|
1321
|
5.5 |
MEDIUM
Local
|
gkostka
|
lwext4
|
A divide-by-zero vulnerability in the ext4_block_set_lb_size function in src/ext4_blockdev.c of the lwext4 1.0.0 library allows attackers to cause a denial of service by providing a malformed ext4 fi…
|
CWE-369
Divide By Zero
|
CVE-2025-70100
|
2026-06-6 06:09 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1322
|
9.8 |
CRITICAL
Network
|
freedesktop
|
libinput
|
In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitrary root code execution
|
CWE-93
CRLF Injection
|
CVE-2026-50292
|
2026-06-6 06:06 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1323
|
9.1 |
CRITICAL
Network
|
netty
|
netty-incubator-codec-ohttp
|
The netty incubator codec.bhttp is a java language binary http parser. The library implements Oblivious HTTP (RFC 9458) using BoringSSL's HPKE C library via JNI. When deriving native memory addresses…
|
CWE-125 CWE-787
Out-of-bounds Read Out-of-bounds Write
|
CVE-2026-48040
|
2026-06-6 06:04 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1324
|
5.3 |
MEDIUM
Network
|
netty
|
netty-incubator-codec-ohttp
|
The netty incubator codec.bhttp is a java language binary http parser. Prior to version 0.0.21.Final, HKDF_expand returns non-NULL on failure. The byte[] is filled with zeros and has no way to distin…
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2026-41207
|
2026-06-6 06:01 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1325
|
- |
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
PCI: endpoint: Add missing NULL check for alloc_workqueue()
alloc_workqueue() can return NULL on memory allocation failure. Witho…
|
-
|
CVE-2025-71313
|
2026-06-6 05:51 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1326
|
- |
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
octeontx2-af: Fix PF driver crash with kexec kernel booting
During a kexec reboot the hardware is not power-cycled, so AF state f…
|
-
|
CVE-2026-46249
|
2026-06-6 05:51 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1327
|
- |
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
drm/panthor: Recover from panthor_gpu_flush_caches() failures
We have seen a few cases where the whole memory subsystem is blocke…
|
-
|
CVE-2025-71314
|
2026-06-6 05:51 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1328
|
- |
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: Fix dc_link NULL handling in HPD init
amdgpu_dm_hpd_init() may see connectors without a valid dc_link.
The code…
|
-
|
CVE-2026-46245
|
2026-06-6 05:51 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1329
|
- |
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
power: supply: pm8916_lbc: Fix use-after-free for extcon in IRQ handler
Using the `devm_` variant for requesting IRQ _before_ the…
|
-
|
CVE-2026-46246
|
2026-06-6 05:51 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1330
|
- |
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
gpio: cdev: Avoid NULL dereference in linehandle_create()
In linehandle_create(), there is a statement like this:
retain_and_nu…
|
-
|
CVE-2026-46258
|
2026-06-6 05:51 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|