Month: February 2026
CVE-2025-21776 USB: hub: Ignore non-compliant devices with too many configs or interfaces
CVE-2024-20505 ClamAV Memory Handling DoS
Information published. Continue reading CVE-2024-20505 ClamAV Memory Handling DoS
CVE-2021-20197 There is an open race window when writing output in the following utilities in GNU binutils version 2.35 and earlier:ar objcopy strip ranlib. When these utilities are run as a privileged user (presumably as part of a script updating binaries across different users) an unprivileged user can trick these utilities into getting ownership of arbitrary files through a symlink.
CVE-2022-43551 A vulnerability exists in curl <7.87.0 HSTS check that could be bypassed to trick it to keep using HTTP. Using its HSTS support curl can be instructed to use HTTPS instead of using an insecure clear-text HTTP step even when HTTP is provided in the URL. However the HSTS mechanism could be bypassed if the host name in the given URL first uses IDN characters that get replaced to ASCII counterparts as part of the IDN conversion. Like using the character UTF-8 U+3002 (IDEOGRAPHIC FULL STOP) instead of the common ASCII full stop (U+002E) `.`. Then in a subsequent request it does not detect the HSTS state and makes a clear text transfer. Because it would store the info IDN encoded but look for it IDN decoded.
CVE-2025-24294
Information published. Continue reading CVE-2025-24294
CVE-2024-47726 f2fs: fix to wait dio completion
Information published. Continue reading CVE-2024-47726 f2fs: fix to wait dio completion
