Month: February 2026
CVE-2023-52435 net: prevent mss overflow in skb_segment()
Information published. Continue reading CVE-2023-52435 net: prevent mss overflow in skb_segment()
CVE-2025-21722 nilfs2: do not force clear folio if buffer is referenced
Information published. Continue reading CVE-2025-21722 nilfs2: do not force clear folio if buffer is referenced
CVE-2019-10638 In the Linux kernel before 5.1.7 a device can be tracked by an attacker using the IP ID values the kernel produces for connection-less protocols (e.g. UDP and ICMP). When such traffic is sent to multiple destination IP addresses it is possible to obtain hash collisions (of indices to the counter array) and thereby obtain the hashing key (via enumeration). An attack may be conducted by hosting a crafted web page that uses WebRTC or gQUIC to force UDP traffic to attacker-controlled IP addresses.
CVE-2024-44946 kcm: Serialise kcm_sendmsg() for the same socket.
Information published. Continue reading CVE-2024-44946 kcm: Serialise kcm_sendmsg() for the same socket.
CVE-2025-5318 Libssh: out-of-bounds read in sftp_handle()
Information published. Continue reading CVE-2025-5318 Libssh: out-of-bounds read in sftp_handle()
CVE-2024-40979 wifi: ath12k: fix kernel crash during resume
Information published. Continue reading CVE-2024-40979 wifi: ath12k: fix kernel crash during resume
CVE-2023-52434 smb: client: fix potential OOBs in smb2_parse_contexts()
Information published. Continue reading CVE-2023-52434 smb: client: fix potential OOBs in smb2_parse_contexts()
