Month: February 2026
CVE-2024-42286 scsi: qla2xxx: validate nvme_local_port correctly
Information published. Continue reading CVE-2024-42286 scsi: qla2xxx: validate nvme_local_port correctly
CVE-2025-37905 firmware: arm_scmi: Balance device refcount when destroying devices
CVE-2022-23772 Rat.SetString in math/big in Go before 1.16.14 and 1.17.x before 1.17.7 has an overflow that can lead to Uncontrolled Memory Consumption.
CVE-2023-26159 Versions of the package follow-redirects before 1.15.4 are vulnerable to Improper Input Validation due to the improper handling of URLs by the url.parse() function. When new URL() throws an error it can be manipulated to misinterpret the hostname. An attacker could exploit this weakness to redirect traffic to a malicious site potentially leading to information disclosure phishing attacks or other security breaches.
CVE-2024-47692 nfsd: return -EINVAL when namelen is 0
Information published. Continue reading CVE-2024-47692 nfsd: return -EINVAL when namelen is 0
CVE-2021-32923 HashiCorp Vault and Vault Enterprise allowed the renewal of nearly-expired token leases and dynamic secret leases (specifically those within 1 second of their maximum TTL) which caused them to be incorrectly treated as non-expiring during subsequent use. Fixed in 1.5.9 1.6.5 and 1.7.2.
CVE-2025-38167 fs/ntfs3: handle hdr_first_de() return value
Information published. Continue reading CVE-2025-38167 fs/ntfs3: handle hdr_first_de() return value
