|
541
|
9.8 |
CRITICAL
Network
|
rust-openssl_project
|
rust-openssl
|
rust-openssl provides OpenSSL bindings for the Rust programming language. From to before 0.10.78, aes::unwrap_key() contains an incorrect assertion: it checks that out.len() + 8 <= in_.len(), but t…
Update
|
CWE-787
Out-of-bounds Write
|
CVE-2026-41678
|
2026-04-29 02:41 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
542
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
ipv4: nexthop: allocate skb dynamically in rtm_get_nexthop()
When querying a nexthop object via RTM_GETNEXTHOP, the kernel curren…
Update
|
NVD-CWE-noinfo
|
CVE-2026-31531
|
2026-04-29 02:38 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
543
|
9.1 |
CRITICAL
Network
|
rust-openssl_project
|
rust-openssl
|
rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.0 to before 0.10.78, the *_from_pem_callback APIs did not validate the length returned by the user's callback. A pa…
Update
|
CWE-125 CWE-1284
Out-of-bounds Read Improper Validation of Specified Quantity in Input
|
CVE-2026-41677
|
2026-04-29 02:34 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
544
|
9.8 |
CRITICAL
Network
|
rust-openssl_project
|
rust-openssl
|
rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.27 to before 0.10.78, Deriver::derive (and PkeyCtxRef::derive) sets len = buf.len() and passes it as the in/out len…
Update
|
CWE-131 CWE-787
Incorrect Calculation of Buffer Size Out-of-bounds Write
|
CVE-2026-41676
|
2026-04-29 02:30 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
545
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: renesas_usb3: validate endpoint index in standard request handlers
The GET_STATUS and SET/CLEAR_FEATURE handlers ext…
Update
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-31615
|
2026-04-29 02:29 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
546
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: f_ncm: validate minimum block_len in ncm_unwrap_ntb()
The block_len read from the host-supplied NTB header is checke…
Update
|
NVD-CWE-noinfo
|
CVE-2026-31617
|
2026-04-29 02:27 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
547
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
esp: fix skb leak with espintcp and async crypto
When the TX queue for espintcp is full, esp_output_tail_tcp will
return an error…
Update
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2026-31518
|
2026-04-29 02:25 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
548
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: f_phonet: fix skb frags[] overflow in pn_rx_complete()
A broken/bored/mean USB host can overflow the skb_shared_info…
Update
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2026-31616
|
2026-04-29 02:21 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
549
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
xfrm: iptfs: fix skb_put() panic on non-linear skb during reassembly
In iptfs_reassem_cont(), IP-TFS attempts to append data to t…
Update
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2026-31517
|
2026-04-29 01:35 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
550
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
xfrm: prevent policy_hthresh.work from racing with netns teardown
A XFRM_MSG_NEWSPDINFO request can queue the per-net work item
p…
Update
|
CWE-362
Race Condition
|
CVE-2026-31516
|
2026-04-29 01:30 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|