Month: February 2026
CVE-2023-27535 An authentication bypass vulnerability exists in libcurl <8.0.0 in the FTP connection reuse feature that can result in wrong credentials being used during subsequent transfers. Previously created connections are kept in a connection pool for reuse if they match the current setup. However certain FTP settings such as CURLOPT_FTP_ACCOUNT CURLOPT_FTP_ALTERNATIVE_TO_USER CURLOPT_FTP_SSL_CCC and CURLOPT_USE_SSL were not included in the configuration match checks causing them to match too easily. This could lead to libcurl using the wrong credentials when performing a transfer potentially allowing unauthorized access to sensitive information.
CVE-2024-58076 clk: qcom: gcc-sm6350: Add missing parent_map for two clocks
Information published. Continue reading CVE-2024-58076 clk: qcom: gcc-sm6350: Add missing parent_map for two clocks
CVE-2025-23048 Apache HTTP Server: mod_ssl access control bypass with session resumption
CVE-2025-38088 powerpc/powernv/memtrace: Fix out of bounds issue in memtrace mmap
CVE-2025-27220 In the CGI gem before 0.4.2 for Ruby, a Regular Expression Denial of Service (ReDoS) vulnerability exists in the Util#escapeElement method.
CVE-2024-56763 tracing: Prevent bad count for tracing_cpumask_write
Information published. Continue reading CVE-2024-56763 tracing: Prevent bad count for tracing_cpumask_write
CVE-2024-43890 tracing: Fix overflow in get_free_elt()
Information published. Continue reading CVE-2024-43890 tracing: Fix overflow in get_free_elt()
