Month: February 2026
CVE-2026-28364 In OCaml before 4.14.3 and 5.x before 5.4.1, a buffer over-read in Marshal deserialization (runtime/intern.c) enables remote code execution through a multi-phase attack chain. The vulnerability stems from missing bounds validation in the readblock() function, which performs unbounded memcpy() operations using attacker-controlled lengths from crafted Marshal data.
CVE-2025-40082 hfsplus: fix slab-out-of-bounds read in hfsplus_uni2asc()
Information published. Continue reading CVE-2025-40082 hfsplus: fix slab-out-of-bounds read in hfsplus_uni2asc()
CVE-2026-22999 net/sched: sch_qfq: do not free existing class in qfq_change_class()
CVE-2026-22998 nvme-tcp: fix NULL pointer dereferences in nvmet_tcp_build_pdu_iovec
CVE-2026-22997 net: can: j1939: j1939_xtp_rx_rts_session_active(): deactivate session upon receiving the second rts
CVE-2026-22996 net/mlx5e: Don’t store mlx5e_priv in mlx5e_dev devlink priv
Information published. Continue reading CVE-2026-22996 net/mlx5e: Don’t store mlx5e_priv in mlx5e_dev devlink priv
