Month: February 2026
CVE-2025-38170 arm64/fpsimd: Discard stale CPU state when handling SME traps
CVE-2022-45639 OS Command injection vulnerability in sleuthkit fls tool 4.11.1 allows attackers to execute arbitrary commands via a crafted value to the m parameter. NOTE: third parties have disputed this because there is no analysis showing that the backtick command executes outside the context of the user account that entered the command line.
CVE-2024-2466 TLS certificate check bypass with mbedTLS
Information published. Continue reading CVE-2024-2466 TLS certificate check bypass with mbedTLS
CVE-2025-38692 exfat: add cluster chain loop check for dir
Information published. Continue reading CVE-2025-38692 exfat: add cluster chain loop check for dir
CVE-2024-53203 usb: typec: fix potential array underflow in ucsi_ccg_sync_control()
CVE-2025-38045 wifi: iwlwifi: fix debug actions order
Information published. Continue reading CVE-2025-38045 wifi: iwlwifi: fix debug actions order
