CVE-2026-42533 NGINX Map directive and Regex matching vulnerability
Information published.
Categories: Microsoft
CVE-2026-39879 SQL injection in syslog-ng SQL destionation driver
Information published.
Categories: Microsoft
CVE-2026-64191 i2c: stub: Reject I2C block transfers with invalid length
Information published.
Categories: Microsoft
CVE-2026-64188 net: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink()
Information published.
Categories: Microsoft
CVE-2026-64189 netfilter: ipset: fix race between dump and ip_set_list resize
Information published.
Categories: Microsoft
CVE-2026-64206 Bluetooth: L2CAP: cancel pending_rx_work before taking conn->lock
Information published.
Categories: Microsoft
CVE-2026-64190 net: team: fix NULL pointer dereference in team_xmit during mode change
Information published.
Categories: Microsoft
CVE-2026-64205 i2c: i801: fix hardware state machine corruption in error path
Information published.
Categories: Microsoft
CVE-2026-64192 bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized
Information published.
Categories: Microsoft
CVE-2026-64187 xfs: fail recovery on a committed log item with no regions
Information published.
Categories: Microsoft
CVE-2026-26199 Buffer underflow in `H5Iget_name `/`H5G_get_name` if size is zero
Information published.
Categories: Microsoft
CVE-2026-26197 Array full size, element count, and element size are not checked to make sure they match in H5Odtype.c
Information published.
Categories: Microsoft
CVE-2026-3842 Qemu-kvm: hyperv/syndbg: missing mapped-length guard after cpu_physical_memory_map causes host oob write
Information published.
Categories: Microsoft
CVE-2026-38755 A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.
Information published.
Categories: Microsoft
CVE-2026-38754 A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.
Information published.
Categories: Microsoft
CVE-2026-42770 FFC-DH Peer Validation Uses Attacker-Supplied q
Information published.
Categories: Microsoft
CVE-2026-38752 A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.
Information published.
Categories: Microsoft
CVE-2026-38753 A use-after-free in the awk_sub() function (editors/awk.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.
Information published.
Categories: Microsoft
CVE-2026-64082 riscv: Fix register corruption from uninitialized cregs on error
Information published.
Categories: Microsoft


