devices — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68133linux-libc-dev7.0.0-31.31 kernel: ice: fix PTP Call Trace during PTP release — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68134linux-libc-dev7.0.0-31.31 kernel: ptp: ptp_s390: Add missing facility check — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68135linux-libc-dev7.0.0-31.31 kernel: net: hip04: fix RX buffer leak on build_skb failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68136linux-libc-dev7.0.0-31.31 kernel: net: gro: fix double aggregation of flush-marked skbs — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68137linux-libc-dev7.0.0-31.31 kernel: net/x25: fix use-after-free in x25_kill_by_neigh() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68138linux-libc-dev7.0.0-31.31 kernel: net/sched: serialize qdisc_rtab_list against concurrent get/put — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68139linux-libc-dev7.0.0-31.31 kernel: net/mlx5e: Use sender devcom for MPV master-up — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68164linux-libc-dev7.0.0-31.31 kernel: mm/damon/core: disallow overlapping input ranges for damon_set_regions() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68095linux-libc-dev7.0.0-31.31 kernel: fuse-uring: fix race between registration and connection abortion — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68096linux-libc-dev7.0.0-31.31 kernel: audit: fix recursive locking deadlock in audit_dupe_exe() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68097linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: k ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68099linux-libc-dev7.0.0-31.31 kernel: ksmbd: restore DACL size on check_add_overflow() to avoid malformed ACL — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68100linux-libc-dev7.0.0-31.31 kernel: ksmbd: validate num_subauth when copying ACE in set_ntacl_dacl — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68102linux-libc-dev7.0.0-31.31 kernel: drm/amdgpu: fix aperture mapping leak — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68103linux-libc-dev7.0.0-31.31 kernel: drm/amdgpu: reject mapping a reserved doorbell to a new queue — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68105linux-libc-dev7.0.0-31.31 kernel: drm/amdgpu: Fix kernel panic during driver load failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68106linux-libc-dev7.0.0-31.31 kernel: drm/amdgpu: fix division by zero with invalid uvd dimensions — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68108linux-libc-dev7.0.0-31.31 kernel: drm/amdgpu/vce: fix integer overflow in image size — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68109linux-libc-dev7.0.0-31.31 kernel: drm/amdgpu/sdma7.1: replace BUG_ON() with WARN_ON() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68110linux-libc-dev7.0.0-31.31 kernel: drm/amdgpu/sdma4.4.2: replace BUG_ON() with WARN_ON() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68111linux-libc-dev7.0.0-31.31 kernel: drm/amdgpu/gfx9: replace BUG_ON() with WARN_ON() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68112linux-libc-dev7.0.0-31.31 kernel: drm/amdgpu/gfx9.4.3: replace BUG_ON() with WARN_ON() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68113linux-libc-dev7.0.0-31.31 kernel: drm/amdgpu/gfx12: replace BUG_ON() with WARN_ON() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68114linux-libc-dev7.0.0-31.31 kernel: drm/amdgpu/gfx12.1: replace BUG_ON() with WARN_ON() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68115linux-libc-dev7.0.0-31.31 kernel: drm/amdgpu/gfx10: replace BUG_ON() with WARN_ON() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68118linux-libc-dev7.0.0-31.31 kernel: tcp: challenge ACK for non-exact RST in SYN-RECEIVED — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68119linux-libc-dev7.0.0-31.31 kernel: tcp: initialize standalone TCP-AO response padding — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68165linux-libc-dev7.0.0-31.31 kernel: mm/damon/core: validate ranges in damon_set_regions() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68166linux-libc-dev7.0.0-31.31 kernel: Linux kernel: Arbitrary code execution via userfaultfd shadow stack manipulation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68168linux-libc-dev7.0.0-31.31 kernel: afs: Fix afs_edit_dir_remove() to get, not find, block 0 — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68169linux-libc-dev7.0.0-31.31 kernel: mptcp: pm: userspace: fix use-after-free in get_local_id — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68170linux-libc-dev7.0.0-31.31 kernel: mptcp: fix stale skb->sk reference on subflow close — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68172linux-libc-dev7.0.0-31.31 kernel: arm64: make huge_ptep_get handled unaligned addresses — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68173linux-libc-dev7.0.0-31.31 kernel: ublk: wait on ublk_dev_ready() instead of ub->completion — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68174linux-libc-dev7.0.0-31.31 kernel: tracing: Fix union collision of module and refcnt for dynamic events — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68175linux-libc-dev7.0.0-31.31 kernel: tracing: Fix resource leak on mmiotrace trace_pipe close — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68176linux-libc-dev7.0.0-31.31 kernel: tracing: Fix mmiotrace possible NULL dereferencing of hiter->dev — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68177linux-libc-dev7.0.0-31.31 kernel: tracing: Delay module ref count for "enable_event" trigger — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68178linux-libc-dev7.0.0-31.31 kernel: misc: nsm: pin the module while the device is open — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68179linux-libc-dev7.0.0-31.31 kernel: misc: nsm: only unlock nsm_dev on post-lock error paths — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68180linux-libc-dev7.0.0-31.31 kernel: intel_th: fix MSC output device reference leak — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68181linux-libc-dev7.0.0-31.31 kernel: mei: bus: access mei_device under device_lock on cleanup — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68182linux-libc-dev7.0.0-31.31 kernel: comedi: comedi_parport: deal with premature interrupt — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68183linux-libc-dev7.0.0-31.31 kernel: firmware: stratix10-svc: fix memory leaks and list corruption bugs — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68184linux-libc-dev7.0.0-31.31 kernel: cdrom: fix stack out-of-bounds read in CDROMVOLCTRL — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68140linux-libc-dev7.0.0-31.31 kernel: net/iucv: fix use-after-free of a severed iucv_path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68141linux-libc-dev7.0.0-31.31 kernel: net/af_iucv: fix NULL deref in afiucv_hs_callback_syn() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68143linux-libc-dev7.0.0-31.31 kernel: Linux kernel SLIP: Out-of-bounds write due to race condition during MTU change — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68144linux-libc-dev7.0.0-31.31 kernel: phonet: pep: fix use-after-free in pep_get_sb() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68145linux-libc-dev7.0.0-31.31 kernel: iomap: fix out-of-bounds bitmap_set() with zero-length range — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68146linux-libc-dev7.0.0-31.31 kernel: ftrace: Add global mutex to serialize trace_parser access — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68148linux-libc-dev7.0.0-31.31 kernel: fscrypt: Add missing superblock check in find_or_insert_direct_key() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68149linux-libc-dev7.0.0-31.31 kernel: fs: preserve ACL_DONT_CACHE state in forget_cached_acl() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68150linux-libc-dev7.0.0-31.31 kernel: fs/super: fix emergency thaw double-unlock of s_umount — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68151linux-libc-dev7.0.0-31.31 kernel: binfmt_elf_fdpic: only honour the first PT_INTERP — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68152linux-libc-dev7.0.0-31.31 kernel: amt: fix use-after-free in AMT delayed works — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68154linux-libc-dev7.0.0-31.31 kernel: libceph: reject zero bucket types in crush_decode — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68155linux-libc-dev7.0.0-31.31 kernel: Linux kernel (libceph): Denial of Service due to malformed monitor maps — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68157linux-libc-dev7.0.0-31.31 kernel: Linux kernel: libceph null pointer dereference leads to denial of service — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68158linux-libc-dev7.0.0-31.31 kernel: libceph: Fix multiplication overflow in decode_new_up_state_weight() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68159linux-libc-dev7.0.0-31.31 kernel: Linux kernel: libceph stack out-of-bounds write via crafted OSDMap — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68160linux-libc-dev7.0.0-31.31 kernel: ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68161linux-libc-dev7.0.0-31.31 kernel: sctp: close UDP tunnel sockets during netns teardown — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-68163linux-libc-dev7.0.0-31.31 kernel: mm/page_vma_mapped: fix device-private PMD handling — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74354linux-libc-dev7.0.0-31.31 kernel: bpf: Take mmap_lock in zap_pages() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74355linux-libc-dev7.0.0-31.31 kernel: iommu/vt-d: Fix RB-tree corruption in probe error path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74356linux-libc-dev7.0.0-31.31 kernel: vhost: fix vhost_get_avail_idx for a non empty ring — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74358linux-libc-dev7.0.0-31.31 kernel: ext4: fix fast commit wait/wake bit mapping on 64-bit — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74359linux-libc-dev7.0.0-31.31 kernel: configfs_lookup(): don't leave ->s_dentry dangling on failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74360linux-libc-dev7.0.0-31.31 kernel: bpf: Reject exclusive maps for bpf_map_elem iterators — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74362linux-libc-dev7.0.0-31.31 kernel: ext2: fix ignored return value of generic_write_sync() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74364linux-libc-dev7.0.0-31.31 kernel: bpf: Reject exclusive maps as inner maps in map-in-map — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74365linux-libc-dev7.0.0-31.31 kernel: nvdimm/btt: Handle preemption in BTT lane acquisition — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74366linux-libc-dev7.0.0-31.31 kernel: wifi: ath12k: fix NULL deref in change_sta_links for unready link — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74367linux-libc-dev7.0.0-31.31 kernel: wifi: ath12k: fix inconsistent arvif state in vdev_create error paths — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74368linux-libc-dev7.0.0-31.31 kernel: wifi: ath12k: fix memory leak in ath12k_wifi7_dp_rx_h_verify_tkip_mic() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74370linux-libc-dev7.0.0-31.31 kernel: liveupdate: fix TOCTOU race in luo_session_retrieve() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74372linux-libc-dev7.0.0-31.31 kernel: raid1: fix nr_pending leak in REQ_ATOMIC bad-block error path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74373linux-libc-dev7.0.0-31.31 kernel: md/raid1,raid10: fix bio accounting for split md cloned bios — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74374linux-libc-dev7.0.0-31.31 kernel: md/raid1,raid10: fix error-path detection with md_cloned_bio() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74375linux-libc-dev7.0.0-31.31 kernel: md/raid1,raid10: fix deadlock in read error recovery path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74376linux-libc-dev7.0.0-31.31 kernel: md/raid10: reset read_slot when reusing r10bio for discard — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74402linux-libc-dev7.0.0-31.31 kernel: crypto: atmel-sha204a - fix blocking and non-blocking rng logic — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74266linux-libc-dev7.0.0-31.31 kernel: net/sched: sch_dualpi2: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74333linux-libc-dev7.0.0-31.31 kernel: ASoC: amd: acp-sdw-legacy: Bound DAI link iteration — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74335linux-libc-dev7.0.0-31.31 kernel: bpf: Fix NULL pointer dereference in bpf_task_from_vpid() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74336linux-libc-dev7.0.0-31.31 kernel: wifi: mac80211: bound S1G TIM PVB walk to the TIM element — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74337linux-libc-dev7.0.0-31.31 kernel: bpf: Fix NMI/tracepoint re-entry deadlock on lru locks — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74338linux-libc-dev7.0.0-31.31 kernel: bpf: Reject sleepable BPF_LSM_CGROUP programs at load time — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74339linux-libc-dev7.0.0-31.31 kernel: ALSA: seq: Clear variable event pointer on read — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74340linux-libc-dev7.0.0-31.31 kernel: wifi: wcn36xx: fix OOB read from firmware count in PRINT_REG_INFO indication — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74342linux-libc-dev7.0.0-31.31 kernel: kernfs: link kn to its parent before the LSM init hook — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74344linux-libc-dev7.0.0-31.31 kernel: bpf: Clear rb node linkage when freeing bpf_rb_root — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74345linux-libc-dev7.0.0-31.31 kernel: RDMA/siw: Fix endpoint/socket association handling — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74346linux-libc-dev7.0.0-31.31 kernel: RDMA/irdma: Fix OOB read during CQ MR registration — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74347linux-libc-dev7.0.0-31.31 kernel: netfilter: cttimeout: detach dataplane timeout policy and repurpose refcount — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74348linux-libc-dev7.0.0-31.31 kernel: ocfs2/dlm: require a ref for locking_state debugfs open — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74349linux-libc-dev7.0.0-31.31 kernel: ocfs2: reject FITRIM ranges shorter than a cluster — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74350linux-libc-dev7.0.0-31.31 kernel: ocfs2: validate fast symlink target during inode read — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74351linux-libc-dev7.0.0-31.31 kernel: ocfs2: rebase copied fsdlm LVB pointers in locking_state — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74352linux-libc-dev7.0.0-31.31 kernel: of: reserved_mem: avoid post-init UAF when alloc_reserved_mem_array() fails — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74353linux-libc-dev7.0.0-31.31 kernel: drm/amdkfd: always resume_all after suspend_all — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74404linux-libc-dev7.0.0-31.31 kernel: crypto: ccp - Fix snp_filter_reserved_mem_regions() off-by-one — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74406linux-libc-dev7.0.0-31.31 kernel: vxlan: Fix potential null-ptr-deref in vxlan_gro_prepare_receive() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74407linux-libc-dev7.0.0-31.31 kernel: wifi: ath11k: cancel SSR work items during PCI shutdown — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74408linux-libc-dev7.0.0-31.31 kernel: wifi: ath9k: fix OOB access from firmware tx status queue ID — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74409linux-libc-dev7.0.0-31.31 kernel: wifi: rtw89: add bounds check on firmware mac_id in link lookup — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74410linux-libc-dev7.0.0-31.31 kernel: wifi: rtw88: fix OOB read from firmware RX descriptor exceeding DMA buffer — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74413linux-libc-dev7.0.0-31.31 kernel: wifi: rtw89: fix wrong pci_get_drvdata type in AER handlers — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74415linux-libc-dev7.0.0-31.31 kernel: spi: atcspi200: fix use-after-free when driver unbind — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74416linux-libc-dev7.0.0-31.31 kernel: drm/radeon: fix memory leak in radeon_ring_restore() on lock failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74417linux-libc-dev7.0.0-31.31 kernel: drm/radeon: fix integer overflow in radeon_align_pitch() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74419linux-libc-dev7.0.0-31.31 kernel: accel/amdxdna: Adjust size for copy_to_user() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74420linux-libc-dev7.0.0-31.31 kernel: drm/gpusvm: Reject VMAs with VM_IO or VM_PFNMAP when creating SVM ranges — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74421linux-libc-dev7.0.0-31.31 kernel: drm/rockchip: dw_dp: Switch to drmm_kzalloc() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74422linux-libc-dev7.0.0-31.31 kernel: drm/rockchip: inno-hdmi: Switch to drmm_kzalloc() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74423linux-libc-dev7.0.0-31.31 kernel: accel/amdxdna: Fix leak when pinning ubuf pages — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74424linux-libc-dev7.0.0-31.31 kernel: fbcon: fix NULL pointer dereference for a console without vc_data — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74425linux-libc-dev7.0.0-31.31 kernel: afs: handle CB.InitCallBackState3 requests without a server record — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74537linux-libc-dev7.0.0-31.31 kernel: Bluetooth: ISO: hold sk properly in iso_conn_ready — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74377linux-libc-dev7.0.0-31.31 kernel: RDMA/rxe: Copy WQE to local buffer in non-SRQ receive path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74379linux-libc-dev7.0.0-31.31 kernel: dax/kmem: account for partial discontiguous resource upon removal — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74380linux-libc-dev7.0.0-31.31 kernel: gpu: host1x: Fix iommu_map_sgtable() return value check — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74381linux-libc-dev7.0.0-31.31 kernel: gpu: host1x: Allow entries in BO caches to be freed — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74382linux-libc-dev7.0.0-31.31 kernel: net/sched: cls_bpf: prevent unbounded recursion in offload rollback — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74384linux-libc-dev7.0.0-31.31 kernel: nvme-multipath: fix flex array size in struct nvme_ns_head — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74385linux-libc-dev7.0.0-31.31 kernel: nvmet-tcp: check return value of nvmet_tcp_set_queue_sock — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74386linux-libc-dev7.0.0-31.31 kernel: nvmet-tcp: fix page fragment cache leak in error path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74387linux-libc-dev7.0.0-31.31 kernel: ALSA: seq: midi: Serialize output teardown with event_input — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74388linux-libc-dev7.0.0-31.31 kernel: ALSA: seq: oss: Fix UAF at handling events with embedded SysEx data — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74389linux-libc-dev7.0.0-31.31 kernel: RDMA/hns: Fix log flood after cmd_mbox failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74391linux-libc-dev7.0.0-31.31 kernel: tracing: Bound synthetic-field strings with seq_buf — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74392linux-libc-dev7.0.0-31.31 kernel: dm: limit target bio polling to one shot — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74393linux-libc-dev7.0.0-31.31 kernel: drm/syncobj: Fix memory leak in drm_syncobj_find_fence() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74395linux-libc-dev7.0.0-31.31 kernel: RDMA/mlx5: Fix devx subscribe-event unwind NULL dereference — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74396linux-libc-dev7.0.0-31.31 kernel: RDMA/mlx5: Fix UMR XLT cleanup on ODP populate failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74398linux-libc-dev7.0.0-31.31 kernel: ipv6: addrconf: bail out of dad_failure when state is no longer POSTDAD — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74399linux-libc-dev7.0.0-31.31 kernel: evm: terminate and bound the evm_xattrs read buffer — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74400linux-libc-dev7.0.0-31.31 kernel: bpf: fix crash in bpf_[set|remove]_dentry_xattr for negative dentries — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74267linux-libc-dev7.0.0-31.31 kernel: net/sched: sch_codel: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74269linux-libc-dev7.0.0-31.31 kernel: bnxt: fix head underflow on XDP head-grow — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74270linux-libc-dev7.0.0-31.31 kernel: handshake: Require admin permission for DONE command — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74271linux-libc-dev7.0.0-31.31 kernel: power: supply: core: fix supplied_from allocations — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74272linux-libc-dev7.0.0-31.31 kernel: cxl/region: Resolve region deletion races — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74273linux-libc-dev7.0.0-31.31 kernel: cxl/region: Block region delete during region creation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74274linux-libc-dev7.0.0-31.31 kernel: cxl/region: Fill first free targets[] slot during auto-discovery — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74276linux-libc-dev7.0.0-31.31 kernel: spi: xilinx: use FIFO occupancy register to determine buffer size — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74277linux-libc-dev7.0.0-31.31 kernel: iommu/dma-iommu: Fix wrong scatterlist length assignment in P2PDMA path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74278linux-libc-dev7.0.0-31.31 kernel: ALSA: seq: Fix kernel heap address leak in bounce_error_event() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74279linux-libc-dev7.0.0-31.31 kernel: crypto: cavium/cpt - fix DMA cleanup using wrong loop index — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74280linux-libc-dev7.0.0-31.31 kernel: crypto: marvell/octeontx - fix DMA cleanup using wrong loop index — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74281linux-libc-dev7.0.0-31.31 kernel: tipc: reject inverted service ranges from peer bindings — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74282linux-libc-dev7.0.0-31.31 kernel: tipc: prevent snt_unacked underflow on CONN_ACK — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74283linux-libc-dev7.0.0-31.31 kernel: tipc: require net admin for TIPCv2 netlink mutators — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74284linux-libc-dev7.0.0-31.31 kernel: net/sched: sch_hfsc: Don't make class passive twice — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74286linux-libc-dev7.0.0-31.31 kernel: net: pfcp: allocate per-cpu tstats for PFCP netdevs — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74308linux-libc-dev7.0.0-31.31 kernel: ext4: fix kernel BUG in ext4_write_inline_data_end — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72493linux-libc-dev7.0.0-31.31 kernel: net: serialize netif_running() check in enqueue_to_backlog() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72494linux-libc-dev7.0.0-31.31 kernel: RDMA/irdma: Replace waitqueue and flag with completion — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72495linux-libc-dev7.0.0-31.31 kernel: RDMA/bnxt_re: Avoid repeated requests to allocate WC pages — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72496linux-libc-dev7.0.0-31.31 kernel: RDMA/bnxt_re: Proper rollback if the ioremap fails — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72497linux-libc-dev7.0.0-31.31 kernel: RDMA/bnxt_re: Add a max slot check for SQ — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72498linux-libc-dev7.0.0-31.31 kernel: RDMA/bnxt_re: Avoid displaying the kernel pointer — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72499linux-libc-dev7.0.0-31.31 kernel: RDMA/bnxt_re: Free CQ toggle page after firmware teardown — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72500linux-libc-dev7.0.0-31.31 kernel: RDMA/bnxt_re: Free SRQ toggle page after firmware teardown — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72501linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: R ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72502linux-libc-dev7.0.0-31.31 kernel: tcp: ipv6: clamp default adverting MSS to avoid GSO_BY_FRAGS (0xFFFF) — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74255linux-libc-dev7.0.0-31.31 kernel: tipc: fix UAF in tipc_l2_send_msg() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74256linux-libc-dev7.0.0-31.31 kernel: bpf, sockmap: fix integer overflow in bpf_msg_pop_data() bounds check — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74257linux-libc-dev7.0.0-31.31 kernel: sockmap: Fix use-after-free in udp_bpf_recvmsg() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74258linux-libc-dev7.0.0-31.31 kernel: bpf: Guard __get_user acesss with access_ok for uprobe_multi data — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74260linux-libc-dev7.0.0-31.31 kernel: netfilter: nf_dup_netdev: add nf_dev_xmit_recursion*() helpers and use them — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74261linux-libc-dev7.0.0-31.31 kernel: ALSA: seq: avoid stale FIFO cells during resize — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74263linux-libc-dev7.0.0-31.31 kernel: net: wwan: t7xx: check skb_clone in control TX — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74264linux-libc-dev7.0.0-31.31 kernel: net: watchdog: fix refcount tracking races — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74265linux-libc-dev7.0.0-31.31 kernel: net: mana: initialize gdma queue id to INVALID_QUEUE_ID — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74309linux-libc-dev7.0.0-31.31 kernel: vdpa/octeon_ep: fix IRQ-to-ring mapping in interrupt handler — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74310linux-libc-dev7.0.0-31.31 kernel: vhost/net: complete zerocopy ubufs only once — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74311linux-libc-dev7.0.0-31.31 kernel: virtio: rtc: tear down old virtqueues before restore — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74314linux-libc-dev7.0.0-31.31 kernel: bpf: Cancel special fields on map value recycle — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74316linux-libc-dev7.0.0-31.31 kernel: NFSD: Handle layout stid in nfsd4_drop_revoked_stid() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74318linux-libc-dev7.0.0-31.31 kernel: btrfs: fix deadlock cloning inline extent when using flushoncommit — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74320linux-libc-dev7.0.0-31.31 kernel: fbdev: sm501fb: Fix buffer errors in OF binding code — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74321linux-libc-dev7.0.0-31.31 kernel: btrfs: fix invalid pointer dereference in __btrfs_run_delayed_refs() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74322linux-libc-dev7.0.0-31.31 kernel: wifi: mt76: mt7996: Fix possible NULL pointer dereference in mt7996_mac_write_txwi_80211() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74323linux-libc-dev7.0.0-31.31 kernel: wifi: mt76: mt7996: Fix possible token leak in mt7996_tx_prepare_skb() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74324linux-libc-dev7.0.0-31.31 kernel: wifi: mt76: mt7925: validate skb length in testmode query — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74325linux-libc-dev7.0.0-31.31 kernel: wifi: mt76: use kfree_rcu for offchannel link in mt76_put_vif_phy_link — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74327linux-libc-dev7.0.0-31.31 kernel: vmalloc: fix NULL pointer dereference in is_vm_area_hugepages() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74328linux-libc-dev7.0.0-31.31 kernel: iommufd: Destroy the pages content after detaching from dmabuf — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74329linux-libc-dev7.0.0-31.31 kernel: watchdog: unregister PM notifier on watchdog unregister — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74330linux-libc-dev7.0.0-31.31 kernel: configfs: fix lockless traversals of ->s_children — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74331linux-libc-dev7.0.0-31.31 kernel: firmware_loader: Fix recursive lock in device_cache_fw_images() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74332linux-libc-dev7.0.0-31.31 kernel: ASoC: amd: acp-sdw-sof: Bound DAI link iteration — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74287linux-libc-dev7.0.0-31.31 kernel: sctp: validate embedded address parameter length — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74288linux-libc-dev7.0.0-31.31 kernel: net: fib_rules: Don't dump dying fib_rule in fib_rules_dump() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74289linux-libc-dev7.0.0-31.31 kernel: ipv4: fib: Don't dump dying fib_info in fib_leaf_notify() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74290linux-libc-dev7.0.0-31.31 kernel: net/sched: cls_flow: Dont expose folded kernel pointers — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74291linux-libc-dev7.0.0-31.31 kernel: ASoC: topology: Check PCM and DAI name strings before use — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74292linux-libc-dev7.0.0-31.31 kernel: ASoC: tegra: tegra210_ahub: Validate written enum value — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74293linux-libc-dev7.0.0-31.31 kernel: ASoC: fsl: fsl_audmix: Validate written enum values — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74294linux-libc-dev7.0.0-31.31 kernel: ASoC: meson: aiu: Validate written enum values — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74295linux-libc-dev7.0.0-31.31 kernel: ASoC: codecs: hdac_hdmi: Validate written enum value — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74296linux-libc-dev7.0.0-31.31 kernel: RDMA/mlx5: Release the HW‑provided UAR index rather than the SW one — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74297linux-libc-dev7.0.0-31.31 kernel: RDMA/mlx5: Fix undefined shift of user RQ WQE size — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74300linux-libc-dev7.0.0-31.31 kernel: Bluetooth: hci: validate codec capability element length — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74301linux-libc-dev7.0.0-31.31 kernel: Bluetooth: btmtk: fix URB leak in alloc_mtk_intr_urb error path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74302linux-libc-dev7.0.0-31.31 kernel: Bluetooth: hci_core: Fix UAF in hci_unregister_dev() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74303linux-libc-dev7.0.0-31.31 kernel: Bluetooth: hci_qca: fix NULL pointer dereference in qca_dmp_hdr() for non-serdev device — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74304linux-libc-dev7.0.0-31.31 kernel: Bluetooth: hci_qca: fix NULL pointer dereference in qca_setup() for non-serdev device — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74305linux-libc-dev7.0.0-31.31 kernel: bpf: Tighten cgroup storage cookie checks for prog arrays — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74306linux-libc-dev7.0.0-31.31 kernel: vfio/qat: fix f_pos race in qat_vf_resume_write() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74307linux-libc-dev7.0.0-31.31 kernel: ext4: validate donor file superblock early in EXT4_IOC_MOVE_EXT — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74538linux-libc-dev7.0.0-31.31 kernel: Bluetooth: ISO: lock sk in iso_connect_ind — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74539linux-libc-dev7.0.0-31.31 kernel: Bluetooth: ISO: lock sk in iso_sock_getname — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74540linux-libc-dev7.0.0-31.31 kernel: Bluetooth: L2CAP: fix UAF in l2cap_le_connect_rsp — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74541linux-libc-dev7.0.0-31.31 kernel: Bluetooth: ISO: clear iso_data always when detaching conn from hcon — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74542linux-libc-dev7.0.0-31.31 kernel: netfs: Fix folio_queue ENOMEM in writeback by adding a mempool — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74543linux-libc-dev7.0.0-31.31 kernel: net: udp_tunnel: fix memory leak in udp_tunnel_nic_unregister() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74544linux-libc-dev7.0.0-31.31 kernel: net/sched: cls_u32: validate offshift to prevent shift-out-of-bounds — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74545linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: r ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74546linux-libc-dev7.0.0-31.31 kernel: hwmon: (adt7470) Fix divide-by-zero TOCTOU crash in fan speed read — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74547linux-libc-dev7.0.0-31.31 kernel: hwmon: (adt7470) Fix busy-loop and I2C flooding in update thread — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74548linux-libc-dev7.0.0-31.31 kernel: forcedeth: fix UAF of txrx_stats in nv_remove — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74549linux-libc-dev7.0.0-31.31 kernel: hwmon: (nct6775-core) Prevent access to unsupported weight registers — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74550linux-libc-dev7.0.0-31.31 kernel: net: do not send ICMP/NDISC Redirects when peer allocation fails — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74551linux-libc-dev7.0.0-31.31 kernel: hwmon: (nzxt-smart2) DMA-align output buffer — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74552linux-libc-dev7.0.0-31.31 kernel: hwmon: (lm90) Only report alarms if driver is ready — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74553linux-libc-dev7.0.0-31.31 kernel: hwmon: (nct6775-core) Fix number of temperature registers for NCT6116 — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74555linux-libc-dev7.0.0-31.31 kernel: scsi: libsas: Fix HA resume deadlock and hisi_sas disk-wake race — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74577linux-libc-dev7.0.0-31.31 kernel: net: mpls: initialize rtm_tos in mpls_getroute() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74448linux-libc-dev7.0.0-31.31 kernel: drm/amdkfd: fix QID bit leak in pqm_create_queue() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74514linux-libc-dev7.0.0-31.31 kernel: KVM: s390: pci: Fix memory accounting for pinned/unpinned pages — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74515linux-libc-dev7.0.0-31.31 kernel: KVM: s390: pci: Reject adapter interrupt forwarding if already enabled — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74516linux-libc-dev7.0.0-31.31 kernel: KVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74517linux-libc-dev7.0.0-31.31 kernel: KVM: x86: Cancel delayed I/O APIC EOI handling before destroying vCPUs — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74518linux-libc-dev7.0.0-31.31 kernel: mm/hugetlb: fix list corruption in allocate_file_region_entries() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74520linux-libc-dev7.0.0-31.31 kernel: iommu/iommufd: Fix IOPF group ownership UAF — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74521linux-libc-dev7.0.0-31.31 kernel: ksmbd: use memcmp() to compare ClientGUIDs — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74522linux-libc-dev7.0.0-31.31 kernel: ksmbd: fix use-after-free in __close_file_table_ids() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74523linux-libc-dev7.0.0-31.31 kernel: qede: sync udp_tunnel ports outside qede_lock in the recovery path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74524linux-libc-dev7.0.0-31.31 kernel: riscv: mm: Fix out-of-bounds page-table walk during memory hot-remove — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74525linux-libc-dev7.0.0-31.31 kernel: net: sxgbe: free TX rings on RX allocation failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74526linux-libc-dev7.0.0-31.31 kernel: scsi: mpi3mr: Fix potential deadlock in mpi3mr_fault_uevent_emit — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74528linux-libc-dev7.0.0-31.31 kernel: Bluetooth: hci_sync: hold conn in hci_past_sync() callback — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74530linux-libc-dev7.0.0-31.31 kernel: Bluetooth: hci_sync: hold conn in hci_connect_big_sync() callback — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74531linux-libc-dev7.0.0-31.31 kernel: Bluetooth: hci_conn: hold conn reference in abort_conn_sync() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74532linux-libc-dev7.0.0-31.31 kernel: Bluetooth: btintel: Validate length before parsing diagnostics TLV — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74533linux-libc-dev7.0.0-31.31 kernel: Bluetooth: ISO: fix race of kfree vs kref_get_unless_zero — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74536linux-libc-dev7.0.0-31.31 kernel: Bluetooth: ISO: fix leaking sk after socket release — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74578linux-libc-dev7.0.0-31.31 kernel: crypto: algif_skcipher - force synchronous processing on trees without ctx->state — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74579linux-libc-dev7.0.0-31.31 kernel: netfilter: nft_payload: fix mask build for partial field offload — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74580linux-libc-dev7.0.0-31.31 kernel: vhost: reset the vring metadata cache on vring reconfiguration — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74581linux-libc-dev7.0.0-31.31 kernel: net: ipv6: use-after-free in fib6_rule_suppress due to stale res->rt6 pointer — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74582linux-libc-dev7.0.0-31.31 kernel: packet: use consistent hard_header_len in non-ring send paths — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74583linux-libc-dev7.0.0-31.31 kernel: net/sched: cls_route: fix fastmap use-after-free on filter — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74585linux-libc-dev7.0.0-31.31 kernel: thunderbolt: Bound the DROM dual link port number before indexing sw->ports — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74586linux-libc-dev7.0.0-31.31 kernel: sctp: clear new_transport when removing a peer — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74587linux-libc-dev7.0.0-31.31 kernel: sctp: fix use-after-free of cached ASCONF chunk — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74588linux-libc-dev7.0.0-31.31 kernel: sctp: keep chunk->transport in step with the list it is queued on — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74589linux-libc-dev7.0.0-31.31 kernel: bpf, sockmap: Fix sk_redir use-after-free in send verdict — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74590linux-libc-dev7.0.0-31.31 kernel: fsverity: Fix bpf_get_fsverity_digest() dynptr assumptions — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74591linux-libc-dev7.0.0-31.31 kernel: mm/filemap: __filemap_add_folio() restore index before retrying — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74592linux-libc-dev7.0.0-31.31 kernel: ima: Instantiate file_truncate and path_truncate hooks — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74593linux-libc-dev7.0.0-31.31 kernel: sched_ext: Take cgroup_lock() first in scx_cgroup_lock() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74594linux-libc-dev7.0.0-31.31 kernel: sched/psi: Shut down rtpoll_timer in psi_cgroup_free() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74595linux-libc-dev7.0.0-31.31 kernel: fscrypt: use the mount idmap for the owner check in fscrypt_ioctl_set_policy() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74596linux-libc-dev7.0.0-31.31 kernel: fs,fsverity: remove check for fsverity being enabled in setattr_prepare() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74556linux-libc-dev7.0.0-31.31 kernel: scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74557linux-libc-dev7.0.0-31.31 kernel: scsi: libiscsi: Fix stale-data leak into the SCSI sense buffer — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74558linux-libc-dev7.0.0-31.31 kernel: xsk: reclaim invalid Tx descriptors in ZC batch path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74559linux-libc-dev7.0.0-31.31 kernel: xsk: drain continuation descs after overflow in xsk_build_skb() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74560linux-libc-dev7.0.0-31.31 kernel: xsk: fix buffer leak in xsk_drop_skb() for AF_XDP multi-buffer Tx — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74561linux-libc-dev7.0.0-31.31 kernel: nexthop: avoid unlocked f6i_list walk in nh_rt_cache_flush — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74562linux-libc-dev7.0.0-31.31 kernel: nexthop: take nh->lock for f6i_list walks in replace check and notify — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74563linux-libc-dev7.0.0-31.31 kernel: rds: tcp: hold the RCU lock across ipv6_chk_addr() in rds_tcp_laddr_check() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74564linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74565linux-libc-dev7.0.0-31.31 kernel: netfilter: nf_tables: make nft_object rhltable per table — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74566linux-libc-dev7.0.0-31.31 kernel: keys: make keyring key-chunk byte order agree with keyring_diff_objects() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74567linux-libc-dev7.0.0-31.31 kernel: keys: fix out-of-bounds read in keyring_get_key_chunk() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74569linux-libc-dev7.0.0-31.31 kernel: netfilter: nf_conntrack_sip: widen NAT rewrite delta to s32 in sip_help_tcp() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74571linux-libc-dev7.0.0-31.31 kernel: btrfs: skip global block reserve accounting for rescue mounts — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74572linux-libc-dev7.0.0-31.31 kernel: btrfs: zoned: fix deadlock between metadata writeback and transaction commit — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74573linux-libc-dev7.0.0-31.31 kernel: iommu/arm-smmu-v3-iommufd: Require exactly one Stream ID for a vDEVICE — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74574linux-libc-dev7.0.0-31.31 kernel: dmaengine: idxd: fix fdev setup failure cleanup in idxd_cdev_open() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74575linux-libc-dev7.0.0-31.31 kernel: thunderbolt: Prevent XDomain delayed work use-after-free on disconnect — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74576linux-libc-dev7.0.0-31.31 kernel: mm/slab: prevent unbounded recursion in free path with new kmalloc type — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74449linux-libc-dev7.0.0-31.31 kernel: drm/amd/display: Fix divide-by-zero in calculate_mcache_setting on zero viewport — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74451linux-libc-dev7.0.0-31.31 kernel: drm/panthor: validate firmware interface structure sizes — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74452linux-libc-dev7.0.0-31.31 kernel: drm/panthor: reject firmware sections with oversized data — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74453linux-libc-dev7.0.0-31.31 kernel: drm/vc4: Zero the tile state data array before each BIN job — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74454linux-libc-dev7.0.0-31.31 kernel: drm/vc4: Supply the overflow slot size in BPOS, not the whole bin BO size — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74455linux-libc-dev7.0.0-31.31 kernel: can: peak_usb: validate uCAN receive record lengths — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74456linux-libc-dev7.0.0-31.31 kernel: can: peak_usb: peak_usb_start(): fix double free of transfer buffer on URB submit error — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74457linux-libc-dev7.0.0-31.31 kernel: can: peak_usb: add bounds check for USB channel index — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74458linux-libc-dev7.0.0-31.31 kernel: can: kvaser_usb_leaf: kvaser_usb_leaf_wait_cmd(): validate received command extents — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74459linux-libc-dev7.0.0-31.31 kernel: can: etas_es58x: es58x_read_bulk_callback(): fix RX buffer leak on URB resubmit failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74460linux-libc-dev7.0.0-31.31 kernel: can: ems_usb: validate CPC message lengths — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74461linux-libc-dev7.0.0-31.31 kernel: i2c: imx: Cancel hrtimer before clearing slave pointer — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74462linux-libc-dev7.0.0-31.31 kernel: i2c: imx: mark I2C adapter when hardware is powered down — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74463linux-libc-dev7.0.0-31.31 kernel: i2c: jz4780: Cache host clock rate at probe to prevent CCF prepare_lock deadlock — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74464linux-libc-dev7.0.0-31.31 kernel: net: openvswitch: fix skb leak on flow key update failure during ct — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74466linux-libc-dev7.0.0-31.31 kernel: s390/zcrypt: Close speculative mem read possibility — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74467linux-libc-dev7.0.0-31.31 kernel: s390/qeth: Check CAP_NET_ADMIN for private ioctls — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74491linux-libc-dev7.0.0-31.31 kernel: of/address: Fix NULL bus dereference in of_pci_range_parser_one() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74426linux-libc-dev7.0.0-31.31 kernel: afs: fix NULL pointer dereference in afs_get_tree() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74428linux-libc-dev7.0.0-31.31 kernel: rxrpc: Fix double unlock in rxrpc_recvmsg() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74429linux-libc-dev7.0.0-31.31 kernel: rxrpc: Fix the reception of a reply packet before data transmission — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74430linux-libc-dev7.0.0-31.31 kernel: rxrpc: Fix ACKALL packet handling — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74431linux-libc-dev7.0.0-31.31 kernel: rxrpc: Fix potential infinite loop in rxrpc_recvmsg() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74432linux-libc-dev7.0.0-31.31 kernel: rxrpc: Fix leak of released call in recvmsg(MSG_PEEK) — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74433linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: r ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74434linux-libc-dev7.0.0-31.31 kernel: rxrpc: Don't move a peeked OOB message onto the pending queue — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74435linux-libc-dev7.0.0-31.31 kernel: rxrpc: rxrpc_verify_data ensure rx_dec_buffer alloc — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74436linux-libc-dev7.0.0-31.31 kernel: rxrpc: serialize kernel accept preallocation with socket teardown — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74437linux-libc-dev7.0.0-31.31 kernel: media: uvcvideo: Fix deadlock if uvc_status_stop is called from async_ctrl.work — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74439linux-libc-dev7.0.0-31.31 kernel: iommu/vt-d: Clear Present bit before tearing down scalable-mode context entry — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74440linux-libc-dev7.0.0-31.31 kernel: drm/xe: Wait on external BO kernel fences in exec IOCTL — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74441linux-libc-dev7.0.0-31.31 kernel: usb: typec: ucsi: Fix race condition and ordering in port unregistration — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74442linux-libc-dev7.0.0-31.31 kernel: drm/vmwgfx: avoid destroy_workqueue(NULL) on vkms init failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74443linux-libc-dev7.0.0-31.31 kernel: drm/vmwgfx: bound DMA command body size against suffix pointer — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74444linux-libc-dev7.0.0-31.31 kernel: drm/vmwgfx: validate DRAW_PRIMITIVES header size before division — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74445linux-libc-dev7.0.0-31.31 kernel: drm/vmwgfx: reject DX_BIND_QUERY without a DX context — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74447linux-libc-dev7.0.0-31.31 kernel: drm/amdkfd: fix uint32_t overflow in EOP ring buffer size alignment — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74492linux-libc-dev7.0.0-31.31 kernel: netfilter: ipset: do not update comments from kernel-side hash adds — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74493linux-libc-dev7.0.0-31.31 kernel: net/smc: fix socket use-after-free during link group termination — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74494linux-libc-dev7.0.0-31.31 kernel: ksmbd: reject repeated SMB2 NEGOTIATE requests — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74495linux-libc-dev7.0.0-31.31 kernel: igbvf: Fix leak in TX DMA error cleanup — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74496linux-libc-dev7.0.0-31.31 kernel: fou: Fix use-after-free in fou_create() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74497linux-libc-dev7.0.0-31.31 kernel: ALSA: usb-audio: Clamp frame size in implicit-feedback mode — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74498linux-libc-dev7.0.0-31.31 kernel: ALSA: usb-audio: Fix DMA buffer out-of-bounds write when fill_max is set — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74499linux-libc-dev7.0.0-31.31 kernel: ALSA: usb-audio: fix OOB write in snd_usbmidi_akai_output() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74500linux-libc-dev7.0.0-31.31 kernel: ALSA: usb-audio: fix stack info leak in RME Digiface status — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74501linux-libc-dev7.0.0-31.31 kernel: ALSA: usb-audio: fix use-after-free in ump_to_endpoint() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74502linux-libc-dev7.0.0-31.31 kernel: ALSA: ump: fix double free of out_cvts on rawmidi error — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74503linux-libc-dev7.0.0-31.31 kernel: ALSA: timer: Clear SNDRV_TIMER_IFLG_DEAD once the close completes — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74504linux-libc-dev7.0.0-31.31 kernel: ALSA: seq: Fix division by zero in initialize_timer() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74505linux-libc-dev7.0.0-31.31 kernel: ALSA: 6fire: Fix UAF at error handling during probe — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74507linux-libc-dev7.0.0-31.31 kernel: Bluetooth: HIDP: validate numbered report payloads — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74508linux-libc-dev7.0.0-31.31 kernel: Bluetooth: HIDP: reject frames without a transaction header — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74509linux-libc-dev7.0.0-31.31 kernel: Bluetooth: hci_sync: Fix advertising data UAFs — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74513linux-libc-dev7.0.0-31.31 kernel: dibs: fix use-after-free of dmb_node in loopback attach/detach/unregister — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74468linux-libc-dev7.0.0-31.31 kernel: gpio: pch: use raw_spinlock_t for the register lock — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74469linux-libc-dev7.0.0-31.31 kernel: sctp: prevent peer transport count overflow — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74471linux-libc-dev7.0.0-31.31 kernel: tracing: Check return value of __register_event() in trace_module_add_events() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74472linux-libc-dev7.0.0-31.31 kernel: ublk: reset kernel-owned dev_info fields in ublk_ctrl_add_dev() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74473linux-libc-dev7.0.0-31.31 kernel: vxlan: use pskb_network_may_pull() in route_shortcircuit() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74474linux-libc-dev7.0.0-31.31 kernel: vxlan: use pskb_network_may_pull() for transmit path header pulls — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74475linux-libc-dev7.0.0-31.31 kernel: vxlan: use neigh_ha_snapshot() in route_shortcircuit() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74476linux-libc-dev7.0.0-31.31 kernel: veth: convert frag_list skbs before running XDP — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74477linux-libc-dev7.0.0-31.31 kernel: uprobes: Fix NULL pointer dereference in hprobe_expire() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74478linux-libc-dev7.0.0-31.31 kernel: um: vector: fix use-after-free in vector_mmsg_rx() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74479linux-libc-dev7.0.0-31.31 kernel: net: pktgen: fix proc entry use-after-free — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74480linux-libc-dev7.0.0-31.31 kernel: net: bridge: stop fast-leave after deleting a port group — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74482linux-libc-dev7.0.0-31.31 kernel: mm/huge_memory: unlock i_mmap_rwsem before releasing after-split folios — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74483linux-libc-dev7.0.0-31.31 kernel: binfmt_misc: don't leak the user namespace when the mount fails — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74484linux-libc-dev7.0.0-31.31 kernel: binfmt_misc: don't let an 'F' entry pin its own instance — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74485linux-libc-dev7.0.0-31.31 kernel: binfmt_misc: reject a flag character as the field delimiter — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74486linux-libc-dev7.0.0-31.31 kernel: binfmt_misc: use exe_file_deny_write_access() for the interpreter clone — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74487linux-libc-dev7.0.0-31.31 kernel: binfmt_misc: restore write access when removing an entry — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-74488linux-libc-dev7.0.0-31.31 kernel: wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72251linux-libc-dev7.0.0-31.31 kernel: netfilter: nf_nat_sip: reload possible stale data pointer — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72252linux-libc-dev7.0.0-31.31 kernel: netfilter: nft_set_pipapo: don't leak bad clone into future transaction — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72253linux-libc-dev7.0.0-31.31 kernel: netfilter: nf_conntrack_sip: validate skb_dst() before accessing it — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72254linux-libc-dev7.0.0-31.31 kernel: netfilter: nft_fib: reject fib expression on the netdev egress hook — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72255linux-libc-dev7.0.0-31.31 kernel: netfilter: nf_queue: pin bridge device while NFQUEUE holds fake dst — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72256linux-libc-dev7.0.0-31.31 kernel: netfilter: xt_cluster: reject template conntracks in hash match — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72257linux-libc-dev7.0.0-31.31 kernel: ASoC: qcom: q6apm: fix NULL pointer dereference in graph_callback — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72258linux-libc-dev7.0.0-31.31 kernel: ASoC: mediatek: mt8183: Release reserved memory on cleanup — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72259linux-libc-dev7.0.0-31.31 kernel: ASoC: mediatek: mt8192: Release reserved memory on cleanup — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72260linux-libc-dev7.0.0-31.31 kernel: ASoC: mediatek: mt8192: Check runtime resume during probe — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72261linux-libc-dev7.0.0-31.31 kernel: ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72262linux-libc-dev7.0.0-31.31 kernel: ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72263linux-libc-dev7.0.0-31.31 kernel: ASoC: SOF: topology: fix memory leak in snd_sof_load_topology — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72264linux-libc-dev7.0.0-31.31 kernel: fbdev: tridentfb: fix potential memory leak in trident_pci_probe() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72265linux-libc-dev7.0.0-31.31 kernel: fbdev: nvidia: fix potential memory leak in nvidiafb_probe() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72266linux-libc-dev7.0.0-31.31 kernel: fbdev: vesafb: fix memory leak in vesafb_probe() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72267linux-libc-dev7.0.0-31.31 kernel: fbdev: carminefb: fix potential memory leak in alloc_carmine_fb() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72268linux-libc-dev7.0.0-31.31 kernel: fbdev: tdfxfb: fix potential memory leak in tdfxfb_probe() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72293linux-libc-dev7.0.0-31.31 kernel: KVM: s390: vsie: Add missing radix_tree_preload() in _gaccess_shadow_fault() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72158linux-libc-dev7.0.0-31.31 kernel: fpga: dfl: add bounds check in dfh_get_param_size() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72231linux-libc-dev7.0.0-31.31 kernel: batman-adv: tt: avoid request storms during pending request — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72232linux-libc-dev7.0.0-31.31 kernel: batman-adv: ensure minimal ethernet header on TX — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72233linux-libc-dev7.0.0-31.31 kernel: batman-adv: bla: reacquire gw address after skb realloc — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72234linux-libc-dev7.0.0-31.31 kernel: batman-adv: access unicast_ttvn skb->data only after skb realloc — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72235linux-libc-dev7.0.0-31.31 kernel: batman-adv: retrieve ethhdr after potential skb realloc on RX — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72236linux-libc-dev7.0.0-31.31 kernel: s390/perf_cpum_cf: Add missing array_index_nospec() to __hw_perf_event_init() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72237linux-libc-dev7.0.0-31.31 kernel: perf/x86/amd/brs: Fix kernel address leakage — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72238linux-libc-dev7.0.0-31.31 kernel: x86/boot: Validate console=uart8250 baud rate to fix early boot hang — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72240linux-libc-dev7.0.0-31.31 kernel: mfd: sm501: Fix reference leak on failed device registration — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72241linux-libc-dev7.0.0-31.31 kernel: leds: uleds: Fix potential buffer overread — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72242linux-libc-dev7.0.0-31.31 kernel: selinux: avoid sk_socket dereference in selinux_sctp_bind_connect() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72243linux-libc-dev7.0.0-31.31 kernel: selinux: check connect-related permissions on TCP Fast Open — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72244linux-libc-dev7.0.0-31.31 kernel: gpu/buddy: bail out of try_harder when alignment cannot be honoured — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72245linux-libc-dev7.0.0-31.31 kernel: gpu: host1x: Fix device reference leak in host1x_device_parse_dt() error path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72247linux-libc-dev7.0.0-31.31 kernel: netfilter: nf_conncount: fix zone comparison in tuple dedup — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72248linux-libc-dev7.0.0-31.31 kernel: netfilter: flowtable: support IPIP tunnel with direct xmit — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72249linux-libc-dev7.0.0-31.31 kernel: netfilter: flowtable: use dst in this direction when pushing IPIP header — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72250linux-libc-dev7.0.0-31.31 kernel: netfilter: nf_conntrack_reasm: guard mac_header adjustment after IPv6 defrag — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72296linux-libc-dev7.0.0-31.31 kernel: net: ife: require ETH_HLEN to be pullable in ife_decode() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72297linux-libc-dev7.0.0-31.31 kernel: net: atm: reject out-of-range traffic classes in QoS validation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72298linux-libc-dev7.0.0-31.31 kernel: net: qrtr: fix 32-bit integer overflow in qrtr_endpoint_post() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72299linux-libc-dev7.0.0-31.31 kernel: tipc: restrict socket queue dumps in enqueue tracepoints — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72300linux-libc-dev7.0.0-31.31 kernel: ASoC: SOF: topology: validate vendor array size before parsing — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72301linux-libc-dev7.0.0-31.31 kernel: ASoC: SOF: ipc3-control: Fix TOCTOU in bytes_put and bytes_get — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72302linux-libc-dev7.0.0-31.31 kernel: ASoC: SOF: ipc3-control: Use overflow checks in control_update size calc — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72304linux-libc-dev7.0.0-31.31 kernel: ASoC: SOF: ipc4-control: Fix TOCTOU in sof_ipc4_bytes_put — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72305linux-libc-dev7.0.0-31.31 kernel: VDUSE: avoid leaking information to userspace — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72306linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: v ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72307linux-libc-dev7.0.0-31.31 kernel: mlxsw: fix refcount leak in mlxsw_sp_vrs_lpm_tree_replace() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72308linux-libc-dev7.0.0-31.31 kernel: mlxsw: fix refcount leak in mlxsw_sp_port_lag_join() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72313linux-libc-dev7.0.0-31.31 kernel: drm/fb-helper: Only consider active CRTCs for vblank sync — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72315linux-libc-dev7.0.0-31.31 kernel: smb: client: fix busy dentry warning on unmount after DIO — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72316linux-libc-dev7.0.0-31.31 kernel: dm era: fix NULL pointer dereference in metadata_open() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72317linux-libc-dev7.0.0-31.31 kernel: SUNRPC: pin upper rpc_clnt across the TLS connect_worker — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72318linux-libc-dev7.0.0-31.31 kernel: cifs: validate DFS referral string offsets — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72491linux-libc-dev7.0.0-31.31 kernel: net/9p: fix race condition on rdma->state in trans_rdma.c — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72269linux-libc-dev7.0.0-31.31 kernel: fbdev: uvesafb: fix potential memory leak in uvesafb_probe() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72270linux-libc-dev7.0.0-31.31 kernel: fbdev: s3fb: fix potential memory leak in s3_pci_probe() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72271linux-libc-dev7.0.0-31.31 kernel: fbdev: i740fb: fix potential memory leak in i740fb_probe() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72272linux-libc-dev7.0.0-31.31 kernel: fbdev: radeon: fix potential memory leak in radeonfb_pci_register() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72273linux-libc-dev7.0.0-31.31 kernel: fbdev: efifb: fix memory leak in efifb_probe() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72274linux-libc-dev7.0.0-31.31 kernel: fbdev: hecubafb: fix potential memory leak in hecubafb_probe() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72275linux-libc-dev7.0.0-31.31 kernel: fbdev: broadsheetfb: fix potential memory leak in broadsheetfb_probe() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72276linux-libc-dev7.0.0-31.31 kernel: fbdev: metronomefb: fix potential memory leak in metronomefb_probe() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72277linux-libc-dev7.0.0-31.31 kernel: KVM: arm64: nv: Inject SEA if guest VNCR isn't normal memory — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72278linux-libc-dev7.0.0-31.31 kernel: KVM: arm64: nv: Re-translate VNCR before injecting abort — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72279linux-libc-dev7.0.0-31.31 kernel: KVM: arm64: nv: Respect read-only PFN when mapping L1 VNCR — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72280linux-libc-dev7.0.0-31.31 kernel: KVM: arm64: nv: Drop bogus WARN for write to ZCR_EL2 — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72282linux-libc-dev7.0.0-31.31 kernel: KVM: Move kvm_io_bus_get_dev() locking responsibilities to callers — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72283linux-libc-dev7.0.0-31.31 kernel: KVM: x86: Nullify irqfd->producer if updating IRTE for bypass fails — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72284linux-libc-dev7.0.0-31.31 kernel: KVM: x86: Ignore pending PV EOI if the vCPU has since disabled PV EOIs — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72285linux-libc-dev7.0.0-31.31 kernel: KVM: TDX: Reject concurrent change to CPUID entry count — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72289linux-libc-dev7.0.0-31.31 kernel: KVM: arm64: vgic: Check the interrupt is still ours before migrating it — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72290linux-libc-dev7.0.0-31.31 kernel: KVM: s390: pci: Fix GISC refcount leak on AIF enable failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72292linux-libc-dev7.0.0-31.31 kernel: KVM: s390: Initialize KVM_S390_GET_CMMA_BITS memory — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72159linux-libc-dev7.0.0-31.31 kernel: ocfs2: reject non-inline dinodes with i_size and zero i_clusters — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72160linux-libc-dev7.0.0-31.31 kernel: ocfs2: reject dinodes with non-canonical i_mode type — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72161linux-libc-dev7.0.0-31.31 kernel: ocfs2: add journal NULL check in ocfs2_checkpoint_inode() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72162linux-libc-dev7.0.0-31.31 kernel: ocfs2: fix UBSAN array-index-out-of-bounds in ocfs2_sum_rightmost_rec — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72163linux-libc-dev7.0.0-31.31 kernel: ocfs2: fix NULL h_transaction deref in ocfs2_assure_trans_credits — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72164linux-libc-dev7.0.0-31.31 kernel: ocfs2: avoid moving extents to occupied clusters — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72165linux-libc-dev7.0.0-31.31 kernel: mtd: rawnand: fix condition in 'nand_select_target()' — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72166linux-libc-dev7.0.0-31.31 kernel: net/9p: fix infinite loop in p9_client_rpc on fatal signal — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72167linux-libc-dev7.0.0-31.31 kernel: mtd: rawnand: pl353: fix probe resource allocation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72168linux-libc-dev7.0.0-31.31 kernel: mtd: maps: vmu-flash: fix fault in unaligned fixup — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72169linux-libc-dev7.0.0-31.31 kernel: kho: make sure scratch size is always aligned by CMA_MIN_ALIGNMENT_BYTES — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72170linux-libc-dev7.0.0-31.31 kernel: 9p: skip nlink update in cacheless mode to fix WARN_ON — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72171linux-libc-dev7.0.0-31.31 kernel: mtd: slram: remove failed entries from the device list — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72172linux-libc-dev7.0.0-31.31 kernel: mm/mm_init: fix uninitialized struct pages for ZONE_DEVICE — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72173linux-libc-dev7.0.0-31.31 kernel: fs/proc/task_mmu: do not warn on seeing non-migration pmd entry — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72174linux-libc-dev7.0.0-31.31 kernel: fs/proc/task_mmu: fix hugetlb self-deadlock in pagemap_scan_pte_hole() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72175linux-libc-dev7.0.0-31.31 kernel: fs/proc/task_mmu: fix make_uffd_wp_huge_pte() prot-update race — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72212linux-libc-dev7.0.0-31.31 kernel: mm/memory_hotplug: fix incorrect altmap passing in error path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72136linux-libc-dev7.0.0-31.31 kernel: xfrm: xfrm_interface: require CAP_NET_ADMIN in the device netns for changelink — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72137linux-libc-dev7.0.0-31.31 kernel: xfrm: nat_keepalive: avoid double free on send error — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72138linux-libc-dev7.0.0-31.31 kernel: xen/gntdev: fix error handling in ioctl — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72139linux-libc-dev7.0.0-31.31 kernel: tcp: defer md5sig_info kfree past RCU grace period in tcp_connect — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72140linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: i ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72141linux-libc-dev7.0.0-31.31 kernel: i2c: imx: fix locked bus on SMBus block-read of 0 (IRQ) — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72142linux-libc-dev7.0.0-31.31 kernel: i2c: imx: fix locked bus on SMBus block-read of 0 (atomic) — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72143linux-libc-dev7.0.0-31.31 kernel: platform/x86: ISST: Restore SST-PP control to all domains — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72144linux-libc-dev7.0.0-31.31 kernel: platform/x86: dell-laptop: fix missing cleanups in init error path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72146linux-libc-dev7.0.0-31.31 kernel: dmaengine: sh: rz-dmac: Move interrupt request after everything is set up — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72147linux-libc-dev7.0.0-31.31 kernel: dmaengine: dw-edma-pcie: Reject devices without driver data — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72148linux-libc-dev7.0.0-31.31 kernel: dmaengine: dw-edma: Add spinlock to protect DONE_INT_MASK and ABORT_INT_MASK — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72149linux-libc-dev7.0.0-31.31 kernel: dmaengine: tegra: Fix burst size calculation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72150linux-libc-dev7.0.0-31.31 kernel: sunrpc: fix uninitialized xprt_create_args structure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72152linux-libc-dev7.0.0-31.31 kernel: tpm: tpm_tis_spi: Use wait_woken() in wait_for_tmp_stat() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72153linux-libc-dev7.0.0-31.31 kernel: irqchip/crossbar: Use correct index in crossbar_domain_free() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72155linux-libc-dev7.0.0-31.31 kernel: mtd: spi-nor: swp: Improve locking user experience — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72156linux-libc-dev7.0.0-31.31 kernel: fpga: microchip-spi: fix zero header_size OOB read in mpf_ops_parse_header() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72157linux-libc-dev7.0.0-31.31 kernel: net: thunderbolt: Fix frags[] overflow by bounding frame_count — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72213linux-libc-dev7.0.0-31.31 kernel: mm/hugetlb: fix hugetlb cgroup rsvd charge/uncharge mismatch — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72214linux-libc-dev7.0.0-31.31 kernel: power: supply: cpcap-battery: Fix missing nvmem_device_put() causing reference leak — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72215linux-libc-dev7.0.0-31.31 kernel: MIPS: DEC: Ensure 32-bit stack location for o32 prom_printf() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72216linux-libc-dev7.0.0-31.31 kernel: remoteproc: qcom: Fix leak when custom dump_segments addition fails — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72217linux-libc-dev7.0.0-31.31 kernel: SUNRPC: Bound-check xdr_buf_to_bvec() stores before writing — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72218linux-libc-dev7.0.0-31.31 kernel: lockd: Plug nlm_file refcount leak on cached nlm_do_fopen() failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72219linux-libc-dev7.0.0-31.31 kernel: lockd: Plug nlm_file leak when nlm_do_fopen() fails — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72220linux-libc-dev7.0.0-31.31 kernel: sunrpc: harden rq_procinfo lifecycle to prevent double-free — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72221linux-libc-dev7.0.0-31.31 kernel: sunrpc: wait for in-flight TLS handshake callback when cancel loses race — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72222linux-libc-dev7.0.0-31.31 kernel: sunrpc: pin svc_xprt across the asynchronous TLS handshake callback — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72223linux-libc-dev7.0.0-31.31 kernel: nvdimm/btt: Free arena sub-allocations on discover_arenas() error path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72224linux-libc-dev7.0.0-31.31 kernel: nvdimm/btt: Free arenas on btt_init() error paths — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72225linux-libc-dev7.0.0-31.31 kernel: jbd2: fix integer underflow in jbd2_journal_initialize_fast_commit() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72226linux-libc-dev7.0.0-31.31 kernel: batman-adv: tt: prevent TVLV OOB check overflow — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72227linux-libc-dev7.0.0-31.31 kernel: batman-adv: mcast: avoid OOB read of num_dests header — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72228linux-libc-dev7.0.0-31.31 kernel: batman-adv: frag: fix primary_if leak on failed linearization — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72229linux-libc-dev7.0.0-31.31 kernel: batman-adv: clean untagged VLAN on netdev registration failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72230linux-libc-dev7.0.0-31.31 kernel: batman-adv: frag: free unfragmentable packet — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72176linux-libc-dev7.0.0-31.31 kernel: mm/damon/sysfs-schemes: put stats for scheme_add_dirs() internal error — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72177linux-libc-dev7.0.0-31.31 kernel: mm/damon/sysfs-schemes: fix dir put orders in access_pattern_add_dirs() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72178linux-libc-dev7.0.0-31.31 kernel: mm/damon/core: always put unsuccessfully committed target pids — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72179linux-libc-dev7.0.0-31.31 kernel: riscv: cacheinfo: Fix node reference leak in populate_cache_leaves — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72180linux-libc-dev7.0.0-31.31 kernel: mm/huge_memory: preserve pmd_swp_uffd_wp on device-private PMD downgrade — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72181linux-libc-dev7.0.0-31.31 kernel: mips: sched: Fix CPUMASK_OFFSTACK memory corruption — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72182linux-libc-dev7.0.0-31.31 kernel: power: supply: charger-manager: fix refcount leak in is_full_charged() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72183linux-libc-dev7.0.0-31.31 kernel: landlock: Fix LANDLOCK_SCOPE_SIGNAL bypass on the SIGIO path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72191linux-libc-dev7.0.0-31.31 kernel: ntfs3: validate split-point offset in indx_insert_into_buffer — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72192linux-libc-dev7.0.0-31.31 kernel: ntfs3: bound to_move in indx_insert_into_root before hdr_insert_head — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72193linux-libc-dev7.0.0-31.31 kernel: ntfs3: cap RESTART_TABLE free-chain walker at rt->used — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72194linux-libc-dev7.0.0-31.31 kernel: fs/ntfs3: add depth limit to indx_find_buffer to prevent stack overflow — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72196linux-libc-dev7.0.0-31.31 kernel: fs/ntfs3: bound copy_lcns dp->page_lcns[] index in analysis pass — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72197linux-libc-dev7.0.0-31.31 kernel: fs/ntfs3: bound DeleteIndexEntryAllocation memmove length — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72198linux-libc-dev7.0.0-31.31 kernel: ntfs: reject non-resident records for resident-only attributes — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72200linux-libc-dev7.0.0-31.31 kernel: ntfs: detect mapping-pairs LCN accumulator overflow — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72202linux-libc-dev7.0.0-31.31 kernel: ntfs: avoid heap allocation for free-cluster readahead state — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72203linux-libc-dev7.0.0-31.31 kernel: ntfs: skip extent mft records in writeback to prevent deadlock — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72205linux-libc-dev7.0.0-31.31 kernel: ntfs: free volume-wide resources on fill_super failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72427linux-libc-dev7.0.0-31.31 kernel: bpf: Fix effective prog array index with BPF_F_PREORDER — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72428linux-libc-dev7.0.0-31.31 kernel: bpf: Fix stack slot index in nospec checks — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72429linux-libc-dev7.0.0-31.31 kernel: ipv6: ioam: fix type confusion of dst_entry — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72430linux-libc-dev7.0.0-31.31 kernel: net/sched: act_ct: fix nf_connlabels leak on two error paths — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72431linux-libc-dev7.0.0-31.31 kernel: alloc_tag: fix use-after-free in /proc/allocinfo after module unload — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72433linux-libc-dev7.0.0-31.31 kernel: netfilter: nft_meta_bridge: fix NFT_META_BRI_IIFPVID stack leak — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72489linux-libc-dev7.0.0-31.31 kernel: staging: nvec: fix use-after-free in nvec_rx_completed() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72434linux-libc-dev7.0.0-31.31 kernel: netfilter: ipset: make sure gc is properly stopped — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72435linux-libc-dev7.0.0-31.31 kernel: netfilter: ipset: fix order of kfree_rcu() and rcu_assign_pointer() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72436linux-libc-dev7.0.0-31.31 kernel: netfilter: ipset: Don't use test_bit() in lockless RCU readers in hash types — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72437linux-libc-dev7.0.0-31.31 kernel: md/raid1: free r1_bio when REQ_NOWAIT is set and read would block on retry — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72438linux-libc-dev7.0.0-31.31 kernel: md/raid10: fix writes_pending and barrier reference leaks on discard failures — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72439linux-libc-dev7.0.0-31.31 kernel: md/raid10: fix writes_pending leak on write request failures — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72440linux-libc-dev7.0.0-31.31 kernel: md/raid1: fix writes_pending and barrier reference leaks on write failures — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72441linux-libc-dev7.0.0-31.31 kernel: ieee802154: fix kernel-infoleak in dgram_recvmsg() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72442linux-libc-dev7.0.0-31.31 kernel: netfilter: flowtable: fix and simplify IP6IP6 tunnel handling — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72443linux-libc-dev7.0.0-31.31 kernel: ALSA: usb-audio: Kill MIDI 2.0 URBs before freeing endpoints — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72465linux-libc-dev7.0.0-31.31 kernel: xprtrdma: Sanitize the reply credit grant after parsing — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72319linux-libc-dev7.0.0-31.31 kernel: ipvs: ensure inner headers in ICMP errors are in headroom — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72407linux-libc-dev7.0.0-31.31 kernel: geneve: validate inner network offset in geneve_gro_complete() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72408linux-libc-dev7.0.0-31.31 kernel: geneve: gate GRO hint in geneve_gro_complete() on gs->gro_hint — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72409linux-libc-dev7.0.0-31.31 kernel: net: mvneta: re-enable percpu interrupt on resume — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72412linux-libc-dev7.0.0-31.31 kernel: s390/mm: Fix handling of _PAGE_UNUSED pte bit — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72413linux-libc-dev7.0.0-31.31 kernel: sctp: fix err_chunk memory leaks in INIT handling — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72414linux-libc-dev7.0.0-31.31 kernel: net: dsa: sja1105: round up PTP perout pin duration — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72415linux-libc-dev7.0.0-31.31 kernel: ASoC: SDCA: Validate written enum value in ge_put_enum_double() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72416linux-libc-dev7.0.0-31.31 kernel: netfilter: nft_compat: ebtables emulation must reject non-bridge targets — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72417linux-libc-dev7.0.0-31.31 kernel: netfilter: flowtable: Validate iph->ihl in nf_flow_ip4_tunnel_proto() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72418linux-libc-dev7.0.0-31.31 kernel: netfilter: nf_conncount: prevent connlimit drops for early confirmed ct — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72419linux-libc-dev7.0.0-31.31 kernel: netfilter: nf_nat: avoid invalid nat_net pointer use on failed nf_nat_init() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72420linux-libc-dev7.0.0-31.31 kernel: md/raid5: avoid R5_Overlap races while breaking stripe batches — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72421linux-libc-dev7.0.0-31.31 kernel: ipv4: fib: Don't ignore error route in local/main tables — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72422linux-libc-dev7.0.0-31.31 kernel: ksmbd: fix use-after-free of conn->preauth_info in concurrent SMB2 NEGOTIATE — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72423linux-libc-dev7.0.0-31.31 kernel: bpf: Guard conntrack opts error writes — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72424linux-libc-dev7.0.0-31.31 kernel: rtc: msc313: fix NULL deref in shared IRQ handler at probe — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72425linux-libc-dev7.0.0-31.31 kernel: ice: fix FDIR CTRL VSI resource leak in ice_reset_all_vfs() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72492linux-libc-dev7.0.0-31.31 kernel: ksmbd: fix use-after-free in same_client_has_lease() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72464linux-libc-dev7.0.0-31.31 kernel: xprtrdma: Repost Receive buffers for malformed replies — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72463linux-libc-dev7.0.0-31.31 kernel: xfrm: Fix dev use-after-free in xfrm async resumption — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72460linux-libc-dev7.0.0-31.31 kernel: apparmor: check label build before no_new_privs test — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72459linux-libc-dev7.0.0-31.31 kernel: apparmor: aa_label_alloc use aa_label_free on alloc failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72458linux-libc-dev7.0.0-31.31 kernel: apparmor: fix NULL pointer dereference in unpack_pdb — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72457linux-libc-dev7.0.0-31.31 kernel: apparmor: fail policy unpack on accept2 allocation failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72456linux-libc-dev7.0.0-31.31 kernel: apparmor: release exe file resources on path failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72455linux-libc-dev7.0.0-31.31 kernel: apparmor: fix uninitialised pointer passed to audit_log_untrustedstring() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72453linux-libc-dev7.0.0-31.31 kernel: regcache: Do not overwrite error code when finalizing cache after error — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72452linux-libc-dev7.0.0-31.31 kernel: drm/i915: clear CRTC color blob pointers after dropping refs — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72451linux-libc-dev7.0.0-31.31 kernel: xfrm: Fix xfrm state cache insertion race — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72450linux-libc-dev7.0.0-31.31 kernel: xfrm: validate selector family and prefixlen during match — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72449linux-libc-dev7.0.0-31.31 kernel: drm/amdkfd: fix list_del corruption in kfd_criu_resume_svm — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72448linux-libc-dev7.0.0-31.31 kernel: octeontx2-pf: Fix leak of SQ timestamp buffer on teardown — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72447linux-libc-dev7.0.0-31.31 kernel: sctp: hold socket lock when dumping endpoints in sctp_diag — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72446linux-libc-dev7.0.0-31.31 kernel: ALSA: usb-audio: qcom: reject stream disable with no active interface — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72445linux-libc-dev7.0.0-31.31 kernel: ALSA: usb-audio: qcom: clear opened when stream enable fails — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72444linux-libc-dev7.0.0-31.31 kernel: flow_dissector: check device type before reading ETH_ADDRS — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72488linux-libc-dev7.0.0-31.31 kernel: soundwire: fix bug in sdw_add_element_group_count found by syzkaller — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72487linux-libc-dev7.0.0-31.31 kernel: PCI: Check ROM header and data structure addr before accessing — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72486linux-libc-dev7.0.0-31.31 kernel: mailbox: mtk-adsp: fix UAF during device teardown — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72485linux-libc-dev7.0.0-31.31 kernel: coresight: platform: defer connection counter increment until alloc succeeds — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72484linux-libc-dev7.0.0-31.31 kernel: staging: most: video: avoid double free on video register failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72483linux-libc-dev7.0.0-31.31 kernel: usb: host: max3421: Fix shift-out-of-bounds in max3421_hub_control() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72481linux-libc-dev7.0.0-31.31 kernel: iio: magnetometer: ak8975: fix potential kernel stack memory leak — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72480linux-libc-dev7.0.0-31.31 kernel: iio: adc: xilinx-ams: fix out-of-bounds channel lookup in event handling — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72479linux-libc-dev7.0.0-31.31 kernel: iio: accel: mma8452: handle I2C read error(s) in mma8452_read() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72477linux-libc-dev7.0.0-31.31 kernel: fs/ntfs3: call _ntfs_bad_inode() when failing to rename — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72475linux-libc-dev7.0.0-31.31 kernel: dmaengine: dma-axi-dmac: Properly free struct axi_dmac_desc — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72474linux-libc-dev7.0.0-31.31 kernel: dmaengine: dma-axi-dmac: use DMA pool to manange DMA descriptor — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72473linux-libc-dev7.0.0-31.31 kernel: xprtrdma: Decouple req recycling from RPC completion — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72471linux-libc-dev7.0.0-31.31 kernel: fs/ntfs3: prevent potential lcn remains uninitialized — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72470linux-libc-dev7.0.0-31.31 kernel: fs/ntfs3: resize log->one_page_buf when adopting on-disk page size — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72469linux-libc-dev7.0.0-31.31 kernel: xprtrdma: Fix ep kref imbalance on ADDR_CHANGE — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72468linux-libc-dev7.0.0-31.31 kernel: xprtrdma: Initialize re_id before removal registration — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72467linux-libc-dev7.0.0-31.31 kernel: xprtrdma: Check frwr_wp_create() during connect — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72466linux-libc-dev7.0.0-31.31 kernel: xprtrdma: Fix bcall rep leak and unbounded peek — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72343linux-libc-dev7.0.0-31.31 kernel: net/mlx5e: Fix HV VHCA stats zero-sized buffer allocation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72345linux-libc-dev7.0.0-31.31 kernel: net/mlx5: LAG, Fix off-by-one in single-FDB error rollback — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72347linux-libc-dev7.0.0-31.31 kernel: netfilter: xt_connmark: reject invalid shift parameters — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72348linux-libc-dev7.0.0-31.31 kernel: netfilter: ip6tables: mark malformed IPv6 extension headers for hotdrop — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72349linux-libc-dev7.0.0-31.31 kernel: netfilter: xt_rateest: fix u64 truncation in xt_rateest_mt() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72350linux-libc-dev7.0.0-31.31 kernel: netfilter: xt_u32: reject invalid shift counts — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72351linux-libc-dev7.0.0-31.31 kernel: gue: validate REMCSUM private option length — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72355linux-libc-dev7.0.0-31.31 kernel: netfs: Fix barriering when walking subrequest list — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72356linux-libc-dev7.0.0-31.31 kernel: cifs: Fix missing credit release on failure in cifs_issue_read() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72357linux-libc-dev7.0.0-31.31 kernel: uprobes/x86: Use proper mm_struct in __in_uprobe_trampoline — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72360linux-libc-dev7.0.0-31.31 kernel: drm/xe/pf: Don't attempt to process FAST_REQ or EVENT relays — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72361linux-libc-dev7.0.0-31.31 kernel: drm/xe/hw_engine: Fix double-free of managed BO in error path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72362linux-libc-dev7.0.0-31.31 kernel: drm/xe/pt: Fix NULL pointer dereference in xe_pt_zap_ptes_entry() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72363linux-libc-dev7.0.0-31.31 kernel: netfs: Fix folio state after ENOMEM whilst under writeback iteration — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72364linux-libc-dev7.0.0-31.31 kernel: netfs: Fix writeback error handling — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72365linux-libc-dev7.0.0-31.31 kernel: netfs: Fix writethrough to use collection offload — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72366linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: n ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72367linux-libc-dev7.0.0-31.31 kernel: iomap: guard io_size EOF trim against concurrent truncate underflow — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72368linux-libc-dev7.0.0-31.31 kernel: cachefiles: Fix double unlock in nomem_d_alloc error path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72320linux-libc-dev7.0.0-31.31 kernel: netfilter: nft_lookup: fix catchall element handling with inverted lookups — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72321linux-libc-dev7.0.0-31.31 kernel: ipv4: igmp: Fix potential memory leaks in igmp_mod_timer() and igmp_stop_timer() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72322linux-libc-dev7.0.0-31.31 kernel: ipv6: mcast: Fix potential UAF in MLD delayed work — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72323linux-libc-dev7.0.0-31.31 kernel: ipv4: igmp: Fix potential UAF in igmp_gq_start_timer() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72324linux-libc-dev7.0.0-31.31 kernel: gpio: mvebu: free generic chips on unbind — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72325linux-libc-dev7.0.0-31.31 kernel: perf/x86/amd/core: Avoid enabling BRS from the SVM reload path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72326linux-libc-dev7.0.0-31.31 kernel: net/sched: cake: reject overhead values that underflow length — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72327linux-libc-dev7.0.0-31.31 kernel: drm/v3d: Reject invalid indirect BO handle in indirect CSD setup — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72328linux-libc-dev7.0.0-31.31 kernel: accel/amdxdna: Fix potential amdxdna_umap lifetime race — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72330linux-libc-dev7.0.0-31.31 kernel: net/tls: Consume empty data records in tls_sw_read_sock() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72332linux-libc-dev7.0.0-31.31 kernel: accel/amdxdna: Prevent PM resume deadlock in hwctx_sync_debug_bo() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72333linux-libc-dev7.0.0-31.31 kernel: Bluetooth: L2CAP: fix tx ident leak for commands without a response — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72334linux-libc-dev7.0.0-31.31 kernel: Bluetooth: ISO: fix malformed ISO_END/CONT handling — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72335linux-libc-dev7.0.0-31.31 kernel: Bluetooth: MGMT: Fix adv monitor add failure cleanup — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72336linux-libc-dev7.0.0-31.31 kernel: Bluetooth: 6lowpan: hold L2CAP conn across debugfs control — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72337linux-libc-dev7.0.0-31.31 kernel: Bluetooth: 6lowpan: avoid untracked enable work — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72339linux-libc-dev7.0.0-31.31 kernel: qede: fix off-by-one in BD ring consumption on build_skb failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72340linux-libc-dev7.0.0-31.31 kernel: net: microchip: vcap: fix races on the shared Super VCAP block — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72341linux-libc-dev7.0.0-31.31 kernel: net/mlx5e: Fix publication race for priv->channel_stats[] — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72369linux-libc-dev7.0.0-31.31 kernel: minix: avoid overflow in bitmap block count calculation — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72387linux-libc-dev7.0.0-31.31 kernel: drm/panthor: Fix potential invalid pointer deref in group_process_tiler_oom() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72388linux-libc-dev7.0.0-31.31 kernel: drm/panthor: Always use the IRQ-safe variant when acquiring the fence lock — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72389linux-libc-dev7.0.0-31.31 kernel: bridge: stp: Fix a potential use-after-free when deleting a bridge — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72391linux-libc-dev7.0.0-31.31 kernel: net: phy: sfp: free mii_bus in sfp_i2c_mdiobus_destroy — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72392linux-libc-dev7.0.0-31.31 kernel: ipv6: fib6: fix NULL deref in fib6_walk_continue() on multi-batch dump — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72393linux-libc-dev7.0.0-31.31 kernel: eth: fbnic: don't cache shinfo across skb realloc — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72394linux-libc-dev7.0.0-31.31 kernel: hwmon: (aspeed-g6-pwm-tach) Guard fan RPM calculation against divide-by-zero — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72395linux-libc-dev7.0.0-31.31 kernel: hwmon: (pmbus) Fix passing events to regulator core — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72396linux-libc-dev7.0.0-31.31 kernel: hwmon: adm1275: Prevent reading uninitialized stack — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72397linux-libc-dev7.0.0-31.31 kernel: hwmon: (pmbus/core) honor vrm_version in pmbus_data2reg_vid() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72398linux-libc-dev7.0.0-31.31 kernel: sctp: add INIT verification after cookie unpacking — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72399linux-libc-dev7.0.0-31.31 kernel: net: enetc: check the number of BDs needed for xdp_frame — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72400linux-libc-dev7.0.0-31.31 kernel: seg6: validate SRH length before reading fixed fields — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72401linux-libc-dev7.0.0-31.31 kernel: bpf: Fix insn_aux_data leak on verifier err_free_env path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72402linux-libc-dev7.0.0-31.31 kernel: bpf: Mask pseudo pointer values in verifier logs — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72403linux-libc-dev7.0.0-31.31 kernel: ALSA: FCP: Fix NULL pointer dereference in interface lookup — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72404linux-libc-dev7.0.0-31.31 kernel: tipc: fix UAF in cleanup_bearer() due to premature dst_cache_destroy() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72405linux-libc-dev7.0.0-31.31 kernel: net: udp_tunnel: prevent double queueing in udp_tunnel_nic_device_sync — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72406linux-libc-dev7.0.0-31.31 kernel: net: sungem: fix probe error cleanup — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72370linux-libc-dev7.0.0-31.31 kernel: iomap: release pages on atomic dio size mismatch — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72371linux-libc-dev7.0.0-31.31 kernel: afs: Fix the volume AFS_VOLUME_RM_TREE is set on — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72373linux-libc-dev7.0.0-31.31 kernel: afs: Fix missing NULL pointer check in afs_break_some_callbacks() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72374linux-libc-dev7.0.0-31.31 kernel: afs: Fix callback service message parsers to pass through -EAGAIN — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72375linux-libc-dev7.0.0-31.31 kernel: afs: Fix reinitialisation of the inode, in particular ->lock_work — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72376linux-libc-dev7.0.0-31.31 kernel: afs: Fix misplaced inc of net->cells_outstanding — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72377linux-libc-dev7.0.0-31.31 kernel: afs: Remove setting of AS_RELEASE_ALWAYS for symlinks and mountpoints — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72378linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: a ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72379linux-libc-dev7.0.0-31.31 kernel: fs: refuse O_TMPFILE creation with an unmapped fsuid or fsgid — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72380linux-libc-dev7.0.0-31.31 kernel: xen/pvcalls: bound backend response req_id before indexing rsp[] — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72381linux-libc-dev7.0.0-31.31 kernel: ksmbd: fix use-after-free of fp->owner.name in durable handle owner check — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72386linux-libc-dev7.0.0-31.31 kernel: drm/panthor: Fix a leak when a group is evicted before the tiler OOM is serviced — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72385linux-libc-dev7.0.0-31.31 kernel: tracing/fprobe: Fix NULL pointer dereference in fprobe_fgraph_entry() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72382linux-libc-dev7.0.0-31.31 kernel: ksmbd: reject undersized DACLs before parsing ACEs — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72383linux-libc-dev7.0.0-31.31 kernel: sctp: fix addr_wq_timer race in sctp_free_addr_wq() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
MEDIUM CVE-2026-72384linux-libc-dev7.0.0-31.31 kernel: irqchip/ts4800: Fix missing chained handler cleanup on remove — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-80657linux-libc-dev7.0.0-31.31 kernel: accel/amdxdna: Guard management mailbox channel cleanup against NULL pointer — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-80658linux-libc-dev7.0.0-31.31 kernel: drm/rockchip: dw_dp: Fix null-ptr-deref in dw_dp_remove() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-80660linux-libc-dev7.0.0-31.31 kernel: hwmon: (occ) unregister sysfs devices outside occ lock — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-80661linux-libc-dev7.0.0-31.31 kernel: ufs: core: tracing: Do not dereference pointers in TP_printk() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-80685linux-libc-dev7.0.0-31.31 kernel: mm/util: don't read __page_2 for order-1 folios in snapshot_page() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-80680linux-libc-dev7.0.0-31.31 kernel: i2c: amd-mp2: Unregister callback on adapter add failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-80679linux-libc-dev7.0.0-31.31 kernel: s390/dasd: Fix potential NULL pointer dereference — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-80689linux-libc-dev7.0.0-31.31 kernel: tracing/mmiotrace: Add NULL check for mmio_trace_array in logging functions — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-80687linux-libc-dev7.0.0-31.31 kernel: iommufd/viommu: Release the igroup lock on the vdevice_size error path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-80678linux-libc-dev7.0.0-31.31 kernel: i2c: imx: Fix slave registration race and error handling — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-80677linux-libc-dev7.0.0-31.31 kernel: driver core: use READ_ONCE() for dev->driver in dev_has_sync_state() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-80688linux-libc-dev7.0.0-31.31 kernel: riscv: drop __init from vec_check_unaligned_access_speed_all_cpus — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-80662linux-libc-dev7.0.0-31.31 kernel: cxl: Fix CXL_HEADERLOG_SIZE to match RAS Capability size — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-80676linux-libc-dev7.0.0-31.31 kernel: Drivers: hv: vmbus: use generic driver_override infrastructure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-80655linux-libc-dev7.0.0-31.31 kernel: soc: xilinx: Fix race condition in event registration — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-80654linux-libc-dev7.0.0-31.31 kernel: soc: xilinx: Shutdown and free rx mailbox channel — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-80653linux-libc-dev7.0.0-31.31 kernel: scsi: hisi_sas: Add slave_destroy interface for v3 hw — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-80652linux-libc-dev7.0.0-31.31 kernel: crypto: ccp - Treat zero-length cert chain as query for blob lengths — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-80651linux-libc-dev7.0.0-31.31 kernel: crypto: ccp/sev-dev-tsm - bail out early when pdev->bus is NULL — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-80650linux-libc-dev7.0.0-31.31 kernel: media: atomisp: gc2235: fix UAF and memory leak — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-80649linux-libc-dev7.0.0-31.31 kernel: firmware: arm_scmi: Fix OOB in scmi_power_name_get() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-80648linux-libc-dev7.0.0-31.31 kernel: pinctrl: spacemit: fix NULL check in spacemit_pin_set_config — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-80647linux-libc-dev7.0.0-31.31 kernel: RDMA/hns: Fix warning in poll cq direct mode — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-80645linux-libc-dev7.0.0-31.31 kernel: rapidio/tsi721: prevent a bad dereference in tsi721_db_dpc() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-80643linux-libc-dev7.0.0-31.31 kernel: EDAC/igen6: Fix call trace due to missing release() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-80642linux-libc-dev7.0.0-31.31 kernel: liveupdate: Reference count incoming FLB data — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-80640linux-libc-dev7.0.0-31.31 kernel: cxl/fwctl: Fix __fortify_panic — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-40228libudev1259.5-0ubuntu3.4 systemd: systemd-journald: Unintended output to user terminals via logger command — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2017-13716libbinutils2.46-3ubuntu2 binutils: Memory leak with the C++ symbol demangler routine in libiberty — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2017-13716libctf-nobfd02.46-3ubuntu2 binutils: Memory leak with the C++ symbol demangler routine in libiberty — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2017-13716libctf02.46-3ubuntu2 binutils: Memory leak with the C++ symbol demangler routine in libiberty — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2017-13716binutils-x86-64-linux-gnu2.46-3ubuntu2 binutils: Memory leak with the C++ symbol demangler routine in libiberty — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2017-13716binutils-common2.46-3ubuntu2 binutils: Memory leak with the C++ symbol demangler routine in libiberty — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2017-13716binutils2.46-3ubuntu2 binutils: Memory leak with the C++ symbol demangler routine in libiberty — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2025-61594ruby3.3-dev3.3.8-2ubuntu3.1 uri: URI module: Credential exposure via URI + operator — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2025-58767ruby3.3-dev3.3.8-2ubuntu3.1 rexml: REXML denial of service — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2025-61594ruby3.33.3.8-2ubuntu3.1 uri: URI module: Credential exposure via URI + operator — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2025-58767ruby3.33.3.8-2ubuntu3.1 rexml: REXML denial of service — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-56289patch2.8-2build1 patch: GNU patch: Denial of Service via crafted unified-diff input — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-56288patch2.8-2build1 patch: GNU patch: Denial of Service via specially crafted patch file — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2021-45261patch2.8-2build1 patch: Invalid Pointer via another_hunk function — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2019-20633patch2.8-2build1 patch: double free in another_hunk function in pch.c — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2018-6952patch2.8-2build1 patch: Double free of memory in pch.c:another_hunk() causes a crash — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2024-56433passwd1:4.17.4-2ubuntu3 shadow-utils: Default subordinate ID configuration in /etc/login.defs could lead to compromise — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2024-56433login.defs1:4.17.4-2ubuntu3 shadow-utils: Default subordinate ID configuration in /etc/login.defs could lead to compromise — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-80724linux-libc-dev7.0.0-31.31 kernel: ptp: vmclock: prevent read-only mappings from becoming writable — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-80723linux-libc-dev7.0.0-31.31 kernel: of: reserved_mem: prevent OOB when too many dynamic regions are defined — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-80712linux-libc-dev7.0.0-31.31 kernel: spi: spi-qpic-snand: write the feature value before executing SET_FEATURE — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-80711linux-libc-dev7.0.0-31.31 kernel: power: supply: max17040: handle missing status supplier — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-80709linux-libc-dev7.0.0-31.31 kernel: s390/zcrypt: Fix wrong domain value verification with EP11 CPRBs — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-80708linux-libc-dev7.0.0-31.31 kernel: s390/zcrypt: Fix missing mem scrub at clear key import in cca_clr2cipherkey() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-80706linux-libc-dev7.0.0-31.31 kernel: can: softing: fw_parse(): validate firmware record spans — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-80704linux-libc-dev7.0.0-31.31 kernel: drm/amd/display: use proper context for logging — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-80698linux-libc-dev7.0.0-31.31 kernel: dmaengine: idxd: fix double free of wq, engine, and group structs — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-80696linux-libc-dev7.0.0-31.31 kernel: hwmon: (ltc4282) Fix reading the minimum alarm voltage — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-80690linux-libc-dev7.0.0-31.31 kernel: scsi: ufs: core: Initialize hba->rpmbs list in ufshcd — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2023-20585linux-libc-dev7.0.0-31.31 kernel-core: hw: amd: AMD-SN-3016: IOMMU Write Buffer Vulnerability — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2023-33053linux-libc-dev7.0.0-31.31 ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2023-6238linux-libc-dev7.0.0-31.31 kernel: nvme: memory corruption via unprivileged user passthrough — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2024-0564linux-libc-dev7.0.0-31.31 kernel: max page sharing of Kernel Samepage Merging (KSM) may cause memory deduplication — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2025-22077linux-libc-dev7.0.0-31.31 kernel: smb: client: Fix netns refcount imbalance causing leaks and use-after-free — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-64574linux-libc-dev7.0.0-31.31 kernel: wifi: mac80211: tear down new links on vif update error path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-64583linux-libc-dev7.0.0-31.31 In the Linux kernel, the following vulnerability has been resolved: u ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-68104linux-libc-dev7.0.0-31.31 kernel: drm/amdgpu: invoke pm_genpd_remove() before freeing genpd — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-68107linux-libc-dev7.0.0-31.31 kernel: drm/amdgpu/vcn4: avoid rereading IB param length — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-68116linux-libc-dev7.0.0-31.31 kernel: vxlan: mdb: Fix source list corruption on a failed replace — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-68124linux-libc-dev7.0.0-31.31 kernel: mctp: serial: handle zero-length frames to prevent rx buffer overflow — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-68142linux-libc-dev7.0.0-31.31 kernel: geneve: require CAP_NET_ADMIN in the device netns for changelink — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-68153linux-libc-dev7.0.0-31.31 kernel: libceph: remove debugfs files before client teardown — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-68156linux-libc-dev7.0.0-31.31 kernel: libceph: refresh auth->authorizer_buf{,_len} after authorizer update — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-68240linux-libc-dev7.0.0-31.31 kernel: drm/gpusvm: publish dpagemap early to avoid device mapping leak on error — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-68305linux-libc-dev7.0.0-31.31 kernel: drm/xe/vf: Add drm_dev guards when detaching CCS read/write buffers — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-68314linux-libc-dev7.0.0-31.31 kernel: net: mctp i3c: clean up notifier and buses if driver register fails — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-68330linux-libc-dev7.0.0-31.31 kernel: net: airoha: Fix DMA direction for NPU mailbox buffer — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-68353linux-libc-dev7.0.0-31.31 kernel: wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-68370linux-libc-dev7.0.0-31.31 kernel: usb: gadget: dummy_hcd: prevent fifo_req reuse during giveback — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-68432linux-libc-dev7.0.0-31.31 kernel: vxlan: require CAP_NET_ADMIN in the device netns for changelink — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-68454linux-libc-dev7.0.0-31.31 kernel: KVM: s390: pci: Fix handling of AIF enable without AISB — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-68466linux-libc-dev7.0.0-31.31 kernel: mtd: rawnand: lpc32xx_slc: fail DMA transfer on completion timeout — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-72051linux-libc-dev7.0.0-31.31 kernel: net: ip6_tunnel: require CAP_NET_ADMIN in the device netns for changelink — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-40228libsystemd0259.5-0ubuntu3.4 systemd: systemd-journald: Unintended output to user terminals via logger command — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2017-13716libsframe32.46-3ubuntu2 binutils: Memory leak with the C++ symbol demangler routine in libiberty — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2025-61594libruby3.33.3.8-2ubuntu3.1 uri: URI module: Credential exposure via URI + operator — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2025-58767libruby3.33.3.8-2ubuntu3.1 rexml: REXML denial of service — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2017-13716libgprofng02.46-3ubuntu2 binutils: Memory leak with the C++ symbol demangler routine in libiberty — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2017-0537linux-libc-dev7.0.0-31.31 ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2017-13165linux-libc-dev7.0.0-31.31 ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2017-13693linux-libc-dev7.0.0-31.31 kernel: ACPI operand cache leak in dsutils.c — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2018-1121linux-libc-dev7.0.0-31.31 procps: process hiding through race condition enumerating /proc — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2018-12928linux-libc-dev7.0.0-31.31 kernel: NULL pointer dereference in hfs_ext_read_extent in hfs.ko — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2018-12929linux-libc-dev7.0.0-31.31 kernel: use-after-free in ntfs_read_locked_inode in the ntfs.ko — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2018-12930linux-libc-dev7.0.0-31.31 kernel: stack-based out-of-bounds write in ntfs_end_buffer_async_read in the ntfs.ko — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2018-12931linux-libc-dev7.0.0-31.31 kernel: stack-based out-of-bounds write in ntfs_attr_find in the ntfs.ko — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2019-14899linux-libc-dev7.0.0-31.31 VPN: an attacker can inject data into the TCP stream which allows a hijack of active connections inside the VPN tunnel — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2019-15213linux-libc-dev7.0.0-31.31 kernel: use-after-free caused by malicious USB device in drivers/media/usb/dvb-usb/dvb-usb-init.c — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2019-19378linux-libc-dev7.0.0-31.31 kernel: out-of-bounds write in index_rbio_pages in fs/btrfs/raid56.c — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2019-19814linux-libc-dev7.0.0-31.31 kernel: out-of-bounds write in __remove_dirty_segment in fs/f2fs/segment.c — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2019-20426linux-libc-dev7.0.0-31.31 ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2020-14304linux-libc-dev7.0.0-31.31 kernel: ethtool when reading eeprom of device could lead to memory leak — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2020-35501linux-libc-dev7.0.0-31.31 kernel: audit not logging access to syscall open_by_handle_at for users with CAP_DAC_READ_SEARCH capability — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2021-26934linux-libc-dev7.0.0-31.31 An issue was discovered in the Linux kernel 4.18 through 5.10.16, as u ... — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2022-41848linux-libc-dev7.0.0-31.31 kernel: Race condition between mgslpc_ioctl and mgslpc_detach — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2022-44034linux-libc-dev7.0.0-31.31 Kernel: A use-after-free due to race between scr24x_open() and scr24x_remove() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2022-45885linux-libc-dev7.0.0-31.31 kernel: use-after-free due to race condition occurring in dvb_frontend.c — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-74383linux-libc-dev7.0.0-31.31 kernel: nvme-pci: fix out-of-bounds access in nvme_setup_descriptor_pools — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-74397linux-libc-dev7.0.0-31.31 kernel: IB/mlx5: Fix transport-domain rollback and initialize lb mutex earlier — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-74401linux-libc-dev7.0.0-31.31 kernel: dlm: fix add msg handle in send_queue ordered — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-74403linux-libc-dev7.0.0-31.31 kernel: crypto: ccp - Check for page allocation failure correctly in TIO — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-74405linux-libc-dev7.0.0-31.31 kernel: OPP: Fix race between OPP addition and lookup — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-74412linux-libc-dev7.0.0-31.31 kernel: wifi: rtw88: fix wrong pci_get_drvdata type in AER handlers — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-74450linux-libc-dev7.0.0-31.31 kernel: drm/amd/pm: fix pptable use-after-free — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-74481linux-libc-dev7.0.0-31.31 kernel: mm/page_reporting: use system_freezable_wq to fix UAF during suspend — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-74490linux-libc-dev7.0.0-31.31 kernel: tipc: avoid use-after-free in poll trace queue dumps — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-74512linux-libc-dev7.0.0-31.31 kernel: audit: fix potential use-after-free in audit_del_rule() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-74519linux-libc-dev7.0.0-31.31 kernel: pinctrl: devicetree: don't free uninitialized dev_name on error path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-74527linux-libc-dev7.0.0-31.31 kernel: octeontx2-af: Block VFs from clobbering special CGX PKIND state — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-74554linux-libc-dev7.0.0-31.31 kernel: wifi: ath12k: fix out-of-bounds clear_bit in ath12k_mac_dp_peer_cleanup() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-74568linux-libc-dev7.0.0-31.31 kernel: KVM: arm64: vgic: Fix race between LPI release and re-registration — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-80622linux-libc-dev7.0.0-31.31 kernel: char: tlclk: fix use-after-free in tlclk_cleanup() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-80623linux-libc-dev7.0.0-31.31 kernel: coresight: ete: Always save state on power down — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-80624linux-libc-dev7.0.0-31.31 kernel: mfd: cs42l43: Sanity check firmware size — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-80625linux-libc-dev7.0.0-31.31 kernel: RDMA/hns: Fix memory leak of bonding resources — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-80627linux-libc-dev7.0.0-31.31 kernel: MIPS: mm: Fix out-of-bounds write in maar_res_walk() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-80628linux-libc-dev7.0.0-31.31 kernel: ALSA: seq: oss: Serialize readq reset state with q->lock — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-80629linux-libc-dev7.0.0-31.31 kernel: octeontx2-af: npc: Fix size of entry2cntr_map — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-80635linux-libc-dev7.0.0-31.31 kernel: wifi: wcn36xx: fix OOB read from short trigger BA firmware response — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-80636linux-libc-dev7.0.0-31.31 kernel: netfilter: conntrack: revert ct extension genid infrastructure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-80639linux-libc-dev7.0.0-31.31 kernel: cxl/test: Fix __fortify_panic — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-72054linux-libc-dev7.0.0-31.31 kernel: net: ip_vti: require CAP_NET_ADMIN in the device netns for changelink — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-72071linux-libc-dev7.0.0-31.31 kernel: tracing/user_events: Fix use-after-free in user_event_mm_dup() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-72090linux-libc-dev7.0.0-31.31 kernel: accel/amdxdna: Use caller client for debug BO sync — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-72100linux-libc-dev7.0.0-31.31 kernel: dm-integrity: fix a bug if the bio is out of limits — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-72108linux-libc-dev7.0.0-31.31 kernel: dm thin metadata: fix metadata snapshot consistency on commit failure — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-72134linux-libc-dev7.0.0-31.31 kernel: spi: imx: reconfigure for PIO when DMA cannot be started — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-72154linux-libc-dev7.0.0-31.31 kernel: openrisc: Fix jump_label smp syncing — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-72286linux-libc-dev7.0.0-31.31 kernel: KVM: SEV: Do not allow intra-host migration/mirroring of SNP VMs — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-72303linux-libc-dev7.0.0-31.31 kernel: ASoC: SOF: ipc4-control: Validate notification payload size — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-72310linux-libc-dev7.0.0-31.31 kernel: smb: client: fix overflow in passthrough ioctl bounds check — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-72312linux-libc-dev7.0.0-31.31 kernel: octeontx2-af: fix VF bringup affecting PF promiscuous state — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-72314linux-libc-dev7.0.0-31.31 kernel: regulator: core: regulator_lock_two() should test for EDEADLK not EDEADLOCK — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-72329linux-libc-dev7.0.0-31.31 kernel: net/liquidio: drop cached VF pci_dev LUT — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-72342linux-libc-dev7.0.0-31.31 kernel: net/mlx5e: Fix HV VHCA stats agent registration race — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-72352linux-libc-dev7.0.0-31.31 kernel: HID: bpf: Fix hid_bpf_get_data() range check — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-72410linux-libc-dev7.0.0-31.31 kernel: octeontx2-af: Validate NIX maximum LFs correctly — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-72454linux-libc-dev7.0.0-31.31 kernel: i3c: mipi-i3c-hci: Fix race in i3c_hci_addr_to_dev() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-72476linux-libc-dev7.0.0-31.31 kernel: dmaengine: Fix possible use after free — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-72482linux-libc-dev7.0.0-31.31 kernel: gpib: fix double decrement of descriptor_busy in command_ioctl() — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-74262linux-libc-dev7.0.0-31.31 kernel: kcm: use WRITE_ONCE() when changing lower socket callbacks — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-74312linux-libc-dev7.0.0-31.31 kernel: vhost/vdpa: validate virtqueue index in mmap and fault paths — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-74313linux-libc-dev7.0.0-31.31 kernel: vduse: hold vduse_lock across IDR lookup in open path — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-74361linux-libc-dev7.0.0-31.31 kernel: nvme: fix FDP fdpcidx bounds check — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)
LOW CVE-2026-74371linux-libc-dev7.0.0-31.31 kernel: bpf: fix BPF_PROG_QUERY OOB write and cgroup backward compat — ghcr.io/openvoxproject/openvoxserver:latest (ubuntu 26.04)

Grype

HIGH 6 MEDIUM 329 LOW 93 UNKNOWN 6
SeverityIDPackageInstalledFixedTitle / target
HIGH GO-2026-6090stdlibgo1.26.5 1.25.13, 1.26.6, 1.27.0-rc.3Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely. — /usr/bin/pebble
HIGH GO-2026-5972stdlibgo1.26.5 1.25.13, 1.26.6, 1.27.0-rc.3Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures. — /usr/bin/pebble
HIGH GO-2026-6089stdlibgo1.26.5 1.25.13, 1.26.6, 1.27.0-rc.3When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this. — /usr/bin/pebble
HIGH GO-2026-5026stdlibgo1.26.5 1.25.13, 1.26.6, 1.27.0-rc.3The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com". — /usr/bin/pebble
HIGH GHSA-q339-8rmv-2mhverb4.0.3 4.0.3.1ERB has an @_init deserialization guard bypass via def_module / def_method / def_class — /usr/lib/ruby/gems/3.3.0/specifications/default/erb-4.0.3.gemspec
HIGH GHSA-jr6h-r7vg-f9mcini4j0.5.4 org.ini4j allows attackers to cause a Denial of Service (DoS) — /opt/puppetlabs/server/apps/puppetserver/puppet-server-release.jar
MEDIUM CVE-2026-90801libgprofng02.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-90801libctf02.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-90801libctf-nobfd02.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-90801libbinutils2.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-90801binutils-x86-64-linux-gnu2.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-90801libsframe32.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-90801binutils-common2.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-90801binutils2.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-35348rust-coreutils0.8.0-0ubuntu3 /var/lib/dpkg/status
MEDIUM CVE-2026-35368rust-coreutils0.8.0-0ubuntu3 /var/lib/dpkg/status
MEDIUM CVE-2026-78409libblkid12.41.3-3ubuntu2.2 /var/lib/dpkg/status
MEDIUM CVE-2026-56407libexpat12.7.4-1 /var/lib/dpkg/status
MEDIUM CVE-2026-56406libexpat12.7.4-1 /var/lib/dpkg/status
MEDIUM CVE-2026-56403libexpat12.7.4-1 /var/lib/dpkg/status
MEDIUM CVE-2026-18508tar1.35+dfsg-4ubuntu0.4 /var/lib/dpkg/status
MEDIUM GHSA-46q3-7gv7-qmggnet-imap0.4.19 0.5.15Net::IMAP: Command Injection via ID command argument — /usr/lib/ruby/gems/3.3.0/specifications/net-imap-0.4.19.gemspec
MEDIUM CVE-2026-6845libsframe32.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-6845libgprofng02.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-6845libctf02.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-6845libctf-nobfd02.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-6845libbinutils2.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-6845binutils-x86-64-linux-gnu2.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-6845binutils-common2.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-6845binutils2.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-35352rust-coreutils0.8.0-0ubuntu3 /var/lib/dpkg/status
MEDIUM CVE-2026-78409bsdutils1:2.41.3-3ubuntu2.2 /var/lib/dpkg/status
MEDIUM CVE-2026-90803libsframe32.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-90803libgprofng02.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-90803libctf02.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-90803libctf-nobfd02.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-90803libbinutils2.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-90803binutils-x86-64-linux-gnu2.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-90803binutils-common2.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-90803binutils2.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-56405libexpat12.7.4-1 /var/lib/dpkg/status
MEDIUM CVE-2026-56408libexpat12.7.4-1 /var/lib/dpkg/status
MEDIUM CVE-2026-86138libxml2-162.15.2+dfsg-0.1ubuntu0.1 /var/lib/dpkg/status
MEDIUM CVE-2026-35350rust-coreutils0.8.0-0ubuntu3 /var/lib/dpkg/status
MEDIUM CVE-2026-86143libxml2-162.15.2+dfsg-0.1ubuntu0.1 /var/lib/dpkg/status
MEDIUM CVE-2025-15649perl-modules-5.405.40.1-7ubuntu0.2 /var/lib/dpkg/status
MEDIUM CVE-2025-15649perl-base5.40.1-7ubuntu0.2 /var/lib/dpkg/status
MEDIUM CVE-2025-15649perl5.40.1-7ubuntu0.2 /var/lib/dpkg/status
MEDIUM CVE-2025-15649libperl5.405.40.1-7ubuntu0.2 /var/lib/dpkg/status
MEDIUM CVE-2026-86137libxml2-162.15.2+dfsg-0.1ubuntu0.1 /var/lib/dpkg/status
MEDIUM CVE-2026-56391coreutils9.5-1ubuntu2+0.0.0~ubuntu25 9.7-3ubuntu2.1/var/lib/dpkg/status
MEDIUM CVE-2026-47242ruby3.3-dev3.3.8-2ubuntu3.1 /var/lib/dpkg/status
MEDIUM CVE-2026-47242ruby3.33.3.8-2ubuntu3.1 /var/lib/dpkg/status
MEDIUM CVE-2026-47242libruby3.33.3.8-2ubuntu3.1 /var/lib/dpkg/status
MEDIUM CVE-2026-35351rust-coreutils0.8.0-0ubuntu3 /var/lib/dpkg/status
MEDIUM CVE-2026-13757libp11-kit00.26.2-2 /var/lib/dpkg/status
MEDIUM CVE-2026-6846libbinutils2.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-6846binutils-x86-64-linux-gnu2.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-6846binutils-common2.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-6846binutils2.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-56131libexpat12.7.4-1 /var/lib/dpkg/status
MEDIUM CVE-2026-76642util-linux2.41.3-3ubuntu2.2 /var/lib/dpkg/status
MEDIUM CVE-2026-76642mount2.41.3-3ubuntu2.2 /var/lib/dpkg/status
MEDIUM CVE-2026-76642login1:4.16.0-2+really2.41.3-3ubuntu2.2 /var/lib/dpkg/status
MEDIUM CVE-2026-76642libuuid12.41.3-3ubuntu2.2 /var/lib/dpkg/status
MEDIUM CVE-2026-76642libsmartcols12.41.3-3ubuntu2.2 /var/lib/dpkg/status
MEDIUM CVE-2026-76642libmount12.41.3-3ubuntu2.2 /var/lib/dpkg/status
MEDIUM CVE-2026-76642libblkid12.41.3-3ubuntu2.2 /var/lib/dpkg/status
MEDIUM CVE-2026-76642bsdutils1:2.41.3-3ubuntu2.2 /var/lib/dpkg/status
MEDIUM CVE-2026-86144libxml2-162.15.2+dfsg-0.1ubuntu0.1 /var/lib/dpkg/status
MEDIUM CVE-2026-56412libexpat12.7.4-1 /var/lib/dpkg/status
MEDIUM CVE-2026-50219libexpat12.7.4-1 /var/lib/dpkg/status
MEDIUM CVE-2026-3441libsframe32.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-3441libgprofng02.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-3441libctf02.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-3441libctf-nobfd02.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-3441libbinutils2.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-3441binutils-x86-64-linux-gnu2.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-3441binutils-common2.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-3441binutils2.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-86140libxml2-162.15.2+dfsg-0.1ubuntu0.1 /var/lib/dpkg/status
MEDIUM CVE-2026-18374libc6-dev2.43-2ubuntu2.4 /var/lib/dpkg/status
MEDIUM CVE-2026-18374libc62.43-2ubuntu2.4 /var/lib/dpkg/status
MEDIUM CVE-2026-18374libc-gconv-modules-extra2.43-2ubuntu2.4 /var/lib/dpkg/status
MEDIUM CVE-2026-18374libc-dev-bin2.43-2ubuntu2.4 /var/lib/dpkg/status
MEDIUM CVE-2026-18374libc-bin2.43-2ubuntu2.4 /var/lib/dpkg/status
MEDIUM CVE-2026-86142libxml2-162.15.2+dfsg-0.1ubuntu0.1 /var/lib/dpkg/status
MEDIUM CVE-2026-54369libacl12.3.2-2 /var/lib/dpkg/status
MEDIUM CVE-2026-32776libexpat12.7.4-1 /var/lib/dpkg/status
MEDIUM CVE-2026-35341rust-coreutils0.8.0-0ubuntu3 /var/lib/dpkg/status
MEDIUM CVE-2026-35363rust-coreutils0.8.0-0ubuntu3 /var/lib/dpkg/status
MEDIUM CVE-2026-4647libsframe32.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-4647libgprofng02.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-4647libctf02.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-4647libctf-nobfd02.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-4647libbinutils2.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-4647binutils-x86-64-linux-gnu2.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-4647binutils-common2.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-4647binutils2.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-32778libexpat12.7.4-1 /var/lib/dpkg/status
MEDIUM CVE-2026-6846libsframe32.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-6846libgprofng02.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-6846libctf02.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-6846libctf-nobfd02.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-82455ruby-rubygems3.6.7-2ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-35377rust-coreutils0.8.0-0ubuntu3 /var/lib/dpkg/status
MEDIUM CVE-2026-89157libpcre2-8-010.46-1build1 /var/lib/dpkg/status
MEDIUM CVE-2026-89156libpcre2-8-010.46-1build1 /var/lib/dpkg/status
MEDIUM CVE-2026-56132libexpat12.7.4-1 /var/lib/dpkg/status
MEDIUM CVE-2026-6844libsframe32.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-6844libgprofng02.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-6844libctf02.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-6844libctf-nobfd02.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-6844libbinutils2.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-6844binutils-x86-64-linux-gnu2.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-6844binutils-common2.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-6844binutils2.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-35360rust-coreutils0.8.0-0ubuntu3 /var/lib/dpkg/status
MEDIUM CVE-2026-89162libpcre2-8-010.46-1build1 /var/lib/dpkg/status
MEDIUM CVE-2026-35359rust-coreutils0.8.0-0ubuntu3 /var/lib/dpkg/status
MEDIUM CVE-2026-15003libsframe32.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-15003libgprofng02.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-15003libctf02.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-15003libctf-nobfd02.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-15003libbinutils2.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-15003binutils-x86-64-linux-gnu2.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-15003binutils-common2.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-15003binutils2.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-76957libexpat12.7.4-1 /var/lib/dpkg/status
MEDIUM CVE-2026-19582libsframe32.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-19582libgprofng02.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-19582libctf02.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-19582libctf-nobfd02.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-19582libbinutils2.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-19582binutils-x86-64-linux-gnu2.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-19582binutils-common2.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-19582binutils2.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-35374rust-coreutils0.8.0-0ubuntu3 /var/lib/dpkg/status
MEDIUM CVE-2026-16517libarchive13t643.8.5-1ubuntu2.2 /var/lib/dpkg/status
MEDIUM CVE-2026-18477tar1.35+dfsg-4ubuntu0.4 /var/lib/dpkg/status
MEDIUM CVE-2026-54370libacl12.3.2-2 /var/lib/dpkg/status
MEDIUM CVE-2026-35357rust-coreutils0.8.0-0ubuntu3 /var/lib/dpkg/status
MEDIUM CVE-2026-35364rust-coreutils0.8.0-0ubuntu3 /var/lib/dpkg/status
MEDIUM CVE-2026-35354rust-coreutils0.8.0-0ubuntu3 /var/lib/dpkg/status
MEDIUM CVE-2026-78410util-linux2.41.3-3ubuntu2.2 /var/lib/dpkg/status
MEDIUM CVE-2026-78410mount2.41.3-3ubuntu2.2 /var/lib/dpkg/status
MEDIUM CVE-2026-78410login1:4.16.0-2+really2.41.3-3ubuntu2.2 /var/lib/dpkg/status
MEDIUM CVE-2026-78410libuuid12.41.3-3ubuntu2.2 /var/lib/dpkg/status
MEDIUM CVE-2026-78410libsmartcols12.41.3-3ubuntu2.2 /var/lib/dpkg/status
MEDIUM CVE-2026-78410libmount12.41.3-3ubuntu2.2 /var/lib/dpkg/status
MEDIUM CVE-2026-78410libblkid12.41.3-3ubuntu2.2 /var/lib/dpkg/status
MEDIUM CVE-2026-78410bsdutils1:2.41.3-3ubuntu2.2 /var/lib/dpkg/status
MEDIUM CVE-2026-35345rust-coreutils0.8.0-0ubuntu3 /var/lib/dpkg/status
MEDIUM CVE-2026-18938libp11-kit00.26.2-2 /var/lib/dpkg/status
MEDIUM CVE-2026-19548libctf-nobfd02.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-19548libbinutils2.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-19548binutils-x86-64-linux-gnu2.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-19548binutils-common2.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-19548binutils2.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-86141libxml2-162.15.2+dfsg-0.1ubuntu0.1 /var/lib/dpkg/status
MEDIUM CVE-2026-90804libsframe32.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-90804libgprofng02.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-90804libctf02.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-90804libctf-nobfd02.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-90804libbinutils2.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-90804binutils-x86-64-linux-gnu2.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-90804binutils-common2.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-90804binutils2.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-56409libexpat12.7.4-1 /var/lib/dpkg/status
MEDIUM CVE-2026-35373rust-coreutils0.8.0-0ubuntu3 /var/lib/dpkg/status
MEDIUM CVE-2025-64031libarchive13t643.8.5-1ubuntu2.2 /var/lib/dpkg/status
MEDIUM CVE-2026-35371rust-coreutils0.8.0-0ubuntu3 /var/lib/dpkg/status
MEDIUM CVE-2026-78409util-linux2.41.3-3ubuntu2.2 /var/lib/dpkg/status
MEDIUM CVE-2026-78409mount2.41.3-3ubuntu2.2 /var/lib/dpkg/status
MEDIUM CVE-2026-78409login1:4.16.0-2+really2.41.3-3ubuntu2.2 /var/lib/dpkg/status
MEDIUM CVE-2026-78409libuuid12.41.3-3ubuntu2.2 /var/lib/dpkg/status
MEDIUM CVE-2026-78409libsmartcols12.41.3-3ubuntu2.2 /var/lib/dpkg/status
MEDIUM CVE-2026-78409libmount12.41.3-3ubuntu2.2 /var/lib/dpkg/status
MEDIUM CVE-2026-35370rust-coreutils0.8.0-0ubuntu3 /var/lib/dpkg/status
MEDIUM CVE-2026-89161libpcre2-8-010.46-1build1 /var/lib/dpkg/status
MEDIUM CVE-2026-90802libsframe32.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-90802libgprofng02.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-90802libctf02.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-90802libctf-nobfd02.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-90802libbinutils2.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-90802binutils-x86-64-linux-gnu2.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-90802binutils-common2.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-90802binutils2.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-78408util-linux2.41.3-3ubuntu2.2 /var/lib/dpkg/status
MEDIUM CVE-2026-78408mount2.41.3-3ubuntu2.2 /var/lib/dpkg/status
MEDIUM CVE-2026-78408login1:4.16.0-2+really2.41.3-3ubuntu2.2 /var/lib/dpkg/status
MEDIUM CVE-2026-78408libuuid12.41.3-3ubuntu2.2 /var/lib/dpkg/status
MEDIUM CVE-2026-78408libsmartcols12.41.3-3ubuntu2.2 /var/lib/dpkg/status
MEDIUM CVE-2026-78408libmount12.41.3-3ubuntu2.2 /var/lib/dpkg/status
MEDIUM CVE-2026-78408libblkid12.41.3-3ubuntu2.2 /var/lib/dpkg/status
MEDIUM CVE-2026-78408bsdutils1:2.41.3-3ubuntu2.2 /var/lib/dpkg/status
MEDIUM CVE-2026-86139libxml2-162.15.2+dfsg-0.1ubuntu0.1 /var/lib/dpkg/status
MEDIUM CVE-2026-35367rust-coreutils0.8.0-0ubuntu3 /var/lib/dpkg/status
MEDIUM CVE-2026-35344rust-coreutils0.8.0-0ubuntu3 /var/lib/dpkg/status
MEDIUM CVE-2026-19548libsframe32.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-19548libgprofng02.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-19548libctf02.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-3442libctf-nobfd02.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-63435libruby3.33.3.8-2ubuntu3.1 /var/lib/dpkg/status
MEDIUM GO-2026-6218stdlibgo1.26.5 1.25.13, 1.26.6, 1.27.0-rc.3Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations. — /usr/bin/pebble
MEDIUM CVE-2026-27820libruby3.33.3.8-2ubuntu3.1 /var/lib/dpkg/status
MEDIUM CVE-2026-27820ruby3.33.3.8-2ubuntu3.1 /var/lib/dpkg/status
MEDIUM CVE-2026-76641libexpat12.7.4-1 /var/lib/dpkg/status
MEDIUM CVE-2026-74860libxml2-162.15.2+dfsg-0.1ubuntu0.1 /var/lib/dpkg/status
MEDIUM CVE-2026-57433perl-modules-5.405.40.1-7ubuntu0.2 5.40.1-7ubuntu0.3/var/lib/dpkg/status
MEDIUM CVE-2026-57433perl-base5.40.1-7ubuntu0.2 5.40.1-7ubuntu0.3/var/lib/dpkg/status
MEDIUM CVE-2026-57433perl5.40.1-7ubuntu0.2 5.40.1-7ubuntu0.3/var/lib/dpkg/status
MEDIUM CVE-2026-57433libperl5.405.40.1-7ubuntu0.2 5.40.1-7ubuntu0.3/var/lib/dpkg/status
MEDIUM CVE-2026-27820ruby3.3-dev3.3.8-2ubuntu3.1 /var/lib/dpkg/status
MEDIUM CVE-2026-82209curl8.18.0-1ubuntu2.5 /var/lib/dpkg/status
MEDIUM CVE-2026-82209libcurl3t64-gnutls8.18.0-1ubuntu2.5 /var/lib/dpkg/status
MEDIUM CVE-2026-82209libcurl4t648.18.0-1ubuntu2.5 /var/lib/dpkg/status
MEDIUM GHSA-8p34-64r3-mwg8net-imap0.4.19 0.5.15Net::IMAP: Command Injection via non-synchronizing literal in "raw" argument — /usr/lib/ruby/gems/3.3.0/specifications/net-imap-0.4.19.gemspec
MEDIUM GHSA-j3g3-5qv5-52mjnet-imap0.4.19 0.4.20net-imap rubygem vulnerable to possible DoS by memory exhaustion — /usr/lib/ruby/gems/3.3.0/specifications/net-imap-0.4.19.gemspec
MEDIUM CVE-2024-52005git1:2.53.0-1ubuntu1 /var/lib/dpkg/status
MEDIUM CVE-2024-52005git-man1:2.53.0-1ubuntu1 /var/lib/dpkg/status
MEDIUM CVE-2026-47240libruby3.33.3.8-2ubuntu3.1 /var/lib/dpkg/status
MEDIUM CVE-2026-3442libbinutils2.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-3442binutils-x86-64-linux-gnu2.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-3442binutils-common2.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-3442binutils2.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-48961perl-modules-5.405.40.1-7ubuntu0.2 /var/lib/dpkg/status
MEDIUM CVE-2026-48961perl-base5.40.1-7ubuntu0.2 /var/lib/dpkg/status
MEDIUM CVE-2026-48961perl5.40.1-7ubuntu0.2 /var/lib/dpkg/status
MEDIUM CVE-2026-48961libperl5.405.40.1-7ubuntu0.2 /var/lib/dpkg/status
MEDIUM CVE-2026-60589openjdk-21-jre-headless21.0.12+8-1~26.04 /var/lib/dpkg/status
MEDIUM CVE-2026-70907openjdk-21-jre-headless21.0.12+8-1~26.04 /var/lib/dpkg/status
MEDIUM CVE-2026-80230libcurl3t64-gnutls8.18.0-1ubuntu2.5 /var/lib/dpkg/status
MEDIUM CVE-2026-80230libcurl4t648.18.0-1ubuntu2.5 /var/lib/dpkg/status
MEDIUM CVE-2026-48962perl-modules-5.405.40.1-7ubuntu0.2 /var/lib/dpkg/status
MEDIUM CVE-2026-48962perl-base5.40.1-7ubuntu0.2 /var/lib/dpkg/status
MEDIUM CVE-2026-48962perl5.40.1-7ubuntu0.2 /var/lib/dpkg/status
MEDIUM CVE-2026-48962libperl5.405.40.1-7ubuntu0.2 /var/lib/dpkg/status
MEDIUM CVE-2026-61308openjdk-21-jre-headless21.0.12+8-1~26.04 /var/lib/dpkg/status
MEDIUM CVE-2026-63435ruby3.3-dev3.3.8-2ubuntu3.1 /var/lib/dpkg/status
MEDIUM CVE-2026-63435ruby3.33.3.8-2ubuntu3.1 /var/lib/dpkg/status
MEDIUM CVE-2026-54696ruby3.33.3.8-2ubuntu3.1 /var/lib/dpkg/status
MEDIUM CVE-2026-54696libruby3.33.3.8-2ubuntu3.1 /var/lib/dpkg/status
MEDIUM CVE-2026-41080libexpat12.7.4-1 /var/lib/dpkg/status
MEDIUM CVE-2026-42497perl-modules-5.405.40.1-7ubuntu0.2 /var/lib/dpkg/status
MEDIUM CVE-2026-42497perl-base5.40.1-7ubuntu0.2 /var/lib/dpkg/status
MEDIUM CVE-2026-42497perl5.40.1-7ubuntu0.2 /var/lib/dpkg/status
MEDIUM CVE-2026-42497libperl5.405.40.1-7ubuntu0.2 /var/lib/dpkg/status
MEDIUM CVE-2026-13221perl-modules-5.405.40.1-7ubuntu0.2 5.40.1-7ubuntu0.3/var/lib/dpkg/status
MEDIUM CVE-2026-13221perl-base5.40.1-7ubuntu0.2 5.40.1-7ubuntu0.3/var/lib/dpkg/status
MEDIUM CVE-2026-13221perl5.40.1-7ubuntu0.2 5.40.1-7ubuntu0.3/var/lib/dpkg/status
MEDIUM CVE-2026-13221libperl5.405.40.1-7ubuntu0.2 5.40.1-7ubuntu0.3/var/lib/dpkg/status
MEDIUM CVE-2026-85091zlib1g-dev1:1.3.dfsg+really1.3.1-1ubuntu3.1 /var/lib/dpkg/status
MEDIUM CVE-2026-85091zlib1g1:1.3.dfsg+really1.3.1-1ubuntu3.1 /var/lib/dpkg/status
MEDIUM CVE-2026-9538perl-modules-5.405.40.1-7ubuntu0.2 /var/lib/dpkg/status
MEDIUM CVE-2026-9538perl-base5.40.1-7ubuntu0.2 /var/lib/dpkg/status
MEDIUM CVE-2026-9538perl5.40.1-7ubuntu0.2 /var/lib/dpkg/status
MEDIUM CVE-2026-9538libperl5.405.40.1-7ubuntu0.2 /var/lib/dpkg/status
MEDIUM CVE-2026-45186libexpat12.7.4-1 /var/lib/dpkg/status
MEDIUM CVE-2026-47057openjdk-21-jre-headless21.0.12+8-1~26.04 /var/lib/dpkg/status
MEDIUM CVE-2026-47240ruby3.33.3.8-2ubuntu3.1 /var/lib/dpkg/status
MEDIUM CVE-2026-47240ruby3.3-dev3.3.8-2ubuntu3.1 /var/lib/dpkg/status
MEDIUM CVE-2026-46727libruby3.33.3.8-2ubuntu3.1 /var/lib/dpkg/status
MEDIUM CVE-2026-46727ruby3.33.3.8-2ubuntu3.1 /var/lib/dpkg/status
MEDIUM CVE-2026-46727ruby3.3-dev3.3.8-2ubuntu3.1 /var/lib/dpkg/status
MEDIUM CVE-2025-10990libruby3.33.3.8-2ubuntu3.1 /var/lib/dpkg/status
MEDIUM CVE-2025-10990ruby3.33.3.8-2ubuntu3.1 /var/lib/dpkg/status
MEDIUM CVE-2025-10990ruby3.3-dev3.3.8-2ubuntu3.1 /var/lib/dpkg/status
MEDIUM CVE-2026-47058openjdk-21-jre-headless21.0.12+8-1~26.04 /var/lib/dpkg/status
MEDIUM CVE-2026-86145libpcre2-8-010.46-1build1 /var/lib/dpkg/status
MEDIUM CVE-2026-48959perl-modules-5.405.40.1-7ubuntu0.2 /var/lib/dpkg/status
MEDIUM CVE-2026-48959perl-base5.40.1-7ubuntu0.2 /var/lib/dpkg/status
MEDIUM CVE-2026-48959perl5.40.1-7ubuntu0.2 /var/lib/dpkg/status
MEDIUM CVE-2026-48959libperl5.405.40.1-7ubuntu0.2 /var/lib/dpkg/status
MEDIUM CVE-2026-12087perl-modules-5.405.40.1-7ubuntu0.2 5.40.1-7ubuntu0.3/var/lib/dpkg/status
MEDIUM CVE-2026-12087perl-base5.40.1-7ubuntu0.2 5.40.1-7ubuntu0.3/var/lib/dpkg/status
MEDIUM CVE-2026-12087perl5.40.1-7ubuntu0.2 5.40.1-7ubuntu0.3/var/lib/dpkg/status
MEDIUM CVE-2026-12087libperl5.405.40.1-7ubuntu0.2 5.40.1-7ubuntu0.3/var/lib/dpkg/status
MEDIUM CVE-2026-54696ruby3.3-dev3.3.8-2ubuntu3.1 /var/lib/dpkg/status
MEDIUM CVE-2026-42258ruby3.33.3.8-2ubuntu3.1 /var/lib/dpkg/status
MEDIUM CVE-2026-89160libpcre2-8-010.46-1build1 /var/lib/dpkg/status
MEDIUM CVE-2026-42258libruby3.33.3.8-2ubuntu3.1 /var/lib/dpkg/status
MEDIUM GHSA-75xq-5h9v-w6pxnet-imap0.4.19 0.4.24net-imap vulnerable to command Injection via unvalidated Symbol inputs — /usr/lib/ruby/gems/3.3.0/specifications/net-imap-0.4.19.gemspec
MEDIUM CVE-2026-5917libgit2-1.91.9.1+ds-1ubuntu1.1 /var/lib/dpkg/status
MEDIUM CVE-2026-18924libcurl4t648.18.0-1ubuntu2.5 /var/lib/dpkg/status
MEDIUM CVE-2026-18924libcurl3t64-gnutls8.18.0-1ubuntu2.5 /var/lib/dpkg/status
MEDIUM CVE-2026-18924curl8.18.0-1ubuntu2.5 /var/lib/dpkg/status
MEDIUM CVE-2026-80229libcurl4t648.18.0-1ubuntu2.5 /var/lib/dpkg/status
MEDIUM CVE-2026-80229libcurl3t64-gnutls8.18.0-1ubuntu2.5 /var/lib/dpkg/status
MEDIUM CVE-2026-32777libexpat12.7.4-1 /var/lib/dpkg/status
MEDIUM CVE-2026-39113libsqlite3-03.46.1-9ubuntu0.2 /var/lib/dpkg/status
MEDIUM CVE-2026-57432libperl5.405.40.1-7ubuntu0.2 5.40.1-7ubuntu0.3/var/lib/dpkg/status
MEDIUM CVE-2026-57432perl5.40.1-7ubuntu0.2 5.40.1-7ubuntu0.3/var/lib/dpkg/status
MEDIUM CVE-2026-57432perl-base5.40.1-7ubuntu0.2 5.40.1-7ubuntu0.3/var/lib/dpkg/status
MEDIUM CVE-2026-57432perl-modules-5.405.40.1-7ubuntu0.2 5.40.1-7ubuntu0.3/var/lib/dpkg/status
MEDIUM CVE-2026-56404libexpat12.7.4-1 /var/lib/dpkg/status
MEDIUM CVE-2026-56410libexpat12.7.4-1 /var/lib/dpkg/status
MEDIUM CVE-2026-56411libexpat12.7.4-1 /var/lib/dpkg/status
MEDIUM CVE-2025-66382libexpat12.7.4-1 /var/lib/dpkg/status
MEDIUM CVE-2026-75466libjpeg-turbo82.1.5-4ubuntu4 /var/lib/dpkg/status
MEDIUM CVE-2026-72522libexpat12.7.4-1 /var/lib/dpkg/status
MEDIUM CVE-2026-53583libgit2-1.91.9.1+ds-1ubuntu1.1 /var/lib/dpkg/status
MEDIUM CVE-2026-80229curl8.18.0-1ubuntu2.5 /var/lib/dpkg/status
MEDIUM CVE-2026-41316ruby3.3-dev3.3.8-2ubuntu3.1 /var/lib/dpkg/status
MEDIUM CVE-2026-41316ruby3.33.3.8-2ubuntu3.1 /var/lib/dpkg/status
MEDIUM CVE-2026-41316libruby3.33.3.8-2ubuntu3.1 /var/lib/dpkg/status
MEDIUM CVE-2026-19931libcurl4t648.18.0-1ubuntu2.5 /var/lib/dpkg/status
MEDIUM CVE-2026-19931libcurl3t64-gnutls8.18.0-1ubuntu2.5 /var/lib/dpkg/status
MEDIUM CVE-2026-19931curl8.18.0-1ubuntu2.5 /var/lib/dpkg/status
MEDIUM CVE-2026-42258ruby3.3-dev3.3.8-2ubuntu3.1 /var/lib/dpkg/status
MEDIUM GHSA-g857-hhfv-j68wzlib3.1.1 3.1.2Buffer Overflow in Zlib::GzipReader ungetc via large input leads to memory corruption — /usr/lib/ruby/gems/3.3.0/specifications/default/zlib-3.1.1.gemspec
MEDIUM CVE-2026-89092libc-gconv-modules-extra2.43-2ubuntu2.4 /var/lib/dpkg/status
MEDIUM CVE-2026-89092libc-dev-bin2.43-2ubuntu2.4 /var/lib/dpkg/status
MEDIUM CVE-2026-89092libc-bin2.43-2ubuntu2.4 /var/lib/dpkg/status
MEDIUM CVE-2026-7017perl-modules-5.405.40.1-7ubuntu0.2 /var/lib/dpkg/status
MEDIUM CVE-2026-7017perl-base5.40.1-7ubuntu0.2 /var/lib/dpkg/status
MEDIUM CVE-2026-7017perl5.40.1-7ubuntu0.2 /var/lib/dpkg/status
MEDIUM CVE-2026-7017libperl5.405.40.1-7ubuntu0.2 /var/lib/dpkg/status
MEDIUM CVE-2026-80255curl8.18.0-1ubuntu2.5 /var/lib/dpkg/status
MEDIUM CVE-2026-3442libsframe32.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-80255libcurl3t64-gnutls8.18.0-1ubuntu2.5 /var/lib/dpkg/status
MEDIUM CVE-2026-80255libcurl4t648.18.0-1ubuntu2.5 /var/lib/dpkg/status
MEDIUM CVE-2026-13608curl8.18.0-1ubuntu2.5 /var/lib/dpkg/status
MEDIUM CVE-2026-13608libcurl3t64-gnutls8.18.0-1ubuntu2.5 /var/lib/dpkg/status
MEDIUM CVE-2026-13608libcurl4t648.18.0-1ubuntu2.5 /var/lib/dpkg/status
MEDIUM CVE-2026-66046libexpat12.7.4-1 /var/lib/dpkg/status
MEDIUM CVE-2026-80230curl8.18.0-1ubuntu2.5 /var/lib/dpkg/status
MEDIUM CVE-2026-3442libgprofng02.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-3442libctf02.46-3ubuntu2 /var/lib/dpkg/status
MEDIUM CVE-2026-89158libpcre2-8-010.46-1build1 /var/lib/dpkg/status
MEDIUM CVE-2026-47241ruby3.3-dev3.3.8-2ubuntu3.1 /var/lib/dpkg/status
MEDIUM CVE-2026-47241ruby3.33.3.8-2ubuntu3.1 /var/lib/dpkg/status
MEDIUM CVE-2026-47241libruby3.33.3.8-2ubuntu3.1 /var/lib/dpkg/status
MEDIUM CVE-2026-89092libc62.43-2ubuntu2.4 /var/lib/dpkg/status
MEDIUM CVE-2026-89092libc6-dev2.43-2ubuntu2.4 /var/lib/dpkg/status
LOW CVE-2026-56289patch2.8-2build1 /var/lib/dpkg/status
LOW CVE-2026-56288patch2.8-2build1 /var/lib/dpkg/status
LOW CVE-2018-10126libjpeg-turbo82.1.5-4ubuntu4 /var/lib/dpkg/status
LOW CVE-2017-13716libsframe32.46-3ubuntu2 /var/lib/dpkg/status
LOW CVE-2017-13716libgprofng02.46-3ubuntu2 /var/lib/dpkg/status
LOW CVE-2017-13716libctf02.46-3ubuntu2 /var/lib/dpkg/status
LOW CVE-2026-40228libsystemd0259.5-0ubuntu3.4 /var/lib/dpkg/status
LOW CVE-2017-13716libctf-nobfd02.46-3ubuntu2 /var/lib/dpkg/status
LOW CVE-2026-40228libudev1259.5-0ubuntu3.4 /var/lib/dpkg/status
LOW CVE-2017-13716libbinutils2.46-3ubuntu2 /var/lib/dpkg/status
LOW GHSA-c2f4-jgmc-q2r5rexml3.3.9 3.4.2REXML has DoS condition when parsing malformed XML file — /usr/lib/ruby/gems/3.3.0/specifications/rexml-3.3.9.gemspec
LOW CVE-2017-13716binutils-x86-64-linux-gnu2.46-3ubuntu2 /var/lib/dpkg/status
LOW CVE-2017-13716binutils-common2.46-3ubuntu2 /var/lib/dpkg/status
LOW CVE-2017-13716binutils2.46-3ubuntu2 /var/lib/dpkg/status
LOW CVE-2025-66861binutils2.46-3ubuntu2 /var/lib/dpkg/status
LOW CVE-2025-66861binutils-common2.46-3ubuntu2 /var/lib/dpkg/status
LOW CVE-2025-66861binutils-x86-64-linux-gnu2.46-3ubuntu2 /var/lib/dpkg/status
LOW CVE-2025-66861libbinutils2.46-3ubuntu2 /var/lib/dpkg/status
LOW CVE-2025-66861libctf-nobfd02.46-3ubuntu2 /var/lib/dpkg/status
LOW CVE-2025-66861libsframe32.46-3ubuntu2 /var/lib/dpkg/status
LOW CVE-2025-66861libgprofng02.46-3ubuntu2 /var/lib/dpkg/status
LOW CVE-2025-66861libctf02.46-3ubuntu2 /var/lib/dpkg/status
LOW CVE-2025-66865libsframe32.46-3ubuntu2 /var/lib/dpkg/status
LOW CVE-2025-66863libsframe32.46-3ubuntu2 /var/lib/dpkg/status
LOW CVE-2025-66865libgprofng02.46-3ubuntu2 /var/lib/dpkg/status
LOW CVE-2025-66863libgprofng02.46-3ubuntu2 /var/lib/dpkg/status
LOW CVE-2025-66865libctf02.46-3ubuntu2 /var/lib/dpkg/status
LOW CVE-2025-66863libctf02.46-3ubuntu2 /var/lib/dpkg/status
LOW CVE-2025-66865libctf-nobfd02.46-3ubuntu2 /var/lib/dpkg/status
LOW CVE-2025-66863libctf-nobfd02.46-3ubuntu2 /var/lib/dpkg/status
LOW CVE-2025-66865libbinutils2.46-3ubuntu2 /var/lib/dpkg/status
LOW CVE-2025-66863libbinutils2.46-3ubuntu2 /var/lib/dpkg/status
LOW CVE-2025-66865binutils-x86-64-linux-gnu2.46-3ubuntu2 /var/lib/dpkg/status
LOW CVE-2025-66863binutils-x86-64-linux-gnu2.46-3ubuntu2 /var/lib/dpkg/status
LOW CVE-2025-66865binutils-common2.46-3ubuntu2 /var/lib/dpkg/status
LOW CVE-2025-66863binutils-common2.46-3ubuntu2 /var/lib/dpkg/status
LOW CVE-2025-66865binutils2.46-3ubuntu2 /var/lib/dpkg/status
LOW CVE-2025-66863binutils2.46-3ubuntu2 /var/lib/dpkg/status
LOW CVE-2025-58767libruby3.33.3.8-2ubuntu3.1 /var/lib/dpkg/status
LOW CVE-2025-58767ruby3.33.3.8-2ubuntu3.1 /var/lib/dpkg/status
LOW CVE-2025-66866libbinutils2.46-3ubuntu2 /var/lib/dpkg/status
LOW CVE-2025-66866libctf-nobfd02.46-3ubuntu2 /var/lib/dpkg/status
LOW CVE-2025-66866libctf02.46-3ubuntu2 /var/lib/dpkg/status
LOW CVE-2025-66866libgprofng02.46-3ubuntu2 /var/lib/dpkg/status
LOW CVE-2025-66866libsframe32.46-3ubuntu2 /var/lib/dpkg/status
LOW CVE-2025-66866binutils-x86-64-linux-gnu2.46-3ubuntu2 /var/lib/dpkg/status
LOW CVE-2025-66866binutils-common2.46-3ubuntu2 /var/lib/dpkg/status
LOW CVE-2025-66866binutils2.46-3ubuntu2 /var/lib/dpkg/status
LOW CVE-2025-66862libsframe32.46-3ubuntu2 /var/lib/dpkg/status
LOW CVE-2025-66862libgprofng02.46-3ubuntu2 /var/lib/dpkg/status
LOW CVE-2025-66862libctf02.46-3ubuntu2 /var/lib/dpkg/status
LOW CVE-2025-66862libctf-nobfd02.46-3ubuntu2 /var/lib/dpkg/status
LOW CVE-2025-5278coreutils9.5-1ubuntu2+0.0.0~ubuntu25 9.7-3ubuntu2.1/var/lib/dpkg/status
LOW CVE-2025-66862libbinutils2.46-3ubuntu2 /var/lib/dpkg/status
LOW CVE-2025-66862binutils-x86-64-linux-gnu2.46-3ubuntu2 /var/lib/dpkg/status
LOW CVE-2025-66862binutils-common2.46-3ubuntu2 /var/lib/dpkg/status
LOW CVE-2025-66862binutils2.46-3ubuntu2 /var/lib/dpkg/status
LOW GHSA-q2mw-fvj9-vvcwnet-imap0.4.19 0.4.24net-imap has quadratic complexity when reading response literals — /usr/lib/ruby/gems/3.3.0/specifications/net-imap-0.4.19.gemspec
LOW CVE-2025-58767ruby3.3-dev3.3.8-2ubuntu3.1 /var/lib/dpkg/status
LOW CVE-2025-1151libsframe32.46-3ubuntu2 /var/lib/dpkg/status
LOW CVE-2025-1151libgprofng02.46-3ubuntu2 /var/lib/dpkg/status
LOW CVE-2025-1151libctf02.46-3ubuntu2 /var/lib/dpkg/status
LOW CVE-2025-1151libctf-nobfd02.46-3ubuntu2 /var/lib/dpkg/status
LOW CVE-2025-1151libbinutils2.46-3ubuntu2 /var/lib/dpkg/status
LOW CVE-2025-1151binutils-x86-64-linux-gnu2.46-3ubuntu2 /var/lib/dpkg/status
LOW CVE-2025-1151binutils-common2.46-3ubuntu2 /var/lib/dpkg/status
LOW CVE-2025-1151binutils2.46-3ubuntu2 /var/lib/dpkg/status
LOW CVE-2025-1150libsframe32.46-3ubuntu2 /var/lib/dpkg/status
LOW CVE-2025-1150libgprofng02.46-3ubuntu2 /var/lib/dpkg/status
LOW CVE-2025-1150libctf02.46-3ubuntu2 /var/lib/dpkg/status
LOW CVE-2025-1150libctf-nobfd02.46-3ubuntu2 /var/lib/dpkg/status
LOW CVE-2025-1150libbinutils2.46-3ubuntu2 /var/lib/dpkg/status
LOW CVE-2025-1150binutils-x86-64-linux-gnu2.46-3ubuntu2 /var/lib/dpkg/status
LOW CVE-2025-1150binutils-common2.46-3ubuntu2 /var/lib/dpkg/status
LOW GHSA-c4fp-cxrr-mj66net-imap0.4.19 0.5.15Net::IMAP: Denial of Service via incomplete raw argument validation — /usr/lib/ruby/gems/3.3.0/specifications/net-imap-0.4.19.gemspec
LOW CVE-2025-1150binutils2.46-3ubuntu2 /var/lib/dpkg/status
LOW GHSA-j4pr-3wm6-xx2ruri0.13.2 0.13.3URI Credential Leakage Bypass over CVE-2025-27221 — /usr/lib/ruby/gems/3.3.0/specifications/default/uri-0.13.2.gemspec
LOW CVE-2024-56433passwd1:4.17.4-2ubuntu3 /var/lib/dpkg/status
LOW CVE-2024-56433login.defs1:4.17.4-2ubuntu3 /var/lib/dpkg/status
LOW CVE-2025-66864binutils2.46-3ubuntu2 /var/lib/dpkg/status
LOW CVE-2025-66864binutils-common2.46-3ubuntu2 /var/lib/dpkg/status
LOW CVE-2025-66864binutils-x86-64-linux-gnu2.46-3ubuntu2 /var/lib/dpkg/status
LOW CVE-2025-66864libbinutils2.46-3ubuntu2 /var/lib/dpkg/status
LOW CVE-2025-66864libctf-nobfd02.46-3ubuntu2 /var/lib/dpkg/status
LOW CVE-2025-66864libctf02.46-3ubuntu2 /var/lib/dpkg/status
LOW CVE-2025-66864libgprofng02.46-3ubuntu2 /var/lib/dpkg/status
LOW CVE-2025-66864libsframe32.46-3ubuntu2 /var/lib/dpkg/status
LOW CVE-2025-43857ruby3.3-dev3.3.8-2ubuntu3.1 /var/lib/dpkg/status
LOW CVE-2025-43857ruby3.33.3.8-2ubuntu3.1 /var/lib/dpkg/status
LOW CVE-2025-43857libruby3.33.3.8-2ubuntu3.1 /var/lib/dpkg/status
LOW CVE-2025-61594ruby3.3-dev3.3.8-2ubuntu3.1 /var/lib/dpkg/status
LOW CVE-2025-61594ruby3.33.3.8-2ubuntu3.1 /var/lib/dpkg/status
LOW CVE-2025-61594libruby3.33.3.8-2ubuntu3.1 /var/lib/dpkg/status
UNKNOWN CVE-2021-45261patch2.8-2build1 /var/lib/dpkg/status
UNKNOWN CVE-2026-11979libxml2-162.15.2+dfsg-0.1ubuntu0.1 /var/lib/dpkg/status
UNKNOWN CVE-2025-9301cmake4.2.3-2ubuntu2 /var/lib/dpkg/status
UNKNOWN CVE-2025-9301cmake-data4.2.3-2ubuntu2 /var/lib/dpkg/status
UNKNOWN CVE-2018-6952patch2.8-2build1 /var/lib/dpkg/status
UNKNOWN CVE-2019-20633patch2.8-2build1 /var/lib/dpkg/status

ghcr.io/openvoxproject/openvoxserver:latest-alpine (2026-09-09)

Trivy

HIGH 1
SeverityIDPackageInstalledFixedTitle / target
HIGH CVE-2022-41404org.ini4j:ini4j0.5.4 org.ini4j: unspecified DoS — Java

Grype

HIGH 2 LOW 1 NVD/CPE filtered 45
SeverityIDPackageInstalledFixedTitle / target
HIGH GHSA-jr6h-r7vg-f9mcini4j0.5.4 org.ini4j allows attackers to cause a Denial of Service (DoS) — /opt/puppetlabs/server/apps/puppetserver/puppet-server-release.jar
HIGH GHSA-q339-8rmv-2mhverb4.0.4 4.0.4.1ERB has an @_init deserialization guard bypass via def_module / def_method / def_class — /usr/lib/ruby/gems/3.4.0/specifications/default/erb-4.0.4.gemspec
LOW GHSA-x2f5-4prf-w687json2.9.1 2.19.9Ruby json: JSON generator heap buffer overflow when streaming to an IO — /usr/lib/ruby/gems/3.4.0/specifications/default/json-2.9.1.gemspec
Filtered NVD/CPE matches (45)

These broad CPE matches are unconfirmed for the distribution package and excluded from scanner totals.

SeverityIDPackageInstalledFixedTitle / target
HIGH CVE-2026-59849libssh21.11.1-r3 A flaw was found in libssh. Logic errors in automatic certificate-based public key authentication can cause libssh clients to loop indefinitely when configured certificates are missing or repeatedly rejected by a server, leading to denial of service. — /lib/apk/db/installed
HIGH CVE-2026-15370libssh21.11.1-r3 A flaw was found in libssh. During SFTP server directory listing, the longname field is constructed with unsafe concatenation into a fixed-size stack buffer. When a client causes the server to list attacker-controlled filenames, sufficiently long names can overflow that stack buffer and may lead to crashes or possible code execution on the server. — /lib/apk/db/installed
HIGH CVE-2026-58051libssh2-dev1.11.1-r3 libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsing populates them, so a parse failure reaching the cleanup path leaves libssh2_publickey_list_free operating on an uninitialized entry. A malicious SSH server offering the publickey subsystem can use a malformed response to make cleanup free an uninitialized, attacker-influenceable attrs pointer in a connecting libssh2 client. — /lib/apk/db/installed
HIGH CVE-2026-58051libssh21.11.1-r3 libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsing populates them, so a parse failure reaching the cleanup path leaves libssh2_publickey_list_free operating on an uninitialized entry. A malicious SSH server offering the publickey subsystem can use a malformed response to make cleanup free an uninitialized, attacker-influenceable attrs pointer in a connecting libssh2 client. — /lib/apk/db/installed
HIGH CVE-2026-59850libssh21.11.1-r3 A flaw was found in libssh. If data packets are processed after a channel is closed, channel data callbacks can be invoked after the associated data has already been freed, leading to crashes or possible use-after-free conditions. — /lib/apk/db/installed
HIGH CVE-2026-59851libssh21.11.1-r3 A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssapi-keyex path does not verify whether the authenticated Kerberos principal is authorized for the requested local user, allowing authenticated clients to log in as arbitrary users. — /lib/apk/db/installed
HIGH CVE-2026-66034libssh2-dev1.11.1-r3 libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitrary-length heap out-of-bounds read and a free of an uninitialized pointer via the publickey subsystem. In libssh2_publickey_list_fetch(), the version 1 response parser reads a server-controlled comment_len value and advances the parse pointer without verifying sufficient bytes remain in the buffer, causing the out-of-bounds read to leak heap pointers from adjacent allocations defeating ASLR, followed by heap allocator state corruption when the error cleanup path frees an uninitialized pointer from a non-zeroed realloc() region. — /lib/apk/db/installed
HIGH CVE-2026-66034libssh21.11.1-r3 libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitrary-length heap out-of-bounds read and a free of an uninitialized pointer via the publickey subsystem. In libssh2_publickey_list_fetch(), the version 1 response parser reads a server-controlled comment_len value and advances the parse pointer without verifying sufficient bytes remain in the buffer, causing the out-of-bounds read to leak heap pointers from adjacent allocations defeating ASLR, followed by heap allocator state corruption when the error cleanup path frees an uninitialized pointer from a non-zeroed realloc() region. — /lib/apk/db/installed
HIGH CVE-2026-58050libssh2-dev1.11.1-r3 libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attrs * sizeof(libssh2_publickey_attribute) without bounds checking, so on 32-bit platforms the multiplication overflows to an undersized buffer. A malicious SSH server can then drive the attribute-parsing loop to write past the allocation, causing a heap buffer overflow in a connecting libssh2 client. — /lib/apk/db/installed
HIGH CVE-2026-58050libssh21.11.1-r3 libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attrs * sizeof(libssh2_publickey_attribute) without bounds checking, so on 32-bit platforms the multiplication overflows to an undersized buffer. A malicious SSH server can then drive the attribute-parsing loop to write past the allocation, causing a heap buffer overflow in a connecting libssh2 client. — /lib/apk/db/installed
HIGH CVE-2026-66035libssh2-dev1.11.1-r3 libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that allows a malicious SSH server to corrupt heap metadata in any connecting client by sending a packet with a packet_length smaller than the cipher's block size during Encrypt-then-MAC cipher negotiation. In the fullpacket() function in src/transport.c, the ETM path allocates a buffer of packet_length bytes but copies blocksize minus one bytes via memcpy, causing an overflow that on 32-bit glibc writes attacker-controlled bytes into an adjacent chunk's SIZE field, enabling tcache bin confusion, overlapping live objects, and function pointer overwrite during the session handshake before authentication. — /lib/apk/db/installed
HIGH CVE-2026-66035libssh21.11.1-r3 libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that allows a malicious SSH server to corrupt heap metadata in any connecting client by sending a packet with a packet_length smaller than the cipher's block size during Encrypt-then-MAC cipher negotiation. In the fullpacket() function in src/transport.c, the ETM path allocates a buffer of packet_length bytes but copies blocksize minus one bytes via memcpy, causing an overflow that on 32-bit glibc writes attacker-controlled bytes into an adjacent chunk's SIZE field, enabling tcache bin confusion, overlapping live objects, and function pointer overwrite during the session handshake before authentication. — /lib/apk/db/installed
HIGH CVE-2026-66032libssh2-dev1.11.1-r3 libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt the heap of any authenticated client opening an SFTP session. When a server responds to SSH_FXP_OPEN with SSH_FXP_STATUS containing FX_OK, the response data buffer is freed, and if a subsequent sftp_packet_require() call returns a specific error such as LIBSSH2_ERROR_CHANNEL_PACKET_EXCEEDED, the same pointer is freed a second time, enabling tcache dup conditions on glibc systems that allow overlapping allocations and function pointer overwrites. — /lib/apk/db/installed
HIGH CVE-2026-66032libssh21.11.1-r3 libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt the heap of any authenticated client opening an SFTP session. When a server responds to SSH_FXP_OPEN with SSH_FXP_STATUS containing FX_OK, the response data buffer is freed, and if a subsequent sftp_packet_require() call returns a specific error such as LIBSSH2_ERROR_CHANNEL_PACKET_EXCEEDED, the same pointer is freed a second time, enabling tcache dup conditions on glibc systems that allow overlapping allocations and function pointer overwrites. — /lib/apk/db/installed
HIGH CVE-2026-66033libssh21.11.1-r3 libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in src/openssl.c that allows a malicious SSH server to crash any connecting client by negotiating AES-GCM ciphers during handshake. Attackers can exploit the underflow in the expression computing blocksize minus aadlen minus authentication tag length to trigger an out-of-bounds read and a memcpy call with a near-SIZE_MAX length argument, causing immediate process crash before any authentication occurs. — /lib/apk/db/installed
HIGH CVE-2026-66033libssh2-dev1.11.1-r3 libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in src/openssl.c that allows a malicious SSH server to crash any connecting client by negotiating AES-GCM ciphers during handshake. Attackers can exploit the underflow in the expression computing blocksize minus aadlen minus authentication tag length to trigger an out-of-bounds read and a memcpy call with a near-SIZE_MAX length argument, causing immediate process crash before any authentication occurs. — /lib/apk/db/installed
MEDIUM CVE-2026-18477tar1.35-r5 A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. This could lead to unauthorized file modification or, in some cases, privilege escalation. Exploitation does not require the attacker to modify or craft the archive, and standard backup and restore workflows—including extracting into a newly created directory without using the -P option do not mitigate the issue. — /lib/apk/db/installed
MEDIUM CVE-2026-58055nghttp2-libs1.69.0-r0 nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning. — /lib/apk/db/installed
MEDIUM CVE-2026-5745libarchive3.8.7-r0 A flaw was found in libarchive. A NULL pointer dereference vulnerability exists in the ACL parsing logic, specifically within the archive_acl_from_text_nl() function. When processing a malformed ACL string (such as a bare "d" or "default" tag without subsequent fields), the function fails to perform adequate validation before advancing the pointer. An attacker can exploit this by providing a maliciously crafted archive, causing an application utilizing the libarchive API (such as bsdtar) to crash, resulting in a Denial of Service (DoS). — /lib/apk/db/installed
MEDIUM CVE-2026-56391coreutils9.11-r0 GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. This incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input. When running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure. This issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371. — /lib/apk/db/installed
MEDIUM CVE-2026-56391coreutils-env9.11-r0 GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. This incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input. When running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure. This issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371. — /lib/apk/db/installed
MEDIUM CVE-2026-56391coreutils-fmt9.11-r0 GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. This incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input. When running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure. This issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371. — /lib/apk/db/installed
MEDIUM CVE-2026-56391coreutils-sha512sum9.11-r0 GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. This incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input. When running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure. This issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371. — /lib/apk/db/installed
MEDIUM CVE-2026-18508tar1.35-r5 A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction. — /lib/apk/db/installed
MEDIUM CVE-2026-56392coreutils9.11-r0 GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer. When processing crafted input, subsequent writes exceed the allocated memory, leading to an out‑of‑bounds heap write. When running GNU coreutils unexpand with attacker-provided large tab stop (-t) arguments, this behavior leads to a crash and potentially achieve a heap write primitive depending on memory layout. This issue has been fixed in the commit b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d — /lib/apk/db/installed
MEDIUM CVE-2026-59845libssh21.11.1-r3 A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may then be sent across the caller's accessible process tree, leading to local denial of service. — /lib/apk/db/installed
MEDIUM CVE-2026-56392coreutils-sha512sum9.11-r0 GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer. When processing crafted input, subsequent writes exceed the allocated memory, leading to an out‑of‑bounds heap write. When running GNU coreutils unexpand with attacker-provided large tab stop (-t) arguments, this behavior leads to a crash and potentially achieve a heap write primitive depending on memory layout. This issue has been fixed in the commit b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d — /lib/apk/db/installed
MEDIUM CVE-2026-56392coreutils-env9.11-r0 GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer. When processing crafted input, subsequent writes exceed the allocated memory, leading to an out‑of‑bounds heap write. When running GNU coreutils unexpand with attacker-provided large tab stop (-t) arguments, this behavior leads to a crash and potentially achieve a heap write primitive depending on memory layout. This issue has been fixed in the commit b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d — /lib/apk/db/installed
MEDIUM CVE-2026-56392coreutils-fmt9.11-r0 GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer. When processing crafted input, subsequent writes exceed the allocated memory, leading to an out‑of‑bounds heap write. When running GNU coreutils unexpand with attacker-provided large tab stop (-t) arguments, this behavior leads to a crash and potentially achieve a heap write primitive depending on memory layout. This issue has been fixed in the commit b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d — /lib/apk/db/installed
MEDIUM CVE-2025-60876ssl_client1.37.0-r31 BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed
MEDIUM CVE-2025-60876busybox-binsh1.37.0-r31 BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed
MEDIUM CVE-2025-60876busybox1.37.0-r31 BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed
MEDIUM CVE-2026-59848libssh21.11.1-r3 A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh clients keep queued indefinitely, causing unbounded memory growth and client-side denial of service. — /lib/apk/db/installed
MEDIUM CVE-2026-59842libssh21.11.1-r3 A flaw was found in libssh. During server-side GSSAPI key exchange, a client-supplied Curve25519 public key shorter than the expected length is copied without proper length validation, leading to an out-of-bounds heap read. This could allow a remote unauthenticated attacker to disclose small amounts of server memory. — /lib/apk/db/installed
MEDIUM CVE-2016-2781coreutils-sha512sum9.11-r0 chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer. — /lib/apk/db/installed
MEDIUM CVE-2016-2781coreutils-fmt9.11-r0 chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer. — /lib/apk/db/installed
MEDIUM CVE-2016-2781coreutils-env9.11-r0 chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer. — /lib/apk/db/installed
MEDIUM CVE-2016-2781coreutils9.11-r0 chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer. — /lib/apk/db/installed
MEDIUM CVE-2026-5704tar1.35-r5 A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection. — /lib/apk/db/installed
MEDIUM CVE-2026-59844libssh21.11.1-r3 A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large length, causing a libssh SFTP server to allocate excessive memory and potentially exhaust it through repeated requests. — /lib/apk/db/installed
MEDIUM CVE-2026-59843libssh21.11.1-r3 A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel writes to loop indefinitely and consume CPU, leading to denial of service. — /lib/apk/db/installed
MEDIUM CVE-2025-15661libssh2-dev1.11.1-r3 libssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bounds heap read vulnerability in the sftp_symlink() function in src/sftp.c that allows a malicious SSH server or man-in-the-middle attacker to disclose heap memory contents or cause a crash by sending a crafted SSH_FXP_NAME response. Attackers can supply a link_len value larger than the actual packet data in SSH_FXP_NAME responses for SFTP READLINK and REALPATH operations, triggering a heap buffer over-read of up to target_len minus one bytes due to the missing validation of available packet buffer size before the memcpy operation. — /lib/apk/db/installed
MEDIUM CVE-2025-15661libssh21.11.1-r3 libssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bounds heap read vulnerability in the sftp_symlink() function in src/sftp.c that allows a malicious SSH server or man-in-the-middle attacker to disclose heap memory contents or cause a crash by sending a crafted SSH_FXP_NAME response. Attackers can supply a link_len value larger than the actual packet data in SSH_FXP_NAME responses for SFTP READLINK and REALPATH operations, triggering a heap buffer over-read of up to target_len minus one bytes due to the missing validation of available packet buffer size before the memcpy operation. — /lib/apk/db/installed
MEDIUM CVE-2013-0256ruby-rdoc3.4.9-r0 darkfish.js in RDoc 2.3.0 through 3.12 and 4.x before 4.0.0.preview2.1, as used in Ruby, does not properly generate documents, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted URL. — /lib/apk/db/installed
LOW CVE-2026-59846libssh21.11.1-r3 A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing unintended shell behavior. — /lib/apk/db/installed

ghcr.io/voxpupuli/commitlint

GitHub Container Registry

Downloads

1,016 downloads

ghcr.io/voxpupuli/commitlint:latest (2026-08-27)

Trivy

HIGH 17 MEDIUM 13 LOW 1 UNKNOWN 3
SeverityIDPackageInstalledFixedTitle / target
HIGH CVE-2026-73566tar7.5.19 7.5.21tar: node-tar: Denial of Service via crafted long-path tar archive — Node.js
HIGH CVE-2026-69192ip-address10.2.0 10.3.1ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass — Node.js
HIGH CVE-2026-69152brace-expansion5.0.7 1.1.18, 2.1.4, 3.0.6, 5.0.9brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation — Node.js
HIGH CVE-2026-14257brace-expansion5.0.7 5.0.8, 3.0.3, 2.1.3, 1.1.17brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function — Node.js
HIGH CVE-2026-56852golang.org/x/textv0.38.0 0.39.0golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc
HIGH CVE-2026-76957libexpat2.8.3-r0 2.8.4-r0libexpat: libexpat: Memory corruption vulnerability allows arbitrary code execution or denial of service — ghcr.io/voxpupuli/commitlint:latest (alpine 3.24.1)
HIGH CVE-2026-76956libexpat2.8.3-r0 2.8.4-r0libexpat: libexpat: Denial of Service via hash flooding attack with crafted XML — ghcr.io/voxpupuli/commitlint:latest (alpine 3.24.1)
HIGH CVE-2026-66046libexpat2.8.3-r0 2.8.4-r0expat: Expat: Denial of Service via quadratic complexity in attribute processing — ghcr.io/voxpupuli/commitlint:latest (alpine 3.24.1)
HIGH CVE-2026-33818stdlibv1.26.4 1.25.13, 1.26.6, 1.27.0-rc.3encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc
HIGH CVE-2026-39821stdlibv1.26.4 1.25.13, 1.26.6, 1.27.0-rc.3golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc
HIGH CVE-2026-39822stdlibv1.26.4 1.25.12, 1.26.5, 1.27.0-rc.2golang: Go os.Root: Symlink following vulnerability allows directory traversal — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc
HIGH CVE-2026-46600stdlibv1.26.4 1.26.6, 1.27.0-rc.3golang.org/x/net/dns/dnsmessage: golang.org/x/net/dns/dnsmessage: Denial of Service via invalid DNS record parsing — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc
HIGH CVE-2026-56853stdlibv1.26.4 1.25.13, 1.26.6, 1.27.0-rc.3net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc
HIGH CVE-2026-56858stdlibv1.26.4 1.25.13, 1.26.6, 1.27.0-rc.3html/template: golang: Go html/template: Cross-Site Scripting via pathological input — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc
HIGH CVE-2026-56859stdlibv1.26.4 1.25.13, 1.26.6, 1.27.0-rc.3encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc
HIGH CVE-2026-56860stdlibv1.26.4 1.25.13, 1.26.6, 1.27.0-rc.3net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc
HIGH CVE-2026-56862stdlibv1.26.4 1.25.13, 1.26.6, 1.27.0-rc.3crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc
MEDIUM CVE-2026-16728undici6.27.0 6.28.0, 7.29.0, 8.9.0undici: undici: Response desynchronization via retry interceptor with mismatched Content-Length — Node.js
MEDIUM CVE-2026-15157undici6.27.0 6.28.0, 7.29.0, 8.9.0undici: undici: HTTP header injection via unvalidated blob-like body type property — Node.js
MEDIUM CVE-2026-16729undici6.27.0 6.28.0, 7.29.0, 8.9.0undici: Undici: Cookie attribute injection allows bypassing security protections — Node.js
MEDIUM CVE-2026-42505stdlibv1.26.4 1.25.12, 1.26.5, 1.27.0-rc.2crypto/tls: golang: Go crypto/tls: Information disclosure in Encrypted Client Hello — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc
MEDIUM CVE-2026-69198ip-address10.2.0 10.2.2ip-address: ip-address: Server-Side Request Forgery (SSRF) and trust-boundary bypass — Node.js
MEDIUM CVE-2026-54272ip-address10.2.0 10.2.1ip-address: ip-address: Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification — Node.js
MEDIUM CVE-2026-76641libexpat2.8.3-r0 2.8.4-r0CVE-2026-76641 affecting package expat for versions less than 2.8.3-2 — ghcr.io/voxpupuli/commitlint:latest (alpine 3.24.1)
MEDIUM CVE-2026-82209libcurl8.21.0-r0 8.22.0-r0When libpsl support is enabled, libcurl fails to enforce the Public Su ... — ghcr.io/voxpupuli/commitlint:latest (alpine 3.24.1)
MEDIUM CVE-2026-80255libcurl8.21.0-r0 8.22.0-r0A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instea ... — ghcr.io/voxpupuli/commitlint:latest (alpine 3.24.1)
MEDIUM CVE-2026-80230libcurl8.21.0-r0 8.22.0-r0When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that di ... — ghcr.io/voxpupuli/commitlint:latest (alpine 3.24.1)
MEDIUM CVE-2026-80229libcurl8.21.0-r0 8.22.0-r0When performing transfers via libcurl\u2019s multi interface, pooled T ... — ghcr.io/voxpupuli/commitlint:latest (alpine 3.24.1)
MEDIUM CVE-2026-19931libcurl8.21.0-r0 8.22.0-r0curl: libcurl: Information disclosure via incorrect connection reuse with Negotiate authentication — ghcr.io/voxpupuli/commitlint:latest (alpine 3.24.1)
MEDIUM CVE-2026-13608libcurl8.21.0-r0 8.22.0-r0A flaw in the libcurl SASL negotiation for LDAP authentication allows ... — ghcr.io/voxpupuli/commitlint:latest (alpine 3.24.1)
LOW CVE-2026-18924libcurl8.21.0-r0 8.22.0-r0curl: libcurl: Use-after-free in HTTP/2 Server Push with shared connections — ghcr.io/voxpupuli/commitlint:latest (alpine 3.24.1)
UNKNOWN CVE-2026-82208libcurl8.21.0-r0 8.22.0-r0With the wolfSSL backend, when CA caching is enabled and an `CURLOPT_S ... — ghcr.io/voxpupuli/commitlint:latest (alpine 3.24.1)
UNKNOWN CVE-2026-80256libcurl8.21.0-r0 8.22.0-r0ghcr.io/voxpupuli/commitlint:latest (alpine 3.24.1)
UNKNOWN CVE-2026-80231libcurl8.21.0-r0 8.22.0-r0native CA store conn reuse — ghcr.io/voxpupuli/commitlint:latest (alpine 3.24.1)

Grype

CRITICAL 2 HIGH 24 MEDIUM 8 UNKNOWN 1 NVD/CPE filtered 10
SeverityIDPackageInstalledFixedTitle / target
CRITICAL CVE-2026-19931libcurl8.21.0-r0 8.22.0-r0/lib/apk/db/installed
CRITICAL CVE-2026-18924libcurl8.21.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-76957libexpat2.8.3-r0 2.8.4-r0/lib/apk/db/installed
HIGH CVE-2026-76956libexpat2.8.3-r0 2.8.4-r0/lib/apk/db/installed
HIGH GHSA-mwp4-54f8-5fhrip-address10.2.0 10.3.1ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass — /usr/local/lib/node_modules/npm/node_modules/ip-address/package.json
HIGH GHSA-r292-9mhp-454mtar7.5.19 7.5.21node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection — /usr/local/lib/node_modules/npm/node_modules/tar/package.json
HIGH CVE-2026-76641libexpat2.8.3-r0 2.8.4-r0/lib/apk/db/installed
HIGH CVE-2026-82208libcurl8.21.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH GO-2026-5970golang.org/x/textv0.38.0 0.39.0A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes. — /npm/node_modules/@typescript/typescript-linux-x64/lib/tsc
HIGH GO-2026-5970golang.org/x/textv0.37.0 0.39.0A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes. — /usr/bin/git-lfs
HIGH GO-2026-5942stdlibgo1.26.3 1.26.6, 1.27.0-rc.3Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer. — /usr/bin/git-lfs
HIGH GO-2026-5942golang.org/x/netv0.54.0 0.56.0Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer. — /usr/bin/git-lfs
HIGH CVE-2026-82209libcurl8.21.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-80230libcurl8.21.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-80231libcurl8.21.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-80229libcurl8.21.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH GO-2026-5026golang.org/x/netv0.54.0 0.55.0The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com". — /usr/bin/git-lfs
HIGH GO-2026-5026stdlibgo1.26.3 1.25.13, 1.26.6, 1.27.0-rc.3The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com". — /usr/bin/git-lfs
HIGH CVE-2026-80255libcurl8.21.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH GHSA-mh99-v99m-4gvgbrace-expansion5.0.7 5.0.8brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash — /usr/local/lib/node_modules/npm/node_modules/brace-expansion/package.json
HIGH CVE-2026-13608libcurl8.21.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-66046libexpat2.8.3-r0 2.8.4-r0/lib/apk/db/installed
HIGH GHSA-rgw5-rvv9-x895brace-expansion5.0.7 5.0.9brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation — /usr/local/lib/node_modules/npm/node_modules/brace-expansion/package.json
HIGH GO-2026-5037stdlibgo1.26.3 1.25.11, 1.26.4(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates. — /usr/bin/git-lfs
HIGH GO-2026-6090stdlibgo1.26.3 1.25.13, 1.26.6, 1.27.0-rc.3Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely. — /usr/bin/git-lfs
HIGH GO-2026-5972stdlibgo1.26.3 1.25.13, 1.26.6, 1.27.0-rc.3Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures. — /usr/bin/git-lfs
MEDIUM GO-2026-6218stdlibgo1.26.3 1.25.13, 1.26.6, 1.27.0-rc.3Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations. — /usr/bin/git-lfs
MEDIUM GHSA-4xrf-jv44-h6hhip-address10.2.0 10.2.2ip-address: a CIDR suffix on the parsed address suppresses special-use classification and can bypass SSRF and trust-boundary checks — /usr/local/lib/node_modules/npm/node_modules/ip-address/package.json
MEDIUM GHSA-22jq-vg5j-6vggip-address10.2.0 10.2.1ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSRF and trust-boundary checks — /usr/local/lib/node_modules/npm/node_modules/ip-address/package.json
MEDIUM GO-2026-5856stdlibgo1.26.3 1.25.12, 1.26.5, 1.27.0-rc.2Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello. — /usr/bin/git-lfs
MEDIUM GO-2026-5039stdlibgo1.26.3 1.25.11, 1.26.4When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or logged. — /usr/bin/git-lfs
MEDIUM GHSA-v3r7-h72x-cjcmundici6.27.0 6.28.0undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields — /usr/local/lib/node_modules/npm/node_modules/undici/package.json
MEDIUM GHSA-m8rv-5g2x-5cg5undici6.27.0 6.28.0undici vulnerable to CRLF Injection via blob-like body 'type' property — /usr/local/lib/node_modules/npm/node_modules/undici/package.json
MEDIUM GHSA-8xcm-r25x-g524undici6.27.0 6.28.0undici vulnerable to downstream response desynchronization via retry interceptor — /usr/local/lib/node_modules/npm/node_modules/undici/package.json
UNKNOWN CVE-2026-80256libcurl8.21.0-r0 8.22.0-r0/lib/apk/db/installed
Filtered NVD/CPE matches (10)

These broad CPE matches are unconfirmed for the distribution package and excluded from scanner totals.

SeverityIDPackageInstalledFixedTitle / target
HIGH CVE-2026-89161pcre210.47-r1 In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context. An incorrect free operation can occur. — /lib/apk/db/installed
HIGH CVE-2026-89157pcre210.47-r1 PCRE2 before 10.48, on 32-bit platforms, has a pcre2_pattern_convert out-of-bounds write when an attacker can provide a large pattern. — /lib/apk/db/installed
MEDIUM CVE-2025-60876busybox1.37.0-r31 BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed
MEDIUM CVE-2025-60876busybox-binsh1.37.0-r31 BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed
MEDIUM CVE-2025-60876ssl_client1.37.0-r31 BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed
MEDIUM CVE-2026-58055nghttp2-libs1.69.0-r0 nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning. — /lib/apk/db/installed
MEDIUM CVE-2026-89158pcre210.47-r1 PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 integer overflow and resultant out-of-bounds write. — /lib/apk/db/installed
MEDIUM CVE-2026-89160pcre210.47-r1 PCRE2 before 10.48 has a pcre2_match out-of-bounds read during the PCRE2_MATCH_INVALID_UTF matching of an invalid UTF subject. — /lib/apk/db/installed
MEDIUM CVE-2026-89156pcre210.47-r1 PCRE2 before 10.48 has a pcre2_match out-of-bounds read after a JIT fallback when an attacker can provide invalid UTF data. — /lib/apk/db/installed
LOW CVE-2026-89162pcre210.47-r1 In PCRE2 before 10.48, pcre2_serialize_encode might disclose two bytes to an adversary, typically in a situation where the access available to the adversary is already unsafe. — /lib/apk/db/installed

ghcr.io/voxpupuli/onceover

GitHub Container Registry

Downloads

4,614 downloads

ghcr.io/voxpupuli/onceover:latest (2026-09-02)

Trivy

CRITICAL 1 HIGH 21 MEDIUM 35 LOW 3 UNKNOWN 6
SeverityIDPackageInstalledFixedTitle / target
CRITICAL CVE-2026-42257net-imap0.3.9 ~> 0.4.24, ~> 0.5.14, >= 0.6.4net-imap: Net::IMAP: Arbitrary IMAP command injection via CRLF sequences in unvalidated input — Ruby
HIGH CVE-2026-80212resolv0.2.3 ~> 0.3.2, >= 0.7.2resolv: resolv gem: Denial of Service via uncontrolled memory growth from crafted DNS responses — Ruby
HIGH CVE-2026-42258net-imap0.3.9 ~> 0.4.24, ~> 0.5.14, >= 0.6.4ruby/net-imap: ruby: Net::IMAP: IMAP Command Injection via Symbol Arguments — Ruby
HIGH CVE-2026-42246net-imap0.3.9 ~> 0.3.10, ~> 0.4.24, ~> 0.5.14, >= 0.6.4net-imap: ruby: Net::IMAP: Information disclosure via man-in-the-middle attack bypassing TLS — Ruby
HIGH CVE-2026-42245net-imap0.3.9 ~> 0.4.24, ~> 0.5.14, >= 0.6.4ruby: net-imap: Net::IMAP: Denial of Service via crafted IMAP responses — Ruby
HIGH CVE-2026-41316erb4.0.2 ~> 4.0.3.1, ~> 4.0.4.1, ~> 6.0.1.1, >= 6.0.4erb: ERB: Arbitrary code execution via deserialization bypass — Ruby
HIGH CVE-2026-9547libcurl8.20.0-r0 8.22.0-r0curl: curl: Man-in-the-middle attack via SSH host key bypass — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4)
HIGH CVE-2026-8927libcurl8.20.0-r0 8.22.0-r0curl: Information disclosure due to uncleared proxy authentication state — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4)
HIGH CVE-2026-8925libcurl8.20.0-r0 8.22.0-r0curl: curl: Double-free vulnerability in SASL authentication — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4)
HIGH CVE-2026-8458libcurl8.20.0-r0 8.22.0-r0curl: libcurl: Unauthorized connection reuse due to a logical error — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4)
HIGH CVE-2026-8286libcurl8.20.0-r0 8.22.0-r0curl: curl: Insecure connection establishment due to TLS configuration mismatch — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4)
HIGH CVE-2026-12064libcurl8.20.0-r0 8.22.0-r0curl: curl: SSH host verification bypass when using schemeless URLs with SFTP/SCP — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4)
HIGH CVE-2026-11586libcurl8.20.0-r0 8.22.0-r0curl: curl: Denial of Service via WebSocket PING flood — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4)
HIGH CVE-2026-11352libcurl8.20.0-r0 8.22.0-r0curl: libcurl: curl/libcurl: Remote denial of service via QUIC UDP receive function vulnerability — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4)
HIGH CVE-2026-11352curl8.20.0-r0 8.22.0-r0curl: libcurl: curl/libcurl: Remote denial of service via QUIC UDP receive function vulnerability — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4)
HIGH CVE-2026-11586curl8.20.0-r0 8.22.0-r0curl: curl: Denial of Service via WebSocket PING flood — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4)
HIGH CVE-2026-12064curl8.20.0-r0 8.22.0-r0curl: curl: SSH host verification bypass when using schemeless URLs with SFTP/SCP — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4)
HIGH CVE-2026-8286curl8.20.0-r0 8.22.0-r0curl: curl: Insecure connection establishment due to TLS configuration mismatch — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4)
HIGH CVE-2026-8458curl8.20.0-r0 8.22.0-r0curl: libcurl: Unauthorized connection reuse due to a logical error — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4)
HIGH CVE-2026-8925curl8.20.0-r0 8.22.0-r0curl: curl: Double-free vulnerability in SASL authentication — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4)
HIGH CVE-2026-8927curl8.20.0-r0 8.22.0-r0curl: Information disclosure due to uncleared proxy authentication state — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4)
HIGH CVE-2026-9547curl8.20.0-r0 8.22.0-r0curl: curl: Man-in-the-middle attack via SSH host key bypass — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4)
MEDIUM CVE-2026-80230curl8.20.0-r0 8.22.0-r0When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that di ... — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4)
MEDIUM CVE-2026-13608libcurl8.20.0-r0 8.22.0-r0A flaw in the libcurl SASL negotiation for LDAP authentication allows ... — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4)
MEDIUM CVE-2026-19931libcurl8.20.0-r0 8.22.0-r0curl: libcurl: Information disclosure via incorrect connection reuse with Negotiate authentication — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4)
MEDIUM CVE-2026-80229libcurl8.20.0-r0 8.22.0-r0When performing transfers via libcurl\u2019s multi interface, pooled T ... — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4)
MEDIUM CVE-2026-80230libcurl8.20.0-r0 8.22.0-r0When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that di ... — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4)
MEDIUM CVE-2026-80255libcurl8.20.0-r0 8.22.0-r0A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instea ... — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4)
MEDIUM CVE-2026-82209libcurl8.20.0-r0 8.22.0-r0When libpsl support is enabled, libcurl fails to enforce the Public Su ... — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4)
MEDIUM CVE-2026-8924libcurl8.20.0-r0 8.22.0-r0curl: curl: Cookie injection via malicious HTTP server using super cookies — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4)
MEDIUM CVE-2026-8926libcurl8.20.0-r0 8.22.0-r0curl: curl: Information disclosure via incorrect .netrc password lookup — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4)
MEDIUM CVE-2026-8932libcurl8.20.0-r0 8.22.0-r0libcurl: libcurl: Security feature bypass due to improper mTLS connection reuse — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4)
MEDIUM CVE-2026-9079libcurl8.20.0-r0 8.22.0-r0libcurl: libcurl: Information disclosure due to failure to clear proxy authentication credentials — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4)
MEDIUM CVE-2026-9080libcurl8.20.0-r0 8.22.0-r0libcurl: libcurl: Use-after-free via curl_easy_pause() in CURLMOPT_SOCKETFUNCTION callback — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4)
MEDIUM CVE-2026-9545libcurl8.20.0-r0 8.22.0-r0libcurl: libcurl: Information disclosure via cached SSL session and early data — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4)
MEDIUM CVE-2026-9546libcurl8.20.0-r0 8.22.0-r0libcurl: libcurl: Information disclosure due to persistent Referer header — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4)
MEDIUM CVE-2026-47240net-imap0.3.9 ~> 0.5.15, >= 0.6.4.1net-imap: Net::IMAP: Command injection via non-synchronizing literals — Ruby
MEDIUM CVE-2026-47242net-imap0.3.9 ~> 0.5.15, >= 0.6.4.1net-imap: Net::IMAP: Arbitrary IMAP command injection due to improper input validation — Ruby
MEDIUM CVE-2026-80213resolv0.2.3 ~> 0.3.2, >= 0.7.2resolv: Resolv gem: DNS allowlist and egress bypass, and cache poisoning via crafted hostnames — Ruby
MEDIUM CVE-2026-80255curl8.20.0-r0 8.22.0-r0A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instea ... — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4)
MEDIUM CVE-2026-82209curl8.20.0-r0 8.22.0-r0When libpsl support is enabled, libcurl fails to enforce the Public Su ... — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4)
MEDIUM CVE-2026-8924curl8.20.0-r0 8.22.0-r0curl: curl: Cookie injection via malicious HTTP server using super cookies — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4)
MEDIUM CVE-2026-8926curl8.20.0-r0 8.22.0-r0curl: curl: Information disclosure via incorrect .netrc password lookup — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4)
MEDIUM CVE-2026-8932curl8.20.0-r0 8.22.0-r0libcurl: libcurl: Security feature bypass due to improper mTLS connection reuse — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4)
MEDIUM CVE-2026-9079curl8.20.0-r0 8.22.0-r0libcurl: libcurl: Information disclosure due to failure to clear proxy authentication credentials — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4)
MEDIUM CVE-2026-9080curl8.20.0-r0 8.22.0-r0libcurl: libcurl: Use-after-free via curl_easy_pause() in CURLMOPT_SOCKETFUNCTION callback — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4)
MEDIUM CVE-2026-9545curl8.20.0-r0 8.22.0-r0libcurl: libcurl: Information disclosure via cached SSL session and early data — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4)
MEDIUM CVE-2026-9546curl8.20.0-r0 8.22.0-r0libcurl: libcurl: Information disclosure due to persistent Referer header — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4)
MEDIUM CVE-2026-11856libcurl8.20.0-r0 8.22.0-r0curl: curl: Information disclosure via incorrect Digest authentication header reuse — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4)
MEDIUM CVE-2026-11564libcurl8.20.0-r0 8.22.0-r0libcurl: libcurl: Certificate validation bypass due to incorrect connection reuse — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4)
MEDIUM CVE-2026-10536libcurl8.20.0-r0 8.22.0-r0libcurl: libcurl: Use-after-free vulnerability leading to Denial of Service — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4)
MEDIUM CVE-2026-10536curl8.20.0-r0 8.22.0-r0libcurl: libcurl: Use-after-free vulnerability leading to Denial of Service — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4)
MEDIUM CVE-2026-11564curl8.20.0-r0 8.22.0-r0libcurl: libcurl: Certificate validation bypass due to incorrect connection reuse — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4)
MEDIUM CVE-2026-11856curl8.20.0-r0 8.22.0-r0curl: curl: Information disclosure via incorrect Digest authentication header reuse — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4)
MEDIUM CVE-2026-13608curl8.20.0-r0 8.22.0-r0A flaw in the libcurl SASL negotiation for LDAP authentication allows ... — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4)
MEDIUM CVE-2026-19931curl8.20.0-r0 8.22.0-r0curl: libcurl: Information disclosure via incorrect connection reuse with Negotiate authentication — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4)
MEDIUM CVE-2026-80229curl8.20.0-r0 8.22.0-r0When performing transfers via libcurl\u2019s multi interface, pooled T ... — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4)
LOW CVE-2026-18924libcurl8.20.0-r0 8.22.0-r0curl: libcurl: Use-after-free in HTTP/2 Server Push with shared connections — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4)
LOW CVE-2026-18924curl8.20.0-r0 8.22.0-r0curl: libcurl: Use-after-free in HTTP/2 Server Push with shared connections — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4)
LOW CVE-2026-47241net-imap0.3.9 ~> 0.5.15, >= 0.6.4.1net-imap: rubygem-net-imap: Net::IMAP: Denial of Service via malformed command input — Ruby
UNKNOWN CVE-2026-82208libcurl8.20.0-r0 8.22.0-r0With the wolfSSL backend, when CA caching is enabled and an `CURLOPT_S ... — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4)
UNKNOWN CVE-2026-80256libcurl8.20.0-r0 8.22.0-r0ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4)
UNKNOWN CVE-2026-80231libcurl8.20.0-r0 8.22.0-r0native CA store conn reuse — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4)
UNKNOWN CVE-2026-82208curl8.20.0-r0 8.22.0-r0With the wolfSSL backend, when CA caching is enabled and an `CURLOPT_S ... — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4)
UNKNOWN CVE-2026-80231curl8.20.0-r0 8.22.0-r0native CA store conn reuse — ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4)
UNKNOWN CVE-2026-80256curl8.20.0-r0 8.22.0-r0ghcr.io/voxpupuli/onceover:latest (alpine 3.23.4)

Grype

CRITICAL 20 HIGH 34 MEDIUM 6 LOW 2 UNKNOWN 2 NVD/CPE filtered 15
SeverityIDPackageInstalledFixedTitle / target
CRITICAL CVE-2026-8926libcurl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
CRITICAL CVE-2026-8926curl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
CRITICAL CVE-2026-11564curl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
CRITICAL CVE-2026-11564libcurl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
CRITICAL CVE-2026-8927libcurl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
CRITICAL CVE-2026-8927curl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
CRITICAL CVE-2026-9079libcurl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
CRITICAL CVE-2026-9079curl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
CRITICAL CVE-2026-10536libcurl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
CRITICAL CVE-2026-10536curl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
CRITICAL CVE-2026-8924libcurl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
CRITICAL CVE-2026-8924curl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
CRITICAL CVE-2026-8925libcurl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
CRITICAL CVE-2026-8925curl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
CRITICAL CVE-2026-11856libcurl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
CRITICAL CVE-2026-11856curl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
CRITICAL CVE-2026-19931curl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
CRITICAL CVE-2026-19931libcurl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
CRITICAL CVE-2026-18924curl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
CRITICAL CVE-2026-18924libcurl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH GHSA-q339-8rmv-2mhverb4.0.2 4.0.3.1ERB has an @_init deserialization guard bypass via def_module / def_method / def_class — /usr/local/lib/ruby/gems/3.2.0/specifications/default/erb-4.0.2.gemspec
HIGH CVE-2026-9546libcurl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-9545libcurl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-82208curl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-82208libcurl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-9545curl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-12064curl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-12064libcurl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-8932curl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-8932libcurl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-9547curl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-9547libcurl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-8286curl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-8286libcurl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-9080libcurl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-9080curl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH GHSA-vcgp-9326-pqcpnet-imap0.3.9 0.3.10net-imap vulnerable to STARTTLS stripping via invalid response timing — /usr/local/lib/ruby/gems/3.2.0/specifications/net-imap-0.3.9.gemspec
HIGH CVE-2026-80231curl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-80231libcurl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-80229curl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-80229libcurl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-11352curl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-11352libcurl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-80255curl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-80255libcurl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-9546curl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-82209libcurl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-82209curl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-80230libcurl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-80230curl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-11586libcurl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-11586curl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-13608libcurl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-13608curl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
MEDIUM GHSA-hm49-wcqc-g2xgnet-imap0.3.9 0.4.24net-imap vulnerable to command Injection via "raw" arguments to multiple commands — /usr/local/lib/ruby/gems/3.2.0/specifications/net-imap-0.3.9.gemspec
MEDIUM GHSA-8p34-64r3-mwg8net-imap0.3.9 0.5.15Net::IMAP: Command Injection via non-synchronizing literal in "raw" argument — /usr/local/lib/ruby/gems/3.2.0/specifications/net-imap-0.3.9.gemspec
MEDIUM CVE-2026-8458curl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
MEDIUM CVE-2026-8458libcurl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
MEDIUM GHSA-75xq-5h9v-w6pxnet-imap0.3.9 0.4.24net-imap vulnerable to command Injection via unvalidated Symbol inputs — /usr/local/lib/ruby/gems/3.2.0/specifications/net-imap-0.3.9.gemspec
MEDIUM GHSA-46q3-7gv7-qmggnet-imap0.3.9 0.5.15Net::IMAP: Command Injection via ID command argument — /usr/local/lib/ruby/gems/3.2.0/specifications/net-imap-0.3.9.gemspec
LOW GHSA-q2mw-fvj9-vvcwnet-imap0.3.9 0.4.24net-imap has quadratic complexity when reading response literals — /usr/local/lib/ruby/gems/3.2.0/specifications/net-imap-0.3.9.gemspec
LOW GHSA-c4fp-cxrr-mj66net-imap0.3.9 0.5.15Net::IMAP: Denial of Service via incomplete raw argument validation — /usr/local/lib/ruby/gems/3.2.0/specifications/net-imap-0.3.9.gemspec
UNKNOWN CVE-2026-80256curl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
UNKNOWN CVE-2026-80256libcurl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
Filtered NVD/CPE matches (15)

These broad CPE matches are unconfirmed for the distribution package and excluded from scanner totals.

SeverityIDPackageInstalledFixedTitle / target
MEDIUM CVE-2026-17084python33.12.14-r0 The "stringprep" module didn't process characters from RFC 3454 tables B.2 or B.3 correctly: the latest Unicode codepoint attributes were used instead of the specified Unicode 3.2.0. This behavior would cause mismatches when processing domain names using IDNA 2003 (the "idna" codec) and the in_table_b2() function of the "stringprep" module. This only affects domain names containing characters that were not previously registered or had their Unicode attributes such as case-folding behavior updated since Unicode 3.2.0. — /lib/apk/db/installed
MEDIUM CVE-2025-12781python33.12.14-r0 When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the "base64" module the characters "+/" will always be accepted, regardless of the value of "altchars" parameter, typically used to establish an "alternative base64 alphabet" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues. This behavior can only be insecure if your application uses an alternate base64 alphabet (without "+/"). If your application does not use the "altchars" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet. The attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64 alphabet they are expecting or verify that their application would not be affected if the b64decode() functions accepted "+" or "/" outside of altchars. — /lib/apk/db/installed
MEDIUM CVE-2026-19672python33.12.14-r0 The tarfile module's tar and data extraction filters created directories outside the destination for members whose name leaves the destination and returns to it, such as ../evil/../dest/sub/file. The containment check used the resolved path, but intermediate directories were created from the name as given. Only empty directories are created outside the destination. Member contents are still extracted inside it. To return to the destination the member's name must contain the destination directory's own final component, so extraction into a secure randomised directory is not affected. This affects POSIX platforms only. On Windows, .. components are collapsed before the path reaches the filesystem, so the directories outside the destination are never created. — /lib/apk/db/installed
MEDIUM CVE-2026-87910python33.12.14-r0 When tarfile extracts a link on a system that doesn't support links, it falls back to extracting a member from the archive. In this case, the filter function is run twice: once for the extracted member, and once with name set to the location of the link. For one of the calls, the return value was ignored. Instead, the member should be skipped if either call returns None. — /lib/apk/db/installed
MEDIUM CVE-2026-15806python33.12.14-r0 The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the same host over http://, so an attacker able to redirect or downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect or an on-path position) could capture credentials in cleartext. Credentials added for http:// URLs could likewise be sent over https://. Credential matching is now scoped by URL scheme. Credentials registered with a URL that includes a scheme are only used for requests with the same scheme. Credentials registered with a bare authority (such as example.com or example.com:8080) continue to match any scheme, preserving compatibility with existing code, including proxy authentication. Users who cannot upgrade immediately can mitigate by ensuring that applications never make plain http:// requests to hosts for which credentials are registered, for example by not following redirects to http:// URLs. — /lib/apk/db/installed
MEDIUM CVE-2025-15366python33.12.14-r0 The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters. — /lib/apk/db/installed
MEDIUM CVE-2025-15367python33.12.14-r0 The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters. — /lib/apk/db/installed
MEDIUM CVE-2025-60876busybox1.37.0-r30 BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed
MEDIUM CVE-2025-60876busybox-binsh1.37.0-r30 BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed
MEDIUM CVE-2025-60876ssl_client1.37.0-r30 BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed
MEDIUM CVE-2026-58055nghttp2-libs1.69.0-r0 nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning. — /lib/apk/db/installed
MEDIUM CVE-2026-6019python33.12.14-r0 http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value. — /lib/apk/db/installed
MEDIUM CVE-2026-3446python33.12.14-r0 When calling base64.b64decode() or related functions the decoding process would stop after encountering the first padded quad regardless of whether there was more information to be processed. This can lead to data being accepted which may be processed differently by other implementations. Use "validate=True" to enable stricter processing of base64 data. — /lib/apk/db/installed
LOW CVE-2026-15310python33.12.14-r0 When decompressing crafted zip files using the bzip/LZMA/Zstandard compressions, Python could use an attacker-controlled size to pre-allocate memory, possibly resulting in memory exhaustion. — /lib/apk/db/installed
UNKNOWN CVE-2026-3479python33.12.14-r0 DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point. There is no vulnerability in the function if following the intended security model. pkgutil.get_data() did not validate the resource argument as documented, allowing path traversals. — /lib/apk/db/installed

ghcr.io/voxpupuli/r10k-webhook

GitHub Container Registry

Downloads

10,017 downloads

ghcr.io/voxpupuli/r10k-webhook:latest (2026-08-27)

Trivy

CRITICAL 1 HIGH 71 MEDIUM 106 LOW 36 UNKNOWN 9
SeverityIDPackageInstalledFixedTitle / target
CRITICAL CVE-2026-54906concurrent-ruby1.3.6 >= 1.3.7concurrent-ruby: rubygem-concurrent-ruby: concurrent-ruby: Synchronization flaw in ReadWriteLock allows unauthorized lock release and denial of service — Ruby
HIGH CVE-2026-56852golang.org/x/textv0.34.0 0.39.0golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input — usr/sbin/webhook-go
HIGH CVE-2026-33814stdlibv1.26.2 1.25.10, 1.26.3net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame — usr/local/bin/supercronic-linux-amd64
HIGH CVE-2026-33811stdlibv1.26.2 1.25.10, 1.26.3net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME — usr/local/bin/supercronic-linux-amd64
HIGH CVE-2026-27145stdlibv1.26.2 1.25.11, 1.26.4crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries — usr/local/bin/supercronic-linux-amd64
HIGH CVE-2026-45363jwt2.10.2 ~> 2.10.3, >= 3.2.0ruby-jwt: ruby-jwt: Authentication bypass due to empty key in HMAC verification — Ruby
HIGH CVE-2026-54297faraday2.14.2 ~> 1.10.6, >= 2.14.3faraday: Faraday: Denial of Service via crafted nested query strings — Ruby
HIGH CVE-2026-54904concurrent-ruby1.3.6 >= 1.3.7concurrent-ruby: rubygem-concurrent-ruby: concurrent-ruby: Denial of Service due to infinite loop in AtomicReference#update — Ruby
HIGH CVE-2026-45447libssl33.5.6-r0 3.5.7-r0openssl: Heap Use-After-Free in OpenSSL PKCS7_verify() — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
HIGH CVE-2026-14456libssl33.5.6-r0 3.5.8-r0openssl: OpenSSL: Denial of Service via unbounded memory growth in QUIC server — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
HIGH CVE-2026-7598libssh21.11.1-r1 1.11.1-r2libssh2: integer overflow via large username or password arguments — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
HIGH CVE-2026-55200libssh21.11.1-r1 1.11.1-r3libssh2: libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
HIGH CVE-2026-55199libssh21.11.1-r1 1.11.1-r3libssh2: libssh2: Denial of Service via crafted SSH_MSG_EXT_INFO message — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
HIGH CVE-2026-5917libgit21.9.2-r0 1.9.7-r0libgit2: libgit2: Arbitrary code execution via shell command injection in SSH backend — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
HIGH CVE-2026-53587libgit21.9.2-r0 1.9.6-r0libgit2: libgit2: Denial of Service due to heap out-of-bounds read from malicious Git server — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
HIGH CVE-2026-76957libexpat2.7.5-r0 2.8.4-r0libexpat: libexpat: Memory corruption vulnerability allows arbitrary code execution or denial of service — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
HIGH CVE-2026-76956libexpat2.7.5-r0 2.8.4-r0libexpat: libexpat: Denial of Service via hash flooding attack with crafted XML — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
HIGH CVE-2026-66046libexpat2.7.5-r0 2.8.4-r0expat: Expat: Denial of Service via quadratic complexity in attribute processing — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
HIGH CVE-2026-45186libexpat2.7.5-r0 2.8.1-r0libexpat: denial of service via crafted XML input — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
HIGH CVE-2026-9547libcurl8.19.0-r0 8.22.0-r0curl: curl: Man-in-the-middle attack via SSH host key bypass — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
HIGH CVE-2026-8927libcurl8.19.0-r0 8.22.0-r0curl: Information disclosure due to uncleared proxy authentication state — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
HIGH CVE-2026-8925libcurl8.19.0-r0 8.22.0-r0curl: curl: Double-free vulnerability in SASL authentication — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
HIGH CVE-2026-8458libcurl8.19.0-r0 8.22.0-r0curl: libcurl: Unauthorized connection reuse due to a logical error — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
HIGH CVE-2026-8286libcurl8.19.0-r0 8.22.0-r0curl: curl: Insecure connection establishment due to TLS configuration mismatch — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
HIGH CVE-2026-6276libcurl8.19.0-r0 8.20.0-r0curl: libcurl: Information disclosure due to cookie leak when reusing connections with custom Host headers — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
HIGH CVE-2026-5773libcurl8.19.0-r0 8.20.0-r0curl: libcurl: Wrong file transfer due to incorrect SMB connection reuse — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
HIGH CVE-2026-12064libcurl8.19.0-r0 8.22.0-r0curl: curl: SSH host verification bypass when using schemeless URLs with SFTP/SCP — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
HIGH CVE-2026-11586libcurl8.19.0-r0 8.22.0-r0curl: curl: Denial of Service via WebSocket PING flood — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
HIGH CVE-2026-11352libcurl8.19.0-r0 8.22.0-r0curl: libcurl: curl/libcurl: Remote denial of service via QUIC UDP receive function vulnerability — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
HIGH CVE-2026-46600golang.org/x/netv0.51.0 0.56.0golang.org/x/net/dns/dnsmessage: golang.org/x/net/dns/dnsmessage: Denial of Service via invalid DNS record parsing — usr/sbin/webhook-go
HIGH CVE-2026-39821golang.org/x/netv0.51.0 0.55.0golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing — usr/sbin/webhook-go
HIGH CVE-2026-33814golang.org/x/netv0.51.0 0.53.0net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame — usr/sbin/webhook-go
HIGH CVE-2026-27136golang.org/x/netv0.51.0 0.55.0golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass — usr/sbin/webhook-go
HIGH CVE-2026-25681golang.org/x/netv0.51.0 0.55.0golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting — usr/sbin/webhook-go
HIGH CVE-2026-56854golang.org/x/cryptov0.48.0 0.55.0golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authentication bypass due to unenforced source-address restrictions — usr/sbin/webhook-go
HIGH CVE-2026-46597golang.org/x/cryptov0.48.0 0.52.0golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs — usr/sbin/webhook-go
HIGH CVE-2026-46595golang.org/x/cryptov0.48.0 0.52.0golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Authorization bypass due to skipped source-address validation — usr/sbin/webhook-go
HIGH CVE-2026-42508golang.org/x/cryptov0.48.0 0.52.0golang.org/x/crypto/ssh/knownhosts: golang: golang.org/x/crypto/ssh/knownhosts: Revocation bypass via unchecked SignatureKey — usr/sbin/webhook-go
HIGH CVE-2026-39835golang.org/x/cryptov0.48.0 0.52.0golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate — usr/sbin/webhook-go
HIGH CVE-2026-39832golang.org/x/cryptov0.48.0 0.52.0golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions — usr/sbin/webhook-go
HIGH CVE-2026-39831golang.org/x/cryptov0.48.0 0.52.0golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check — usr/sbin/webhook-go
HIGH CVE-2026-39830golang.org/x/cryptov0.48.0 0.52.0golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses — usr/sbin/webhook-go
HIGH CVE-2026-39829golang.org/x/cryptov0.48.0 0.52.0golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters — usr/sbin/webhook-go
HIGH CVE-2026-39828golang.org/x/cryptov0.48.0 0.52.0golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions — usr/sbin/webhook-go
HIGH CVE-2026-56862stdlibv1.26.2 1.25.13, 1.26.6, 1.27.0-rc.3crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages — usr/local/bin/supercronic-linux-amd64
HIGH CVE-2026-56860stdlibv1.26.2 1.25.13, 1.26.6, 1.27.0-rc.3net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution — usr/local/bin/supercronic-linux-amd64
HIGH CVE-2026-56859stdlibv1.26.2 1.25.13, 1.26.6, 1.27.0-rc.3encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue — usr/local/bin/supercronic-linux-amd64
HIGH CVE-2026-56858stdlibv1.26.2 1.25.13, 1.26.6, 1.27.0-rc.3html/template: golang: Go html/template: Cross-Site Scripting via pathological input — usr/local/bin/supercronic-linux-amd64
HIGH CVE-2026-56853stdlibv1.26.2 1.25.13, 1.26.6, 1.27.0-rc.3net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service — usr/local/bin/supercronic-linux-amd64
HIGH CVE-2026-46600stdlibv1.26.2 1.26.6, 1.27.0-rc.3golang.org/x/net/dns/dnsmessage: golang.org/x/net/dns/dnsmessage: Denial of Service via invalid DNS record parsing — usr/local/bin/supercronic-linux-amd64
HIGH CVE-2026-42504stdlibv1.26.2 1.25.11, 1.26.4mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header — usr/local/bin/supercronic-linux-amd64
HIGH CVE-2026-42499stdlibv1.26.2 1.25.10, 1.26.3net/mail: golang: net/mail: Denial of Service via pathological email address parsing — usr/local/bin/supercronic-linux-amd64
HIGH CVE-2026-39836stdlibv1.26.2 1.25.10, 1.26.3net: golang: Go net package: Denial of Service via NUL byte in Dial and LookupPort on Windows — usr/local/bin/supercronic-linux-amd64
HIGH CVE-2026-39822stdlibv1.26.2 1.25.12, 1.26.5, 1.27.0-rc.2golang: Go os.Root: Symlink following vulnerability allows directory traversal — usr/local/bin/supercronic-linux-amd64
HIGH CVE-2026-39821stdlibv1.26.2 1.25.13, 1.26.6, 1.27.0-rc.3golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing — usr/local/bin/supercronic-linux-amd64
HIGH CVE-2026-39820stdlibv1.26.2 1.25.10, 1.26.3net/mail: golang: Go net/mail: Denial of Service via crafted email inputs — usr/local/bin/supercronic-linux-amd64
HIGH CVE-2026-33818stdlibv1.26.2 1.25.13, 1.26.6, 1.27.0-rc.3encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal — usr/local/bin/supercronic-linux-amd64
HIGH CVE-2026-9547curl8.19.0-r0 8.22.0-r0curl: curl: Man-in-the-middle attack via SSH host key bypass — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
HIGH CVE-2026-8927curl8.19.0-r0 8.22.0-r0curl: Information disclosure due to uncleared proxy authentication state — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
HIGH CVE-2026-8925curl8.19.0-r0 8.22.0-r0curl: curl: Double-free vulnerability in SASL authentication — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
HIGH CVE-2026-8458curl8.19.0-r0 8.22.0-r0curl: libcurl: Unauthorized connection reuse due to a logical error — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
HIGH CVE-2026-8286curl8.19.0-r0 8.22.0-r0curl: curl: Insecure connection establishment due to TLS configuration mismatch — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
HIGH CVE-2026-40164jq1.8.1-r0 1.8.2-r0jq: jq: Denial of Service via crafted JSON object causing hash collisions — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
HIGH CVE-2026-45447libcrypto33.5.6-r0 3.5.7-r0openssl: Heap Use-After-Free in OpenSSL PKCS7_verify() — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
HIGH CVE-2026-14456libcrypto33.5.6-r0 3.5.8-r0openssl: OpenSSL: Denial of Service via unbounded memory growth in QUIC server — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
HIGH CVE-2026-32316jq1.8.1-r0 1.8.2-r0jq: jq: Denial of Service or potential arbitrary code execution due to integer overflow and heap-based buffer overflow — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
HIGH CVE-2026-6276curl8.19.0-r0 8.20.0-r0curl: libcurl: Information disclosure due to cookie leak when reusing connections with custom Host headers — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
HIGH CVE-2026-5773curl8.19.0-r0 8.20.0-r0curl: libcurl: Wrong file transfer due to incorrect SMB connection reuse — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
HIGH CVE-2026-12064curl8.19.0-r0 8.22.0-r0curl: curl: SSH host verification bypass when using schemeless URLs with SFTP/SCP — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
HIGH CVE-2026-11586curl8.19.0-r0 8.22.0-r0curl: curl: Denial of Service via WebSocket PING flood — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
HIGH CVE-2026-11352curl8.19.0-r0 8.22.0-r0curl: libcurl: curl/libcurl: Remote denial of service via QUIC UDP receive function vulnerability — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
HIGH CVE-2026-33630c-ares1.34.6-r0 1.34.8-r0c-ares: c-ares: Use-after-free / double-free in query-completion handling — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-63076libssl33.5.6-r0 3.5.8-r0openssl: invalid pointer dereference in CMP server via crafted protectionAlg — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-54905concurrent-ruby1.3.6 >= 1.3.7concurrent-ruby: Concurrent-ruby: Incorrect write lock granting leading to broken mutual exclusion — Ruby
MEDIUM CVE-2026-63072libssl33.5.6-r0 3.5.8-r0openssl: heap buffer overflow in CMS key unwrapping — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-45445libssl33.5.6-r0 3.5.7-r0openssl: AES-OCB IV Ignored on EVP_Cipher() Path — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-42764libssl33.5.6-r0 3.5.7-r0openssl: NULL pointer dereference in QUIC server initial packet handling — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-9546curl8.19.0-r0 8.22.0-r0libcurl: libcurl: Information disclosure due to persistent Referer header — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-9545curl8.19.0-r0 8.22.0-r0libcurl: libcurl: Information disclosure via cached SSL session and early data — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-9080curl8.19.0-r0 8.22.0-r0libcurl: libcurl: Use-after-free via curl_easy_pause() in CURLMOPT_SOCKETFUNCTION callback — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-9079curl8.19.0-r0 8.22.0-r0libcurl: libcurl: Information disclosure due to failure to clear proxy authentication credentials — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-8932curl8.19.0-r0 8.22.0-r0libcurl: libcurl: Security feature bypass due to improper mTLS connection reuse — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-8926curl8.19.0-r0 8.22.0-r0curl: curl: Information disclosure via incorrect .netrc password lookup — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-8924curl8.19.0-r0 8.22.0-r0curl: curl: Cookie injection via malicious HTTP server using super cookies — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-82209curl8.19.0-r0 8.22.0-r0When libpsl support is enabled, libcurl fails to enforce the Public Su ... — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-42506golang.org/x/netv0.51.0 0.55.0golang.org/x/net/html: golang.org/x/net/html: Cross-Site Scripting (XSS) via arbitrary HTML parsing — usr/sbin/webhook-go
MEDIUM CVE-2026-34183libssl33.5.6-r0 3.5.7-r0openssl: Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-34182libssl33.5.6-r0 3.5.7-r0openssl: CMS AuthEnvelopedData Processing May Accept Forged Messages — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-18798libssl33.5.6-r0 3.5.8-r0openssl: QUIC server may trigger double free when processing INITIAL packet — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-33947jq1.8.1-r0 1.8.2-r0jq: unbounded Recursion in jv_setpath() / jv_getpath() / delpaths_sorted() — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-33948jq1.8.1-r0 1.8.2-r0jq: jq: Input validation bypass via embedded NUL bytes allows parser differential attacks — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-53586libgit21.9.2-r0 1.9.6-r0libgit2: libgit2: Information disclosure via HTTP redirect allows credential leakage — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-53585libgit21.9.2-r0 1.9.6-r0libgit2: libgit2: Denial of Service via Unbounded Memory Allocation — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-53583libgit21.9.2-r0 1.9.6-r0libgit2: libgit2: Network attacker can intercept HTTPS connections via inverted IP SubjectAltName comparison — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-39956jq1.8.1-r0 1.8.2-r0jq: missing runtime type checks for _strindices lead to crash and limited memory disclosure — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-39979jq1.8.1-r0 1.8.2-r0jq: out-of-bounds read in jv_parse_sized() on error formatting for non-NUL-terminated buffers — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-76641libexpat2.7.5-r0 2.8.4-r0CVE-2026-76641 affecting package expat for versions less than 2.8.3-2 — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-56412libexpat2.7.5-r0 2.8.2-r0libexpat: libexpat: Use-after-free vulnerability due to improper handling of XML CDATA sections — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-56411libexpat2.7.5-r0 2.8.2-r0expat: libexpat: Integer Overflow Vulnerability Leading to Information Disclosure or Code Execution — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-19931libcurl8.19.0-r0 8.22.0-r0curl: libcurl: Information disclosure via incorrect connection reuse with Negotiate authentication — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-42502golang.org/x/netv0.51.0 0.55.0golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering — usr/sbin/webhook-go
MEDIUM CVE-2026-25680golang.org/x/netv0.51.0 0.55.0golang.org/x/net/html: golang.org/x/net/html: Denial of Service due to excessive HTML parsing — usr/sbin/webhook-go
MEDIUM CVE-2026-78662golang.org/x/cryptov0.48.0 0.56.0golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via channel request flooding — usr/sbin/webhook-go
MEDIUM CVE-2026-56855golang.org/x/cryptov0.48.0 0.56.0golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted messages — usr/sbin/webhook-go
MEDIUM CVE-2026-46598golang.org/x/cryptov0.48.0 0.52.0golang.org/x/crypto/ssh/agent: golang: golang.org/x/crypto/ssh/agent: Denial of Service via malformed input — usr/sbin/webhook-go
MEDIUM CVE-2026-39834golang.org/x/cryptov0.48.0 0.52.0golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service due to integer overflow in SSH channel write — usr/sbin/webhook-go
MEDIUM CVE-2026-39833golang.org/x/cryptov0.48.0 0.52.0golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to unenforced key confirmation — usr/sbin/webhook-go
MEDIUM CVE-2026-39827golang.org/x/cryptov0.48.0 0.52.0golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via repeated rejected channel openings — usr/sbin/webhook-go
MEDIUM CVE-2026-10536curl8.19.0-r0 8.22.0-r0libcurl: libcurl: Use-after-free vulnerability leading to Denial of Service — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-11564curl8.19.0-r0 8.22.0-r0libcurl: libcurl: Certificate validation bypass due to incorrect connection reuse — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-11856curl8.19.0-r0 8.22.0-r0curl: curl: Information disclosure via incorrect Digest authentication header reuse — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-13608curl8.19.0-r0 8.22.0-r0A flaw in the libcurl SASL negotiation for LDAP authentication allows ... — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-19931curl8.19.0-r0 8.22.0-r0curl: libcurl: Information disclosure via incorrect connection reuse with Negotiate authentication — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM GHSA-gxhx-2686-5h9ggithub.com/slack-go/slackv0.18.0 0.23.1slack-go `SecretsVerifier` accepts empty signing secret without precondition — usr/sbin/webhook-go
MEDIUM CVE-2026-40898github.com/quic-go/quic-gov0.59.0 0.59.1github.com/quic-go/quic-go: quic-go: Denial of Service via excessive memory allocation in HTTP/3 trailers — usr/sbin/webhook-go
MEDIUM CVE-2026-42507stdlibv1.26.2 1.25.11, 1.26.4net/textproto: golang: Golang net/textproto: Misleading error messages via input injection — usr/local/bin/supercronic-linux-amd64
MEDIUM CVE-2026-42505stdlibv1.26.2 1.25.12, 1.26.5, 1.27.0-rc.2crypto/tls: golang: Go crypto/tls: Information disclosure in Encrypted Client Hello — usr/local/bin/supercronic-linux-amd64
MEDIUM CVE-2026-39826stdlibv1.26.2 1.25.10, 1.26.3html/template: golang: html/template: Cross-site scripting due to incorrect script tag escaping — usr/local/bin/supercronic-linux-amd64
MEDIUM CVE-2026-39825stdlibv1.26.2 1.25.10, 1.26.3net/http/httputil: golang: net/http/httputil: ReverseProxy forwards hidden query parameters, potentially bypassing security controls — usr/local/bin/supercronic-linux-amd64
MEDIUM CVE-2026-39823stdlibv1.26.2 1.25.10, 1.26.3html/template: golang: Go html/template: Cross-Site Scripting via improper URL escaping in meta tag content — usr/local/bin/supercronic-linux-amd64
MEDIUM CVE-2026-4873curl8.19.0-r0 8.20.0-r0curl: curl: Information disclosure due to incorrect TLS connection reuse — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-5545curl8.19.0-r0 8.20.0-r0curl: libcurl: Authentication bypass due to incorrect HTTP Negotiate connection reuse — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-6253curl8.19.0-r0 8.20.0-r0curl: curl: Proxy credential disclosure via redirects to unauthenticated proxies — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-6429curl8.19.0-r0 8.20.0-r0curl: libcurl: Credential leak via reused proxy connection during HTTP redirects — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-7009curl8.19.0-r0 8.20.0-r0curl: Curl: Certificate validation bypass due to OCSP stapling flaw — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-7168curl8.19.0-r0 8.20.0-r0curl: libcurl: Information disclosure via incorrect Proxy-Authorization header reuse — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-80229curl8.19.0-r0 8.22.0-r0When performing transfers via libcurl\u2019s multi interface, pooled T ... — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-80230curl8.19.0-r0 8.22.0-r0When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that di ... — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-80255curl8.19.0-r0 8.22.0-r0A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instea ... — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-4873libcurl8.19.0-r0 8.20.0-r0curl: curl: Information disclosure due to incorrect TLS connection reuse — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-5545libcurl8.19.0-r0 8.20.0-r0curl: libcurl: Authentication bypass due to incorrect HTTP Negotiate connection reuse — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-6253libcurl8.19.0-r0 8.20.0-r0curl: curl: Proxy credential disclosure via redirects to unauthenticated proxies — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-6429libcurl8.19.0-r0 8.20.0-r0curl: libcurl: Credential leak via reused proxy connection during HTTP redirects — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-7009libcurl8.19.0-r0 8.20.0-r0curl: Curl: Certificate validation bypass due to OCSP stapling flaw — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-7168libcurl8.19.0-r0 8.20.0-r0curl: libcurl: Information disclosure via incorrect Proxy-Authorization header reuse — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-80229libcurl8.19.0-r0 8.22.0-r0When performing transfers via libcurl\u2019s multi interface, pooled T ... — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-80230libcurl8.19.0-r0 8.22.0-r0When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that di ... — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-80255libcurl8.19.0-r0 8.22.0-r0A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instea ... — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-82209libcurl8.19.0-r0 8.22.0-r0When libpsl support is enabled, libcurl fails to enforce the Public Su ... — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-8924libcurl8.19.0-r0 8.22.0-r0curl: curl: Cookie injection via malicious HTTP server using super cookies — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-8926libcurl8.19.0-r0 8.22.0-r0curl: curl: Information disclosure via incorrect .netrc password lookup — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-8932libcurl8.19.0-r0 8.22.0-r0libcurl: libcurl: Security feature bypass due to improper mTLS connection reuse — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-9079libcurl8.19.0-r0 8.22.0-r0libcurl: libcurl: Information disclosure due to failure to clear proxy authentication credentials — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-9080libcurl8.19.0-r0 8.22.0-r0libcurl: libcurl: Use-after-free via curl_easy_pause() in CURLMOPT_SOCKETFUNCTION callback — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-9545libcurl8.19.0-r0 8.22.0-r0libcurl: libcurl: Information disclosure via cached SSL session and early data — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-34183libcrypto33.5.6-r0 3.5.7-r0openssl: Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-42764libcrypto33.5.6-r0 3.5.7-r0openssl: NULL pointer dereference in QUIC server initial packet handling — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-45445libcrypto33.5.6-r0 3.5.7-r0openssl: AES-OCB IV Ignored on EVP_Cipher() Path — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-63072libcrypto33.5.6-r0 3.5.8-r0openssl: heap buffer overflow in CMS key unwrapping — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-63076libcrypto33.5.6-r0 3.5.8-r0openssl: invalid pointer dereference in CMP server via crafted protectionAlg — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-34182libcrypto33.5.6-r0 3.5.7-r0openssl: CMS AuthEnvelopedData Processing May Accept Forged Messages — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-18798libcrypto33.5.6-r0 3.5.8-r0openssl: QUIC server may trigger double free when processing INITIAL packet — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-54679jq1.8.1-r0 1.8.2-r0jq: jq: Denial of Service via integer overflow and buffer overrun on 32-bit systems — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-49839jq1.8.1-r0 1.8.2-r0jq: jq: Heap out-of-bounds write via oversized raw file processing — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-47770jq1.8.1-r0 1.8.2-r0jq: jq: Denial of Service via deeply nested array comparison — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-44777jq1.8.1-r0 1.8.2-r0jq: stack overflow in module loading on mutual include — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-43896jq1.8.1-r0 1.8.2-r0jq: stack overflow in recursive object merge — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-43895jq1.8.1-r0 1.8.2-r0jq: embedded NUL in jq import paths causes local redaction-policy bypass and preserves sensitive fields in published artifacts — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-10536libcurl8.19.0-r0 8.22.0-r0libcurl: libcurl: Use-after-free vulnerability leading to Denial of Service — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-11564libcurl8.19.0-r0 8.22.0-r0libcurl: libcurl: Certificate validation bypass due to incorrect connection reuse — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-11856libcurl8.19.0-r0 8.22.0-r0curl: curl: Information disclosure via incorrect Digest authentication header reuse — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-13608libcurl8.19.0-r0 8.22.0-r0A flaw in the libcurl SASL negotiation for LDAP authentication allows ... — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-56410libexpat2.7.5-r0 2.8.2-r0libexpat: libexpat: Integer overflow in xmlwf can lead to information disclosure and arbitrary code execution. — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-56409libexpat2.7.5-r0 2.8.2-r0xmlwf in libexpat before 2.8.2 has an integer overflow for the output ... — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-56408libexpat2.7.5-r0 2.8.2-r0libexpat before 2.8.2 has an integer overflow in copyString. — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-56407libexpat2.7.5-r0 2.8.2-r0libexpat: libexpat: Arbitrary code execution due to integer overflow — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-56406libexpat2.7.5-r0 2.8.2-r0libexpat: libexpat: Arbitrary code execution via integer overflow in XML_ParseBuffer — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-56405libexpat2.7.5-r0 2.8.2-r0libexpat: libexpat: Information disclosure and arbitrary code execution via integer overflow — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-56404libexpat2.7.5-r0 2.8.2-r0libexpat: libexpat: Arbitrary Code Execution via integer overflow in addBinding — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-56403libexpat2.7.5-r0 2.8.2-r0libexpat: libexpat: Arbitrary code execution due to integer overflow in storeAtts — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-56132libexpat2.7.5-r0 2.8.2-r0expat: libexpat: Arbitrary Code Execution via Heap-based Buffer Overflow — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-56131libexpat2.7.5-r0 2.8.2-r0libexpat: libexpat: Use-after-free vulnerability due to insufficient handler call depth tracking — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-50219libexpat2.7.5-r0 2.8.2-r0expat: libexpat: Use-after-free vulnerability due to improper handler call depth tracking — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-40612jq1.8.1-r0 1.8.2-r0jq: stack overflow via unbounded recursion in jv_contains — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-41256jq1.8.1-r0 1.8.2-r0jq: embedded NUL truncates top-level jq programs loaded with -f — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-41257jq1.8.1-r0 1.8.2-r0jq: signed-int overflow in stack_reallocate — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-43894jq1.8.1-r0 1.8.2-r0jq: jq: Arbitrary Code Execution or Denial of Service via Signed Integer Overflow — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
MEDIUM CVE-2026-9546libcurl8.19.0-r0 8.22.0-r0libcurl: libcurl: Information disclosure due to persistent Referer header — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
LOW CVE-2026-42766libssl33.5.6-r0 3.5.7-r0openssl: Possible NULL Dereference in Password-Based CMS Decryption — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
LOW CVE-2026-9076libcrypto33.5.6-r0 3.5.7-r0openssl: OpenSSL: Denial of Service due to heap out-of-bounds read in CMS password-based decryption — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
LOW CVE-2026-75803libcrypto33.5.6-r0 3.5.8-r0openssl: openssl: AEAD forgeries possible with empty ciphertext in EVP_Cipher() — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
LOW CVE-2026-7383libcrypto33.5.6-r0 3.5.7-r0openssl: OpenSSL: Heap buffer overflow due to signed integer overflow in Unicode output sizing — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
LOW CVE-2026-63075libcrypto33.5.6-r0 3.5.8-r0openssl: QUIC ACK-only packet retention can cause memory exhaustion — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
LOW CVE-2026-63074libcrypto33.5.6-r0 3.5.8-r0openssl: CMP indefinite cache growth of ExtraCerts — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
LOW CVE-2026-63073libcrypto33.5.6-r0 3.5.8-r0openssl: untrusted sender DN used as format string in CMP response validation — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
LOW CVE-2026-54874libcrypto33.5.6-r0 3.5.8-r0openssl: excessive memory use buffering DTLS records for a future epoch — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
LOW CVE-2026-45446libcrypto33.5.6-r0 3.5.7-r0openssl: Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
LOW CVE-2026-42770libcrypto33.5.6-r0 3.5.7-r0openssl: FFC-DH Peer Validation Uses Attacker-Supplied q — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
LOW CVE-2026-42769libcrypto33.5.6-r0 3.5.7-r0openssl: Trust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdate — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
LOW CVE-2026-42768libcrypto33.5.6-r0 3.5.7-r0openssl: Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt() — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
LOW CVE-2026-42767libcrypto33.5.6-r0 3.5.7-r0openssl: NULL Pointer Dereference in CRMF EncryptedValue Decryption — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
LOW CVE-2026-42766libcrypto33.5.6-r0 3.5.7-r0openssl: Possible NULL Dereference in Password-Based CMS Decryption — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
LOW CVE-2026-34181libcrypto33.5.6-r0 3.5.7-r0openssl: PKCS#12 Files with PBMAC1 Are Accepted with Short HMAC Keys — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
LOW CVE-2026-34180libcrypto33.5.6-r0 3.5.7-r0openssl: OpenSSL: Heap buffer over-read in ASN.1 decoding can lead to denial of service or information disclosure. — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
LOW CVE-2026-14457libcrypto33.5.6-r0 3.5.8-r0openssl: RPK server signature algorithm selection can dereference a missing certificate — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
LOW CVE-2026-41080libexpat2.7.5-r0 2.8.1-r0libexpat: expat: libexpat: Denial of Service via hash flooding with crafted XML — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
LOW CVE-2026-75803libssl33.5.6-r0 3.5.8-r0openssl: openssl: AEAD forgeries possible with empty ciphertext in EVP_Cipher() — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
LOW CVE-2026-7383libssl33.5.6-r0 3.5.7-r0openssl: OpenSSL: Heap buffer overflow due to signed integer overflow in Unicode output sizing — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
LOW CVE-2026-63075libssl33.5.6-r0 3.5.8-r0openssl: QUIC ACK-only packet retention can cause memory exhaustion — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
LOW CVE-2026-63074libssl33.5.6-r0 3.5.8-r0openssl: CMP indefinite cache growth of ExtraCerts — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
LOW CVE-2026-34181libssl33.5.6-r0 3.5.7-r0openssl: PKCS#12 Files with PBMAC1 Are Accepted with Short HMAC Keys — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
LOW CVE-2026-34180libssl33.5.6-r0 3.5.7-r0openssl: OpenSSL: Heap buffer over-read in ASN.1 decoding can lead to denial of service or information disclosure. — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
LOW CVE-2026-14457libssl33.5.6-r0 3.5.8-r0openssl: RPK server signature algorithm selection can dereference a missing certificate — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
LOW CVE-2026-42767libssl33.5.6-r0 3.5.7-r0openssl: NULL Pointer Dereference in CRMF EncryptedValue Decryption — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
LOW CVE-2026-18924libcurl8.19.0-r0 8.22.0-r0curl: libcurl: Use-after-free in HTTP/2 Server Push with shared connections — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
LOW CVE-2026-42768libssl33.5.6-r0 3.5.7-r0openssl: Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt() — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
LOW CVE-2026-42769libssl33.5.6-r0 3.5.7-r0openssl: Trust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdate — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
LOW CVE-2026-42770libssl33.5.6-r0 3.5.7-r0openssl: FFC-DH Peer Validation Uses Attacker-Supplied q — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
LOW CVE-2026-45446libssl33.5.6-r0 3.5.7-r0openssl: Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
LOW CVE-2026-54874libssl33.5.6-r0 3.5.8-r0openssl: excessive memory use buffering DTLS records for a future epoch — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
LOW CVE-2026-53584libgit21.9.2-r0 1.9.6-r0libgit2: libgit2: Submodule path traversal allows arbitrary directory creation — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
LOW CVE-2026-18924curl8.19.0-r0 8.22.0-r0curl: libcurl: Use-after-free in HTTP/2 Server Push with shared connections — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
LOW CVE-2026-63073libssl33.5.6-r0 3.5.8-r0openssl: untrusted sender DN used as format string in CMP response validation — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
LOW CVE-2026-9076libssl33.5.6-r0 3.5.7-r0openssl: OpenSSL: Denial of Service due to heap out-of-bounds read in CMS password-based decryption — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
UNKNOWN CVE-2026-82208curl8.19.0-r0 8.22.0-r0With the wolfSSL backend, when CA caching is enabled and an `CURLOPT_S ... — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
UNKNOWN CVE-2026-39824golang.org/x/sysv0.43.0 0.44.0Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows — usr/local/bin/supercronic-linux-amd64
UNKNOWN GO-2026-5932golang.org/x/cryptov0.48.0 The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues — usr/sbin/webhook-go
UNKNOWN CVE-2026-82208libcurl8.19.0-r0 8.22.0-r0With the wolfSSL backend, when CA caching is enabled and an `CURLOPT_S ... — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
UNKNOWN CVE-2026-80256libcurl8.19.0-r0 8.22.0-r0ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
UNKNOWN CVE-2026-80231libcurl8.19.0-r0 8.22.0-r0native CA store conn reuse — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
UNKNOWN CVE-2026-80231curl8.19.0-r0 8.22.0-r0native CA store conn reuse — ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
UNKNOWN CVE-2026-80256curl8.19.0-r0 8.22.0-r0ghcr.io/voxpupuli/r10k-webhook:latest (alpine 3.23.4)
UNKNOWN CVE-2026-39824golang.org/x/sysv0.41.0 0.44.0Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows — usr/sbin/webhook-go

Grype

CRITICAL 27 HIGH 93 MEDIUM 57 LOW 7 UNKNOWN 2 NVD/CPE filtered 27
SeverityIDPackageInstalledFixedTitle / target
CRITICAL CVE-2026-8925curl8.19.0-r0 8.22.0-r0/lib/apk/db/installed
CRITICAL CVE-2026-11856libcurl8.19.0-r0 8.22.0-r0/lib/apk/db/installed
CRITICAL CVE-2026-11856curl8.19.0-r0 8.22.0-r0/lib/apk/db/installed
CRITICAL CVE-2026-8925libcurl8.19.0-r0 8.22.0-r0/lib/apk/db/installed
CRITICAL CVE-2026-8924curl8.19.0-r0 8.22.0-r0/lib/apk/db/installed
CRITICAL CVE-2026-8924libcurl8.19.0-r0 8.22.0-r0/lib/apk/db/installed
CRITICAL CVE-2026-8926libcurl8.19.0-r0 8.22.0-r0/lib/apk/db/installed
CRITICAL CVE-2026-8926curl8.19.0-r0 8.22.0-r0/lib/apk/db/installed
CRITICAL CVE-2026-7598libssh21.11.1-r1 1.11.1-r2/lib/apk/db/installed
CRITICAL CVE-2026-11564curl8.19.0-r0 8.22.0-r0/lib/apk/db/installed
CRITICAL CVE-2026-10536curl8.19.0-r0 8.22.0-r0/lib/apk/db/installed
CRITICAL CVE-2026-18924libcurl8.19.0-r0 8.22.0-r0/lib/apk/db/installed
CRITICAL CVE-2026-18924curl8.19.0-r0 8.22.0-r0/lib/apk/db/installed
CRITICAL CVE-2026-11564libcurl8.19.0-r0 8.22.0-r0/lib/apk/db/installed
CRITICAL CVE-2026-9079libcurl8.19.0-r0 8.22.0-r0/lib/apk/db/installed
CRITICAL CVE-2026-9079curl8.19.0-r0 8.22.0-r0/lib/apk/db/installed
CRITICAL CVE-2026-8927libcurl8.19.0-r0 8.22.0-r0/lib/apk/db/installed
CRITICAL CVE-2026-8927curl8.19.0-r0 8.22.0-r0/lib/apk/db/installed
CRITICAL CVE-2026-19931curl8.19.0-r0 8.22.0-r0/lib/apk/db/installed
CRITICAL CVE-2026-19931libcurl8.19.0-r0 8.22.0-r0/lib/apk/db/installed
CRITICAL CVE-2026-75803libssl33.5.6-r0 3.5.8-r0/lib/apk/db/installed
CRITICAL CVE-2026-75803libcrypto33.5.6-r0 3.5.8-r0/lib/apk/db/installed
CRITICAL CVE-2026-34182libssl33.5.6-r0 3.5.7-r0/lib/apk/db/installed
CRITICAL CVE-2026-34182libcrypto33.5.6-r0 3.5.7-r0/lib/apk/db/installed
CRITICAL CVE-2026-10536libcurl8.19.0-r0 8.22.0-r0/lib/apk/db/installed
CRITICAL CVE-2026-63073libcrypto33.5.6-r0 3.5.8-r0/lib/apk/db/installed
CRITICAL CVE-2026-63073libssl33.5.6-r0 3.5.8-r0/lib/apk/db/installed
HIGH CVE-2026-33630c-ares1.34.6-r0 1.34.8-r0/lib/apk/db/installed
HIGH CVE-2026-45186libexpat2.7.5-r0 2.8.1-r0/lib/apk/db/installed
HIGH CVE-2026-53587libgit21.9.2-r0 1.9.6-r0/lib/apk/db/installed
HIGH GO-2026-5970golang.org/x/textv0.34.0 0.39.0A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes. — /usr/sbin/webhook-go
HIGH CVE-2026-63075libssl33.5.6-r0 3.5.8-r0/lib/apk/db/installed
HIGH CVE-2026-63075libcrypto33.5.6-r0 3.5.8-r0/lib/apk/db/installed
HIGH GHSA-98m9-hrrm-r99rfaraday2.14.2 2.14.3Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters — /usr/lib/ruby/gems/3.4.0/specifications/faraday-2.14.2.gemspec
HIGH CVE-2026-9546libcurl8.19.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-9546curl8.19.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-54874libssl33.5.6-r0 3.5.8-r0/lib/apk/db/installed
HIGH CVE-2026-54874libcrypto33.5.6-r0 3.5.8-r0/lib/apk/db/installed
HIGH CVE-2026-82209libcurl8.19.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-82209curl8.19.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-80230libcurl8.19.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-80230curl8.19.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH GO-2026-6089stdlibgo1.26.2 1.25.13, 1.26.6, 1.27.0-rc.3When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this. — /usr/local/bin/supercronic-linux-amd64
HIGH GO-2026-5972stdlibgo1.26.2 1.25.13, 1.26.6, 1.27.0-rc.3Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures. — /usr/local/bin/supercronic-linux-amd64
HIGH GO-2026-6090stdlibgo1.26.2 1.25.13, 1.26.6, 1.27.0-rc.3Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely. — /usr/local/bin/supercronic-linux-amd64
HIGH GO-2026-4971stdlibgo1.26.2 1.25.10, 1.26.3The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0). — /usr/local/bin/supercronic-linux-amd64
HIGH CVE-2026-76957libexpat2.7.5-r0 2.8.4-r0/lib/apk/db/installed
HIGH CVE-2026-49839jq1.8.1-r0 1.8.2-r0/lib/apk/db/installed
HIGH CVE-2026-34181libssl33.5.6-r0 3.5.7-r0/lib/apk/db/installed
HIGH CVE-2026-34181libcrypto33.5.6-r0 3.5.7-r0/lib/apk/db/installed
HIGH GHSA-c32j-vqhx-rx3xjwt2.10.2 2.10.3ruby-jwt: Empty-key HMAC bypass; cross-language sibling of CVE-2026-44351 — /usr/lib/ruby/gems/3.4.0/specifications/jwt-2.10.2.gemspec
HIGH CVE-2026-9545libcurl8.19.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-9545curl8.19.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-76956libexpat2.7.5-r0 2.8.4-r0/lib/apk/db/installed
HIGH CVE-2026-9080libcurl8.19.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-9080curl8.19.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-6276libcurl8.19.0-r0 8.20.0-r0/lib/apk/db/installed
HIGH CVE-2026-6276curl8.19.0-r0 8.20.0-r0/lib/apk/db/installed
HIGH CVE-2026-8286libcurl8.19.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-8286curl8.19.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-9547libcurl8.19.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-9547curl8.19.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-40164jq1.8.1-r0 1.8.2-r0/lib/apk/db/installed
HIGH CVE-2026-76641libexpat2.7.5-r0 2.8.4-r0/lib/apk/db/installed
HIGH CVE-2026-8932libcurl8.19.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-8932curl8.19.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-41080libexpat2.7.5-r0 2.8.1-r0/lib/apk/db/installed
HIGH CVE-2026-12064libcurl8.19.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-12064curl8.19.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-82208libcurl8.19.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-82208curl8.19.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-14456libcrypto33.5.6-r0 3.5.8-r0/lib/apk/db/installed
HIGH GHSA-q339-8rmv-2mhverb4.0.4 4.0.4.1ERB has an @_init deserialization guard bypass via def_module / def_method / def_class — /usr/lib/ruby/gems/3.4.0/specifications/default/erb-4.0.4.gemspec
HIGH CVE-2026-45447libssl33.5.6-r0 3.5.7-r0/lib/apk/db/installed
HIGH CVE-2026-18798libcrypto33.5.6-r0 3.5.8-r0/lib/apk/db/installed
HIGH CVE-2026-63076libssl33.5.6-r0 3.5.8-r0/lib/apk/db/installed
HIGH CVE-2026-42764libssl33.5.6-r0 3.5.7-r0/lib/apk/db/installed
HIGH GO-2026-4918stdlibgo1.26.2 1.25.10, 1.26.3When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0. — /usr/local/bin/supercronic-linux-amd64
HIGH CVE-2026-7383libssl33.5.6-r0 3.5.7-r0/lib/apk/db/installed
HIGH CVE-2026-7383libcrypto33.5.6-r0 3.5.7-r0/lib/apk/db/installed
HIGH CVE-2026-80229libcurl8.19.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-80229curl8.19.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-55199libssh21.11.1-r1 1.11.1-r3/lib/apk/db/installed
HIGH CVE-2026-18798libssl33.5.6-r0 3.5.8-r0/lib/apk/db/installed
HIGH CVE-2026-80231libcurl8.19.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-34183libcrypto33.5.6-r0 3.5.7-r0/lib/apk/db/installed
HIGH CVE-2026-55200libssh21.11.1-r1 1.11.1-r3/lib/apk/db/installed
HIGH CVE-2026-34183libssl33.5.6-r0 3.5.7-r0/lib/apk/db/installed
HIGH CVE-2026-34180libcrypto33.5.6-r0 3.5.7-r0/lib/apk/db/installed
HIGH CVE-2026-34180libssl33.5.6-r0 3.5.7-r0/lib/apk/db/installed
HIGH CVE-2026-45447libcrypto33.5.6-r0 3.5.7-r0/lib/apk/db/installed
HIGH CVE-2026-80231curl8.19.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-5917libgit21.9.2-r0 1.9.7-r0/lib/apk/db/installed
HIGH CVE-2026-14457libssl33.5.6-r0 3.5.8-r0/lib/apk/db/installed
HIGH CVE-2026-14457libcrypto33.5.6-r0 3.5.8-r0/lib/apk/db/installed
HIGH CVE-2026-63076libcrypto33.5.6-r0 3.5.8-r0/lib/apk/db/installed
HIGH GO-2026-5037stdlibgo1.26.2 1.25.11, 1.26.4(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates. — /usr/local/bin/supercronic-linux-amd64
HIGH CVE-2026-45445libssl33.5.6-r0 3.5.7-r0/lib/apk/db/installed
HIGH CVE-2026-45445libcrypto33.5.6-r0 3.5.7-r0/lib/apk/db/installed
HIGH CVE-2026-11586libcurl8.19.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-11586curl8.19.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-5773libcurl8.19.0-r0 8.20.0-r0/lib/apk/db/installed
HIGH CVE-2026-5773curl8.19.0-r0 8.20.0-r0/lib/apk/db/installed
HIGH CVE-2026-32316jq1.8.1-r0 1.8.2-r0/lib/apk/db/installed
HIGH CVE-2026-66046libexpat2.7.5-r0 2.8.4-r0/lib/apk/db/installed
HIGH CVE-2026-13608libcurl8.19.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-13608curl8.19.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-63072libssl33.5.6-r0 3.5.8-r0/lib/apk/db/installed
HIGH CVE-2026-63072libcrypto33.5.6-r0 3.5.8-r0/lib/apk/db/installed
HIGH CVE-2026-42764libcrypto33.5.6-r0 3.5.7-r0/lib/apk/db/installed
HIGH CVE-2026-80255libcurl8.19.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-80255curl8.19.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH GHSA-h8w8-99g7-qmvjconcurrent-ruby1.3.6 1.3.7Concurrent Ruby : `AtomicReference#update` livelocks when the stored value is `Float::NAN` — /usr/lib/ruby/gems/3.4.0/specifications/concurrent-ruby-1.3.6.gemspec
HIGH CVE-2026-9076libssl33.5.6-r0 3.5.7-r0/lib/apk/db/installed
HIGH CVE-2026-9076libcrypto33.5.6-r0 3.5.7-r0/lib/apk/db/installed
HIGH CVE-2026-11352libcurl8.19.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-11352curl8.19.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH GO-2026-5026stdlibgo1.26.2 1.25.13, 1.26.6, 1.27.0-rc.3The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com". — /usr/local/bin/supercronic-linux-amd64
HIGH GO-2026-5026golang.org/x/netv0.51.0 0.55.0The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com". — /usr/sbin/webhook-go
HIGH CVE-2026-14456libssl33.5.6-r0 3.5.8-r0/lib/apk/db/installed
MEDIUM CVE-2026-54679jq1.8.1-r0 1.8.2-r0/lib/apk/db/installed
MEDIUM CVE-2026-50219libexpat2.7.5-r0 2.8.2-r0/lib/apk/db/installed
MEDIUM CVE-2026-53583libgit21.9.2-r0 1.9.6-r0/lib/apk/db/installed
MEDIUM CVE-2026-56411libexpat2.7.5-r0 2.8.2-r0/lib/apk/db/installed
MEDIUM CVE-2026-56410libexpat2.7.5-r0 2.8.2-r0/lib/apk/db/installed
MEDIUM CVE-2026-56404libexpat2.7.5-r0 2.8.2-r0/lib/apk/db/installed
MEDIUM CVE-2026-33947jq1.8.1-r0 1.8.2-r0/lib/apk/db/installed
MEDIUM CVE-2026-33948jq1.8.1-r0 1.8.2-r0/lib/apk/db/installed
MEDIUM CVE-2026-7009libcurl8.19.0-r0 8.20.0-r0/lib/apk/db/installed
MEDIUM CVE-2026-7009curl8.19.0-r0 8.20.0-r0/lib/apk/db/installed
MEDIUM CVE-2026-53584libgit21.9.2-r0 1.9.6-r0/lib/apk/db/installed
MEDIUM CVE-2026-56132libexpat2.7.5-r0 2.8.2-r0/lib/apk/db/installed
MEDIUM CVE-2026-56409libexpat2.7.5-r0 2.8.2-r0/lib/apk/db/installed
MEDIUM CVE-2026-43895jq1.8.1-r0 1.8.2-r0/lib/apk/db/installed
MEDIUM CVE-2026-56405libexpat2.7.5-r0 2.8.2-r0/lib/apk/db/installed
MEDIUM CVE-2026-56408libexpat2.7.5-r0 2.8.2-r0/lib/apk/db/installed
MEDIUM CVE-2026-41257jq1.8.1-r0 1.8.2-r0/lib/apk/db/installed
MEDIUM CVE-2026-47770jq1.8.1-r0 1.8.2-r0/lib/apk/db/installed
MEDIUM CVE-2026-43896jq1.8.1-r0 1.8.2-r0/lib/apk/db/installed
MEDIUM CVE-2026-56407libexpat2.7.5-r0 2.8.2-r0/lib/apk/db/installed
MEDIUM CVE-2026-56406libexpat2.7.5-r0 2.8.2-r0/lib/apk/db/installed
MEDIUM CVE-2026-41256jq1.8.1-r0 1.8.2-r0/lib/apk/db/installed
MEDIUM CVE-2026-43894jq1.8.1-r0 1.8.2-r0/lib/apk/db/installed
MEDIUM CVE-2026-56403libexpat2.7.5-r0 2.8.2-r0/lib/apk/db/installed
MEDIUM CVE-2026-44777jq1.8.1-r0 1.8.2-r0/lib/apk/db/installed
MEDIUM CVE-2026-40612jq1.8.1-r0 1.8.2-r0/lib/apk/db/installed
MEDIUM CVE-2026-56131libexpat2.7.5-r0 2.8.2-r0/lib/apk/db/installed
MEDIUM CVE-2026-39956jq1.8.1-r0 1.8.2-r0/lib/apk/db/installed
MEDIUM CVE-2026-56412libexpat2.7.5-r0 2.8.2-r0/lib/apk/db/installed
MEDIUM CVE-2026-42766libssl33.5.6-r0 3.5.7-r0/lib/apk/db/installed
MEDIUM CVE-2026-42766libcrypto33.5.6-r0 3.5.7-r0/lib/apk/db/installed
MEDIUM CVE-2026-42767libcrypto33.5.6-r0 3.5.7-r0/lib/apk/db/installed
MEDIUM CVE-2026-42767libssl33.5.6-r0 3.5.7-r0/lib/apk/db/installed
MEDIUM GO-2026-6218stdlibgo1.26.2 1.25.13, 1.26.6, 1.27.0-rc.3Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations. — /usr/local/bin/supercronic-linux-amd64
MEDIUM CVE-2026-63074libcrypto33.5.6-r0 3.5.8-r0/lib/apk/db/installed
MEDIUM CVE-2026-63074libssl33.5.6-r0 3.5.8-r0/lib/apk/db/installed
MEDIUM CVE-2026-6429curl8.19.0-r0 8.20.0-r0/lib/apk/db/installed
MEDIUM CVE-2026-6429libcurl8.19.0-r0 8.20.0-r0/lib/apk/db/installed
MEDIUM CVE-2026-7168curl8.19.0-r0 8.20.0-r0/lib/apk/db/installed
MEDIUM CVE-2026-7168libcurl8.19.0-r0 8.20.0-r0/lib/apk/db/installed
MEDIUM CVE-2026-5545curl8.19.0-r0 8.20.0-r0/lib/apk/db/installed
MEDIUM CVE-2026-5545libcurl8.19.0-r0 8.20.0-r0/lib/apk/db/installed
MEDIUM CVE-2026-8458curl8.19.0-r0 8.22.0-r0/lib/apk/db/installed
MEDIUM CVE-2026-8458libcurl8.19.0-r0 8.22.0-r0/lib/apk/db/installed
MEDIUM CVE-2026-42769libcrypto33.5.6-r0 3.5.7-r0/lib/apk/db/installed
MEDIUM CVE-2026-42769libssl33.5.6-r0 3.5.7-r0/lib/apk/db/installed
MEDIUM GO-2026-5856stdlibgo1.26.2 1.25.12, 1.26.5, 1.27.0-rc.2Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello. — /usr/local/bin/supercronic-linux-amd64
MEDIUM CVE-2026-39979jq1.8.1-r0 1.8.2-r0/lib/apk/db/installed
MEDIUM GO-2026-5039stdlibgo1.26.2 1.25.11, 1.26.4When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or logged. — /usr/local/bin/supercronic-linux-amd64
MEDIUM CVE-2026-45446libcrypto33.5.6-r0 3.5.7-r0/lib/apk/db/installed
MEDIUM CVE-2026-45446libssl33.5.6-r0 3.5.7-r0/lib/apk/db/installed
MEDIUM CVE-2026-4873curl8.19.0-r0 8.20.0-r0/lib/apk/db/installed
MEDIUM CVE-2026-6253libcurl8.19.0-r0 8.20.0-r0/lib/apk/db/installed
MEDIUM CVE-2026-4873libcurl8.19.0-r0 8.20.0-r0/lib/apk/db/installed
MEDIUM CVE-2026-53585libgit21.9.2-r0 1.9.6-r0/lib/apk/db/installed
MEDIUM CVE-2026-53586libgit21.9.2-r0 1.9.6-r0/lib/apk/db/installed
MEDIUM CVE-2026-6253curl8.19.0-r0 8.20.0-r0/lib/apk/db/installed
LOW GHSA-6wx8-w4f5-wwcrconcurrent-ruby1.3.6 1.3.7Concurrent Ruby: ReadWriteLock allows wrong-thread write release and stray read-release counter corruption — /usr/lib/ruby/gems/3.4.0/specifications/concurrent-ruby-1.3.6.gemspec
LOW GHSA-wv3x-4vxv-whppconcurrent-ruby1.3.6 1.3.7Concurrent Ruby: `ReentrantReadWriteLock` read-count overflow grants a write lock without exclusivity — /usr/lib/ruby/gems/3.4.0/specifications/concurrent-ruby-1.3.6.gemspec
LOW CVE-2026-42768libcrypto33.5.6-r0 3.5.7-r0/lib/apk/db/installed
LOW CVE-2026-42768libssl33.5.6-r0 3.5.7-r0/lib/apk/db/installed
LOW GHSA-x2f5-4prf-w687json2.9.1 2.19.9Ruby json: JSON generator heap buffer overflow when streaming to an IO — /usr/lib/ruby/gems/3.4.0/specifications/default/json-2.9.1.gemspec
LOW CVE-2026-42770libcrypto33.5.6-r0 3.5.7-r0/lib/apk/db/installed
LOW CVE-2026-42770libssl33.5.6-r0 3.5.7-r0/lib/apk/db/installed
UNKNOWN CVE-2026-80256curl8.19.0-r0 8.22.0-r0/lib/apk/db/installed
UNKNOWN CVE-2026-80256libcurl8.19.0-r0 8.22.0-r0/lib/apk/db/installed
Filtered NVD/CPE matches (27)

These broad CPE matches are unconfirmed for the distribution package and excluded from scanner totals.

SeverityIDPackageInstalledFixedTitle / target
HIGH CVE-2026-59849libssh21.11.1-r1 A flaw was found in libssh. Logic errors in automatic certificate-based public key authentication can cause libssh clients to loop indefinitely when configured certificates are missing or repeatedly rejected by a server, leading to denial of service. — /lib/apk/db/installed
HIGH CVE-2026-15370libssh21.11.1-r1 A flaw was found in libssh. During SFTP server directory listing, the longname field is constructed with unsafe concatenation into a fixed-size stack buffer. When a client causes the server to list attacker-controlled filenames, sufficiently long names can overflow that stack buffer and may lead to crashes or possible code execution on the server. — /lib/apk/db/installed
HIGH CVE-2026-89161pcre210.47-r0 In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context. An incorrect free operation can occur. — /lib/apk/db/installed
HIGH CVE-2026-58051libssh21.11.1-r1 libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsing populates them, so a parse failure reaching the cleanup path leaves libssh2_publickey_list_free operating on an uninitialized entry. A malicious SSH server offering the publickey subsystem can use a malformed response to make cleanup free an uninitialized, attacker-influenceable attrs pointer in a connecting libssh2 client. — /lib/apk/db/installed
HIGH CVE-2026-59850libssh21.11.1-r1 A flaw was found in libssh. If data packets are processed after a channel is closed, channel data callbacks can be invoked after the associated data has already been freed, leading to crashes or possible use-after-free conditions. — /lib/apk/db/installed
HIGH CVE-2026-59851libssh21.11.1-r1 A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssapi-keyex path does not verify whether the authenticated Kerberos principal is authorized for the requested local user, allowing authenticated clients to log in as arbitrary users. — /lib/apk/db/installed
HIGH CVE-2026-66034libssh21.11.1-r1 libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitrary-length heap out-of-bounds read and a free of an uninitialized pointer via the publickey subsystem. In libssh2_publickey_list_fetch(), the version 1 response parser reads a server-controlled comment_len value and advances the parse pointer without verifying sufficient bytes remain in the buffer, causing the out-of-bounds read to leak heap pointers from adjacent allocations defeating ASLR, followed by heap allocator state corruption when the error cleanup path frees an uninitialized pointer from a non-zeroed realloc() region. — /lib/apk/db/installed
HIGH CVE-2026-89157pcre210.47-r0 PCRE2 before 10.48, on 32-bit platforms, has a pcre2_pattern_convert out-of-bounds write when an attacker can provide a large pattern. — /lib/apk/db/installed
HIGH CVE-2026-58050libssh21.11.1-r1 libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attrs * sizeof(libssh2_publickey_attribute) without bounds checking, so on 32-bit platforms the multiplication overflows to an undersized buffer. A malicious SSH server can then drive the attribute-parsing loop to write past the allocation, causing a heap buffer overflow in a connecting libssh2 client. — /lib/apk/db/installed
HIGH CVE-2026-66035libssh21.11.1-r1 libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that allows a malicious SSH server to corrupt heap metadata in any connecting client by sending a packet with a packet_length smaller than the cipher's block size during Encrypt-then-MAC cipher negotiation. In the fullpacket() function in src/transport.c, the ETM path allocates a buffer of packet_length bytes but copies blocksize minus one bytes via memcpy, causing an overflow that on 32-bit glibc writes attacker-controlled bytes into an adjacent chunk's SIZE field, enabling tcache bin confusion, overlapping live objects, and function pointer overwrite during the session handshake before authentication. — /lib/apk/db/installed
HIGH CVE-2026-66032libssh21.11.1-r1 libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt the heap of any authenticated client opening an SFTP session. When a server responds to SSH_FXP_OPEN with SSH_FXP_STATUS containing FX_OK, the response data buffer is freed, and if a subsequent sftp_packet_require() call returns a specific error such as LIBSSH2_ERROR_CHANNEL_PACKET_EXCEEDED, the same pointer is freed a second time, enabling tcache dup conditions on glibc systems that allow overlapping allocations and function pointer overwrites. — /lib/apk/db/installed
HIGH CVE-2026-66033libssh21.11.1-r1 libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in src/openssl.c that allows a malicious SSH server to crash any connecting client by negotiating AES-GCM ciphers during handshake. Attackers can exploit the underflow in the expression computing blocksize minus aadlen minus authentication tag length to trigger an out-of-bounds read and a memcpy call with a near-SIZE_MAX length argument, causing immediate process crash before any authentication occurs. — /lib/apk/db/installed
MEDIUM CVE-2026-59845libssh21.11.1-r1 A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may then be sent across the caller's accessible process tree, leading to local denial of service. — /lib/apk/db/installed
MEDIUM CVE-2026-89156pcre210.47-r0 PCRE2 before 10.48 has a pcre2_match out-of-bounds read after a JIT fallback when an attacker can provide invalid UTF data. — /lib/apk/db/installed
MEDIUM CVE-2026-89160pcre210.47-r0 PCRE2 before 10.48 has a pcre2_match out-of-bounds read during the PCRE2_MATCH_INVALID_UTF matching of an invalid UTF subject. — /lib/apk/db/installed
MEDIUM CVE-2026-89158pcre210.47-r0 PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 integer overflow and resultant out-of-bounds write. — /lib/apk/db/installed
MEDIUM CVE-2026-58055nghttp2-libs1.69.0-r0 nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning. — /lib/apk/db/installed
MEDIUM CVE-2025-60876ssl_client1.37.0-r30 BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed
MEDIUM CVE-2025-60876busybox-binsh1.37.0-r30 BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed
MEDIUM CVE-2025-60876busybox1.37.0-r30 BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed
MEDIUM CVE-2026-59848libssh21.11.1-r1 A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh clients keep queued indefinitely, causing unbounded memory growth and client-side denial of service. — /lib/apk/db/installed
MEDIUM CVE-2026-59842libssh21.11.1-r1 A flaw was found in libssh. During server-side GSSAPI key exchange, a client-supplied Curve25519 public key shorter than the expected length is copied without proper length validation, leading to an out-of-bounds heap read. This could allow a remote unauthenticated attacker to disclose small amounts of server memory. — /lib/apk/db/installed
MEDIUM CVE-2026-59844libssh21.11.1-r1 A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large length, causing a libssh SFTP server to allocate excessive memory and potentially exhaust it through repeated requests. — /lib/apk/db/installed
MEDIUM CVE-2026-59843libssh21.11.1-r1 A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel writes to loop indefinitely and consume CPU, leading to denial of service. — /lib/apk/db/installed
MEDIUM CVE-2025-15661libssh21.11.1-r1 libssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bounds heap read vulnerability in the sftp_symlink() function in src/sftp.c that allows a malicious SSH server or man-in-the-middle attacker to disclose heap memory contents or cause a crash by sending a crafted SSH_FXP_NAME response. Attackers can supply a link_len value larger than the actual packet data in SSH_FXP_NAME responses for SFTP READLINK and REALPATH operations, triggering a heap buffer over-read of up to target_len minus one bytes due to the missing validation of available packet buffer size before the memcpy operation. — /lib/apk/db/installed
LOW CVE-2026-59846libssh21.11.1-r1 A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing unintended shell behavior. — /lib/apk/db/installed
LOW CVE-2026-89162pcre210.47-r0 In PCRE2 before 10.48, pcre2_serialize_encode might disclose two bytes to an adversary, typically in a situation where the access available to the adversary is already unsafe. — /lib/apk/db/installed

ghcr.io/voxpupuli/r10k

GitHub Container Registry

Downloads

27,357 downloads

ghcr.io/voxpupuli/r10k:latest (2026-08-27)

Trivy

CRITICAL 3 HIGH 25 MEDIUM 39 LOW 5 UNKNOWN 7
SeverityIDPackageInstalledFixedTitle / target
CRITICAL CVE-2026-60002openssh-client-default10.3_p1-r0 10.3_p1-r1openssh: OpenSSH: Use-after-free vulnerability during host key re-exchange on the client side — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1)
CRITICAL CVE-2026-60002openssh-keygen10.3_p1-r0 10.3_p1-r1openssh: OpenSSH: Use-after-free vulnerability during host key re-exchange on the client side — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1)
CRITICAL CVE-2026-60002openssh-client-common10.3_p1-r0 10.3_p1-r1openssh: OpenSSH: Use-after-free vulnerability during host key re-exchange on the client side — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1)
HIGH CVE-2026-59999openssh-client-default10.3_p1-r0 10.3_p1-r1openssh: OpenSSH sshd: Security bypass due to incorrect handling of forwarding and tunneling options — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1)
HIGH CVE-2026-60000openssh-client-default10.3_p1-r0 10.3_p1-r1openssh: OpenSSH: Denial of Service via excessive GSSAPI authentication attempts — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1)
HIGH CVE-2026-60000openssh-client-common10.3_p1-r0 10.3_p1-r1openssh: OpenSSH: Denial of Service via excessive GSSAPI authentication attempts — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1)
HIGH CVE-2026-59999openssh-client-common10.3_p1-r0 10.3_p1-r1openssh: OpenSSH sshd: Security bypass due to incorrect handling of forwarding and tunneling options — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1)
HIGH CVE-2026-27145stdlibv1.26.2 1.25.11, 1.26.4crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries — usr/local/bin/supercronic-linux-amd64
HIGH CVE-2026-76957libexpat2.8.3-r0 2.8.4-r0libexpat: libexpat: Memory corruption vulnerability allows arbitrary code execution or denial of service — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1)
HIGH CVE-2026-76956libexpat2.8.3-r0 2.8.4-r0libexpat: libexpat: Denial of Service via hash flooding attack with crafted XML — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1)
HIGH CVE-2026-66046libexpat2.8.3-r0 2.8.4-r0expat: Expat: Denial of Service via quadratic complexity in attribute processing — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1)
HIGH CVE-2026-33811stdlibv1.26.2 1.25.10, 1.26.3net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME — usr/local/bin/supercronic-linux-amd64
HIGH CVE-2026-33814stdlibv1.26.2 1.25.10, 1.26.3net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame — usr/local/bin/supercronic-linux-amd64
HIGH CVE-2026-33818stdlibv1.26.2 1.25.13, 1.26.6, 1.27.0-rc.3encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal — usr/local/bin/supercronic-linux-amd64
HIGH CVE-2026-39820stdlibv1.26.2 1.25.10, 1.26.3net/mail: golang: Go net/mail: Denial of Service via crafted email inputs — usr/local/bin/supercronic-linux-amd64
HIGH CVE-2026-39821stdlibv1.26.2 1.25.13, 1.26.6, 1.27.0-rc.3golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing — usr/local/bin/supercronic-linux-amd64
HIGH CVE-2026-39822stdlibv1.26.2 1.25.12, 1.26.5, 1.27.0-rc.2golang: Go os.Root: Symlink following vulnerability allows directory traversal — usr/local/bin/supercronic-linux-amd64
HIGH CVE-2026-39836stdlibv1.26.2 1.25.10, 1.26.3net: golang: Go net package: Denial of Service via NUL byte in Dial and LookupPort on Windows — usr/local/bin/supercronic-linux-amd64
HIGH CVE-2026-42499stdlibv1.26.2 1.25.10, 1.26.3net/mail: golang: net/mail: Denial of Service via pathological email address parsing — usr/local/bin/supercronic-linux-amd64
HIGH CVE-2026-42504stdlibv1.26.2 1.25.11, 1.26.4mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header — usr/local/bin/supercronic-linux-amd64
HIGH CVE-2026-46600stdlibv1.26.2 1.26.6, 1.27.0-rc.3golang.org/x/net/dns/dnsmessage: golang.org/x/net/dns/dnsmessage: Denial of Service via invalid DNS record parsing — usr/local/bin/supercronic-linux-amd64
HIGH CVE-2026-56853stdlibv1.26.2 1.25.13, 1.26.6, 1.27.0-rc.3net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service — usr/local/bin/supercronic-linux-amd64
HIGH CVE-2026-56858stdlibv1.26.2 1.25.13, 1.26.6, 1.27.0-rc.3html/template: golang: Go html/template: Cross-Site Scripting via pathological input — usr/local/bin/supercronic-linux-amd64
HIGH CVE-2026-56859stdlibv1.26.2 1.25.13, 1.26.6, 1.27.0-rc.3encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue — usr/local/bin/supercronic-linux-amd64
HIGH CVE-2026-56860stdlibv1.26.2 1.25.13, 1.26.6, 1.27.0-rc.3net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution — usr/local/bin/supercronic-linux-amd64
HIGH CVE-2026-56862stdlibv1.26.2 1.25.13, 1.26.6, 1.27.0-rc.3crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages — usr/local/bin/supercronic-linux-amd64
HIGH CVE-2026-59999openssh-keygen10.3_p1-r0 10.3_p1-r1openssh: OpenSSH sshd: Security bypass due to incorrect handling of forwarding and tunneling options — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1)
HIGH CVE-2026-60000openssh-keygen10.3_p1-r0 10.3_p1-r1openssh: OpenSSH: Denial of Service via excessive GSSAPI authentication attempts — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1)
MEDIUM CVE-2026-59995openssh-keygen10.3_p1-r0 10.3_p1-r1openssh: OpenSSH: sftp client allows attacker to control downloaded file location — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1)
MEDIUM CVE-2026-59996openssh-keygen10.3_p1-r0 10.3_p1-r1openssh: OpenSSH: `scp` file misplacement vulnerability during remote copy — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1)
MEDIUM CVE-2026-73283openssh-client-default10.3_p1-r0 10.3_p1-r1openssh: OpenSSH: Tunnel forwarding restriction bypass — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1)
MEDIUM CVE-2026-73282openssh-client-default10.3_p1-r0 10.3_p1-r1openssh: OpenSSH: Information disclosure and data corruption via use-after-free in ssh client — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1)
MEDIUM CVE-2026-13608curl8.21.0-r0 8.22.0-r0A flaw in the libcurl SASL negotiation for LDAP authentication allows ... — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1)
MEDIUM CVE-2026-59997openssh-keygen10.3_p1-r0 10.3_p1-r1openssh: OpenSSH: SFTP security bypass due to command-line argument parsing flaw — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1)
MEDIUM CVE-2026-59998openssh-keygen10.3_p1-r0 10.3_p1-r1openssh: OpenSSH: Undocumented GSSAPIStrictAcceptorCheck behavior impacts security in Windows Active Directory — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1)
MEDIUM CVE-2026-60001openssh-keygen10.3_p1-r0 10.3_p1-r1openssh: OpenSSH: Brute-force attacks facilitated due to insufficient authentication delay — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1)
MEDIUM CVE-2026-73282openssh-keygen10.3_p1-r0 10.3_p1-r1openssh: OpenSSH: Information disclosure and data corruption via use-after-free in ssh client — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1)
MEDIUM CVE-2026-73283openssh-keygen10.3_p1-r0 10.3_p1-r1openssh: OpenSSH: Tunnel forwarding restriction bypass — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1)
MEDIUM CVE-2026-39823stdlibv1.26.2 1.25.10, 1.26.3html/template: golang: Go html/template: Cross-Site Scripting via improper URL escaping in meta tag content — usr/local/bin/supercronic-linux-amd64
MEDIUM CVE-2026-39825stdlibv1.26.2 1.25.10, 1.26.3net/http/httputil: golang: net/http/httputil: ReverseProxy forwards hidden query parameters, potentially bypassing security controls — usr/local/bin/supercronic-linux-amd64
MEDIUM CVE-2026-39826stdlibv1.26.2 1.25.10, 1.26.3html/template: golang: html/template: Cross-site scripting due to incorrect script tag escaping — usr/local/bin/supercronic-linux-amd64
MEDIUM CVE-2026-42505stdlibv1.26.2 1.25.12, 1.26.5, 1.27.0-rc.2crypto/tls: golang: Go crypto/tls: Information disclosure in Encrypted Client Hello — usr/local/bin/supercronic-linux-amd64
MEDIUM CVE-2026-42507stdlibv1.26.2 1.25.11, 1.26.4net/textproto: golang: Golang net/textproto: Misleading error messages via input injection — usr/local/bin/supercronic-linux-amd64
MEDIUM CVE-2026-19931curl8.21.0-r0 8.22.0-r0curl: libcurl: Information disclosure via incorrect connection reuse with Negotiate authentication — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1)
MEDIUM CVE-2026-80229curl8.21.0-r0 8.22.0-r0When performing transfers via libcurl\u2019s multi interface, pooled T ... — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1)
MEDIUM CVE-2026-80230curl8.21.0-r0 8.22.0-r0When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that di ... — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1)
MEDIUM CVE-2026-80255curl8.21.0-r0 8.22.0-r0A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instea ... — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1)
MEDIUM CVE-2026-82209curl8.21.0-r0 8.22.0-r0When libpsl support is enabled, libcurl fails to enforce the Public Su ... — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1)
MEDIUM CVE-2026-13608libcurl8.21.0-r0 8.22.0-r0A flaw in the libcurl SASL negotiation for LDAP authentication allows ... — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1)
MEDIUM CVE-2026-19931libcurl8.21.0-r0 8.22.0-r0curl: libcurl: Information disclosure via incorrect connection reuse with Negotiate authentication — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1)
MEDIUM CVE-2026-80229libcurl8.21.0-r0 8.22.0-r0When performing transfers via libcurl\u2019s multi interface, pooled T ... — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1)
MEDIUM CVE-2026-80230libcurl8.21.0-r0 8.22.0-r0When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that di ... — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1)
MEDIUM CVE-2026-80255libcurl8.21.0-r0 8.22.0-r0A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instea ... — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1)
MEDIUM CVE-2026-82209libcurl8.21.0-r0 8.22.0-r0When libpsl support is enabled, libcurl fails to enforce the Public Su ... — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1)
MEDIUM CVE-2026-76641libexpat2.8.3-r0 2.8.4-r0CVE-2026-76641 affecting package expat for versions less than 2.8.3-2 — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1)
MEDIUM CVE-2026-60001openssh-client-default10.3_p1-r0 10.3_p1-r1openssh: OpenSSH: Brute-force attacks facilitated due to insufficient authentication delay — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1)
MEDIUM CVE-2026-59998openssh-client-default10.3_p1-r0 10.3_p1-r1openssh: OpenSSH: Undocumented GSSAPIStrictAcceptorCheck behavior impacts security in Windows Active Directory — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1)
MEDIUM CVE-2026-59997openssh-client-default10.3_p1-r0 10.3_p1-r1openssh: OpenSSH: SFTP security bypass due to command-line argument parsing flaw — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1)
MEDIUM CVE-2026-59996openssh-client-default10.3_p1-r0 10.3_p1-r1openssh: OpenSSH: `scp` file misplacement vulnerability during remote copy — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1)
MEDIUM CVE-2026-59995openssh-client-default10.3_p1-r0 10.3_p1-r1openssh: OpenSSH: sftp client allows attacker to control downloaded file location — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1)
MEDIUM CVE-2026-73283openssh-client-common10.3_p1-r0 10.3_p1-r1openssh: OpenSSH: Tunnel forwarding restriction bypass — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1)
MEDIUM CVE-2026-73282openssh-client-common10.3_p1-r0 10.3_p1-r1openssh: OpenSSH: Information disclosure and data corruption via use-after-free in ssh client — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1)
MEDIUM CVE-2026-60001openssh-client-common10.3_p1-r0 10.3_p1-r1openssh: OpenSSH: Brute-force attacks facilitated due to insufficient authentication delay — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1)
MEDIUM CVE-2026-59998openssh-client-common10.3_p1-r0 10.3_p1-r1openssh: OpenSSH: Undocumented GSSAPIStrictAcceptorCheck behavior impacts security in Windows Active Directory — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1)
MEDIUM CVE-2026-59997openssh-client-common10.3_p1-r0 10.3_p1-r1openssh: OpenSSH: SFTP security bypass due to command-line argument parsing flaw — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1)
MEDIUM CVE-2026-59996openssh-client-common10.3_p1-r0 10.3_p1-r1openssh: OpenSSH: `scp` file misplacement vulnerability during remote copy — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1)
MEDIUM CVE-2026-59995openssh-client-common10.3_p1-r0 10.3_p1-r1openssh: OpenSSH: sftp client allows attacker to control downloaded file location — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1)
LOW CVE-2026-18924libcurl8.21.0-r0 8.22.0-r0curl: libcurl: Use-after-free in HTTP/2 Server Push with shared connections — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1)
LOW CVE-2026-73281openssh-client-common10.3_p1-r0 10.3_p1-r1openssh: OpenSSH: ssh-agent allows remote execution of local operations — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1)
LOW CVE-2026-18924curl8.21.0-r0 8.22.0-r0curl: libcurl: Use-after-free in HTTP/2 Server Push with shared connections — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1)
LOW CVE-2026-73281openssh-client-default10.3_p1-r0 10.3_p1-r1openssh: OpenSSH: ssh-agent allows remote execution of local operations — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1)
LOW CVE-2026-73281openssh-keygen10.3_p1-r0 10.3_p1-r1openssh: OpenSSH: ssh-agent allows remote execution of local operations — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1)
UNKNOWN CVE-2026-80231libcurl8.21.0-r0 8.22.0-r0native CA store conn reuse — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1)
UNKNOWN CVE-2026-80256libcurl8.21.0-r0 8.22.0-r0ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1)
UNKNOWN CVE-2026-82208curl8.21.0-r0 8.22.0-r0With the wolfSSL backend, when CA caching is enabled and an `CURLOPT_S ... — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1)
UNKNOWN CVE-2026-80256curl8.21.0-r0 8.22.0-r0ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1)
UNKNOWN CVE-2026-80231curl8.21.0-r0 8.22.0-r0native CA store conn reuse — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1)
UNKNOWN CVE-2026-82208libcurl8.21.0-r0 8.22.0-r0With the wolfSSL backend, when CA caching is enabled and an `CURLOPT_S ... — ghcr.io/voxpupuli/r10k:latest (alpine 3.24.1)
UNKNOWN CVE-2026-39824golang.org/x/sysv0.43.0 0.44.0Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows — usr/local/bin/supercronic-linux-amd64

Grype

CRITICAL 7 HIGH 32 MEDIUM 21 LOW 7 UNKNOWN 2 NVD/CPE filtered 27
SeverityIDPackageInstalledFixedTitle / target
CRITICAL CVE-2026-60002openssh-keygen10.3_p1-r0 10.3_p1-r1/lib/apk/db/installed
CRITICAL CVE-2026-60002openssh-client-default10.3_p1-r0 10.3_p1-r1/lib/apk/db/installed
CRITICAL CVE-2026-60002openssh-client-common10.3_p1-r0 10.3_p1-r1/lib/apk/db/installed
CRITICAL CVE-2026-18924libcurl8.21.0-r0 8.22.0-r0/lib/apk/db/installed
CRITICAL CVE-2026-18924curl8.21.0-r0 8.22.0-r0/lib/apk/db/installed
CRITICAL CVE-2026-19931curl8.21.0-r0 8.22.0-r0/lib/apk/db/installed
CRITICAL CVE-2026-19931libcurl8.21.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-80230libcurl8.21.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-82209curl8.21.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-82209libcurl8.21.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-60000openssh-client-common10.3_p1-r0 10.3_p1-r1/lib/apk/db/installed
HIGH CVE-2026-60000openssh-client-default10.3_p1-r0 10.3_p1-r1/lib/apk/db/installed
HIGH CVE-2026-60000openssh-keygen10.3_p1-r0 10.3_p1-r1/lib/apk/db/installed
HIGH CVE-2026-82208curl8.21.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-82208libcurl8.21.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-76641libexpat2.8.3-r0 2.8.4-r0/lib/apk/db/installed
HIGH GHSA-q339-8rmv-2mhverb4.0.4 4.0.4.1ERB has an @_init deserialization guard bypass via def_module / def_method / def_class — /usr/lib/ruby/gems/3.4.0/specifications/default/erb-4.0.4.gemspec
HIGH CVE-2026-76956libexpat2.8.3-r0 2.8.4-r0/lib/apk/db/installed
HIGH CVE-2026-76957libexpat2.8.3-r0 2.8.4-r0/lib/apk/db/installed
HIGH CVE-2026-59999openssh-keygen10.3_p1-r0 10.3_p1-r1/lib/apk/db/installed
HIGH CVE-2026-59999openssh-client-default10.3_p1-r0 10.3_p1-r1/lib/apk/db/installed
HIGH CVE-2026-59999openssh-client-common10.3_p1-r0 10.3_p1-r1/lib/apk/db/installed
HIGH CVE-2026-80231curl8.21.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-80231libcurl8.21.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-80229curl8.21.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-80229libcurl8.21.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH GO-2026-4918stdlibgo1.26.2 1.25.10, 1.26.3When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0. — /usr/local/bin/supercronic-linux-amd64
HIGH GO-2026-5026stdlibgo1.26.2 1.25.13, 1.26.6, 1.27.0-rc.3The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com". — /usr/local/bin/supercronic-linux-amd64
HIGH CVE-2026-80255curl8.21.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-80255libcurl8.21.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-80230curl8.21.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH GO-2026-6089stdlibgo1.26.2 1.25.13, 1.26.6, 1.27.0-rc.3When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this. — /usr/local/bin/supercronic-linux-amd64
HIGH GO-2026-5972stdlibgo1.26.2 1.25.13, 1.26.6, 1.27.0-rc.3Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures. — /usr/local/bin/supercronic-linux-amd64
HIGH GO-2026-6090stdlibgo1.26.2 1.25.13, 1.26.6, 1.27.0-rc.3Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely. — /usr/local/bin/supercronic-linux-amd64
HIGH GO-2026-4971stdlibgo1.26.2 1.25.10, 1.26.3The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0). — /usr/local/bin/supercronic-linux-amd64
HIGH GO-2026-5037stdlibgo1.26.2 1.25.11, 1.26.4(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates. — /usr/local/bin/supercronic-linux-amd64
HIGH CVE-2026-66046libexpat2.8.3-r0 2.8.4-r0/lib/apk/db/installed
HIGH CVE-2026-13608libcurl8.21.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-13608curl8.21.0-r0 8.22.0-r0/lib/apk/db/installed
MEDIUM CVE-2026-73282openssh-client-default10.3_p1-r0 10.3_p1-r1/lib/apk/db/installed
MEDIUM CVE-2026-73282openssh-client-common10.3_p1-r0 10.3_p1-r1/lib/apk/db/installed
MEDIUM CVE-2026-59997openssh-keygen10.3_p1-r0 10.3_p1-r1/lib/apk/db/installed
MEDIUM CVE-2026-59997openssh-client-default10.3_p1-r0 10.3_p1-r1/lib/apk/db/installed
MEDIUM CVE-2026-59997openssh-client-common10.3_p1-r0 10.3_p1-r1/lib/apk/db/installed
MEDIUM CVE-2026-59998openssh-keygen10.3_p1-r0 10.3_p1-r1/lib/apk/db/installed
MEDIUM CVE-2026-59998openssh-client-default10.3_p1-r0 10.3_p1-r1/lib/apk/db/installed
MEDIUM CVE-2026-59998openssh-client-common10.3_p1-r0 10.3_p1-r1/lib/apk/db/installed
MEDIUM CVE-2026-73282openssh-keygen10.3_p1-r0 10.3_p1-r1/lib/apk/db/installed
MEDIUM CVE-2026-59995openssh-keygen10.3_p1-r0 10.3_p1-r1/lib/apk/db/installed
MEDIUM CVE-2026-59995openssh-client-default10.3_p1-r0 10.3_p1-r1/lib/apk/db/installed
MEDIUM CVE-2026-59995openssh-client-common10.3_p1-r0 10.3_p1-r1/lib/apk/db/installed
MEDIUM CVE-2026-59996openssh-keygen10.3_p1-r0 10.3_p1-r1/lib/apk/db/installed
MEDIUM CVE-2026-59996openssh-client-default10.3_p1-r0 10.3_p1-r1/lib/apk/db/installed
MEDIUM CVE-2026-59996openssh-client-common10.3_p1-r0 10.3_p1-r1/lib/apk/db/installed
MEDIUM CVE-2026-60001openssh-keygen10.3_p1-r0 10.3_p1-r1/lib/apk/db/installed
MEDIUM CVE-2026-60001openssh-client-default10.3_p1-r0 10.3_p1-r1/lib/apk/db/installed
MEDIUM CVE-2026-60001openssh-client-common10.3_p1-r0 10.3_p1-r1/lib/apk/db/installed
MEDIUM GO-2026-5039stdlibgo1.26.2 1.25.11, 1.26.4When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or logged. — /usr/local/bin/supercronic-linux-amd64
MEDIUM GO-2026-5856stdlibgo1.26.2 1.25.12, 1.26.5, 1.27.0-rc.2Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello. — /usr/local/bin/supercronic-linux-amd64
MEDIUM GO-2026-6218stdlibgo1.26.2 1.25.13, 1.26.6, 1.27.0-rc.3Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations. — /usr/local/bin/supercronic-linux-amd64
LOW CVE-2026-73283openssh-keygen10.3_p1-r0 10.3_p1-r1/lib/apk/db/installed
LOW CVE-2026-73283openssh-client-default10.3_p1-r0 10.3_p1-r1/lib/apk/db/installed
LOW CVE-2026-73283openssh-client-common10.3_p1-r0 10.3_p1-r1/lib/apk/db/installed
LOW CVE-2026-73281openssh-keygen10.3_p1-r0 10.3_p1-r1/lib/apk/db/installed
LOW CVE-2026-73281openssh-client-default10.3_p1-r0 10.3_p1-r1/lib/apk/db/installed
LOW CVE-2026-73281openssh-client-common10.3_p1-r0 10.3_p1-r1/lib/apk/db/installed
LOW GHSA-x2f5-4prf-w687json2.9.1 2.19.9Ruby json: JSON generator heap buffer overflow when streaming to an IO — /usr/lib/ruby/gems/3.4.0/specifications/default/json-2.9.1.gemspec
UNKNOWN CVE-2026-80256curl8.21.0-r0 8.22.0-r0/lib/apk/db/installed
UNKNOWN CVE-2026-80256libcurl8.21.0-r0 8.22.0-r0/lib/apk/db/installed
Filtered NVD/CPE matches (27)

These broad CPE matches are unconfirmed for the distribution package and excluded from scanner totals.

SeverityIDPackageInstalledFixedTitle / target
HIGH CVE-2026-59849libssh21.11.1-r3 A flaw was found in libssh. Logic errors in automatic certificate-based public key authentication can cause libssh clients to loop indefinitely when configured certificates are missing or repeatedly rejected by a server, leading to denial of service. — /lib/apk/db/installed
HIGH CVE-2026-15370libssh21.11.1-r3 A flaw was found in libssh. During SFTP server directory listing, the longname field is constructed with unsafe concatenation into a fixed-size stack buffer. When a client causes the server to list attacker-controlled filenames, sufficiently long names can overflow that stack buffer and may lead to crashes or possible code execution on the server. — /lib/apk/db/installed
HIGH CVE-2026-89161pcre210.47-r1 In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context. An incorrect free operation can occur. — /lib/apk/db/installed
HIGH CVE-2026-58051libssh21.11.1-r3 libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsing populates them, so a parse failure reaching the cleanup path leaves libssh2_publickey_list_free operating on an uninitialized entry. A malicious SSH server offering the publickey subsystem can use a malformed response to make cleanup free an uninitialized, attacker-influenceable attrs pointer in a connecting libssh2 client. — /lib/apk/db/installed
HIGH CVE-2026-59850libssh21.11.1-r3 A flaw was found in libssh. If data packets are processed after a channel is closed, channel data callbacks can be invoked after the associated data has already been freed, leading to crashes or possible use-after-free conditions. — /lib/apk/db/installed
HIGH CVE-2026-59851libssh21.11.1-r3 A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssapi-keyex path does not verify whether the authenticated Kerberos principal is authorized for the requested local user, allowing authenticated clients to log in as arbitrary users. — /lib/apk/db/installed
HIGH CVE-2026-66034libssh21.11.1-r3 libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitrary-length heap out-of-bounds read and a free of an uninitialized pointer via the publickey subsystem. In libssh2_publickey_list_fetch(), the version 1 response parser reads a server-controlled comment_len value and advances the parse pointer without verifying sufficient bytes remain in the buffer, causing the out-of-bounds read to leak heap pointers from adjacent allocations defeating ASLR, followed by heap allocator state corruption when the error cleanup path frees an uninitialized pointer from a non-zeroed realloc() region. — /lib/apk/db/installed
HIGH CVE-2026-89157pcre210.47-r1 PCRE2 before 10.48, on 32-bit platforms, has a pcre2_pattern_convert out-of-bounds write when an attacker can provide a large pattern. — /lib/apk/db/installed
HIGH CVE-2026-58050libssh21.11.1-r3 libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attrs * sizeof(libssh2_publickey_attribute) without bounds checking, so on 32-bit platforms the multiplication overflows to an undersized buffer. A malicious SSH server can then drive the attribute-parsing loop to write past the allocation, causing a heap buffer overflow in a connecting libssh2 client. — /lib/apk/db/installed
HIGH CVE-2026-66035libssh21.11.1-r3 libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that allows a malicious SSH server to corrupt heap metadata in any connecting client by sending a packet with a packet_length smaller than the cipher's block size during Encrypt-then-MAC cipher negotiation. In the fullpacket() function in src/transport.c, the ETM path allocates a buffer of packet_length bytes but copies blocksize minus one bytes via memcpy, causing an overflow that on 32-bit glibc writes attacker-controlled bytes into an adjacent chunk's SIZE field, enabling tcache bin confusion, overlapping live objects, and function pointer overwrite during the session handshake before authentication. — /lib/apk/db/installed
HIGH CVE-2026-66032libssh21.11.1-r3 libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt the heap of any authenticated client opening an SFTP session. When a server responds to SSH_FXP_OPEN with SSH_FXP_STATUS containing FX_OK, the response data buffer is freed, and if a subsequent sftp_packet_require() call returns a specific error such as LIBSSH2_ERROR_CHANNEL_PACKET_EXCEEDED, the same pointer is freed a second time, enabling tcache dup conditions on glibc systems that allow overlapping allocations and function pointer overwrites. — /lib/apk/db/installed
HIGH CVE-2026-66033libssh21.11.1-r3 libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in src/openssl.c that allows a malicious SSH server to crash any connecting client by negotiating AES-GCM ciphers during handshake. Attackers can exploit the underflow in the expression computing blocksize minus aadlen minus authentication tag length to trigger an out-of-bounds read and a memcpy call with a near-SIZE_MAX length argument, causing immediate process crash before any authentication occurs. — /lib/apk/db/installed
MEDIUM CVE-2026-59845libssh21.11.1-r3 A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may then be sent across the caller's accessible process tree, leading to local denial of service. — /lib/apk/db/installed
MEDIUM CVE-2026-89156pcre210.47-r1 PCRE2 before 10.48 has a pcre2_match out-of-bounds read after a JIT fallback when an attacker can provide invalid UTF data. — /lib/apk/db/installed
MEDIUM CVE-2026-89160pcre210.47-r1 PCRE2 before 10.48 has a pcre2_match out-of-bounds read during the PCRE2_MATCH_INVALID_UTF matching of an invalid UTF subject. — /lib/apk/db/installed
MEDIUM CVE-2026-89158pcre210.47-r1 PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 integer overflow and resultant out-of-bounds write. — /lib/apk/db/installed
MEDIUM CVE-2026-58055nghttp2-libs1.69.0-r0 nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning. — /lib/apk/db/installed
MEDIUM CVE-2025-60876ssl_client1.37.0-r31 BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed
MEDIUM CVE-2025-60876busybox-binsh1.37.0-r31 BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed
MEDIUM CVE-2025-60876busybox1.37.0-r31 BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed
MEDIUM CVE-2026-59848libssh21.11.1-r3 A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh clients keep queued indefinitely, causing unbounded memory growth and client-side denial of service. — /lib/apk/db/installed
MEDIUM CVE-2026-59842libssh21.11.1-r3 A flaw was found in libssh. During server-side GSSAPI key exchange, a client-supplied Curve25519 public key shorter than the expected length is copied without proper length validation, leading to an out-of-bounds heap read. This could allow a remote unauthenticated attacker to disclose small amounts of server memory. — /lib/apk/db/installed
MEDIUM CVE-2026-59844libssh21.11.1-r3 A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large length, causing a libssh SFTP server to allocate excessive memory and potentially exhaust it through repeated requests. — /lib/apk/db/installed
MEDIUM CVE-2026-59843libssh21.11.1-r3 A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel writes to loop indefinitely and consume CPU, leading to denial of service. — /lib/apk/db/installed
MEDIUM CVE-2025-15661libssh21.11.1-r3 libssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bounds heap read vulnerability in the sftp_symlink() function in src/sftp.c that allows a malicious SSH server or man-in-the-middle attacker to disclose heap memory contents or cause a crash by sending a crafted SSH_FXP_NAME response. Attackers can supply a link_len value larger than the actual packet data in SSH_FXP_NAME responses for SFTP READLINK and REALPATH operations, triggering a heap buffer over-read of up to target_len minus one bytes due to the missing validation of available packet buffer size before the memcpy operation. — /lib/apk/db/installed
LOW CVE-2026-59846libssh21.11.1-r3 A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing unintended shell behavior. — /lib/apk/db/installed
LOW CVE-2026-89162pcre210.47-r1 In PCRE2 before 10.48, pcre2_serialize_encode might disclose two bytes to an adversary, typically in a situation where the access available to the adversary is already unsafe. — /lib/apk/db/installed

ghcr.io/voxpupuli/renovate

GitHub Container Registry

Downloads

6,979 downloads

ghcr.io/voxpupuli/renovate:latest (2026-09-17)

Trivy

HIGH 4 MEDIUM 8
SeverityIDPackageInstalledFixedTitle / target
HIGH CVE-2026-14257brace-expansion5.0.7 5.0.8, 3.0.3, 2.1.3, 1.1.17brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function — Node.js
HIGH CVE-2026-69152brace-expansion5.0.7 1.1.18, 2.1.4, 3.0.6, 5.0.9brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation — Node.js
HIGH CVE-2026-69192ip-address10.2.0 10.3.1ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass — Node.js
HIGH CVE-2026-73566tar7.5.19 7.5.21tar: node-tar: Denial of Service via crafted long-path tar archive — Node.js
MEDIUM CVE-2026-76845adm-zip0.6.0 adm-zip: adm-zip: Arbitrary File Overwrite via Symlink Following — Node.js
MEDIUM CVE-2026-54272ip-address10.2.0 10.2.1ip-address: ip-address: Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification — Node.js
MEDIUM CVE-2026-69198ip-address10.2.0 10.2.2ip-address: ip-address: Server-Side Request Forgery (SSRF) and trust-boundary bypass — Node.js
MEDIUM CVE-2026-82417qs6.15.3 6.16.0qs: qs: Denial of Service via improper validation in stringify function — Node.js
MEDIUM CVE-2026-82562qs6.15.3 6.16.0qs: qs: Denial of Service via array limit bypass in query string parsing — Node.js
MEDIUM CVE-2026-15157undici6.27.0 6.28.0, 7.29.0, 8.9.0undici: undici: HTTP header injection via unvalidated blob-like body type property — Node.js
MEDIUM CVE-2026-16728undici6.27.0 6.28.0, 7.29.0, 8.9.0undici: undici: Response desynchronization via retry interceptor with mismatched Content-Length — Node.js
MEDIUM CVE-2026-16729undici6.27.0 6.28.0, 7.29.0, 8.9.0undici: Undici: Cookie attribute injection allows bypassing security protections — Node.js

Grype

HIGH 4 MEDIUM 8 NVD/CPE filtered 4
SeverityIDPackageInstalledFixedTitle / target
HIGH GHSA-mh99-v99m-4gvgbrace-expansion5.0.7 5.0.8brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash — /usr/local/lib/node_modules/npm/node_modules/brace-expansion/package.json
HIGH GHSA-rgw5-rvv9-x895brace-expansion5.0.7 5.0.9brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation — /usr/local/lib/node_modules/npm/node_modules/brace-expansion/package.json
HIGH GHSA-r292-9mhp-454mtar7.5.19 7.5.21node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection — /usr/local/lib/node_modules/npm/node_modules/tar/package.json
HIGH GHSA-mwp4-54f8-5fhrip-address10.2.0 10.3.1ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass — /usr/local/lib/node_modules/npm/node_modules/ip-address/package.json
MEDIUM GHSA-4xrf-jv44-h6hhip-address10.2.0 10.2.2ip-address: a CIDR suffix on the parsed address suppresses special-use classification and can bypass SSRF and trust-boundary checks — /usr/local/lib/node_modules/npm/node_modules/ip-address/package.json
MEDIUM GHSA-22jq-vg5j-6vggip-address10.2.0 10.2.1ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSRF and trust-boundary checks — /usr/local/lib/node_modules/npm/node_modules/ip-address/package.json
MEDIUM GHSA-x5fp-wj9c-mxmxqs6.15.3 6.16.0qs array-limit bypass via bracket-key comma parsing — /npm/node_modules/qs/package.json
MEDIUM GHSA-4mjr-xmp4-gh2gqs6.15.3 6.16.0qs: Denial of Service via Attacker Controlled isBuffer — /npm/node_modules/qs/package.json
MEDIUM GHSA-v3r7-h72x-cjcmundici6.27.0 6.28.0undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields — /usr/local/lib/node_modules/npm/node_modules/undici/package.json
MEDIUM GHSA-m8rv-5g2x-5cg5undici6.27.0 6.28.0undici vulnerable to CRLF Injection via blob-like body 'type' property — /usr/local/lib/node_modules/npm/node_modules/undici/package.json
MEDIUM GHSA-8xcm-r25x-g524undici6.27.0 6.28.0undici vulnerable to downstream response desynchronization via retry interceptor — /usr/local/lib/node_modules/npm/node_modules/undici/package.json
MEDIUM GHSA-vwc7-r8mq-g2x9adm-zip0.6.0 adm-zip extraction follows destination symlinks, allowing arbitrary file overwrite — /npm/node_modules/adm-zip/package.json
Filtered NVD/CPE matches (4)

These broad CPE matches are unconfirmed for the distribution package and excluded from scanner totals.

SeverityIDPackageInstalledFixedTitle / target
MEDIUM CVE-2025-60876busybox1.37.0-r31 BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed
MEDIUM CVE-2025-60876busybox-binsh1.37.0-r31 BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed
MEDIUM CVE-2025-60876ssl_client1.37.0-r31 BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed
MEDIUM CVE-2026-58055nghttp2-libs1.69.0-r0 nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning. — /lib/apk/db/installed

ghcr.io/voxpupuli/semantic-release

GitHub Container Registry

Downloads

10,039 downloads

ghcr.io/voxpupuli/semantic-release:latest (2026-08-27)

Trivy

CRITICAL 3 HIGH 25 MEDIUM 60 LOW 5 UNKNOWN 6
SeverityIDPackageInstalledFixedTitle / target
CRITICAL CVE-2026-60002openssh-client-common10.3_p1-r0 10.3_p1-r1openssh: OpenSSH: Use-after-free vulnerability during host key re-exchange on the client side — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.1)
CRITICAL CVE-2026-60002openssh-keygen10.3_p1-r0 10.3_p1-r1openssh: OpenSSH: Use-after-free vulnerability during host key re-exchange on the client side — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.1)
CRITICAL CVE-2026-60002openssh-client-default10.3_p1-r0 10.3_p1-r1openssh: OpenSSH: Use-after-free vulnerability during host key re-exchange on the client side — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.1)
HIGH CVE-2026-60000openssh-keygen10.3_p1-r0 10.3_p1-r1openssh: OpenSSH: Denial of Service via excessive GSSAPI authentication attempts — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.1)
HIGH CVE-2026-66046libexpat2.8.3-r0 2.8.4-r0expat: Expat: Denial of Service via quadratic complexity in attribute processing — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.1)
HIGH CVE-2026-76956libexpat2.8.3-r0 2.8.4-r0libexpat: libexpat: Denial of Service via hash flooding attack with crafted XML — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.1)
HIGH CVE-2026-76957libexpat2.8.3-r0 2.8.4-r0libexpat: libexpat: Memory corruption vulnerability allows arbitrary code execution or denial of service — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.1)
HIGH CVE-2026-59999openssh-keygen10.3_p1-r0 10.3_p1-r1openssh: OpenSSH sshd: Security bypass due to incorrect handling of forwarding and tunneling options — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.1)
HIGH CVE-2026-59999openssh-client-common10.3_p1-r0 10.3_p1-r1openssh: OpenSSH sshd: Security bypass due to incorrect handling of forwarding and tunneling options — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.1)
HIGH CVE-2026-60000openssh-client-common10.3_p1-r0 10.3_p1-r1openssh: OpenSSH: Denial of Service via excessive GSSAPI authentication attempts — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.1)
HIGH CVE-2026-14257brace-expansion5.0.7 5.0.8, 3.0.3, 2.1.3, 1.1.17brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function — Node.js
HIGH CVE-2026-69152brace-expansion5.0.7 1.1.18, 2.1.4, 3.0.6, 5.0.9brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation — Node.js
HIGH CVE-2026-69192ip-address10.2.0 10.3.1ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass — Node.js
HIGH CVE-2026-73566tar7.5.19 7.5.21tar: node-tar: Denial of Service via crafted long-path tar archive — Node.js
HIGH CVE-2026-60000openssh-client-default10.3_p1-r0 10.3_p1-r1openssh: OpenSSH: Denial of Service via excessive GSSAPI authentication attempts — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.1)
HIGH CVE-2026-56862stdlibv1.26.4 1.25.13, 1.26.6, 1.27.0-rc.3crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc
HIGH CVE-2026-56860stdlibv1.26.4 1.25.13, 1.26.6, 1.27.0-rc.3net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc
HIGH CVE-2026-56859stdlibv1.26.4 1.25.13, 1.26.6, 1.27.0-rc.3encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc
HIGH CVE-2026-56858stdlibv1.26.4 1.25.13, 1.26.6, 1.27.0-rc.3html/template: golang: Go html/template: Cross-Site Scripting via pathological input — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc
HIGH CVE-2026-56853stdlibv1.26.4 1.25.13, 1.26.6, 1.27.0-rc.3net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc
HIGH CVE-2026-46600stdlibv1.26.4 1.26.6, 1.27.0-rc.3golang.org/x/net/dns/dnsmessage: golang.org/x/net/dns/dnsmessage: Denial of Service via invalid DNS record parsing — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc
HIGH CVE-2026-39822stdlibv1.26.4 1.25.12, 1.26.5, 1.27.0-rc.2golang: Go os.Root: Symlink following vulnerability allows directory traversal — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc
HIGH CVE-2026-39821stdlibv1.26.4 1.25.13, 1.26.6, 1.27.0-rc.3golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc
HIGH CVE-2026-33818stdlibv1.26.4 1.25.13, 1.26.6, 1.27.0-rc.3encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc
HIGH CVE-2026-32316jq1.8.1-r0 1.8.2-r0jq: jq: Denial of Service or potential arbitrary code execution due to integer overflow and heap-based buffer overflow — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.1)
HIGH CVE-2026-40164jq1.8.1-r0 1.8.2-r0jq: jq: Denial of Service via crafted JSON object causing hash collisions — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.1)
HIGH CVE-2026-56852golang.org/x/textv0.38.0 0.39.0golang.org/x/text: golang.org/x/text: Denial of Service via invalid UTF-8 input — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc
HIGH CVE-2026-59999openssh-client-default10.3_p1-r0 10.3_p1-r1openssh: OpenSSH sshd: Security bypass due to incorrect handling of forwarding and tunneling options — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.1)
MEDIUM CVE-2026-60001openssh-client-default10.3_p1-r0 10.3_p1-r1openssh: OpenSSH: Brute-force attacks facilitated due to insufficient authentication delay — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.1)
MEDIUM CVE-2026-73282openssh-client-default10.3_p1-r0 10.3_p1-r1openssh: OpenSSH: Information disclosure and data corruption via use-after-free in ssh client — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.1)
MEDIUM CVE-2026-73283openssh-client-default10.3_p1-r0 10.3_p1-r1openssh: OpenSSH: Tunnel forwarding restriction bypass — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.1)
MEDIUM CVE-2026-59998openssh-client-default10.3_p1-r0 10.3_p1-r1openssh: OpenSSH: Undocumented GSSAPIStrictAcceptorCheck behavior impacts security in Windows Active Directory — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.1)
MEDIUM CVE-2026-59997openssh-client-default10.3_p1-r0 10.3_p1-r1openssh: OpenSSH: SFTP security bypass due to command-line argument parsing flaw — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.1)
MEDIUM CVE-2026-59996openssh-client-default10.3_p1-r0 10.3_p1-r1openssh: OpenSSH: `scp` file misplacement vulnerability during remote copy — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.1)
MEDIUM CVE-2026-59995openssh-client-default10.3_p1-r0 10.3_p1-r1openssh: OpenSSH: sftp client allows attacker to control downloaded file location — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.1)
MEDIUM CVE-2026-42505stdlibv1.26.4 1.25.12, 1.26.5, 1.27.0-rc.2crypto/tls: golang: Go crypto/tls: Information disclosure in Encrypted Client Hello — npm/node_modules/@typescript/typescript-linux-x64/lib/tsc
MEDIUM CVE-2026-16729undici6.27.0 6.28.0, 7.29.0, 8.9.0undici: Undici: Cookie attribute injection allows bypassing security protections — Node.js
MEDIUM CVE-2026-16728undici6.27.0 6.28.0, 7.29.0, 8.9.0undici: undici: Response desynchronization via retry interceptor with mismatched Content-Length — Node.js
MEDIUM CVE-2026-15157undici6.27.0 6.28.0, 7.29.0, 8.9.0undici: undici: HTTP header injection via unvalidated blob-like body type property — Node.js
MEDIUM CVE-2026-69198ip-address10.2.0 10.2.2ip-address: ip-address: Server-Side Request Forgery (SSRF) and trust-boundary bypass — Node.js
MEDIUM CVE-2026-54272ip-address10.2.0 10.2.1ip-address: ip-address: Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification — Node.js
MEDIUM CVE-2025-25289@octokit/request-error3.0.3 5.1.1, 6.1.7@octokit/request-error: @octokit/request-error has a Regular Expression in index that Leads to ReDoS Vulnerability Due to Catastrophic Backtracking — Node.js
MEDIUM CVE-2025-25289@octokit/request-error2.1.0 5.1.1, 6.1.7@octokit/request-error: @octokit/request-error has a Regular Expression in index that Leads to ReDoS Vulnerability Due to Catastrophic Backtracking — Node.js
MEDIUM CVE-2025-25290@octokit/request6.2.8 9.2.1, 8.4.1octokit/request: @octokit/request has a Regular Expression in fetchWrapper that Leads to ReDoS Vulnerability Due to Catastrophic Backtracking — Node.js
MEDIUM CVE-2025-25290@octokit/request5.6.3 9.2.1, 8.4.1octokit/request: @octokit/request has a Regular Expression in fetchWrapper that Leads to ReDoS Vulnerability Due to Catastrophic Backtracking — Node.js
MEDIUM CVE-2025-25288@octokit/plugin-paginate-rest6.1.2 11.4.1, 9.2.2octokit/plugin-paginate-rest: @octokit/plugin-paginate-rest has a Regular Expression in iterator that Leads to ReDoS Vulnerability Due to Catastrophic Backtracking — Node.js
MEDIUM CVE-2025-25288@octokit/plugin-paginate-rest2.21.3 11.4.1, 9.2.2octokit/plugin-paginate-rest: @octokit/plugin-paginate-rest has a Regular Expression in iterator that Leads to ReDoS Vulnerability Due to Catastrophic Backtracking — Node.js
MEDIUM CVE-2026-73283openssh-keygen10.3_p1-r0 10.3_p1-r1openssh: OpenSSH: Tunnel forwarding restriction bypass — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.1)
MEDIUM CVE-2026-73282openssh-keygen10.3_p1-r0 10.3_p1-r1openssh: OpenSSH: Information disclosure and data corruption via use-after-free in ssh client — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.1)
MEDIUM CVE-2026-60001openssh-keygen10.3_p1-r0 10.3_p1-r1openssh: OpenSSH: Brute-force attacks facilitated due to insufficient authentication delay — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.1)
MEDIUM CVE-2026-59998openssh-keygen10.3_p1-r0 10.3_p1-r1openssh: OpenSSH: Undocumented GSSAPIStrictAcceptorCheck behavior impacts security in Windows Active Directory — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.1)
MEDIUM CVE-2026-59997openssh-keygen10.3_p1-r0 10.3_p1-r1openssh: OpenSSH: SFTP security bypass due to command-line argument parsing flaw — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.1)
MEDIUM CVE-2026-59996openssh-keygen10.3_p1-r0 10.3_p1-r1openssh: OpenSSH: `scp` file misplacement vulnerability during remote copy — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.1)
MEDIUM CVE-2026-59995openssh-keygen10.3_p1-r0 10.3_p1-r1openssh: OpenSSH: sftp client allows attacker to control downloaded file location — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.1)
MEDIUM CVE-2026-73283openssh-client-common10.3_p1-r0 10.3_p1-r1openssh: OpenSSH: Tunnel forwarding restriction bypass — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.1)
MEDIUM CVE-2026-54679jq1.8.1-r0 1.8.2-r0jq: jq: Denial of Service via integer overflow and buffer overrun on 32-bit systems — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.1)
MEDIUM CVE-2026-49839jq1.8.1-r0 1.8.2-r0jq: jq: Heap out-of-bounds write via oversized raw file processing — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.1)
MEDIUM CVE-2026-47770jq1.8.1-r0 1.8.2-r0jq: jq: Denial of Service via deeply nested array comparison — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.1)
MEDIUM CVE-2026-44777jq1.8.1-r0 1.8.2-r0jq: stack overflow in module loading on mutual include — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.1)
MEDIUM CVE-2026-43896jq1.8.1-r0 1.8.2-r0jq: stack overflow in recursive object merge — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.1)
MEDIUM CVE-2026-43895jq1.8.1-r0 1.8.2-r0jq: embedded NUL in jq import paths causes local redaction-policy bypass and preserves sensitive fields in published artifacts — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.1)
MEDIUM CVE-2026-43894jq1.8.1-r0 1.8.2-r0jq: jq: Arbitrary Code Execution or Denial of Service via Signed Integer Overflow — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.1)
MEDIUM CVE-2026-41257jq1.8.1-r0 1.8.2-r0jq: signed-int overflow in stack_reallocate — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.1)
MEDIUM CVE-2026-41256jq1.8.1-r0 1.8.2-r0jq: embedded NUL truncates top-level jq programs loaded with -f — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.1)
MEDIUM CVE-2026-40612jq1.8.1-r0 1.8.2-r0jq: stack overflow via unbounded recursion in jv_contains — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.1)
MEDIUM CVE-2026-39979jq1.8.1-r0 1.8.2-r0jq: out-of-bounds read in jv_parse_sized() on error formatting for non-NUL-terminated buffers — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.1)
MEDIUM CVE-2026-39956jq1.8.1-r0 1.8.2-r0jq: missing runtime type checks for _strindices lead to crash and limited memory disclosure — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.1)
MEDIUM CVE-2026-33948jq1.8.1-r0 1.8.2-r0jq: jq: Input validation bypass via embedded NUL bytes allows parser differential attacks — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.1)
MEDIUM CVE-2026-33947jq1.8.1-r0 1.8.2-r0jq: unbounded Recursion in jv_setpath() / jv_getpath() / delpaths_sorted() — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.1)
MEDIUM CVE-2026-82209curl8.21.0-r0 8.22.0-r0When libpsl support is enabled, libcurl fails to enforce the Public Su ... — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.1)
MEDIUM CVE-2026-80255curl8.21.0-r0 8.22.0-r0A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instea ... — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.1)
MEDIUM CVE-2026-80230curl8.21.0-r0 8.22.0-r0When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that di ... — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.1)
MEDIUM CVE-2026-80229curl8.21.0-r0 8.22.0-r0When performing transfers via libcurl\u2019s multi interface, pooled T ... — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.1)
MEDIUM CVE-2026-19931curl8.21.0-r0 8.22.0-r0curl: libcurl: Information disclosure via incorrect connection reuse with Negotiate authentication — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.1)
MEDIUM CVE-2026-13608curl8.21.0-r0 8.22.0-r0A flaw in the libcurl SASL negotiation for LDAP authentication allows ... — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.1)
MEDIUM CVE-2026-73282openssh-client-common10.3_p1-r0 10.3_p1-r1openssh: OpenSSH: Information disclosure and data corruption via use-after-free in ssh client — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.1)
MEDIUM CVE-2026-60001openssh-client-common10.3_p1-r0 10.3_p1-r1openssh: OpenSSH: Brute-force attacks facilitated due to insufficient authentication delay — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.1)
MEDIUM CVE-2026-59998openssh-client-common10.3_p1-r0 10.3_p1-r1openssh: OpenSSH: Undocumented GSSAPIStrictAcceptorCheck behavior impacts security in Windows Active Directory — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.1)
MEDIUM CVE-2026-59997openssh-client-common10.3_p1-r0 10.3_p1-r1openssh: OpenSSH: SFTP security bypass due to command-line argument parsing flaw — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.1)
MEDIUM CVE-2026-59996openssh-client-common10.3_p1-r0 10.3_p1-r1openssh: OpenSSH: `scp` file misplacement vulnerability during remote copy — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.1)
MEDIUM CVE-2026-59995openssh-client-common10.3_p1-r0 10.3_p1-r1openssh: OpenSSH: sftp client allows attacker to control downloaded file location — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.1)
MEDIUM CVE-2026-76641libexpat2.8.3-r0 2.8.4-r0CVE-2026-76641 affecting package expat for versions less than 2.8.3-2 — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.1)
MEDIUM CVE-2026-13608libcurl8.21.0-r0 8.22.0-r0A flaw in the libcurl SASL negotiation for LDAP authentication allows ... — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.1)
MEDIUM CVE-2026-19931libcurl8.21.0-r0 8.22.0-r0curl: libcurl: Information disclosure via incorrect connection reuse with Negotiate authentication — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.1)
MEDIUM CVE-2026-82209libcurl8.21.0-r0 8.22.0-r0When libpsl support is enabled, libcurl fails to enforce the Public Su ... — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.1)
MEDIUM CVE-2026-80255libcurl8.21.0-r0 8.22.0-r0A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instea ... — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.1)
MEDIUM CVE-2026-80229libcurl8.21.0-r0 8.22.0-r0When performing transfers via libcurl\u2019s multi interface, pooled T ... — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.1)
MEDIUM CVE-2026-80230libcurl8.21.0-r0 8.22.0-r0When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that di ... — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.1)
LOW CVE-2026-73281openssh-client-common10.3_p1-r0 10.3_p1-r1openssh: OpenSSH: ssh-agent allows remote execution of local operations — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.1)
LOW CVE-2026-18924libcurl8.21.0-r0 8.22.0-r0curl: libcurl: Use-after-free in HTTP/2 Server Push with shared connections — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.1)
LOW CVE-2026-73281openssh-client-default10.3_p1-r0 10.3_p1-r1openssh: OpenSSH: ssh-agent allows remote execution of local operations — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.1)
LOW CVE-2026-73281openssh-keygen10.3_p1-r0 10.3_p1-r1openssh: OpenSSH: ssh-agent allows remote execution of local operations — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.1)
LOW CVE-2026-18924curl8.21.0-r0 8.22.0-r0curl: libcurl: Use-after-free in HTTP/2 Server Push with shared connections — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.1)
UNKNOWN CVE-2026-80231curl8.21.0-r0 8.22.0-r0native CA store conn reuse — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.1)
UNKNOWN CVE-2026-80256curl8.21.0-r0 8.22.0-r0ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.1)
UNKNOWN CVE-2026-82208curl8.21.0-r0 8.22.0-r0With the wolfSSL backend, when CA caching is enabled and an `CURLOPT_S ... — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.1)
UNKNOWN CVE-2026-82208libcurl8.21.0-r0 8.22.0-r0With the wolfSSL backend, when CA caching is enabled and an `CURLOPT_S ... — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.1)
UNKNOWN CVE-2026-80256libcurl8.21.0-r0 8.22.0-r0ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.1)
UNKNOWN CVE-2026-80231libcurl8.21.0-r0 8.22.0-r0native CA store conn reuse — ghcr.io/voxpupuli/semantic-release:latest (alpine 3.24.1)

Grype

CRITICAL 7 HIGH 40 MEDIUM 45 LOW 6 UNKNOWN 2 NVD/CPE filtered 10
SeverityIDPackageInstalledFixedTitle / target
CRITICAL CVE-2026-60002openssh-client-common10.3_p1-r0 10.3_p1-r1/lib/apk/db/installed
CRITICAL CVE-2026-60002openssh-client-default10.3_p1-r0 10.3_p1-r1/lib/apk/db/installed
CRITICAL CVE-2026-60002openssh-keygen10.3_p1-r0 10.3_p1-r1/lib/apk/db/installed
CRITICAL CVE-2026-18924libcurl8.21.0-r0 8.22.0-r0/lib/apk/db/installed
CRITICAL CVE-2026-18924curl8.21.0-r0 8.22.0-r0/lib/apk/db/installed
CRITICAL CVE-2026-19931libcurl8.21.0-r0 8.22.0-r0/lib/apk/db/installed
CRITICAL CVE-2026-19931curl8.21.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-80231libcurl8.21.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH GO-2026-5942stdlibgo1.26.3 1.26.6, 1.27.0-rc.3Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer. — /usr/bin/git-lfs
HIGH GO-2026-5970golang.org/x/textv0.37.0 0.39.0A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes. — /usr/bin/git-lfs
HIGH GO-2026-5970golang.org/x/textv0.38.0 0.39.0A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes. — /npm/node_modules/@typescript/typescript-linux-x64/lib/tsc
HIGH CVE-2026-60000openssh-client-common10.3_p1-r0 10.3_p1-r1/lib/apk/db/installed
HIGH CVE-2026-60000openssh-client-default10.3_p1-r0 10.3_p1-r1/lib/apk/db/installed
HIGH CVE-2026-60000openssh-keygen10.3_p1-r0 10.3_p1-r1/lib/apk/db/installed
HIGH CVE-2026-82208curl8.21.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-82208libcurl8.21.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-76641libexpat2.8.3-r0 2.8.4-r0/lib/apk/db/installed
HIGH GHSA-r292-9mhp-454mtar7.5.19 7.5.21node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection — /usr/local/lib/node_modules/npm/node_modules/tar/package.json
HIGH GHSA-mwp4-54f8-5fhrip-address10.2.0 10.3.1ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass — /usr/local/lib/node_modules/npm/node_modules/ip-address/package.json
HIGH CVE-2026-40164jq1.8.1-r0 1.8.2-r0/lib/apk/db/installed
HIGH CVE-2026-76956libexpat2.8.3-r0 2.8.4-r0/lib/apk/db/installed
HIGH CVE-2026-59999openssh-client-common10.3_p1-r0 10.3_p1-r1/lib/apk/db/installed
HIGH CVE-2026-59999openssh-client-default10.3_p1-r0 10.3_p1-r1/lib/apk/db/installed
HIGH CVE-2026-59999openssh-keygen10.3_p1-r0 10.3_p1-r1/lib/apk/db/installed
HIGH CVE-2026-49839jq1.8.1-r0 1.8.2-r0/lib/apk/db/installed
HIGH CVE-2026-76957libexpat2.8.3-r0 2.8.4-r0/lib/apk/db/installed
HIGH CVE-2026-80229curl8.21.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-80229libcurl8.21.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH GO-2026-5026golang.org/x/netv0.54.0 0.55.0The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com". — /usr/bin/git-lfs
HIGH GO-2026-5026stdlibgo1.26.3 1.25.13, 1.26.6, 1.27.0-rc.3The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com". — /usr/bin/git-lfs
HIGH CVE-2026-80231curl8.21.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-80255curl8.21.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-80255libcurl8.21.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH GHSA-mh99-v99m-4gvgbrace-expansion5.0.7 5.0.8brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash — /usr/local/lib/node_modules/npm/node_modules/brace-expansion/package.json
HIGH CVE-2026-13608curl8.21.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-13608libcurl8.21.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-66046libexpat2.8.3-r0 2.8.4-r0/lib/apk/db/installed
HIGH CVE-2026-32316jq1.8.1-r0 1.8.2-r0/lib/apk/db/installed
HIGH GHSA-rgw5-rvv9-x895brace-expansion5.0.7 5.0.9brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation — /usr/local/lib/node_modules/npm/node_modules/brace-expansion/package.json
HIGH GO-2026-5942golang.org/x/netv0.54.0 0.56.0Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer. — /usr/bin/git-lfs
HIGH CVE-2026-82209libcurl8.21.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-82209curl8.21.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-80230libcurl8.21.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-80230curl8.21.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH GO-2026-5972stdlibgo1.26.3 1.25.13, 1.26.6, 1.27.0-rc.3Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures. — /usr/bin/git-lfs
HIGH GO-2026-6090stdlibgo1.26.3 1.25.13, 1.26.6, 1.27.0-rc.3Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely. — /usr/bin/git-lfs
HIGH GO-2026-5037stdlibgo1.26.3 1.25.11, 1.26.4(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates. — /usr/bin/git-lfs
MEDIUM CVE-2026-73282openssh-client-common10.3_p1-r0 10.3_p1-r1/lib/apk/db/installed
MEDIUM CVE-2026-54679jq1.8.1-r0 1.8.2-r0/lib/apk/db/installed
MEDIUM CVE-2026-43895jq1.8.1-r0 1.8.2-r0/lib/apk/db/installed
MEDIUM CVE-2026-59998openssh-client-common10.3_p1-r0 10.3_p1-r1/lib/apk/db/installed
MEDIUM CVE-2026-59998openssh-client-default10.3_p1-r0 10.3_p1-r1/lib/apk/db/installed
MEDIUM CVE-2026-59998openssh-keygen10.3_p1-r0 10.3_p1-r1/lib/apk/db/installed
MEDIUM CVE-2026-39956jq1.8.1-r0 1.8.2-r0/lib/apk/db/installed
MEDIUM GHSA-v3r7-h72x-cjcmundici6.27.0 6.28.0undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields — /usr/local/lib/node_modules/npm/node_modules/undici/package.json
MEDIUM CVE-2026-59997openssh-client-common10.3_p1-r0 10.3_p1-r1/lib/apk/db/installed
MEDIUM CVE-2026-59997openssh-client-default10.3_p1-r0 10.3_p1-r1/lib/apk/db/installed
MEDIUM CVE-2026-59997openssh-keygen10.3_p1-r0 10.3_p1-r1/lib/apk/db/installed
MEDIUM GHSA-m8rv-5g2x-5cg5undici6.27.0 6.28.0undici vulnerable to CRLF Injection via blob-like body 'type' property — /usr/local/lib/node_modules/npm/node_modules/undici/package.json
MEDIUM GHSA-8xcm-r25x-g524undici6.27.0 6.28.0undici vulnerable to downstream response desynchronization via retry interceptor — /usr/local/lib/node_modules/npm/node_modules/undici/package.json
MEDIUM CVE-2026-40612jq1.8.1-r0 1.8.2-r0/lib/apk/db/installed
MEDIUM CVE-2026-44777jq1.8.1-r0 1.8.2-r0/lib/apk/db/installed
MEDIUM CVE-2026-43894jq1.8.1-r0 1.8.2-r0/lib/apk/db/installed
MEDIUM CVE-2026-41256jq1.8.1-r0 1.8.2-r0/lib/apk/db/installed
MEDIUM CVE-2026-73282openssh-client-default10.3_p1-r0 10.3_p1-r1/lib/apk/db/installed
MEDIUM CVE-2026-73282openssh-keygen10.3_p1-r0 10.3_p1-r1/lib/apk/db/installed
MEDIUM CVE-2026-43896jq1.8.1-r0 1.8.2-r0/lib/apk/db/installed
MEDIUM CVE-2026-47770jq1.8.1-r0 1.8.2-r0/lib/apk/db/installed
MEDIUM CVE-2026-41257jq1.8.1-r0 1.8.2-r0/lib/apk/db/installed
MEDIUM GHSA-rmvr-2pp2-xj38@octokit/request5.6.3 8.4.1@octokit/request has a Regular Expression in fetchWrapper that Leads to ReDoS Vulnerability Due to Catastrophic Backtracking — /npm/node_modules/@octokit/rest/node_modules/@octokit/request/package.json
MEDIUM GHSA-rmvr-2pp2-xj38@octokit/request6.2.8 8.4.1@octokit/request has a Regular Expression in fetchWrapper that Leads to ReDoS Vulnerability Due to Catastrophic Backtracking — /npm/node_modules/semantic-release-github-pullrequest/node_modules/@octokit/request/package.json
MEDIUM GHSA-xx4v-prfh-6cgc@octokit/request-error2.1.0 5.1.1@octokit/request-error has a Regular Expression in index that Leads to ReDoS Vulnerability Due to Catastrophic Backtracking — /npm/node_modules/@octokit/rest/node_modules/@octokit/request-error/package.json
MEDIUM GHSA-xx4v-prfh-6cgc@octokit/request-error3.0.3 5.1.1@octokit/request-error has a Regular Expression in index that Leads to ReDoS Vulnerability Due to Catastrophic Backtracking — /npm/node_modules/semantic-release-github-pullrequest/node_modules/@octokit/request-error/package.json
MEDIUM GHSA-h5c3-5r3r-rr8q@octokit/plugin-paginate-rest2.21.3 9.2.2@octokit/plugin-paginate-rest has a Regular Expression in iterator Leads to ReDoS Vulnerability Due to Catastrophic Backtracking — /npm/node_modules/@octokit/rest/node_modules/@octokit/plugin-paginate-rest/package.json
MEDIUM GHSA-h5c3-5r3r-rr8q@octokit/plugin-paginate-rest6.1.2 9.2.2@octokit/plugin-paginate-rest has a Regular Expression in iterator Leads to ReDoS Vulnerability Due to Catastrophic Backtracking — /npm/node_modules/semantic-release-github-pullrequest/node_modules/@octokit/plugin-paginate-rest/package.json
MEDIUM CVE-2026-39979jq1.8.1-r0 1.8.2-r0/lib/apk/db/installed
MEDIUM GO-2026-6218stdlibgo1.26.3 1.25.13, 1.26.6, 1.27.0-rc.3Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations. — /usr/bin/git-lfs
MEDIUM GHSA-4xrf-jv44-h6hhip-address10.2.0 10.2.2ip-address: a CIDR suffix on the parsed address suppresses special-use classification and can bypass SSRF and trust-boundary checks — /usr/local/lib/node_modules/npm/node_modules/ip-address/package.json
MEDIUM GHSA-22jq-vg5j-6vggip-address10.2.0 10.2.1ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSRF and trust-boundary checks — /usr/local/lib/node_modules/npm/node_modules/ip-address/package.json
MEDIUM GO-2026-5856stdlibgo1.26.3 1.25.12, 1.26.5, 1.27.0-rc.2Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello. — /usr/bin/git-lfs
MEDIUM CVE-2026-33947jq1.8.1-r0 1.8.2-r0/lib/apk/db/installed
MEDIUM CVE-2026-59995openssh-keygen10.3_p1-r0 10.3_p1-r1/lib/apk/db/installed
MEDIUM CVE-2026-59995openssh-client-default10.3_p1-r0 10.3_p1-r1/lib/apk/db/installed
MEDIUM CVE-2026-59995openssh-client-common10.3_p1-r0 10.3_p1-r1/lib/apk/db/installed
MEDIUM CVE-2026-59996openssh-keygen10.3_p1-r0 10.3_p1-r1/lib/apk/db/installed
MEDIUM CVE-2026-59996openssh-client-default10.3_p1-r0 10.3_p1-r1/lib/apk/db/installed
MEDIUM CVE-2026-59996openssh-client-common10.3_p1-r0 10.3_p1-r1/lib/apk/db/installed
MEDIUM CVE-2026-33948jq1.8.1-r0 1.8.2-r0/lib/apk/db/installed
MEDIUM CVE-2026-60001openssh-keygen10.3_p1-r0 10.3_p1-r1/lib/apk/db/installed
MEDIUM CVE-2026-60001openssh-client-default10.3_p1-r0 10.3_p1-r1/lib/apk/db/installed
MEDIUM CVE-2026-60001openssh-client-common10.3_p1-r0 10.3_p1-r1/lib/apk/db/installed
MEDIUM GO-2026-5039stdlibgo1.26.3 1.25.11, 1.26.4When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or logged. — /usr/bin/git-lfs
LOW CVE-2026-73281openssh-client-common10.3_p1-r0 10.3_p1-r1/lib/apk/db/installed
LOW CVE-2026-73281openssh-client-default10.3_p1-r0 10.3_p1-r1/lib/apk/db/installed
LOW CVE-2026-73281openssh-keygen10.3_p1-r0 10.3_p1-r1/lib/apk/db/installed
LOW CVE-2026-73283openssh-client-common10.3_p1-r0 10.3_p1-r1/lib/apk/db/installed
LOW CVE-2026-73283openssh-client-default10.3_p1-r0 10.3_p1-r1/lib/apk/db/installed
LOW CVE-2026-73283openssh-keygen10.3_p1-r0 10.3_p1-r1/lib/apk/db/installed
UNKNOWN CVE-2026-80256curl8.21.0-r0 8.22.0-r0/lib/apk/db/installed
UNKNOWN CVE-2026-80256libcurl8.21.0-r0 8.22.0-r0/lib/apk/db/installed
Filtered NVD/CPE matches (10)

These broad CPE matches are unconfirmed for the distribution package and excluded from scanner totals.

SeverityIDPackageInstalledFixedTitle / target
HIGH CVE-2026-89161pcre210.47-r1 In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context. An incorrect free operation can occur. — /lib/apk/db/installed
HIGH CVE-2026-89157pcre210.47-r1 PCRE2 before 10.48, on 32-bit platforms, has a pcre2_pattern_convert out-of-bounds write when an attacker can provide a large pattern. — /lib/apk/db/installed
MEDIUM CVE-2025-60876busybox1.37.0-r31 BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed
MEDIUM CVE-2025-60876busybox-binsh1.37.0-r31 BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed
MEDIUM CVE-2025-60876ssl_client1.37.0-r31 BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed
MEDIUM CVE-2026-58055nghttp2-libs1.69.0-r0 nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning. — /lib/apk/db/installed
MEDIUM CVE-2026-89158pcre210.47-r1 PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 integer overflow and resultant out-of-bounds write. — /lib/apk/db/installed
MEDIUM CVE-2026-89160pcre210.47-r1 PCRE2 before 10.48 has a pcre2_match out-of-bounds read during the PCRE2_MATCH_INVALID_UTF matching of an invalid UTF subject. — /lib/apk/db/installed
MEDIUM CVE-2026-89156pcre210.47-r1 PCRE2 before 10.48 has a pcre2_match out-of-bounds read after a JIT fallback when an attacker can provide invalid UTF data. — /lib/apk/db/installed
LOW CVE-2026-89162pcre210.47-r1 In PCRE2 before 10.48, pcre2_serialize_encode might disclose two bytes to an adversary, typically in a situation where the access available to the adversary is already unsafe. — /lib/apk/db/installed

ghcr.io/voxpupuli/voxbox

GitHub Container Registry

Downloads

147,514 downloads

ghcr.io/voxpupuli/voxbox:latest (2026-08-06)

Trivy

HIGH 50 MEDIUM 70 LOW 22 UNKNOWN 6
SeverityIDPackageInstalledFixedTitle / target
HIGH CVE-2026-11352curl8.20.0-r0 8.22.0-r0curl: libcurl: curl/libcurl: Remote denial of service via QUIC UDP receive function vulnerability — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
HIGH CVE-2026-32316jq1.8.1-r0 1.8.2-r0jq: jq: Denial of Service or potential arbitrary code execution due to integer overflow and heap-based buffer overflow — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
HIGH CVE-2026-40164jq1.8.1-r0 1.8.2-r0jq: jq: Denial of Service via crafted JSON object causing hash collisions — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
HIGH CVE-2026-4786python3-pyc3.12.13-r0 3.12.14-r0python: cpython: Python: Arbitrary code execution via command injection in webbrowser.open() API — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
HIGH CVE-2026-3644python3-pyc3.12.13-r0 3.12.14-r0cpython: Incomplete control character validation in http.cookies — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
HIGH CVE-2026-15308python3-pyc3.12.13-r0 3.12.14-r0python: Python: CPU Denial of Service in HTML parser via repeated unterminated markup declarations — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
HIGH CVE-2026-11940python3-pyc3.12.13-r0 3.12.14-r0python: cpython: CPython: tarfile extraction filter bypass allows escaping the destination directory — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
HIGH CVE-2026-11940pyc3.12.13-r0 3.12.14-r0python: cpython: CPython: tarfile extraction filter bypass allows escaping the destination directory — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
HIGH CVE-2026-7210python33.12.13-r0 3.12.14-r0python: expat: Python/Expat: Denial of Service via crafted XML document — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
HIGH CVE-2026-6100python33.12.13-r0 3.12.14-r0python: Python: Arbitrary code execution or information disclosure via use-after-free in decompression modules — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
HIGH CVE-2026-4786python33.12.13-r0 3.12.14-r0python: cpython: Python: Arbitrary code execution via command injection in webbrowser.open() API — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
HIGH CVE-2026-3644python33.12.13-r0 3.12.14-r0cpython: Incomplete control character validation in http.cookies — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
HIGH CVE-2026-15308python33.12.13-r0 3.12.14-r0python: Python: CPU Denial of Service in HTML parser via repeated unterminated markup declarations — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
HIGH CVE-2026-11940python33.12.13-r0 3.12.14-r0python: cpython: CPython: tarfile extraction filter bypass allows escaping the destination directory — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
HIGH CVE-2026-14456libcrypto33.5.7-r0 3.5.8-r0openssl: OpenSSL: Denial of Service via unbounded memory growth in QUIC server — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
HIGH CVE-2026-9547libcurl8.20.0-r0 8.22.0-r0curl: curl: Man-in-the-middle attack via SSH host key bypass — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
HIGH CVE-2026-8927libcurl8.20.0-r0 8.22.0-r0curl: Information disclosure due to uncleared proxy authentication state — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
HIGH CVE-2026-8925libcurl8.20.0-r0 8.22.0-r0curl: curl: Double-free vulnerability in SASL authentication — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
HIGH CVE-2026-8458libcurl8.20.0-r0 8.22.0-r0curl: libcurl: Unauthorized connection reuse due to a logical error — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
HIGH CVE-2026-7210pyc3.12.13-r0 3.12.14-r0python: expat: Python/Expat: Denial of Service via crafted XML document — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
HIGH CVE-2026-6100pyc3.12.13-r0 3.12.14-r0python: Python: Arbitrary code execution or information disclosure via use-after-free in decompression modules — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
HIGH CVE-2026-4786pyc3.12.13-r0 3.12.14-r0python: cpython: Python: Arbitrary code execution via command injection in webbrowser.open() API — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
HIGH CVE-2026-3644pyc3.12.13-r0 3.12.14-r0cpython: Incomplete control character validation in http.cookies — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
HIGH CVE-2026-15308pyc3.12.13-r0 3.12.14-r0python: Python: CPU Denial of Service in HTML parser via repeated unterminated markup declarations — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
HIGH CVE-2026-11352libcurl8.20.0-r0 8.22.0-r0curl: libcurl: curl/libcurl: Remote denial of service via QUIC UDP receive function vulnerability — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
HIGH CVE-2026-11586libcurl8.20.0-r0 8.22.0-r0curl: curl: Denial of Service via WebSocket PING flood — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
HIGH CVE-2026-12064libcurl8.20.0-r0 8.22.0-r0curl: curl: SSH host verification bypass when using schemeless URLs with SFTP/SCP — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
HIGH CVE-2026-8286libcurl8.20.0-r0 8.22.0-r0curl: curl: Insecure connection establishment due to TLS configuration mismatch — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
HIGH CVE-2026-11586curl8.20.0-r0 8.22.0-r0curl: curl: Denial of Service via WebSocket PING flood — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
HIGH CVE-2026-12064curl8.20.0-r0 8.22.0-r0curl: curl: SSH host verification bypass when using schemeless URLs with SFTP/SCP — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
HIGH CVE-2026-8286curl8.20.0-r0 8.22.0-r0curl: curl: Insecure connection establishment due to TLS configuration mismatch — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
HIGH CVE-2026-8458curl8.20.0-r0 8.22.0-r0curl: libcurl: Unauthorized connection reuse due to a logical error — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
HIGH CVE-2026-8925curl8.20.0-r0 8.22.0-r0curl: curl: Double-free vulnerability in SASL authentication — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
HIGH CVE-2026-8927curl8.20.0-r0 8.22.0-r0curl: Information disclosure due to uncleared proxy authentication state — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
HIGH CVE-2026-9547curl8.20.0-r0 8.22.0-r0curl: curl: Man-in-the-middle attack via SSH host key bypass — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
HIGH CVE-2026-80212resolv0.2.3 ~> 0.3.2, >= 0.7.2resolv: resolv gem: Denial of Service via uncontrolled memory growth from crafted DNS responses — Ruby
HIGH CVE-2026-11824sqlite-libs3.51.2-r0 3.53.4-r0sqlite: SQLite: Arbitrary code execution and crash via heap-based buffer overflow in FTS5 — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
HIGH CVE-2026-11822sqlite-libs3.51.2-r0 3.53.4-r0sqlite: SQLite: Arbitrary code execution via crafted FTS5 full-text search data — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
HIGH CVE-2026-66046libexpat2.8.2-r0 2.8.4-r0expat: Expat: Denial of Service via quadratic complexity in attribute processing — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
HIGH CVE-2026-7210python3-pycache-pyc03.12.13-r0 3.12.14-r0python: expat: Python/Expat: Denial of Service via crafted XML document — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
HIGH CVE-2026-6100python3-pyc3.12.13-r0 3.12.14-r0python: Python: Arbitrary code execution or information disclosure via use-after-free in decompression modules — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
HIGH CVE-2026-7210python3-pyc3.12.13-r0 3.12.14-r0python: expat: Python/Expat: Denial of Service via crafted XML document — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
HIGH CVE-2026-14456libssl33.5.7-r0 3.5.8-r0openssl: OpenSSL: Denial of Service via unbounded memory growth in QUIC server — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
HIGH CVE-2026-76957libexpat2.8.2-r0 2.8.4-r0libexpat: libexpat: Memory corruption vulnerability allows arbitrary code execution or denial of service — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
HIGH CVE-2026-76956libexpat2.8.2-r0 2.8.4-r0libexpat: libexpat: Denial of Service via hash flooding attack with crafted XML — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
HIGH CVE-2026-11940python3-pycache-pyc03.12.13-r0 3.12.14-r0python: cpython: CPython: tarfile extraction filter bypass allows escaping the destination directory — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
HIGH CVE-2026-15308python3-pycache-pyc03.12.13-r0 3.12.14-r0python: Python: CPU Denial of Service in HTML parser via repeated unterminated markup declarations — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
HIGH CVE-2026-3644python3-pycache-pyc03.12.13-r0 3.12.14-r0cpython: Incomplete control character validation in http.cookies — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
HIGH CVE-2026-4786python3-pycache-pyc03.12.13-r0 3.12.14-r0python: cpython: Python: Arbitrary code execution via command injection in webbrowser.open() API — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
HIGH CVE-2026-6100python3-pycache-pyc03.12.13-r0 3.12.14-r0python: Python: Arbitrary code execution or information disclosure via use-after-free in decompression modules — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
MEDIUM CVE-2026-63076libssl33.5.7-r0 3.5.8-r0openssl: invalid pointer dereference in CMP server via crafted protectionAlg — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
MEDIUM CVE-2026-63072libssl33.5.7-r0 3.5.8-r0openssl: heap buffer overflow in CMS key unwrapping — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
MEDIUM CVE-2026-18798libcrypto33.5.7-r0 3.5.8-r0openssl: QUIC server may trigger double free when processing INITIAL packet — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
MEDIUM CVE-2026-18798libssl33.5.7-r0 3.5.8-r0openssl: QUIC server may trigger double free when processing INITIAL packet — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
MEDIUM CVE-2026-9080libcurl8.20.0-r0 8.22.0-r0libcurl: libcurl: Use-after-free via curl_easy_pause() in CURLMOPT_SOCKETFUNCTION callback — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
MEDIUM CVE-2026-9545libcurl8.20.0-r0 8.22.0-r0libcurl: libcurl: Information disclosure via cached SSL session and early data — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
MEDIUM CVE-2026-9546libcurl8.20.0-r0 8.22.0-r0libcurl: libcurl: Information disclosure due to persistent Referer header — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
MEDIUM CVE-2026-76641libexpat2.8.2-r0 2.8.4-r0CVE-2026-76641 affecting package expat for versions less than 2.8.3-2 — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
MEDIUM CVE-2026-80213resolv0.2.3 ~> 0.3.2, >= 0.7.2resolv: Resolv gem: DNS allowlist and egress bypass, and cache poisoning via crafted hostnames — Ruby
MEDIUM CVE-2026-4360python3-pycache-pyc03.12.13-r0 3.12.14-r0python: Python Tarfile: Unexpected file ownership when extracting hardlinks — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
MEDIUM CVE-2026-1502python3-pycache-pyc03.12.13-r0 3.12.14-r0python: Python: HTTP header injection via CR/LF in proxy tunnel headers — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
MEDIUM CVE-2026-11972python3-pycache-pyc03.12.13-r0 3.12.14-r0python: Python tarfile module: Denial of Service via improper EOF handling in streaming mode — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
MEDIUM CVE-2026-0864python3-pycache-pyc03.12.13-r0 3.12.14-r0python: cpython: Python configparser: Configuration injection via crafted multi-line input — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
MEDIUM CVE-2026-4360python3-pyc3.12.13-r0 3.12.14-r0python: Python Tarfile: Unexpected file ownership when extracting hardlinks — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
MEDIUM CVE-2026-1502python3-pyc3.12.13-r0 3.12.14-r0python: Python: HTTP header injection via CR/LF in proxy tunnel headers — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
MEDIUM CVE-2026-11972python3-pyc3.12.13-r0 3.12.14-r0python: Python tarfile module: Denial of Service via improper EOF handling in streaming mode — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
MEDIUM CVE-2026-0864python3-pyc3.12.13-r0 3.12.14-r0python: cpython: Python configparser: Configuration injection via crafted multi-line input — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
MEDIUM CVE-2026-4360python33.12.13-r0 3.12.14-r0python: Python Tarfile: Unexpected file ownership when extracting hardlinks — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
MEDIUM CVE-2026-1502python33.12.13-r0 3.12.14-r0python: Python: HTTP header injection via CR/LF in proxy tunnel headers — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
MEDIUM CVE-2026-11972python33.12.13-r0 3.12.14-r0python: Python tarfile module: Denial of Service via improper EOF handling in streaming mode — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
MEDIUM CVE-2026-0864python33.12.13-r0 3.12.14-r0python: cpython: Python configparser: Configuration injection via crafted multi-line input — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
MEDIUM CVE-2026-4360pyc3.12.13-r0 3.12.14-r0python: Python Tarfile: Unexpected file ownership when extracting hardlinks — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
MEDIUM CVE-2026-1502pyc3.12.13-r0 3.12.14-r0python: Python: HTTP header injection via CR/LF in proxy tunnel headers — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
MEDIUM CVE-2026-11972pyc3.12.13-r0 3.12.14-r0python: Python tarfile module: Denial of Service via improper EOF handling in streaming mode — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
MEDIUM CVE-2026-0864pyc3.12.13-r0 3.12.14-r0python: cpython: Python configparser: Configuration injection via crafted multi-line input — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
MEDIUM CVE-2026-54679jq1.8.1-r0 1.8.2-r0jq: jq: Denial of Service via integer overflow and buffer overrun on 32-bit systems — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
MEDIUM CVE-2026-49839jq1.8.1-r0 1.8.2-r0jq: jq: Heap out-of-bounds write via oversized raw file processing — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
MEDIUM CVE-2026-47770jq1.8.1-r0 1.8.2-r0jq: jq: Denial of Service via deeply nested array comparison — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
MEDIUM CVE-2026-44777jq1.8.1-r0 1.8.2-r0jq: stack overflow in module loading on mutual include — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
MEDIUM CVE-2026-43896jq1.8.1-r0 1.8.2-r0jq: stack overflow in recursive object merge — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
MEDIUM CVE-2026-43895jq1.8.1-r0 1.8.2-r0jq: embedded NUL in jq import paths causes local redaction-policy bypass and preserves sensitive fields in published artifacts — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
MEDIUM CVE-2026-43894jq1.8.1-r0 1.8.2-r0jq: jq: Arbitrary Code Execution or Denial of Service via Signed Integer Overflow — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
MEDIUM CVE-2026-41257jq1.8.1-r0 1.8.2-r0jq: signed-int overflow in stack_reallocate — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
MEDIUM CVE-2026-41256jq1.8.1-r0 1.8.2-r0jq: embedded NUL truncates top-level jq programs loaded with -f — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
MEDIUM CVE-2026-40612jq1.8.1-r0 1.8.2-r0jq: stack overflow via unbounded recursion in jv_contains — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
MEDIUM CVE-2026-39979jq1.8.1-r0 1.8.2-r0jq: out-of-bounds read in jv_parse_sized() on error formatting for non-NUL-terminated buffers — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
MEDIUM CVE-2026-39956jq1.8.1-r0 1.8.2-r0jq: missing runtime type checks for _strindices lead to crash and limited memory disclosure — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
MEDIUM CVE-2026-33948jq1.8.1-r0 1.8.2-r0jq: jq: Input validation bypass via embedded NUL bytes allows parser differential attacks — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
MEDIUM CVE-2026-33947jq1.8.1-r0 1.8.2-r0jq: unbounded Recursion in jv_setpath() / jv_getpath() / delpaths_sorted() — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
MEDIUM CVE-2026-9546curl8.20.0-r0 8.22.0-r0libcurl: libcurl: Information disclosure due to persistent Referer header — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
MEDIUM CVE-2026-9545curl8.20.0-r0 8.22.0-r0libcurl: libcurl: Information disclosure via cached SSL session and early data — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
MEDIUM CVE-2026-9080curl8.20.0-r0 8.22.0-r0libcurl: libcurl: Use-after-free via curl_easy_pause() in CURLMOPT_SOCKETFUNCTION callback — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
MEDIUM CVE-2026-9079curl8.20.0-r0 8.22.0-r0libcurl: libcurl: Information disclosure due to failure to clear proxy authentication credentials — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
MEDIUM CVE-2026-8932curl8.20.0-r0 8.22.0-r0libcurl: libcurl: Security feature bypass due to improper mTLS connection reuse — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
MEDIUM CVE-2026-8926curl8.20.0-r0 8.22.0-r0curl: curl: Information disclosure via incorrect .netrc password lookup — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
MEDIUM CVE-2026-8924curl8.20.0-r0 8.22.0-r0curl: curl: Cookie injection via malicious HTTP server using super cookies — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
MEDIUM CVE-2026-82209curl8.20.0-r0 8.22.0-r0When libpsl support is enabled, libcurl fails to enforce the Public Su ... — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
MEDIUM CVE-2026-80255curl8.20.0-r0 8.22.0-r0A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instea ... — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
MEDIUM CVE-2026-80230curl8.20.0-r0 8.22.0-r0When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that di ... — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
MEDIUM CVE-2026-80229curl8.20.0-r0 8.22.0-r0When performing transfers via libcurl\u2019s multi interface, pooled T ... — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
MEDIUM CVE-2026-19931curl8.20.0-r0 8.22.0-r0curl: libcurl: Information disclosure via incorrect connection reuse with Negotiate authentication — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
MEDIUM CVE-2026-13608curl8.20.0-r0 8.22.0-r0A flaw in the libcurl SASL negotiation for LDAP authentication allows ... — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
MEDIUM CVE-2026-11856curl8.20.0-r0 8.22.0-r0curl: curl: Information disclosure via incorrect Digest authentication header reuse — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
MEDIUM CVE-2026-11564curl8.20.0-r0 8.22.0-r0libcurl: libcurl: Certificate validation bypass due to incorrect connection reuse — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
MEDIUM CVE-2026-10536curl8.20.0-r0 8.22.0-r0libcurl: libcurl: Use-after-free vulnerability leading to Denial of Service — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
MEDIUM CVE-2026-9079libcurl8.20.0-r0 8.22.0-r0libcurl: libcurl: Information disclosure due to failure to clear proxy authentication credentials — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
MEDIUM CVE-2026-8932libcurl8.20.0-r0 8.22.0-r0libcurl: libcurl: Security feature bypass due to improper mTLS connection reuse — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
MEDIUM CVE-2026-8926libcurl8.20.0-r0 8.22.0-r0curl: curl: Information disclosure via incorrect .netrc password lookup — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
MEDIUM CVE-2026-8924libcurl8.20.0-r0 8.22.0-r0curl: curl: Cookie injection via malicious HTTP server using super cookies — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
MEDIUM CVE-2026-82209libcurl8.20.0-r0 8.22.0-r0When libpsl support is enabled, libcurl fails to enforce the Public Su ... — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
MEDIUM CVE-2026-80255libcurl8.20.0-r0 8.22.0-r0A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instea ... — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
MEDIUM CVE-2026-80230libcurl8.20.0-r0 8.22.0-r0When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that di ... — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
MEDIUM CVE-2026-80229libcurl8.20.0-r0 8.22.0-r0When performing transfers via libcurl\u2019s multi interface, pooled T ... — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
MEDIUM CVE-2026-19931libcurl8.20.0-r0 8.22.0-r0curl: libcurl: Information disclosure via incorrect connection reuse with Negotiate authentication — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
MEDIUM CVE-2026-13608libcurl8.20.0-r0 8.22.0-r0A flaw in the libcurl SASL negotiation for LDAP authentication allows ... — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
MEDIUM CVE-2026-11856libcurl8.20.0-r0 8.22.0-r0curl: curl: Information disclosure via incorrect Digest authentication header reuse — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
MEDIUM CVE-2026-11564libcurl8.20.0-r0 8.22.0-r0libcurl: libcurl: Certificate validation bypass due to incorrect connection reuse — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
MEDIUM CVE-2026-63072libcrypto33.5.7-r0 3.5.8-r0openssl: heap buffer overflow in CMS key unwrapping — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
MEDIUM CVE-2026-63076libcrypto33.5.7-r0 3.5.8-r0openssl: invalid pointer dereference in CMP server via crafted protectionAlg — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
MEDIUM CVE-2026-10536libcurl8.20.0-r0 8.22.0-r0libcurl: libcurl: Use-after-free vulnerability leading to Denial of Service — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
LOW CVE-2026-2297pyc3.12.13-r0 3.12.14-r0cpython: CPython: Logging Bypass in Legacy .pyc File Handling — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
LOW CVE-2026-4519pyc3.12.13-r0 3.12.14-r0python: Python: Command-line option injection in webbrowser.open() via crafted URLs — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
LOW CVE-2026-4519python3-pycache-pyc03.12.13-r0 3.12.14-r0python: Python: Command-line option injection in webbrowser.open() via crafted URLs — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
LOW CVE-2026-2297python3-pycache-pyc03.12.13-r0 3.12.14-r0cpython: CPython: Logging Bypass in Legacy .pyc File Handling — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
LOW CVE-2026-18924libcurl8.20.0-r0 8.22.0-r0curl: libcurl: Use-after-free in HTTP/2 Server Push with shared connections — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
LOW CVE-2026-14457libcrypto33.5.7-r0 3.5.8-r0openssl: RPK server signature algorithm selection can dereference a missing certificate — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
LOW CVE-2026-54874libcrypto33.5.7-r0 3.5.8-r0openssl: excessive memory use buffering DTLS records for a future epoch — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
LOW CVE-2026-63073libcrypto33.5.7-r0 3.5.8-r0openssl: untrusted sender DN used as format string in CMP response validation — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
LOW CVE-2026-63074libcrypto33.5.7-r0 3.5.8-r0openssl: CMP indefinite cache growth of ExtraCerts — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
LOW CVE-2026-63075libcrypto33.5.7-r0 3.5.8-r0openssl: QUIC ACK-only packet retention can cause memory exhaustion — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
LOW CVE-2026-75803libcrypto33.5.7-r0 3.5.8-r0openssl: openssl: AEAD forgeries possible with empty ciphertext in EVP_Cipher() — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
LOW CVE-2026-63075libssl33.5.7-r0 3.5.8-r0openssl: QUIC ACK-only packet retention can cause memory exhaustion — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
LOW CVE-2026-2297python33.12.13-r0 3.12.14-r0cpython: CPython: Logging Bypass in Legacy .pyc File Handling — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
LOW CVE-2026-4519python33.12.13-r0 3.12.14-r0python: Python: Command-line option injection in webbrowser.open() via crafted URLs — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
LOW CVE-2026-63074libssl33.5.7-r0 3.5.8-r0openssl: CMP indefinite cache growth of ExtraCerts — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
LOW CVE-2026-63073libssl33.5.7-r0 3.5.8-r0openssl: untrusted sender DN used as format string in CMP response validation — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
LOW CVE-2026-54874libssl33.5.7-r0 3.5.8-r0openssl: excessive memory use buffering DTLS records for a future epoch — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
LOW CVE-2026-14457libssl33.5.7-r0 3.5.8-r0openssl: RPK server signature algorithm selection can dereference a missing certificate — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
LOW CVE-2026-18924curl8.20.0-r0 8.22.0-r0curl: libcurl: Use-after-free in HTTP/2 Server Push with shared connections — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
LOW CVE-2026-75803libssl33.5.7-r0 3.5.8-r0openssl: openssl: AEAD forgeries possible with empty ciphertext in EVP_Cipher() — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
LOW CVE-2026-2297python3-pyc3.12.13-r0 3.12.14-r0cpython: CPython: Logging Bypass in Legacy .pyc File Handling — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
LOW CVE-2026-4519python3-pyc3.12.13-r0 3.12.14-r0python: Python: Command-line option injection in webbrowser.open() via crafted URLs — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
UNKNOWN CVE-2026-82208libcurl8.20.0-r0 8.22.0-r0With the wolfSSL backend, when CA caching is enabled and an `CURLOPT_S ... — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
UNKNOWN CVE-2026-80256libcurl8.20.0-r0 8.22.0-r0ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
UNKNOWN CVE-2026-80231libcurl8.20.0-r0 8.22.0-r0native CA store conn reuse — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
UNKNOWN CVE-2026-82208curl8.20.0-r0 8.22.0-r0With the wolfSSL backend, when CA caching is enabled and an `CURLOPT_S ... — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
UNKNOWN CVE-2026-80256curl8.20.0-r0 8.22.0-r0ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)
UNKNOWN CVE-2026-80231curl8.20.0-r0 8.22.0-r0native CA store conn reuse — ghcr.io/voxpupuli/voxbox:latest (alpine 3.23.4)

Grype

CRITICAL 24 HIGH 83 MEDIUM 33 LOW 4 UNKNOWN 2 NVD/CPE filtered 34
SeverityIDPackageInstalledFixedTitle / target
CRITICAL CVE-2026-11564libcurl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
CRITICAL CVE-2026-11564curl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
CRITICAL CVE-2026-9079libcurl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
CRITICAL CVE-2026-9079curl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
CRITICAL CVE-2026-10536libcurl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
CRITICAL CVE-2026-10536curl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
CRITICAL CVE-2026-8927curl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
CRITICAL CVE-2026-8927libcurl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
CRITICAL CVE-2026-8924libcurl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
CRITICAL CVE-2026-8924curl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
CRITICAL CVE-2026-8925libcurl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
CRITICAL CVE-2026-8925curl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
CRITICAL CVE-2026-11856libcurl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
CRITICAL CVE-2026-11856curl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
CRITICAL CVE-2026-19931curl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
CRITICAL CVE-2026-8926curl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
CRITICAL CVE-2026-75803libcrypto33.5.7-r0 3.5.8-r0/lib/apk/db/installed
CRITICAL CVE-2026-75803libssl33.5.7-r0 3.5.8-r0/lib/apk/db/installed
CRITICAL CVE-2026-18924libcurl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
CRITICAL CVE-2026-18924curl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
CRITICAL CVE-2026-8926libcurl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
CRITICAL CVE-2026-63073libssl33.5.7-r0 3.5.8-r0/lib/apk/db/installed
CRITICAL CVE-2026-63073libcrypto33.5.7-r0 3.5.8-r0/lib/apk/db/installed
CRITICAL CVE-2026-19931libcurl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-3644python3-pycache-pyc03.12.13-r0 3.12.14-r0/lib/apk/db/installed
HIGH CVE-2026-11972pyc3.12.13-r0 3.12.14-r0/lib/apk/db/installed
HIGH CVE-2026-11972python33.12.13-r0 3.12.14-r0/lib/apk/db/installed
HIGH CVE-2026-11972python3-pyc3.12.13-r0 3.12.14-r0/lib/apk/db/installed
HIGH CVE-2026-11972python3-pycache-pyc03.12.13-r0 3.12.14-r0/lib/apk/db/installed
HIGH CVE-2026-82208curl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-82208libcurl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-76957libexpat2.8.2-r0 2.8.4-r0/lib/apk/db/installed
HIGH CVE-2026-3644python3-pyc3.12.13-r0 3.12.14-r0/lib/apk/db/installed
HIGH CVE-2026-54874libcrypto33.5.7-r0 3.5.8-r0/lib/apk/db/installed
HIGH CVE-2026-54874libssl33.5.7-r0 3.5.8-r0/lib/apk/db/installed
HIGH CVE-2026-3644python33.12.13-r0 3.12.14-r0/lib/apk/db/installed
HIGH CVE-2026-3644pyc3.12.13-r0 3.12.14-r0/lib/apk/db/installed
HIGH CVE-2026-9546curl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-9546libcurl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-63075libssl33.5.7-r0 3.5.8-r0/lib/apk/db/installed
HIGH CVE-2026-63075libcrypto33.5.7-r0 3.5.8-r0/lib/apk/db/installed
HIGH CVE-2026-49839jq1.8.1-r0 1.8.2-r0/lib/apk/db/installed
HIGH CVE-2026-11824sqlite-libs3.51.2-r0 3.53.4-r0/lib/apk/db/installed
HIGH CVE-2026-11822sqlite-libs3.51.2-r0 3.53.4-r0/lib/apk/db/installed
HIGH CVE-2026-9545libcurl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-9545curl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-4786python3-pycache-pyc03.12.13-r0 3.12.14-r0/lib/apk/db/installed
HIGH CVE-2026-4786python3-pyc3.12.13-r0 3.12.14-r0/lib/apk/db/installed
HIGH CVE-2026-4786python33.12.13-r0 3.12.14-r0/lib/apk/db/installed
HIGH CVE-2026-4786pyc3.12.13-r0 3.12.14-r0/lib/apk/db/installed
HIGH CVE-2026-76956libexpat2.8.2-r0 2.8.4-r0/lib/apk/db/installed
HIGH CVE-2026-9080libcurl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-9080curl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-8286libcurl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-8286curl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-9547libcurl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-9547curl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-40164jq1.8.1-r0 1.8.2-r0/lib/apk/db/installed
HIGH CVE-2026-76641libexpat2.8.2-r0 2.8.4-r0/lib/apk/db/installed
HIGH CVE-2026-8932libcurl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-8932curl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-12064libcurl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-12064curl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-82209libcurl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-7210python33.12.13-r0 3.12.14-r0/lib/apk/db/installed
HIGH CVE-2026-7210pyc3.12.13-r0 3.12.14-r0/lib/apk/db/installed
HIGH CVE-2026-63072libssl33.5.7-r0 3.5.8-r0/lib/apk/db/installed
HIGH CVE-2026-63072libcrypto33.5.7-r0 3.5.8-r0/lib/apk/db/installed
HIGH CVE-2026-80255libcurl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-80255curl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-11352libcurl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-11352curl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-14456libssl33.5.7-r0 3.5.8-r0/lib/apk/db/installed
HIGH CVE-2026-14456libcrypto33.5.7-r0 3.5.8-r0/lib/apk/db/installed
HIGH CVE-2026-11940python3-pycache-pyc03.12.13-r0 3.12.14-r0/lib/apk/db/installed
HIGH CVE-2026-11940python3-pyc3.12.13-r0 3.12.14-r0/lib/apk/db/installed
HIGH CVE-2026-11940python33.12.13-r0 3.12.14-r0/lib/apk/db/installed
HIGH CVE-2026-11940pyc3.12.13-r0 3.12.14-r0/lib/apk/db/installed
HIGH CVE-2026-80229libcurl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-80229curl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-80231libcurl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-80231curl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-14457libssl33.5.7-r0 3.5.8-r0/lib/apk/db/installed
HIGH CVE-2026-14457libcrypto33.5.7-r0 3.5.8-r0/lib/apk/db/installed
HIGH CVE-2026-63076libssl33.5.7-r0 3.5.8-r0/lib/apk/db/installed
HIGH CVE-2026-63076libcrypto33.5.7-r0 3.5.8-r0/lib/apk/db/installed
HIGH CVE-2026-18798libssl33.5.7-r0 3.5.8-r0/lib/apk/db/installed
HIGH CVE-2026-18798libcrypto33.5.7-r0 3.5.8-r0/lib/apk/db/installed
HIGH CVE-2026-82209curl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-80230libcurl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-80230curl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-6100python3-pycache-pyc03.12.13-r0 3.12.14-r0/lib/apk/db/installed
HIGH CVE-2026-6100python3-pyc3.12.13-r0 3.12.14-r0/lib/apk/db/installed
HIGH CVE-2026-6100python33.12.13-r0 3.12.14-r0/lib/apk/db/installed
HIGH CVE-2026-6100pyc3.12.13-r0 3.12.14-r0/lib/apk/db/installed
HIGH CVE-2026-11586libcurl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-11586curl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-32316jq1.8.1-r0 1.8.2-r0/lib/apk/db/installed
HIGH CVE-2026-66046libexpat2.8.2-r0 2.8.4-r0/lib/apk/db/installed
HIGH CVE-2026-15308python3-pycache-pyc03.12.13-r0 3.12.14-r0/lib/apk/db/installed
HIGH CVE-2026-15308python3-pyc3.12.13-r0 3.12.14-r0/lib/apk/db/installed
HIGH CVE-2026-15308python33.12.13-r0 3.12.14-r0/lib/apk/db/installed
HIGH CVE-2026-15308pyc3.12.13-r0 3.12.14-r0/lib/apk/db/installed
HIGH CVE-2026-13608libcurl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-13608curl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
HIGH CVE-2026-7210python3-pycache-pyc03.12.13-r0 3.12.14-r0/lib/apk/db/installed
HIGH CVE-2026-7210python3-pyc3.12.13-r0 3.12.14-r0/lib/apk/db/installed
MEDIUM CVE-2026-2297python3-pycache-pyc03.12.13-r0 3.12.14-r0/lib/apk/db/installed
MEDIUM CVE-2026-1502python3-pycache-pyc03.12.13-r0 3.12.14-r0/lib/apk/db/installed
MEDIUM CVE-2026-39956jq1.8.1-r0 1.8.2-r0/lib/apk/db/installed
MEDIUM CVE-2026-40612jq1.8.1-r0 1.8.2-r0/lib/apk/db/installed
MEDIUM CVE-2026-44777jq1.8.1-r0 1.8.2-r0/lib/apk/db/installed
MEDIUM CVE-2026-43894jq1.8.1-r0 1.8.2-r0/lib/apk/db/installed
MEDIUM CVE-2026-41256jq1.8.1-r0 1.8.2-r0/lib/apk/db/installed
MEDIUM CVE-2026-43896jq1.8.1-r0 1.8.2-r0/lib/apk/db/installed
MEDIUM CVE-2026-47770jq1.8.1-r0 1.8.2-r0/lib/apk/db/installed
MEDIUM CVE-2026-41257jq1.8.1-r0 1.8.2-r0/lib/apk/db/installed
MEDIUM CVE-2026-43895jq1.8.1-r0 1.8.2-r0/lib/apk/db/installed
MEDIUM CVE-2026-0864pyc3.12.13-r0 3.12.14-r0/lib/apk/db/installed
MEDIUM CVE-2026-0864python33.12.13-r0 3.12.14-r0/lib/apk/db/installed
MEDIUM CVE-2026-0864python3-pyc3.12.13-r0 3.12.14-r0/lib/apk/db/installed
MEDIUM CVE-2026-0864python3-pycache-pyc03.12.13-r0 3.12.14-r0/lib/apk/db/installed
MEDIUM CVE-2026-54679jq1.8.1-r0 1.8.2-r0/lib/apk/db/installed
MEDIUM CVE-2026-8458curl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
MEDIUM CVE-2026-8458libcurl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
MEDIUM CVE-2026-39979jq1.8.1-r0 1.8.2-r0/lib/apk/db/installed
MEDIUM CVE-2026-63074libssl33.5.7-r0 3.5.8-r0/lib/apk/db/installed
MEDIUM CVE-2026-63074libcrypto33.5.7-r0 3.5.8-r0/lib/apk/db/installed
MEDIUM CVE-2026-1502pyc3.12.13-r0 3.12.14-r0/lib/apk/db/installed
MEDIUM CVE-2026-4360pyc3.12.13-r0 3.12.14-r0/lib/apk/db/installed
MEDIUM CVE-2026-4360python33.12.13-r0 3.12.14-r0/lib/apk/db/installed
MEDIUM CVE-2026-4360python3-pyc3.12.13-r0 3.12.14-r0/lib/apk/db/installed
MEDIUM CVE-2026-4360python3-pycache-pyc03.12.13-r0 3.12.14-r0/lib/apk/db/installed
MEDIUM CVE-2026-1502python33.12.13-r0 3.12.14-r0/lib/apk/db/installed
MEDIUM CVE-2026-1502python3-pyc3.12.13-r0 3.12.14-r0/lib/apk/db/installed
MEDIUM CVE-2026-33948jq1.8.1-r0 1.8.2-r0/lib/apk/db/installed
MEDIUM CVE-2026-33947jq1.8.1-r0 1.8.2-r0/lib/apk/db/installed
MEDIUM CVE-2026-2297pyc3.12.13-r0 3.12.14-r0/lib/apk/db/installed
MEDIUM CVE-2026-2297python33.12.13-r0 3.12.14-r0/lib/apk/db/installed
MEDIUM CVE-2026-2297python3-pyc3.12.13-r0 3.12.14-r0/lib/apk/db/installed
LOW CVE-2026-4519python3-pycache-pyc03.12.13-r0 3.12.14-r0/lib/apk/db/installed
LOW CVE-2026-4519python3-pyc3.12.13-r0 3.12.14-r0/lib/apk/db/installed
LOW CVE-2026-4519python33.12.13-r0 3.12.14-r0/lib/apk/db/installed
LOW CVE-2026-4519pyc3.12.13-r0 3.12.14-r0/lib/apk/db/installed
UNKNOWN CVE-2026-80256curl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
UNKNOWN CVE-2026-80256libcurl8.20.0-r0 8.22.0-r0/lib/apk/db/installed
Filtered NVD/CPE matches (34)

These broad CPE matches are unconfirmed for the distribution package and excluded from scanner totals.

SeverityIDPackageInstalledFixedTitle / target
HIGH CVE-2026-9669python33.12.13-r0 bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted input could cause the decompressor to resume from an invalid internal state and perform out-of-bounds writes to a stack buffer. This could crash the process when processing untrusted data. — /lib/apk/db/installed
HIGH CVE-2026-4224python33.12.13-r0 When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply nested content model a C stack overflow occurs. — /lib/apk/db/installed
HIGH CVE-2026-89157pcre210.47-r0 PCRE2 before 10.48, on 32-bit platforms, has a pcre2_pattern_convert out-of-bounds write when an attacker can provide a large pattern. — /lib/apk/db/installed
HIGH CVE-2026-89161pcre210.47-r0 In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context. An incorrect free operation can occur. — /lib/apk/db/installed
MEDIUM CVE-2026-89156pcre210.47-r0 PCRE2 before 10.48 has a pcre2_match out-of-bounds read after a JIT fallback when an attacker can provide invalid UTF data. — /lib/apk/db/installed
MEDIUM CVE-2026-12003python33.12.13-r0 To allow builds of Python to be run from an in-tree layout (rather than an installed file layout), the VPATH variable is defined at build time and used to locate certain landmarks - specifically, Modules/setup.local. When this landmark is found relative to VPATH relative to the executable, Python assumes it is running in a source tree and generates a different default sys.path. This code remains in release builds, so that release-ready builds can be built in-tree. On Windows, since builds are written to 'PCbuild/', the value of VPATH is set to '..\..', which results in a landmark of '..\..\Modules\setup.local'. This path is outside the install directory of Python, and may have different permissions, potentially allowing a low-privilege user to create the landmark and an alternative `Lib` folder that will be discovered by an otherwise restricted install. Such a setup occurs with the legacy default install location for all users (in the now superseded EXE installer), due to how Windows allows all users to create folders in the root directory of their OS drive. Our recommended mitigation on Windows is to migrate away from the legacy installer and use the new [Python install manager](https://www.python.org/downloads/latest/pymanager/) to install for the current user. Installs where the directory two levels above the Python installation directory have equivalent permissions are unaffected (in general, a per-user install cannot be modified at all by other users, removing any escalation of privilege risk, and could be directly modified by a privileged user, making the potential tampering irrelevant). Alternative mitigations might include preemptively creating and restricting access to a `Modules` directory. Be aware that only 3.13 and 3.14 will receive updated legacy installers - earlier fixes are only provided as sources. Platforms other than Windows allow VPATH to be overridden, but as they don't usually use a separated directory in the build for binaries, are unlikely to have a landmark reference outside of the install directory. The landmark detection involving VPATH is a fallback for when a more specific landmark - .\pybuilddir.txt - is absent, and was included for compatibility. Future releases of Python will no longer include the fallback, and so builds will need to generate or preserve the pybuilddir.txt file in order to work in-tree. This landmark file has been generated on Windows since 3.11, and on other platforms for longer. — /lib/apk/db/installed
MEDIUM CVE-2026-3446python33.12.13-r0 When calling base64.b64decode() or related functions the decoding process would stop after encountering the first padded quad regardless of whether there was more information to be processed. This can lead to data being accepted which may be processed differently by other implementations. Use "validate=True" to enable stricter processing of base64 data. — /lib/apk/db/installed
MEDIUM CVE-2026-6019python33.12.13-r0 http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value. — /lib/apk/db/installed
MEDIUM CVE-2026-89160pcre210.47-r0 PCRE2 before 10.48 has a pcre2_match out-of-bounds read during the PCRE2_MATCH_INVALID_UTF matching of an invalid UTF subject. — /lib/apk/db/installed
MEDIUM CVE-2026-89158pcre210.47-r0 PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 integer overflow and resultant out-of-bounds write. — /lib/apk/db/installed
MEDIUM CVE-2026-58055nghttp2-libs1.69.0-r0 nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning. — /lib/apk/db/installed
MEDIUM CVE-2025-60876ssl_client1.37.0-r30 BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed
MEDIUM CVE-2025-60876busybox-binsh1.37.0-r30 BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed
MEDIUM CVE-2025-60876busybox1.37.0-r30 BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20). — /lib/apk/db/installed
MEDIUM CVE-2025-15367python33.12.13-r0 The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters. — /lib/apk/db/installed
MEDIUM CVE-2025-15366python33.12.13-r0 The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters. — /lib/apk/db/installed
MEDIUM CVE-2026-15806python33.12.13-r0 The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the same host over http://, so an attacker able to redirect or downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect or an on-path position) could capture credentials in cleartext. Credentials added for http:// URLs could likewise be sent over https://. Credential matching is now scoped by URL scheme. Credentials registered with a URL that includes a scheme are only used for requests with the same scheme. Credentials registered with a bare authority (such as example.com or example.com:8080) continue to match any scheme, preserving compatibility with existing code, including proxy authentication. Users who cannot upgrade immediately can mitigate by ensuring that applications never make plain http:// requests to hosts for which credentials are registered, for example by not following redirects to http:// URLs. — /lib/apk/db/installed
MEDIUM CVE-2026-87910python33.12.13-r0 When tarfile extracts a link on a system that doesn't support links, it falls back to extracting a member from the archive. In this case, the filter function is run twice: once for the extracted member, and once with name set to the location of the link. For one of the calls, the return value was ignored. Instead, the member should be skipped if either call returns None. — /lib/apk/db/installed
MEDIUM CVE-2026-19672python33.12.13-r0 The tarfile module's tar and data extraction filters created directories outside the destination for members whose name leaves the destination and returns to it, such as ../evil/../dest/sub/file. The containment check used the resolved path, but intermediate directories were created from the name as given. Only empty directories are created outside the destination. Member contents are still extracted inside it. To return to the destination the member's name must contain the destination directory's own final component, so extraction into a secure randomised directory is not affected. This affects POSIX platforms only. On Windows, .. components are collapsed before the path reaches the filesystem, so the directories outside the destination are never created. — /lib/apk/db/installed
MEDIUM CVE-2026-8328python33.12.13-r0 The ftpcp() function in Lib/ftplib.py was not updated when CVE-2021-4189 was fixed. While makepasv() was patched to replace server-supplied PASV host addresses with the actual peer address (getpeername()[0]), ftpcp() still calls parse227() directly and passes the raw attacker-controllable IP address and port to target.sendport(). This patch is related to CVE-2021-4189. — /lib/apk/db/installed
MEDIUM CVE-2026-7774python33.12.13-r0 tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive members outside the intended extraction directory. This allowed a malicious tar archive to cause tarfile.extractall() to write files outside the destination directory, subject to the permissions of the extracting process. — /lib/apk/db/installed
MEDIUM CVE-2026-17084python33.12.13-r0 The "stringprep" module didn't process characters from RFC 3454 tables B.2 or B.3 correctly: the latest Unicode codepoint attributes were used instead of the specified Unicode 3.2.0. This behavior would cause mismatches when processing domain names using IDNA 2003 (the "idna" codec) and the in_table_b2() function of the "stringprep" module. This only affects domain names containing characters that were not previously registered or had their Unicode attributes such as case-folding behavior updated since Unicode 3.2.0. — /lib/apk/db/installed
MEDIUM CVE-2025-12781python33.12.13-r0 When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the "base64" module the characters "+/" will always be accepted, regardless of the value of "altchars" parameter, typically used to establish an "alternative base64 alphabet" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues. This behavior can only be insecure if your application uses an alternate base64 alphabet (without "+/"). If your application does not use the "altchars" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet. The attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64 alphabet they are expecting or verify that their application would not be affected if the b64decode() functions accepted "+" or "/" outside of altchars. — /lib/apk/db/installed
MEDIUM CVE-2026-3276python33.12.13-r0 unicodedata.normalize() can take excessive CPU time when processing specially crafted Unicode input containing long runs of combining characters with alternating Canonical Combining Class values. This affects all normalization forms. — /lib/apk/db/installed
LOW CVE-2026-89162pcre210.47-r0 In PCRE2 before 10.48, pcre2_serialize_encode might disclose two bytes to an adversary, typically in a situation where the access available to the adversary is already unsafe. — /lib/apk/db/installed
LOW CVE-2026-18503python33.12.13-r0 Attacker-controlled CSV samples can trigger super-linear regular-expression work during dialect sniffing and consume significant CPU when applications pass unbounded input to csv.Sniffer.sniff(). — /lib/apk/db/installed
LOW CVE-2025-13462python33.12.13-r0 The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_LONGNAME or GNUTYPE_LONGLINK. This could result in a crafted tar archive being misinterpreted by the tarfile module compared to other implementations. — /lib/apk/db/installed
LOW CVE-2026-15310python33.12.13-r0 When decompressing crafted zip files using the bzip/LZMA/Zstandard compressions, Python could use an attacker-controlled size to pre-allocate memory, possibly resulting in memory exhaustion. — /lib/apk/db/installed
LOW CVE-2026-6879python33.12.13-r0 `Element.findall()` and fully-consumed `Element.iterfind()` exhibit `O(n^2)` time complexity when using XPath index predicates (e.g. `[1]`, `[last()]`, `[last()-N]`) on XML documents with many same-tag siblings. `Element.find()` is only affected when the first match is near the end  of the sibling list, such as with `[last()]` or `[last()-N]`;  `.//item[1]` short-circuits after the first match. — /lib/apk/db/installed
LOW CVE-2022-3219gpg2.4.9-r0 GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB. — /lib/apk/db/installed
LOW CVE-2022-3219gnupg-keyboxd2.4.9-r0 GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB. — /lib/apk/db/installed
LOW CVE-2022-3219gnupg-gpgconf2.4.9-r0 GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB. — /lib/apk/db/installed
LOW CVE-2022-3219gnupg-dirmngr2.4.9-r0 GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB. — /lib/apk/db/installed
UNKNOWN CVE-2026-3479python33.12.13-r0 DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point. There is no vulnerability in the function if following the intended security model. pkgutil.get_data() did not validate the resource argument as documented, allowing path traversals. — /lib/apk/db/installed